Hierarchical authentication system and method

By integrating the account center management system and accessing the unified security management system, the problems of authentication complexity and inefficiency caused by the fragmentation of the 4A system were solved, and efficient and convenient hierarchical authentication and permission sharing were achieved.

CN118802166BActive Publication Date: 2025-11-21HANDAN BRANCH OF CHINA MOBILE GRP HEBEI COMPANYLIMITED +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410995236.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2025-11-21
Estimated Expiration
2044-07-24

AI Technical Summary

Technical Problem

The existing 4A systems are fragmented, requiring users to register separate accounts, which increases authentication complexity and inefficiency. The system communication and permission sharing mechanisms are complex, making it difficult to guarantee overall availability.

Method used

By integrating the account center management system, the unified security management system for user access, and the unified security management system for application access, seamless communication between the systems is achieved. Combined with local and remote authentication mechanisms, the user authentication process is simplified, and efficient verification of authentication tickets and permission sharing are realized.

Benefits of technology

It achieves efficient and convenient hierarchical authentication, simplifies the user authentication process, improves system availability and permission sharing efficiency, and reduces management and maintenance complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802166B_ABST
    Figure CN118802166B_ABST
Patent Text Reader

Abstract

The application provides a hierarchical authentication system and method, and relates to the technical field of data security. The system comprises: a user access unified security management system, which is used for transmitting authentication operation information to a target user access unified security management module, and performing local authentication according to the authentication operation information by the target user access unified security management module, or transmitting the authentication operation information to an account center management system to perform remote authentication, so as to output a final authentication result; and an application access unified security management system, which is used for transmitting authentication tickets obtained by a target user through the final authentication result to a first application access unified security management module, and performing local verification according to the authentication tickets by the first application access unified security management module, or transmitting the authentication tickets to the account center management system or the target user access unified security management module to perform remote verification, so as to return a final verification result to an application to be accessed. The application realizes efficient and convenient hierarchical authentication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a hierarchical authentication system and method. BACKGROUND

[0002] In order to better manage account authentication information, an integrated authentication, authorization, account and audit unified security management system (referred to as 4A system) emerges as the times require, which can abstract the basic functions of account, authentication, authorization and audit in the original customer information management system, supply chain system and office system, and perform unified management.

[0003] At present, in order to meet the needs of information interconnection and cross-domain access, the 4A system has evolved into a first-level 4A system, a second-level 4A system and a front-end 4A system, but each 4A system is in a fragmented state, users need to register an account for each 4A system, and use the corresponding account of each 4A system to access each 4A system, which leads to a complex communication and permission sharing mechanism between each 4A system, and the difficulty of ensuring the usability of the overall system is large, thereby leading to complex hierarchical authentication and low efficiency.

[0004] Therefore, there is an urgent need for a hierarchical authentication system and method to achieve efficient and convenient hierarchical authentication. SUMMARY

[0005] The present application provides a hierarchical authentication system and method to solve the defects of complex hierarchical authentication and low efficiency in the prior art, and to achieve efficient and convenient hierarchical authentication.

[0006] The present application provides a hierarchical authentication system, comprising an account center management system, a user access unified security management system and an application access unified security management system.

[0007] Each two of the account center management system, the user access unified security management system and the application access unified security management system are communicatively connected.

[0008] The user access unified security management system comprises a plurality of user access unified security management modules under different regions, and the application access unified security management system comprises a plurality of application access unified security management modules under different regions.

[0009] The user access unified security management system is configured to select a target user access unified security management module from the plurality of user access unified security management modules according to authentication operation information input by a target user, and transmit the authentication operation information to the target user access unified security management module.

[0010] The target user accesses the unified security management module, and performs local authentication on the target user according to the authentication operation information, or transmits the authentication operation information to the account center management system for remote authentication, and outputs a final authentication result of the target user according to a local authentication result or a remote authentication result;

[0011] The application accesses the unified security management system, acquires a to-be-accessed application and an authentication ticket corresponding to the to-be-accessed application according to an application access request submitted by the target user through the final authentication result, selects a first application access unified security management module from the plurality of application access unified security management modules according to a region to which the to-be-accessed application belongs, and transmits the authentication ticket to the first application access unified security management module;

[0012] The first application access unified security management module performs local verification according to the authentication ticket, or transmits the authentication ticket to the account center management system for remote verification, or transmits the authentication ticket to the target user access unified security management module for remote verification, and returns a final verification result to the to-be-accessed application according to a local verification result or a remote verification result.

[0013] According to the hierarchical authentication system provided by the application, the account center management system comprises a plurality of account center management nodes;

[0014] The target user access unified security management module is further configured to:

[0015] search for account information of the target user in locally stored user information;

[0016] In the case that the account information of the target user is found, perform local authentication on the target user according to the authentication operation information;

[0017] In the case that the account information of the target user is not found, iteratively transmit the authentication operation information to an account center management node with optimal performance in the account center management system for remote authentication.

[0018] According to the hierarchical authentication system provided by the application, the target user access unified security management module is further configured to:

[0019] In the case that the target user submits account registration application information, generate an account information query instruction according to the account registration application information; the account information query instruction is used to query associated account information associated with the account registration application information;

[0020] sending the account information query instruction to the account center management system;

[0021] receiving the associated account information returned by the account center management system and outputting the associated account information;

[0022] receiving account information processing instructions generated by the target user according to the associated account information;

[0023] According to the account information processing instructions, the associated account information is merged and / or deleted, and new account information is formed;

[0024] synchronizing the new account information to the account center management system.

[0025] According to the application, a hierarchical authentication system is provided, and the target user accesses the unified security management module, and is further used for:

[0026] When the permission application information submitted by the target user is received, the target application is obtained according to the permission application information, the second application access unified security management module is obtained from the plurality of application access unified security management modules according to the region to which the target application belongs;

[0027] determining whether the target user access unified security management module and the second application access unified security management module belong to the same access unified security management module;

[0028] If the target user access unified security management module and the second application access unified security management module belong to the same access unified security management module, the permission application information is approved to obtain a first approval result, and the first approval result is output.

[0029] According to the application, a hierarchical authentication system is provided, and the second application access unified security management module is used for:

[0030] If the target user access unified security management module and the second application access unified security management module do not belong to the same access unified security management module, the permission application information transmitted by the target user access unified security management module is received;

[0031] The permission application information is approved to obtain a second approval result;

[0032] The second approval result is synchronized to the account center management system;

[0033] In a case where it is judged that the account center management system completes storage of the second approval result, a third approval result that the permission application information approval is completed is sent to the target user access unified security management module, so that the target user access unified security management module outputs the third approval result.

[0034] According to the hierarchical authentication system provided by the application, the account center management system comprises a plurality of account center management nodes.

[0035] The account center management system is configured to process data change requests submitted by each user access unified security management module or each application access unified security management module in the plurality of account center management nodes through a block chain consensus algorithm.

[0036] The data change request comprises at least one of a request for updating account information, a request for updating permission information, a request for updating authentication information, and a request for updating registration information.

[0037] According to the hierarchical authentication system provided by the application, the first application access unified security management module is further configured to:

[0038] Search for the issuance record of the authentication ticket in the locally stored application information.

[0039] In a case where the issuance record is found, locally verify the authentication ticket according to the issuance record.

[0040] In a case where the issuance record is not found, iteratively transmit the authentication ticket to the account center management system for remote verification, or iteratively transmit the authentication ticket to the target user access unified security management module for remote verification.

[0041] The application further provides a hierarchical authentication method applied to the hierarchical authentication system as described in any one of the above.

[0042] Based on the user access unified security management system, a target user access unified security management module is selected from a plurality of user access unified security management modules of the user access unified security management system according to authentication operation information input by a target user, and the authentication operation information is transmitted to the target user access unified security management module.

[0043] Based on the target user access unified security management module, the target user is locally authenticated according to the authentication operation information, or the authentication operation information is transmitted to an account center management system for remote authentication, and a final authentication result of the target user is output according to a local authentication result or a remote authentication result.

[0044] Based on the application access unified security management system, according to the application access request submitted by the target user through the final authentication result, the application to be accessed is obtained, and the authentication ticket corresponding to the application to be accessed is obtained, and according to the region to which the application to be accessed belongs, a first application access unified security management module is selected from a plurality of application access unified security management modules of the application access unified security management system, and the authentication ticket is transmitted to the first application access unified security management module.

[0045] Based on the first application access unified security management module, local verification is performed according to the authentication ticket, or the authentication ticket is transmitted to the account center management system for remote verification, or the authentication ticket is transmitted to the target user access unified security management module for remote verification, and a final verification result is returned to the application to be accessed according to the local verification result or the remote verification result.

[0046] The application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the hierarchical authentication method of any of the above when executing the program.

[0047] The application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement the hierarchical authentication method of any of the above.

[0048] The application also provides a computer program product, including a computer program, and the computer program is executed by a processor to implement the hierarchical authentication method of any of the above.

[0049] The hierarchical authentication system and method provided by the application integrates the account center management system, the user access unified security management system and the application access unified security management system for unified authentication management, and realizes seamless communication connection between systems, effectively breaking the barriers between different 4A modules, realizing centralized sharing of account information, and through intelligent selection of user access 4A module and application access 4A module, and combined with the account center management system, the local and remote authentication and combined verification mechanism, not only simplifies the user authentication process, but also realizes efficient verification of authentication tickets and sharing of permissions, thereby greatly improving the efficiency of hierarchical authentication and the usability of the overall system, reducing the complexity of management and maintenance, and realizing efficient and convenient hierarchical authentication. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0051] Figure 1 is a structural schematic diagram of a two-level 4A authentication system provided by the prior art.

[0052] Figure 2 is a structural schematic diagram of a front 4A authentication system provided by the prior art.

[0053] Figure 3 is a structural schematic diagram of a hierarchical authentication system provided by the present application.

[0054] Figure 4 is a flowchart of user authentication provided by the present application.

[0055] Figure 5 is a flowchart of application access provided by the present application.

[0056] Figure 6 is a flowchart of user account registration provided by the present application.

[0057] Figure 7 is a flowchart of user permission application provided by the present application.

[0058] Figure 8 is a flowchart of data recording provided by the present application.

[0059] Figure 9 is a flowchart of a hierarchical authentication method provided by the present application.

[0060] Figure 10 is a structural schematic diagram of an electronic device provided by the present application. DETAILED DESCRIPTION

[0061] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below in combination with the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0062] With the rapid deepening of the informationization of society and the rapid development of the informationization of enterprises, the number of accounts in IT (Information Technology) systems has also increased exponentially. Before the emergence of the 4A system, the accounts of the customer information management system, the supply chain system, the office system, and other systems were managed by themselves, resulting in users needing to log in to multiple systems to complete their work. In order to better manage account authentication information, the 4A system emerged. The 4A system defines identity authentication, authorization, accounting, and auditing as the four components of network security, thereby establishing the status and role of identity authentication in the entire network security system. That is, the basic functions of account, authentication, authorization, and auditing that were originally scattered in the customer information management system, the supply chain system, the office system, and other systems are abstracted to form a unified management platform, such as a 4A platform of a certain company. If a user needs to log in to the customer relationship management system, for example, the user only needs to log in to the 4A platform once, and after completing the authentication and authorization, the user can log in to the customer relationship management system through a jump, without having to repeat the user identity verification action.

[0063] However, with the further expansion of the scale of enterprises and the information interconnection needs of large groups of enterprises, as well as the emergence of new needs such as system centralization reconstruction and cross-domain access, the original 4A platform based on cross-domain application platform authentication and authorization centralized management and control is difficult to meet the new cross-domain access needs.

[0064] To solve this problem, the 4A system proposes several technical architecture evolution paths. One of them is to establish a two-level 4A authentication system, as shown in Figure 1 The two-level 4A authentication system includes a primary 4A authentication system and multiple secondary 4A authentication systems. The primary 4A is responsible for the management and control of application resources within the global region, and the secondary 4A systems provide management and control of application resources within the local region. This architecture aims to meet the security access and management needs of large enterprises or groups in different regions and organizational levels.

[0065] Under this architecture system, a user needs to have an account of both the primary 4A and the secondary 4A in order to access applications (such as application a and application b) that access the primary 4A and the secondary 4A, respectively. Due to the isolation between the 4A systems of each security domain and the failure to synchronize account information, the user has to create multiple 4A accounts in different management domains (including operation support domains and management informationization domains, which are further divided into primary and secondary). In this case, because it is easy to confuse the correspondence between applications and 4A systems, users face the problem of low efficiency when applying for accounts. In addition, users need to remember the login addresses and account information of multiple 4A systems, which increases the complexity and inconvenience of use.

[0066] For example, a cloud platform's operations and maintenance personnel might need a primary 4A account to access resource pool devices to complete operations and maintenance tasks, while also needing a secondary operations support domain 4A account to handle tasks such as work orders, event reporting, and job scheduling. This complexity of multi-account management significantly impacts work efficiency and user experience.

[0067] To address these issues and adapt to the centralized construction requirements of application systems, the 4A system entered its second evolution phase. In this phase, a front-end 4A system architecture was proposed, forming a system architecture comprising Level 1 4A, Front-end 4A, and Level 2 4A, such as... Figure 2 As shown.

[0068] In this architecture, such as Figure 2 The secondary 4A system in the localized area shown primarily handles user access management, while the front-end 4A system (also known as the 4A front-end service) focuses on access control for the centralized system. The specific authentication process includes: the secondary 4A system processes user registration requests and synchronizes registered user information to the front-end 4A system, ensuring the consistency and integrity of user data; when a user attempts to access the centralized system, the secondary 4A system generates a user authentication ticket; the user then submits the authentication ticket generated by the secondary 4A system to the front-end 4A system for further verification. The front-end 4A system first verifies the ticket's ownership and validity, then communicates with the secondary 4A to further verify the ticket and authenticate the user's access rights. This communication and verification mechanism between the secondary and front-end 4A systems, to a certain extent, meets the needs of centralized applications for account permission authentication. However, as complex many-to-many access relationships form between multiple front-end and secondary 4A systems, the complexity of the system architecture increases. Furthermore, this architecture does not fundamentally improve the ease of use of the authentication function, and users still face challenges when managing and using multiple accounts.

[0069] In the current 4A system architecture, the following key issues affect user experience and system efficiency:

[0070] First, account, authentication, and permission information is not fully shared among Level 1, Level 2, and front-end 4A systems. Each system operates independently, requiring users to possess multiple 4A accounts at different levels to access applications managed by different systems. This fragmentation results in inefficient account authentication and permission control services provided by each 4A system, leaving significant room for improvement.

[0071] Secondly, in order to meet the needs of centralized construction of application systems, a pre-4A system architecture is introduced. Under this architecture, the secondary 4A system is responsible for user access, and the pre-4A system is responsible for access control of the centralized system. The secondary 4A system handles user registration and synchronizes information to the pre-4A system. When the user accesses the centralized system, the secondary 4A system generates authentication tickets, and the user submits these tickets to the pre-4A system for authentication. The pre-4A system verifies the ownership of the tickets and communicates with the secondary 4A system to confirm the user's access rights. When a new application needs to be accessed, it needs to be connected with the secondary 4A system to complete the access of the application account, connected with the pre-4A system to complete the management of permissions and vaults, and connected with the 4A system to complete the operation of application log access. When a user logs in to an application, the 4A system needs to be connected to complete the account application and permission application of the user, and connected with the pre-4A system to complete the authentication and authorization operation. As can be seen, although this architecture to some extent solves the account and permission authentication needs of centralized applications, the access process of new applications is still complex, and needs to be connected with multiple 4A systems for function connection and interface adjustment, which undoubtedly increases unnecessary development costs.

[0072] Thirdly, in order to access different application systems, users need to manage multiple 4A accounts and remember the corresponding relationship between each application system and the 4A system, which has obvious deficiencies in ease of use.

[0073] Fourthly, the communication and permission sharing mechanism between the secondary 4A, pre-4A, and primary 4A systems is complex, increasing the difficulty of system maintenance and the complexity of the system, and is prone to single point failure of network, application, middleware, database, and other links, resulting in reduced availability of the entire system.

[0074] In summary, although the current 4A system plays an important role in account authentication and permission management, each 4A system is in a fragmented state, users need to register accounts for each 4A system, and use the corresponding accounts of each 4A system to access each 4A system, resulting in a complex communication and permission sharing mechanism between each 4A system, making it difficult to ensure the availability of the overall system, and further leading to complex and inefficient hierarchical authentication.

[0075] To solve this problem, the present embodiment provides a hierarchical authentication system, which simplifies the communication and permission sharing mechanism between 4A systems through centralized management of user access 4A modules and application access 4A modules in different regions, and close linkage with the account center management system, so that user and application access, authentication, and permission allocation operations are carried out in a unified and simplified framework, reducing the complexity of authentication and improving efficiency.

[0076] Figure 3It is a structural schematic diagram of the multi-level authentication system provided by the application. The system can realize unified management of account numbers of a multi-level system (or a parent-child level system) currently having regional restrictions, and the same authority of regional information based on different regional account numbers. It can be applied to the scene of account number association and information sharing between parallel level systems with multiple different regions, such as 4A platforms of various communication companies, 4A platforms of various bank enterprises, and 4A platforms of various insurance enterprises, etc., and has wide application prospects. As shown in Figure 3 The system includes an account center management system 310, a user access unified security management system 320 (also referred to as a user access 4A system), and an application access unified security management system 330 (also referred to as an application access 4A system). Each of the account center management system 310, the user access unified security management system 320, and the application access unified security management system 330 is communicatively connected between two systems. The user access unified security management system 320 includes a plurality of user access unified security management modules under different regions, and the application access unified security management system 330 includes a plurality of application access unified security management modules under different regions.

[0077] The account center management system 310 is responsible for centralized management of account information, authentication information, and permission information of all users. The management includes but is not limited to recording, querying, etc., which are not specifically limited in this embodiment. For example, the account information, authentication information, and permission information of the user are recorded using blockchain technology, and the user account of the user access 4A system is saved, and the authentication information and permission information are queried and identified.

[0078] The user access unified security management system includes a plurality of user access unified security management modules (also referred to as user access 4A modules) under different regions, including but not limited to a global user access 4A module under a global region, and a plurality of user access unified security management modules under local regions, such as an A region user access 4A module, a B region user access 4A module, and an M region user access 4A module, etc., which are not specifically limited in this embodiment.

[0079] The user access 4A module is the only entrance for users to access the system, and can provide registration, identity verification, permission allocation, and log recording functions for users under different regional organizations. At the same time, it can also provide a unique access point for users to access other regional resources, and undertake registration, identity authentication, and permission acquisition between the account center association system.

[0080] The application access unified security management system includes a plurality of application access unified security management modules (also referred to as application access 4A modules) in different regions, including but not limited to a global application access 4A module in a global region, and a plurality of application access unified security management modules in local regions, such as an A-region application access 4A module, a B-region application access 4A module, and an M-region application access 4A module, etc. The present embodiment does not make specific limitations thereto.

[0081] The application access 4A module is responsible for application access, provides a basic entry for ticket verification of the application, and is linked with the account center management system and the user access 4A module to verify and authenticate the ticket.

[0082] Each two of the account center management system, the user access unified security management system, and the application access unified security management system is connected in communication to ensure smooth transmission and real-time update of information, and further to realize hierarchical authentication through linkage of the account center management system, the user access unified security management system, and the application access unified security management system.

[0083] In the process of obtaining an authentication ticket by user authentication, the user access unified security management system is configured to select a target user access unified security management module from a plurality of user access unified security management modules according to authentication operation information input by a target user, and transmit the authentication operation information to the target user access unified security management module; and the target user access unified security management module is configured to locally authenticate the target user according to the authentication operation information, or transmit the authentication operation information to the account center management system for remote authentication, and output a final authentication result of the target user according to a local authentication result or a remote authentication result.

[0084] As shown in Figure 4 For the process of obtaining an authentication ticket by user authentication, the user access unified security management system can be combined with the account center management system to implement, specifically, local user authentication in the user access 4A module or remote user authentication in the account center management system to obtain an authentication ticket issued by the user access 4A module or the account center management system when the user authentication is passed, so as to access the application by means of the obtained authentication ticket. Specifically, the following steps can be implemented:

[0085] At step 410, the target user selects a user access 4A module according to the use habit and / or organizes the area, and inputs account information and other necessary information such as authentication password to form authentication operation information, and inputs the authentication operation information into the user access 4A system. After the user access 4A system obtains the authentication operation information input by the target user, the user access 4A system can determine the target user access unified security management module from the plurality of user access unified security management modules according to the user access 4A module selected by the target user in the authentication operation information, and transmit the authentication operation information to the target user access 4A module, so that the target user access 4A module performs local authentication on the target user according to the authentication operation information by calling local user data, or transmits the authentication operation information to the account center management system to perform remote authentication on the target user by calling user data stored in the account center management system.

[0086] It should be noted that the implementation mode of selecting local authentication or remote authentication for the target user includes: randomly selecting local authentication or remote authentication; or, first performing local authentication, and then performing remote authentication when the local authentication cannot be implemented. The present embodiment does not make a specific limitation on this.

[0087] In some embodiments, the account center management system includes a plurality of account center management nodes; the target user access unified security management module can first perform authentication attempt on the account information of the target user locally, if the target user access 4A module has the account information of the target user, the target user access 4A module performs local authentication attempt on the user internally, and returns an authentication ticket according to the authentication result; if the target user access 4A module does not have the account information of the target user, the target user access 4A module iteratively requests the account center management node with the best performance in the account center management system to perform remote authentication, so as to return an authentication ticket, so that the user accesses the application by means of the obtained authentication ticket. The specific execution steps include:

[0088] Searching the account information of the target user in the locally stored user information;

[0089] In the case that the account information of the target user is found, performing local authentication on the target user according to the authentication operation information;

[0090] In the case that the account information of the target user is not found, transmitting the authentication operation information to the account center management system to perform remote authentication.

[0091] Optionally, the target user access 4A module can interact with the account center management system to perform the following steps to realize user authentication:

[0092] Step 420, the target user accesses the 4A module, and authenticates the account information contained in the authentication operation information input by the user by using the locally stored user information. If the target user's account information is locally stored, the target user is locally authenticated according to the authentication operation information, if the authentication fails, a local authentication result of user authentication failure is returned, if the authentication succeeds, a local authentication result of user authentication success is returned; if the target user's account information does not exist locally, local authentication cannot be performed, and then the process jumps to step 430;

[0093] Step 430, in the case that the target user accesses the 4A module and cannot perform local authentication, the target user accesses the 4A module and transfers the authentication operation information (containing account information and authentication password and other necessary information for authentication) to the account center management node with the best performance in the account center management system, iteratively requests the account center management node with the best performance to attempt authentication; the account center management node compares the submitted authentication operation information with the locally stored user to complete the authentication process;

[0094] Step 440, the account center management node attempts to authenticate the authentication operation information, and executes step 450 according to the result;

[0095] Step 450, if the authentication succeeds, a remote authentication result including an authentication ticket is returned to the target user access 4A module; if the authentication fails, a remote authentication result of authentication failure is returned; if there is no such account information, a remote authentication result of no such account information is returned;

[0096] Step 460, the target user access 4A module outputs the final authentication result of the target user according to the local authentication result or the remote authentication result returned by the account center management system, so that the user can access the specified application according to the authentication ticket in the final authentication result. The so-called final authentication result can include an authentication failure result or an authentication ticket issued by successful authentication.

[0097] The performance optimal account center management node selection method includes: after the target access 4A module is configured with the information of the account center management node, the account center management node provides the information of the full-amount account center management node to the target access 4A module. The target access 4A module tests the network condition of the full-amount account center management node, obtains the performance result of the account center management node, and sorts the performance result, so as to determine the performance optimal account center management node. When the current performance optimal account center management node cannot meet the access demand, a new performance optimal account center management node can be selected by re-determination, so that the remote authentication is performed through the intelligent selection of the performance optimal account center management node, the authentication efficiency is improved, the utilization of system resources is optimized, the performance bottleneck caused by the overload of a single node is avoided, and the scalability and stability of the system are enhanced.

[0098] In the process that the user accesses the specified application by using the obtained authentication ticket, the application accesses the unified security management system, obtains the to-be-accessed application and the authentication ticket corresponding to the to-be-accessed application according to the application access request submitted by the target user through the final authentication result, selects a first application access unified security management module from the plurality of application access unified security management modules according to the region to which the to-be-accessed application belongs, and transmits the authentication ticket to the first application access unified security management module; the first application access unified security management module is configured to perform local verification according to the authentication ticket, or transmit the authentication ticket to the account center management system for remote verification, or transmit the authentication ticket to the target user access unified security management module for remote verification, and return a final verification result to the to-be-accessed application according to the local verification result or the remote verification result.

[0099] As shown in Figure 5 In the process that the user accesses the specified application by using the obtained authentication ticket, the application accesses the unified security management system, obtains the to-be-accessed application and the authentication ticket corresponding to the to-be-accessed application according to the application access request submitted by the target user through the final authentication result, selects a first application access unified security management module from the plurality of application access unified security management modules according to the region to which the to-be-accessed application belongs, and transmits the authentication ticket to the first application access unified security management module; the first application access unified security management module is configured to perform local verification according to the authentication ticket, or transmit the authentication ticket to the account center management system for remote verification, or transmit the authentication ticket to the target user access unified security management module for remote verification, and return a final verification result to the to-be-accessed application according to the local verification result or the remote verification result.

[0100] At step 510, after obtaining the authentication ticket through the final authentication result, the target user submits the authentication ticket to the application to be accessed to form an application access request.

[0101] At step 520, the application to be accessed submits the application access request to the application access unified security management system, so that the application access unified security management system obtains the application to be accessed according to the application accessed by the application access request, parses the application access request to obtain the authentication ticket corresponding to the application to be accessed, and selects the first application access 4A module accessible to the application to be accessed from the plurality of application access unified security management modules according to the region to which the application to be accessed belongs, and transmits the authentication ticket to the first application access 4A module to verify the authenticity of the authentication ticket.

[0102] At step 530, the first application access 4A module performs local authenticity verification of the authentication ticket according to the issuance information in the authentication ticket submitted by the application to be accessed, or submits to the target user access 4A module for remote authenticity verification of the authentication ticket, or submits to the account center management system for remote authenticity verification of the authentication ticket.

[0103] At step 540, the first application access 4A module returns the final verification result to the application to be accessed according to the local verification result or the remote verification result.

[0104] At step 550, the application to be accessed determines whether to provide services for the target user according to the returned final verification result.

[0105] It should be noted that the implementation mode of selecting local verification or remote verification of the authentication ticket includes: randomly selecting local verification or remote verification; or, first performing local verification, and then performing remote verification if the local verification cannot be implemented, which is not limited in the embodiment.

[0106] In summary, the system provided in the embodiment can realize the single sign-on mechanism, reduce the operation process of frequent login of the user between different systems, and promote the data exchange and permission synchronization between systems by the user authentication of the unified security management module, so that the permission management is more centralized and efficient, the complexity of communication and permission sharing between systems is reduced, and efficient and convenient hierarchical authentication is realized.

[0107] In some embodiments, the target user obtains an authentication ticket with application access rights after successful user authentication, and submits the authentication ticket to the application to be accessed for user authentication. After the application to be accessed obtains the authentication ticket, it is first submitted to the first application access 4A module accessible to the application to be accessed for verification. If the first application access 4A module has no record of issuing the ticket, further iteration is performed according to the issuing record in the ticket to the target user access 4A module or the account center management system for ticket verification. After the above verification is successful, the application to be accessed provides the user with access rights to the application, and starts to provide services for the user. The first application access uniform security management module can implement the following steps:

[0108] searching the application information stored locally for the issuing record of the authentication ticket;

[0109] in the case of finding the issuing record, locally verifying the authentication ticket according to the issuing record;

[0110] in the case of not finding the issuing record, iteratively transmitting the authentication ticket to the account center management system for remote verification, or iteratively transmitting the authentication ticket to the target user access uniform security management module for remote verification.

[0111] Optionally, the first application access 4A module can interact with the account center management system and the target user access 4A module to implement the following steps to realize application access verification:

[0112] The first application access 4A module searches the application information stored locally for the issuing record of the authentication ticket. If the local storage has the issuing record of the authentication ticket, the authentication ticket is locally verified according to the issuing record. If the verification fails, a local verification result of verification failure is returned. If the verification succeeds, a local verification result of verification success is returned. If the local storage does not have the issuing record of the authentication ticket, local verification cannot be performed. At this time, it is necessary to iteratively transmit to the account center management system with the best performance of the account center management node for remote verification or to the target user access 4A module for remote verification.

[0113] For example, in the scenario that the employees of the A-area organization need to access the customer relationship management system of the B-area organization, the employees of the A-area organization can submit the authentication ticket to the customer relationship management system of the B-area organization. The customer relationship management system of the B-area organization first submits the authentication ticket to the application access 4A module under the B-area organization for verification. In the case that there is no record of the issuance of the authentication ticket in the local of the application access 4A module under the B-area organization, the application access 4A module under the B-area organization iterates to the target user access 4A module, i.e., the user access 4A module or the account center management system under the A-area organization, for ticket verification according to the record of the issuance of the authentication ticket. Until any one of the three iteration verification links is verified successfully, the customer relationship management system of the B-area organization starts to provide services for the employees of the A-area organization.

[0114] In summary, the system provided in the embodiment breaks the access barriers between the 4A modules, reduces the operations of the user for applying for an account and recording the application attribution 4A module. For example, the employees of the A-area organization do not need to apply for an account of the 4A module under the B-area organization again in order to access the customer relationship management system of the B-area organization, but can access the customer relationship management system of the B-area organization from the application access 4A module under the B-area organization by using the account of the 4A module under the A-area organization, thereby providing the implementation feasibility for one-point login and full-network roaming of the user, and realizing efficient and convenient hierarchical authentication.

[0115] The hierarchical authentication system provided in the embodiment integrates the account center management system, the user access unified security management system and the application access unified security management system for unified authentication management, and realizes seamless communication connection between the systems, effectively breaking the barriers between different 4A modules, realizing centralized sharing of account information, and through intelligent selection of the user access 4A module and the application access 4A module and in combination with the account center management system, realizing the verification mechanism of local and remote authentication and combination, which not only simplifies the user authentication process, but also realizes efficient verification and permission sharing of the authentication ticket, thereby greatly improving the efficiency of hierarchical authentication and the usability of the overall system, reducing the complexity of management and maintenance, and further realizing efficient and convenient hierarchical authentication.

[0116] In some embodiments, the target user access unified security management module is further configured to:

[0117] In the case that the target user submits the account registration application information, generate an account information query instruction according to the account registration application information; the account information query instruction is used to query the associated account information associated with the account registration application information;

[0118] send the account information query instruction to the account center management system;

[0119] receiving the associated account information returned by the account center management system, and outputting the associated account information;

[0120] receiving account information processing instructions generated by the target user according to the associated account information;

[0121] According to the account information processing instructions, the associated account information is merged and / or deleted, and new account information is formed;

[0122] Synchronize the new account information to the account center management system.

[0123] Optionally, for the user account registration process, the target user can select the corresponding target user access 4A module as his access path to the application according to his own use habits and / or the organization area he belongs to, in order to log in using the 4A account under the organization area he belongs to. And register his own account information on the target user access 4A module. The target user access 4A module queries the relevant account to the account center management system according to the user's filled registration information, and prompts the user whether to do the association. When the user selects the associated account, the authentication operation of the associated account needs to be done. After successful authentication, the newly registered account and the original associated account are normalized stored, and the newly registered account information is attached to the original account, realizing the unified storage of the account.

[0124] As shown in Figure 6 The target user access 4A module can cooperate with the account center management system to realize the user account registration as follows:

[0125] Step 610, the target user submits account registration application information;

[0126] Step 620, the target user access 4A module sends an account information query instruction to the account center management system according to the account registration application information submitted by the target user, to query whether the account center management system has the associated account information marked with the same access subject, that is, the target user, including but not limited to ID number, mobile phone number, employee number, name, enterprise mailbox, etc. If there is no associated account information marked with the target user, jump to step 670; if there is associated account information marked with the target user, jump to step 630;

[0127] Step 630, the account center management system retrieves all existing account information list according to the information of the identifiable access subject (target user) and returns to the target user. The account list includes but is not limited to the information of the identity card number, mobile phone number, employee number, name, enterprise mailbox and the like of the individual identifiable access subject (target user). The target user checks whether there is an account that needs to be merged in the list, and if not, jumps to step 670; if there is an account that needs to be merged, jumps to step 640;

[0128] Step 640, the target user decides whether the account needs to be merged, and if not, jumps to step 670; if the selected account is merged, a first account information processing instruction is formed and transmitted to the target user access 4A module, and the target user access 4A module merges the associated account information according to the first account information processing instruction, and jumps to step 650;

[0129] Step 650, the user decides whether to delete the old account, if selected, a second account information processing instruction is formed and transmitted to the target user access 4A module, and jumps to step 660; if selected, jumps to step 670;

[0130] Step 660, the target user access 4A module deletes the old account according to the second account information processing instruction, and submits the request for deleting the old account to the account center management system;

[0131] Step 670, the new account information is submitted to the account center management system.

[0132] The system provided by the embodiment reduces the repeated registration and management work of the user in multiple 4A modules, improves the efficiency of account management, realizes the unified login of the user by increasing the process of associating the new account registration process with the original account, and realizes the nationwide roaming function of the user account. The user can reuse the previously applied account authorization role through account association without reapplying for an account, thereby realizing the optimization of account management, improving the security and user experience of the system.

[0133] In some embodiments, the target user access unified security management module is further used for:

[0134] In the case where the target user submits the permission application information, the target application is obtained according to the permission application information, and the second application access unified security management module is obtained from the plurality of application access unified security management modules according to the region to which the target application belongs.

[0135] determine whether the target user access uniform security management module and the second application access uniform security management module belong to the same access uniform security management module;

[0136] In the case where the target user access uniform security management module and the second application access uniform security management module belong to the same access uniform security management module, the permission application information is approved to obtain a first approval result, and the first approval result is output.

[0137] The second application access uniform security management module is configured to:

[0138] If the target user access uniform security management module and the second application access uniform security management module do not belong to the same access uniform security management module, the permission application information transmitted by the target user access uniform security management module is received.

[0139] The permission application information is approved to obtain a second approval result.

[0140] The second approval result is synchronized to the account center management system.

[0141] In the case where it is determined that the account center management system completes the storage of the second approval result, a third approval result of the completion of the permission application information approval is sent to the target user access uniform security management module, so that the target user access uniform security management module outputs the third approval result.

[0142] Optionally, for the user permission application approval process, the user needs to perform two parts of approval in the permission application process, one part of approval is in the target user access 4A module of the organization region to which the user belongs, and the other part is in the second application access 4A module. In order to reduce the steps of the subsequent account authentication link and improve the efficiency of the subsequent account authentication link, if the target user access 4A module and the second application access 4A module belong to the same access 4A module, it is proved that the application to be accessed by the user is a local application, and then the user permission information is saved in the local of the target user access 4A module. Otherwise, the user permission information is saved in the account center management system after the second application access 4A module completes the approval. As shown in Figure 7 The target user access 4A module and the second application access 4A module can cooperate to implement the user permission application approval process by performing the following steps:

[0143] Step 710, the target user submits the permission application information to the target user access 4A module, and the target user access 4A module performs a local permission application approval process. After the local permission application approval is completed, if the permission application only involves local applications, that is, the target user access 4A module and the second application access 4A module under the region to which the target application belongs belong to the same access 4A module, then jump to step 750; otherwise, jump to step 720;

[0144] Step 720, the target user access 4A module transfers the target user's permission application information to the second application access 4A module side, and the second application access 4A module performs application-side permission application information approval. After the approval is completed, then jump to step 730;

[0145] Step 730, the second application access 4A module synchronizes the user's permission approval result to the account center management system. The account center management system completes the distributed accounting record to ensure that the user account information is properly and safely saved. Then jump to step 740;

[0146] Step 740, after the account center management system completes the user permission information saving, the target user access 4A module is informed of the target user's permission application success result;

[0147] Step 750, the target user access 4A module informs the target user of the final permission approval result.

[0148] For example, personnel in the A organization region need to apply for video website permissions. When the video website is also a video website under the A organization region, it belongs to the same access 4A scenario of the user access 4A module and the application access 4A module, and the user permission information is approved and saved locally in the user access 4A module. When the accessed video website is a video website under the B organization region, it is a different access 4A scenario of the user access 4A module and the application access 4A module, and the user permission information is transferred to the account center management system for approval and saving.

[0149] The system provided by the embodiment cooperates the user access 4A module, the application access 4A module, and the account center management system to perform the user permission hierarchical approval process, effectively improves the security and approval efficiency of cross-module permission application, and ensures the accuracy and timeliness of permission allocation.

[0150] In some embodiments, the account center management system includes a plurality of account center management nodes;

[0151] The account center management system is configured to process data change requests submitted by the user access unified security management module or the application access unified security management module through a blockchain consensus algorithm in multiple account center management nodes.

[0152] The data change request includes at least one of a request for updating account information, a request for updating permission information, a request for updating authentication information, and a request for updating registration information.

[0153] Optionally, for the data recording process of the account center management system, a distributed ledger technology based on a blockchain can be established, and the two core features of the blockchain technology, i.e., data difficulty to tamper and decentralization, are used to realize the account information sharing function between the 4A modules at all levels, so that the user enjoys the registration and the account service capability shared by the entire network. At the same time, the data difficulty to tamper of the blockchain also provides strong protection for the security of the user information, thereby realizing the centralized and shared function of the account information and reducing the workload of the interface joint debugging between the 4A modules and the data security.

[0154] It should be noted that the account center management system uses a blockchain consensus algorithm to solve the data consistency problem, and therefore, the number of account center nodes should be N>=3F+1, F being a positive integer greater than or equal to 1. The data recording process of the account center management system is described in detail below.

[0155] As shown in Figure 8 The data recording includes a request stage (request), a pre-preparation stage (pre-prepare), a preparation stage (prepare), a submission stage (commit), and a reply stage (reply), and the specific steps include:

[0156] Step 810, when the user access 4A module or the application access 4A module as a client C submits a data change request, an account center management node 0 with the optimal network access condition (optimal performance) is selected as a master node from multiple account center management nodes to submit the data change request.

[0157] Step 820, the client C sends a data change request to the primary node 0 to enter the request phase; the data change request can be represented as <Request, operation, timestamp, client>, wherein Request, operation, timestamp and client represent the request information, operation information, timestamp information and client information, respectively; the primary node 0 is responsible for broadcasting the data change request to all other replica nodes, such as node 1, node 2 and node 3, after receiving the data change request, to enter the pre-preparation phase;

[0158] Step 830, the primary node 0 assigns a proposal number to the data change request received from the client C, and then sends a pre-preparation message to each replica node; wherein the pre-preparation message can be specifically represented as <<pre-prepare, view, n, digest>, message>, wherein pre-prepare, view, n and digest represent the pre-preparation information, view information, sequence number, data change request digest and data change request, respectively;

[0159] Step 840, after the replica node receives the pre-preparation message, it checks the legality of the message, and if the check passes, it sends a preparation message to other nodes except the replica node to enter the preparation phase; wherein the preparation message can be specifically represented as <<prepare, view, n. digest, id>>; prepare, view, n, digest and id represent the preparation information, view information, sequence number, data change request digest and identification of the replica node, respectively. At the same time, the preparation information from other nodes is received, and the node receiving the preparation message also checks the legality of the message, and after verification, the preparation message is written into the message log until at least 2F+1 verified messages are collected to enter the preparation state;

[0160] Step 850, broadcast commit (commit) message to tell other nodes that a proposal n is in the preparation state in view v to enter the commit phase. If at least 2F+1 verified commit messages are collected, it means that the proposal is passed;

[0161] Step 860, all nodes process the data change request and return the processing result to the terminal to enter the reply phase. The terminal checks whether it has received at least 2F+1 same results from different nodes as the final result;

[0162] The processing result can represent <Reply, timestamp, client, id_node, response>, wherein, Reply, timestamp, client, id_node and response respectively represent reply information, a time stamp, client information, a node representation and a response result.

[0163] At step 870, all nodes time and synchronize the blockchain state with all nodes, and after collecting the state of each node, it is determined that the common state of 2F+1 nodes is the correct latest state recorded by the current system, and the data state of the node is updated to the latest state.

[0164] The system provided by the embodiment provides an account authentication sharing method based on a blockchain technology in an account center management system, so that an account center management system is added on the basis of not changing the original 4A system structure, the account center management system stores user account information by using a distributed accounting technology of a blockchain, effectively realizes centralized sharing of accounts and basic mutual trust between 4A modules, and then performs efficient and convenient hierarchical authentication based on account information stored by the account center management system.

[0165] The hierarchical authentication method provided by the present application is described below, and the hierarchical authentication method described below can be correspondingly referred to the hierarchical authentication system described above.

[0166] The hierarchical authentication method can be implemented by the hierarchical authentication system provided by each of the above embodiments; for example, Figure 9 As shown in the figure, the method comprises the following steps:

[0167] At step 910, based on the user accessing the unified security management system, according to the authentication operation information input by the target user, a target user access unified security management module is selected from a plurality of user access unified security management modules of the user access unified security management system, and the authentication operation information is transmitted to the target user access unified security management module.

[0168] At step 920, based on the target user access unified security management module, according to the authentication operation information, the target user is locally authenticated, or the authentication operation information is transmitted to the account center management system for remote authentication, and according to the local authentication result or the remote authentication result, the final authentication result of the target user is output.

[0169] In step 930, based on the application access unified security management system, the application to be accessed and the authentication ticket corresponding to the application to be accessed are obtained according to the application access request submitted by the target user through the final authentication result, and the first application access unified security management module is selected from the plurality of application access unified security management modules of the application access unified security management system according to the region to which the application to be accessed belongs, and the authentication ticket is transmitted to the first application access unified security management module.

[0170] In step 940, based on the first application access unified security management module, local verification is performed according to the authentication ticket, or the authentication ticket is transmitted to the account center management system for remote verification, or the authentication ticket is transmitted to the target user access unified security management module for remote verification, and a final verification result is returned to the application to be accessed according to the local verification result or the remote verification result.

[0171] The hierarchical authentication method provided in the embodiment integrates the account center management system, the user access unified security management system and the application access unified security management system for unified authentication management, realizes seamless communication connection between systems, effectively breaks the barriers between different 4A modules, realizes centralized sharing of account information, and through intelligent selection of user access 4A modules and application access 4A modules, and in combination with the account center management system, a local and remote authentication and combined verification mechanism is realized, which not only simplifies the user authentication process, but also realizes efficient verification of authentication tickets and sharing of permissions, thereby greatly improving the efficiency of hierarchical authentication and the usability of the overall system, reducing the complexity of management and maintenance, and thereby realizing efficient and convenient hierarchical authentication.

[0172] The method provided in the application is realized based on the above-mentioned system embodiments, and the specific process and detailed content are referred to the above-mentioned embodiments, which will not be repeated here.

[0173] Figure 10 An example of an entity structure schematic diagram of an electronic device is shown in FIG. 1. Figure 10As shown, the electronic device can include a processor 1010, a communications interface 1020, a memory 1030, and a communications bus 1040, wherein the processor 1010, the communications interface 1020, and the memory 1030 complete mutual communication through the communications bus 1040. The processor 1010 can invoke a logical instruction in the memory 1030 to execute a hierarchical authentication method, which includes: based on a user accessing a unified security management system, according to authentication operation information input by a target user, selecting a target user access unified security management module from a plurality of user access unified security management modules of the unified security management system, and transmitting the authentication operation information to the target user access unified security management module; based on the target user access unified security management module, performing local authentication on the target user according to the authentication operation information, or transmitting the authentication operation information to an account center management system for remote authentication, and outputting a final authentication result of the target user according to a local authentication result or a remote authentication result; based on an application accessing a unified security management system, according to an application access request submitted by the target user through the final authentication result, obtaining a to-be-accessed application and an authentication ticket corresponding to the to-be-accessed application, and according to a region to which the to-be-accessed application belongs, selecting a first application access unified security management module from a plurality of application access unified security management modules of the application accessing unified security management system, and transmitting the authentication ticket to the first application access unified security management module; based on the first application access unified security management module, performing local verification according to the authentication ticket, or transmitting the authentication ticket to the account center management system for remote verification, or transmitting the authentication ticket to the target user access unified security management module for remote verification, and returning a final verification result to the to-be-accessed application according to a local verification result or a remote verification result.

[0174] Further, the logic instructions in the memory 1030 described above can be implemented in the form of software functional units and sold or used as independent products, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of software products. The computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0175] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program can be stored on a non-transitory computer readable storage medium, and the computer program can be executed by a processor to enable a computer to execute the hierarchical authentication method provided by the above-mentioned methods. The method comprises the following steps: based on a user accessing a unified security management system, according to authentication operation information input by a target user, selecting a target user access unified security management module from a plurality of user access unified security management modules of the unified security management system, and transmitting the authentication operation information to the target user access unified security management module; based on the target user access unified security management module, performing local authentication on the target user according to the authentication operation information, or transmitting the authentication operation information to an account center management system for remote authentication, and outputting a final authentication result of the target user according to a local authentication result or a remote authentication result; based on an application accessing a unified security management system, according to an application access request submitted by the target user through the final authentication result, obtaining a to-be-accessed application and an authentication ticket corresponding to the to-be-accessed application, and according to a region to which the to-be-accessed application belongs, selecting a first application access unified security management module from a plurality of application access unified security management modules of the application access unified security management system, and transmitting the authentication ticket to the first application access unified security management module; based on the first application access unified security management module, performing local verification according to the authentication ticket, or transmitting the authentication ticket to the account center management system for remote verification, or transmitting the authentication ticket to the target user access unified security management module for remote verification, and returning a final verification result to the to-be-accessed application according to a local verification result or a remote verification result.

[0176] In yet another aspect, the present application also provides a non-transitory computer readable storage medium having stored thereon a computer program, which, when executed by a processor, implements the hierarchical authentication method provided by the above method, and the method comprises: based on a user accessing a unified security management system, according to authentication operation information input by a target user, selecting a target user access unified security management module from a plurality of user access unified security management modules of the unified security management system, and transmitting the authentication operation information to the target user access unified security management module; based on the target user access unified security management module, performing local authentication on the target user according to the authentication operation information, or transmitting the authentication operation information to an account center management system for remote authentication, and outputting a final authentication result of the target user according to a local authentication result or a remote authentication result; based on an application accessing a unified security management system, according to an application access request submitted by the target user through the final authentication result, obtaining an application to be accessed and an authentication ticket corresponding to the application to be accessed, and according to a region to which the application to be accessed belongs, selecting a first application access unified security management module from a plurality of application access unified security management modules of the application accessing unified security management system, and transmitting the authentication ticket to the first application access unified security management module; based on the first application access unified security management module, performing local verification according to the authentication ticket, or transmitting the authentication ticket to the account center management system for remote verification, or transmitting the authentication ticket to the target user access unified security management module for remote verification, and returning a final verification result to the application to be accessed according to a local verification result or a remote verification result.

[0177] The device embodiments described above are merely illustrative, wherein the units illustrated as separate components can or can not be physically separated, and the components illustrated as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the present embodiment scheme according to actual needs. Those skilled in the art can understand and implement it without creative labor.

[0178] Those skilled in the art can clearly understand the technical solutions of the various embodiments from the above description of the embodiments, and the various embodiments can be implemented by means of software with the necessary general hardware platforms, and of course, can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that makes a contribution, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0179] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for some technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A hierarchical authentication system, characterized in that, This includes an account center management system, a unified security management system for user access, and a unified security management system for application access. Communication connections exist between every two systems in the Account Center Management System, the User Access Unified Security Management System, and the Application Access Unified Security Management System; The unified security management system for user access includes unified security management modules for user access in multiple different regions, and the unified security management system for application access includes unified security management modules for application access in multiple different regions. The unified security management system for user access is used to select a target user access unified security management module from multiple user access unified security management modules based on the authentication operation information input by the target user, and to transmit the authentication operation information to the target user access unified security management module. The target user access unified security management module is used to perform local authentication on the target user according to the authentication operation information, or to transmit the authentication operation information to the account center management system for remote authentication, and output the final authentication result of the target user according to the local authentication result or the remote authentication result. The unified security management system for application access is used to obtain the application to be accessed and the authentication ticket corresponding to the application to be accessed based on the application access request submitted by the target user through the final authentication result, and select the first unified security management module for application access from among multiple unified security management modules for application access based on the region to which the application to be accessed belongs, and transmit the authentication ticket to the first unified security management module for application access. The first application access unified security management module is used to perform local verification based on the authentication ticket, or transmit the authentication ticket to the account center management system for remote verification, or transmit the authentication ticket to the target user access unified security management module for remote verification, and return the final verification result to the application to be accessed based on the local verification result or the remote verification result.

2. The hierarchical authentication system according to claim 1, characterized in that, The account center management system includes multiple account center management nodes; The target user access unified security management module is also used for: Search for the target user's account information in the locally stored user information; If the target user's account information is found, the target user is locally authenticated according to the authentication operation information; If the target user's account information is not found, the authentication operation information is iteratively transmitted to the best-performing account center management node in the account center management system for remote authentication.

3. The hierarchical authentication system according to claim 1, characterized in that, The target user access unified security management module is also used for: Upon receiving account registration application information submitted by the target user, an account information query instruction is generated based on the account registration application information; the account information query instruction is used to query associated account information related to the account registration application information. Send the account information query instruction to the account center management system; Receive the associated account information returned by the account center management system, and output the associated account information; Receive the account information processing instruction generated by the target user based on the associated account information; According to the account information processing instruction, the associated account information is merged and / or deleted to form new account information; The new account information will be synchronized to the account center management system.

4. The hierarchical authentication system according to any one of claims 1-3, characterized in that, The target user access unified security management module is also used for: Upon receiving permission request information submitted by the target user, the target application is obtained based on the permission request information. Based on the region to which the target application belongs, a second application is obtained from among the multiple application access unified security management modules. Determine whether the target user access unified security management module and the second application access unified security management module belong to the same access unified security management module; If the target user access unified security management module and the second application access unified security management module belong to the same unified security management module, the permission application information is approved to obtain a first approval result, and the first approval result is output.

5. The hierarchical authentication system according to claim 4, characterized in that, The second application connects to the unified security management module for: If the target user access unified security management module and the second application access unified security management module do not belong to the same access unified security management module, then the permission request information transmitted by the target user access unified security management module is received; The permission request information is reviewed and approved to obtain a second approval result; The second approval result will be synchronized to the account center management system. If it is determined that the account center management system has completed the storage of the second approval result, a third approval result indicating that the permission application information has been approved is sent to the target user access unified security management module, so that the target user access unified security management module can output the third approval result.

6. The hierarchical authentication system according to any one of claims 1-3, characterized in that, The account center management system includes multiple account center management nodes; The account center management system is used to process data change requests submitted by each user accessing the unified security management module or each application accessing the unified security management module through a blockchain consensus algorithm in multiple account center management nodes; The data change request includes at least one of the following: a request to update account information, a request to update permission information, a request to update authentication information, and a request to update registration information.

7. The hierarchical authentication system according to any one of claims 1-3, characterized in that, The first application, when connected to the unified security management module, is also used for: Locate the issuance record of the authentication ticket in the locally stored application information; If the issuance record is found, the authentication ticket is locally verified based on the issuance record; If the issuance record is not found, the authentication ticket is iteratively transmitted to the account center management system for remote verification, or the authentication ticket is iteratively transmitted to the target user access unified security management module for remote verification.

8. A tiered authentication method, characterized in that, Applied to the hierarchical authentication system as described in any one of claims 1 to 7, the method comprises: Based on the unified security management system for user access, according to the authentication operation information input by the target user, the target user access unified security management module is selected from multiple user access unified security management modules in the unified security management system for user access, and the authentication operation information is transmitted to the target user access unified security management module. Based on the target user access unified security management module, the target user is locally authenticated according to the authentication operation information, or the authentication operation information is transmitted to the account center management system for remote authentication, and the final authentication result of the target user is output according to the local authentication result or the remote authentication result. Based on the unified security management system for application access, according to the application access request submitted by the target user through the final authentication result, the application to be accessed and the authentication ticket corresponding to the application to be accessed are obtained. Based on the region to which the application to be accessed belongs, the first unified security management module for application access is selected from the multiple unified security management modules for application access in the unified security management system for application access, and the authentication ticket is transmitted to the first unified security management module for application access. Based on the first application access unified security management module, the system performs local verification according to the authentication ticket, or transmits the authentication ticket to the account center management system for remote verification, or transmits the authentication ticket to the target user access unified security management module for remote verification, and returns the final verification result to the application to be accessed based on the local verification result or the remote verification result.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the hierarchical authentication method as described in claim 8.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the hierarchical authentication method as described in claim 8.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the hierarchical authentication method as described in claim 8.

Citation Information

Patent Citations

  • End-to-end verification method and system for telecommunication service unauthorized access prevention

    CN111625803A

  • Unified security management system and identity authentication method

    CN113114464A