A single sign-on method, device, medium and equipment based on server cluster
By adopting a server cluster-based architecture in a single sign-on system, calculating the user's authentication group index number and distributing requests to the corresponding authentication group server, the performance and reliability of the single server architecture is solved, and a single sign-on system with high reliability and performance is achieved.
Patent Information
- Application Number
- CN202411854662.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-12-17
AI Technical Summary
Existing single sign-on authentication servers usually adopt a single server architecture, which causes the system to be unavailable and user data to be lost in situations such as server downtime or natural disasters in the production environment. As users increase, the single server architecture does not meet the performance requirements, resulting in low user login reliability.
Using a single sign-on method based on the server cluster, by calculating the authentication group index number corresponding to the user's user name, an authentication request is sent to the authentication group corresponding to the server cluster. Each authentication group includes one login server and multiple authentication servers. When the authentication request is a login request, it is sent to the login server of the authentication group for detection; when it is an authentication request, it is sent to the verification server of the authentication group for verification, and election processing is performed within the authentication group to ensure that a backup server takes over when the login server fails.
Through the server cluster architecture, the performance and reliability of single sign-on is improved, ensuring that the system can still run normally in the event of a single server failure, and improving the reliability and performance of user login.
Smart Images

Figure CN119316232B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a single sign-on method, device, medium and equipment based on a server cluster. Background Art
[0002] As the enterprise grows, the number of systems used increases, and operators need to log in to different systems multiple times. Each system has a different account, which makes the operation cumbersome. To solve this problem, the concept of single sign-on came into being, aiming to achieve one-time login and access to multiple systems. Single sign-on is a user authentication and authorization solution that allows users to log in to multiple interrelated applications and websites with one set of credentials without repeated entry. User identities are managed through a centralized authentication server, and tokens are generated after verifying the user identity. Authentication information is shared between different applications to achieve seamless access to multiple systems. Single sign-on improves user experience, reduces password fatigue, enhances security, simplifies management, reduces support costs, and helps improve compliance.
[0003] The emergence of single sign-on authentication servers has effectively solved the cumbersome problem of multi-system login in enterprises, and improved user experience and work efficiency. However, in the prior art, single sign-on authentication servers are usually in the form of single servers to synchronize the login status between multiple applications, but in a production environment, server downtime or natural disasters may cause system unavailability and user data loss. And with the increasing number of users, the single-server architecture will not meet the performance requirements. Since the single-server architecture does not meet the performance requirements, the problem of low user login reliability will occur during the single sign-on process. Summary of the invention
[0004] Based on this, it is necessary to provide a single sign-on method, device, medium and equipment based on a server cluster to address the above technical problems. This method can solve the problem of poor performance of the single sign-on authentication server.
[0005] The present invention adopts the following technical solutions:
[0006] The present invention provides a single sign-on method based on a server cluster, comprising:
[0007] In response to an identity authentication request initiated by a user, an authentication group index number is calculated based on the user's username;
[0008] According to the authentication group index number, the identity authentication request is sent to the authentication group corresponding to the server cluster; the server cluster includes multiple authentication groups, each authentication group includes a login server and multiple verification servers;
[0009] When the identity authentication request is a login request, the identity authentication request is sent to a login server of the authentication group, and the login information of the user is detected by the login server to determine the login result;
[0010] When the identity authentication request is an authentication request, the identity authentication request is sent to the authentication server of the authentication group, and the user's valid login credentials are verified by the authentication server to determine the login result.
[0011] Preferably, calculating the authentication group index number according to the user name includes:
[0012] Get the decimal number corresponding to the last character of the user name;
[0013] Perform a modulo operation on the decimal number and the number of authentication groups in the server cluster to obtain the authentication group index.
[0014] Preferably, the method further comprises:
[0015] Find the server address corresponding to the identity authentication request from the address table of the authentication group;
[0016] Dispatches authentication requests to the server corresponding to the server address.
[0017] Preferably, searching the address of the server corresponding to the identity authentication request from the address table of the authentication group includes:
[0018] If the identity authentication request is a login request, obtain the server address of the login server from the address table;
[0019] If the identity verification request is an authentication request, the verification server number is determined by load balancing, and a server address corresponding to the verification server number is obtained from the router.
[0020] Preferably, the method further comprises:
[0021] For any authentication group, when a verification server in the authentication group determines that the login server has failed, the verification server sends election information to other verification servers in the authentication group. When all verification servers in the authentication group confirm that the login server has failed, the verification server that initiated the election information will be determined as the new login server.
[0022] Preferably, the login information includes an account number and a password; detecting the user's login information and determining the login result includes:
[0023] Check whether the user's account and password are correct. If correct, check whether the user's valid login credentials exist in the login server;
[0024] If there is a valid login credential, the validity period of the valid login credential is refreshed and the valid login credential is synchronized to multiple verification servers within the authentication group to which it belongs. If there is no valid login credential, a valid login credential for the user is generated and synchronized to multiple verification servers within the authentication group to which it belongs.
[0025] Preferably, verifying the user's valid login credentials and determining the login result includes:
[0026] Check whether there is a valid login credential of the user in the verification server. If so, determine that the user's authentication request is authenticated and return the user information. If not, redirect the current authentication request page to the unified single sign-on page.
[0027] The present invention provides a single sign-on device based on a server cluster, comprising:
[0028] A calculation module, used to calculate the authentication group index number according to the user's username in response to the identity authentication request initiated by the user;
[0029] A sending module, used to send the identity authentication request to the authentication group corresponding to the server cluster according to the authentication group index number; the server cluster includes multiple authentication groups, each authentication group includes a login server and multiple verification servers;
[0030] A first determination module is used to send the identity authentication request to a login server of the authentication group when the identity authentication request is a login request, detect the user's login information through the login server, and determine the login result;
[0031] The second determination module is used to send the identity authentication request to the verification server of the authentication group when the identity authentication request is an authentication request, verify the user's valid login credentials through the verification server, and determine the login result.
[0032] The present invention provides a computer-readable storage medium, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, the single sign-on method based on a server cluster is implemented.
[0033] The present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the above-mentioned single sign-on method based on a server cluster is implemented.
[0034] At least one of the above technical solutions adopted by the present invention can achieve the following beneficial effects:
[0035] The server cluster includes multiple authentication groups, each of which includes a login server and multiple verification servers. When a user initiates a login request or an authentication request, the authentication group index number corresponding to the user is obtained by calculation. If the request is a login request, the request is sent to the login server in the authentication group and the login result is confirmed. If the request is an authentication request, the request is sent to the verification server in the authentication group and the login result is confirmed. This method confirms the login result through the server cluster built during single sign-on, effectively solving the problem of low user login reliability caused by poor performance of the single server architecture during single sign-on. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0037] Figure 1 A system diagram of a server cluster provided by the present invention;
[0038] Figure 2 A schematic diagram of a single sign-on method based on a server cluster provided by the present invention;
[0039] Figure 3 A schematic diagram of a single sign-on device based on a server cluster provided by the present invention;
[0040] Figure 4 A schematic diagram of a computer device for implementing a single sign-on method based on a server cluster provided by the present invention.
[0041] Description of reference numerals:
[0042] 101. Authentication gateway; 102. Authentication group; 103. Login server; 104. Verification server. DETAILED DESCRIPTION
[0043] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0044] In an exemplary embodiment, the present invention provides a server cluster, which is built in a one-master-multiple-slave mode, with a login server as the master server and multiple authentication servers as slave servers. A server cluster includes multiple authentication groups, such as Figure 1As shown, the server cluster 100 includes an authentication gateway 101 and multiple authentication groups 102 , each of which includes a login server 103 and multiple verification servers 104 .
[0045] It should be noted that there is no limitation on the number of authentication groups and the number of verification servers in each authentication group, and the number of verification servers in each authentication group can be the same or different, and can be determined according to actual conditions.
[0046] The authentication group grouping method is to calculate the last character of the user's username and group them according to the calculation result. The specific calculation method is to compare the last character of the username with the American Standard Code for Information Interchange (ASCII) code table to obtain a decimal number, and then perform a modulus operation on the decimal number and the number of groups to be grouped to obtain the index of the authentication group. An authentication group only stores the user data assigned to it, and all user operations will be distributed to the corresponding server through the authentication gateway. In an authentication group, both the login server and the verification server have the same data and functions. When a verification server finds that the current login server is unavailable, it will send election information to other verification servers. When all verification servers confirm that the login server is unavailable, the verification server that first initiates the election request becomes the login server and updates the address table in the authentication gateway.
[0047] The technical solutions provided by various embodiments of the present invention are described in detail below in conjunction with the accompanying drawings.
[0048] Figure 2 The present invention is a flow chart of a single sign-on method based on a server cluster, which specifically includes the following steps:
[0049] S201: In response to an identity authentication request initiated by a user, an authentication group index number is calculated according to the user's username.
[0050] In an exemplary embodiment, the authentication group index number is calculated based on the user's username, including: obtaining a decimal number corresponding to the last character of the username; performing a modulo operation on the decimal number and the number of authentication groups in the server cluster to obtain the authentication group index number.
[0051] Specifically, the index number of the authentication group is obtained by performing a modulo operation on the decimal number corresponding to the last character of the user's username and the number of authentication groups in the server cluster, and only data assigned to users in the group is stored in each authentication group.
[0052] S202: Sending an identity authentication request to an authentication group corresponding to a server cluster according to an authentication group index number; the server cluster includes multiple authentication groups, each authentication group includes a login server and multiple verification servers.
[0053] Specifically, the operations of obtaining login credentials are few, and the operations of verifying whether the login credentials are valid are frequent, so the servers in each authentication group are divided into one login server and multiple verification servers according to the frequency of operations.
[0054] Specifically, according to the calculated authentication group index number corresponding to the user's username, the user's request is sent to the corresponding authentication group in the server cluster. All servers in any authentication group in the server cluster have the same function and store the same user data.
[0055] S203: When the identity authentication request is a login request, the identity authentication request is sent to a login server of the authentication group, and the login server detects the login information of the user to determine the login result.
[0056] In an exemplary embodiment, the method further includes: searching for a server address corresponding to the identity authentication request from an address table of the authentication group; and distributing the identity authentication request to a server corresponding to the server address.
[0057] Specifically, the address table of the authentication group includes the correspondence between the user's identity authentication request and the corresponding server address. Therefore, the server address corresponding to the identity authentication request can be directly obtained from the address table according to the identity authentication request, and the server address is determined as the address of the identity authentication request server.
[0058] In an exemplary embodiment, if the identity authentication request is a login request, the server address of the login server is obtained from the address table.
[0059] Specifically, when the identity authentication request is a login request, the address table includes the correspondence between the user's login request and the corresponding server address. Therefore, the server address corresponding to the login request can be directly obtained from the address table according to the login request, and the server address is determined as the address of the login server.
[0060] In an exemplary embodiment, the login information includes an account number and a password; the user's login information is detected and the login result is determined, including: detecting whether the user's account number and password are correct, and if correct, detecting whether the user's valid login credentials exist in the login server; if there are valid login credentials, refreshing the validity period of the valid login credentials and synchronizing the valid login credentials to multiple verification servers within the authentication group to which they belong; if there are no valid login credentials, generating a valid login credential for the user, and synchronizing the valid login credentials to multiple verification servers within the authentication group to which they belong.
[0061] Specifically, when the identity authentication request is a login request, it is checked whether the user's account and password are correct. If the user's account and password are correct, it is checked whether the login server has the user's valid login credentials. If the user's valid login credentials exist, the validity period of the valid login credentials is refreshed and the refreshed valid login credentials are synchronized to multiple verification servers in the authentication group to which it belongs. If no valid login credentials exist, a valid login credential for the user is generated and synchronized to multiple verification servers in the authentication group to which it belongs.
[0062] S204: When the identity authentication request is an authentication request, the identity authentication request is sent to a verification server of the authentication group, and the verification server verifies the valid login credentials of the user to determine the login result.
[0063] In an exemplary embodiment, if the identity verification request is an authentication request, the verification server number is determined by load balancing, and the server address corresponding to the verification server number is obtained from the address table.
[0064] Specifically, the load balancing method is to balance and distribute the work tasks to multiple servers for execution. When the request initiated by the user is an authentication request, the number of the verification server corresponding to the request is determined in the load balancing method, and the address of the corresponding verification server is found in the address table of the router according to the verification server number.
[0065] In an exemplary embodiment, verifying the user's valid login credentials and determining the login result include: detecting whether the user's valid login credentials exist in the verification server; if so, determining that the user's authentication request is authenticated and returning user information; if not, redirecting the current authentication request page to a unified single sign-on page.
[0066] Specifically, when the request initiated by the user is an authentication request, the verification server corresponding to the authentication request is checked to see whether the user has valid login credentials. If so, it is determined that the user's authentication request has been authenticated and the user information is returned. If not, the current authentication request page is redirected to the unified single sign-on page.
[0067] In an exemplary embodiment, the method also includes: for any authentication group, when a verification server in the authentication group determines that a login server has failed, sending election information to other verification servers in the authentication group through the verification server; when all verification servers in the authentication group confirm that the login server has failed, determining the verification server that initiated the election information as the new login server.
[0068] Specifically, within an authentication group, both the login server and the verification server have the same user data and functions. When a verification server discovers that the login server in the group has failed, the server sends election information to other verification servers in the group. When all verification servers confirm that the login server has failed, the verification server that first initiates the election request becomes the login server and updates the address table in the authentication gateway.
[0069] In an exemplary embodiment, the server cluster may include two authentication groups, namely authentication group 1 and authentication group 2. Authentication group 1 includes login server M, verification server A and verification server B, and authentication group 2 includes login server N, verification server C and verification server D. Therefore, when a user initiates a login request, it can be processed according to the following steps:
[0070] (1) The authentication gateway in the server cluster calculates the index value of the authentication group by calculating the user name that submits the request.
[0071] (2) Find the login server address corresponding to the user request in the stored address table, and distribute the request to the server. In this embodiment, login server M is used.
[0072] (3) After the request is sent to the login server M, the login server M checks to see whether the user's account and password are correct.
[0073] (4) If the account and password are detected to be correct, the user's current login status is checked. If a valid login credential already exists, the credential is directly returned and the validity period is refreshed. At the same time, the valid login credential is synchronized to verification server A and verification server B.
[0074] (5) If there is no valid login credential, the login server M will generate a new login and synchronize the token to the verification server A and verification server B.
[0075] In an exemplary embodiment, Figure 1 As shown in the figure, when a user initiates an authentication request, it is processed according to the following steps:
[0076] (1) The authentication gateway in the server cluster calculates the index value of the authentication group by calculating the user name that submits the request.
[0077] (2) Find the authentication server address list corresponding to the request in the stored address table, and use the polling load balancing strategy to access it. In this embodiment, authentication server A is used.
[0078] (3) Verify that Server A checks whether there are valid login credentials.
[0079] (5) If no valid login credentials are found or the valid login credentials have expired, the current authentication request page will be redirected to the unified single sign-on page. If a valid login credential is found, the user information will be returned.
[0080] When applying the single sign-on method based on a server cluster provided by the present invention, it is not necessary to Figure 1 The steps are executed in the order shown. The specific execution order of the steps can be determined according to needs, and the present invention does not limit this.
[0081] The above is a single sign-on method based on a server cluster provided by one or more embodiments of the present invention. Based on the same idea, the present invention also provides a corresponding single sign-on device based on a server cluster, such as Figure 3 shown.
[0082] Figure 3 A schematic diagram of a single sign-on device based on a server cluster provided by the present invention includes:
[0083] The calculation module 301 is used to calculate the authentication group index number according to the user's username in response to the identity authentication request initiated by the user;
[0084] The sending module 302 is used to send the identity authentication request to the authentication group corresponding to the server cluster according to the authentication group index number; the server cluster includes multiple authentication groups, each authentication group includes a login server and multiple verification servers;
[0085] The first determination module 303 is used to send the identity authentication request to the login server of the authentication group when the identity authentication request is a login request, detect the login information of the user through the login server, and determine the login result;
[0086] The second determination module 304 is used to send the identity authentication request to the verification server of the authentication group when the identity authentication request is an authentication request, verify the valid login credentials of the user through the verification server, and determine the login result.
[0087] For the specific definition of a single sign-on device based on a server cluster, please refer to the definition of a single sign-on method based on a server cluster above, which will not be repeated here. Each module in the above-mentioned single sign-on device based on a server cluster can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0088] The present invention also provides a computer-readable storage medium, which stores a computer program, which can be used to execute the above Figure 1 A single sign-on method based on server cluster is provided.
[0089] The present invention also provides Figure 4 The structural diagram of the computer device shown in FIG. Figure 4 As shown in the figure, at the hardware level, the computer device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to achieve the above Figure 1 A single sign-on method based on server cluster is provided.
[0090] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided by the present invention can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0091] The technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of the present invention.
Claims
1. A single sign-on method based on a server cluster, characterized in that: include: In response to an identity authentication request initiated by a user, obtaining a decimal number corresponding to the last character of the user name; Perform a modulo operation on the decimal number and the number of authentication groups in the server cluster to obtain the authentication group index number; According to the authentication group index number, the identity authentication request is sent to the authentication group corresponding to the server cluster; the server cluster includes multiple authentication groups, each authentication group includes a login server and multiple verification servers; When the identity authentication request is a login request, the identity authentication request is sent to a login server of the authentication group, and the login information of the user is detected by the login server to determine the login result; When the identity verification request is an authentication request, the identity verification request is sent to a verification server of the authentication group, and the verification server verifies the valid login credentials of the user to determine the login result.
2. The method according to claim 1, characterized in that The method further comprises: Searching the server address corresponding to the identity authentication request from the address table of the authentication group; The identity authentication request is distributed to the server corresponding to the server address.
3. The method according to claim 2, characterized in that The searching the address of the server corresponding to the identity authentication request from the address table of the authentication group includes: If the identity authentication request is a login request, obtaining a server address of the login server from the address table; If the identity verification request is an authentication request, the verification server number is determined by load balancing, and the server address corresponding to the verification server number is obtained from the address table.
4. The method according to claim 1, characterized in that The method further comprises: For any authentication group, when a verification server in the authentication group determines that the login server has failed, election information is sent to other verification servers in the authentication group through the verification server. When all verification servers in the authentication group confirm that the login server has failed, the verification server that initiated the election information is determined as the new login server.
5. The method according to claim 1, characterized in that The login information includes an account number and a password; the detecting the login information of the user and determining the login result includes: Check whether the user's account and password are correct, and if so, check whether the user's valid login credentials exist in the login server; If the valid login credential exists, the validity period of the valid login credential is refreshed and the valid login credential is synchronized to multiple verification servers within the authentication group to which it belongs; if the valid login credential does not exist, a valid login credential for the user is generated and the valid login credential is synchronized to multiple verification servers within the authentication group to which it belongs.
6. The method according to claim 1, characterized in that The verifying the valid login credentials of the user and determining the login result includes: Check whether there is a valid login credential of the user in the verification server. If so, determine that the authentication request of the user is authenticated and return the user information. If not, redirect the current authentication request page to the unified single sign-on page.
7. A single sign-on device based on a server cluster, characterized in that: include: A calculation module, configured to obtain, in response to an identity authentication request initiated by a user, a decimal number corresponding to the last character of the user name; Perform a modulo operation on the decimal number and the number of authentication groups in the server cluster to obtain the authentication group index number; A sending module, used for sending the identity authentication request to the authentication group corresponding to the server cluster according to the authentication group index number; The server cluster includes multiple authentication groups, each authentication group includes a login server and multiple verification servers; A first determination module is used for, when the identity authentication request is a login request, sending the identity authentication request to a login server of the authentication group, detecting the login information of the user through the login server, and determining a login result; The second determination module is used to send the identity authentication request to the verification server of the authentication group when the identity authentication request is an authentication request, verify the valid login credentials of the user through the verification server, and determine the login result.
8. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
9. A computer device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Single sign-on method and system
CN117375886A