Cross-domain account management methods, devices, equipment, media and products
By constructing an account model that links users together, the problem of achieving unified account authentication and cross-domain data access without modifying the data domain interface is solved, thus realizing secure and stable cross-domain access and permission management.
Patent Information
- Application Number
- CN202411455475.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-10-17
AI Technical Summary
Existing technologies cannot achieve unified account authentication and cross-domain data access without modifying the interfaces of each data domain, and cannot meet the permission management needs of different types of employees.
Construct an account model that links user information into primary, secondary, and secondary accounts. Determine the account information of the first network terminal through centralized authentication requests, match and log in to the account information of the second network terminal, and enable switching between different data domains and business systems.
Unified authentication and cross-domain data access were achieved without modifying the interfaces of each data domain, which improved the security and stability of the system and met the permission management needs of different types of employees.
Smart Images

Figure CN119363409B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and in particular relates to a method, apparatus, device, medium and product for cross-domain account management. Background Technology
[0002] With the development of information technology at present, people are becoming increasingly dependent on information technology and information systems in their production and life. However, data from a single department is increasingly unable to meet people's information requirements, so information sharing across units, organizations, and information domains is needed.
[0003] To facilitate cross-domain access for users, a current approach involves building a unified authentication system, a unified user organizational structure, and a unified information push platform to achieve unified authentication and cross-domain access. However, this unified access method requires modifying the interfaces of various unit systems to achieve a unified, standardized interface, resulting in high construction costs and timelines. Furthermore, it cannot meet the needs of managing access permissions for different types of employees.
[0004] Therefore, it is crucial to ensure unified account authentication and cross-domain data access without modifying the interfaces of each data domain. Summary of the Invention
[0005] This application provides a method, apparatus, device, storage medium, and computer program product for cross-domain account management, in order to solve the technical problem in the related art that it is impossible to achieve unified account authentication and cross-domain data access without modifying the interfaces of each data domain.
[0006] In a first aspect, embodiments of this application provide a cross-domain account management method, applied to a user management system, wherein the user management system is associated with multiple data domains, and each data domain includes multiple business systems, the method comprising:
[0007] Upon receiving a centralized authentication request, the account information corresponding to the first network terminal currently logged in by the user is determined. The centralized authentication request is used to instruct the user to access the second network terminal from the first network terminal. Both the first and second network terminals include any one of the user management system, data domain, and business system.
[0008] Based on the account information corresponding to the first network terminal, the account information corresponding to the second network terminal is matched in the account model. The account model includes the user's main account information, secondary account information, and secondary account information. The main account information is associated with at least one secondary account information, and the secondary account information is associated with at least one secondary account information. The main account information is the account information corresponding to the user management system, the secondary account information is the account information corresponding to the data domain, and the secondary account information is the account information corresponding to the business system.
[0009] Log in to the second network terminal using the account information corresponding to the second network terminal.
[0010] Secondly, embodiments of this application provide a cross-domain account management device, the device comprising:
[0011] The determination module is used to determine the account information corresponding to the first network terminal currently logged in by the user when a centralized authentication request is received. The centralized authentication request is used to instruct the user to access the second network terminal from the first network terminal. Both the first network terminal and the second network terminal include any one of the user management system, data domain and business system.
[0012] The matching module is used to match the account information of the second network terminal in the account model based on the account information of the first network terminal. The account model includes the user's main account information, sub-account information and slave account information. The main account information is associated with at least one sub-account information and the sub-account information is associated with at least one slave account information. The main account information is the account information corresponding to the user management system, the sub-account information is the account information corresponding to the data domain, and the slave account information is the account information corresponding to the business system.
[0013] The login module is used to log in to the second network terminal based on the account information corresponding to the second network terminal.
[0014] Thirdly, embodiments of this application provide an electronic device, the device comprising:
[0015] Processor and memory storing programs or instructions;
[0016] The processor implements the above methods when executing programs or instructions.
[0017] Fourthly, embodiments of this application provide a machine-readable storage medium storing a program or instructions that, when executed by a processor, implement the method described above.
[0018] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the above-described method.
[0019] This application, upon receiving a centralized authentication request, determines the account information corresponding to the user's currently logged-in primary network endpoint. Based on this account information, it matches the account information for the secondary network endpoint within the account model, and then logs in to the secondary network endpoint based on that same information. By constructing an account model that links user-related primary, secondary, and secondary account information, and establishing a mapping between account information and the user management system, this application enables switching between different data domains and business systems, ensuring unified authentication and cross-domain data access without requiring modifications to the interfaces of each data domain. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a flowchart illustrating a cross-domain account management method according to an embodiment of the present invention;
[0022] Figure 2 This is a schematic diagram of an account model according to an embodiment of the present invention;
[0023] Figure 3 This is a flowchart illustrating the creation of an account model according to an embodiment of the present invention;
[0024] Figure 4 This is a schematic diagram of a process for locking an account according to an embodiment of the present invention;
[0025] Figure 5 This is a schematic diagram of a process for creating a new account according to an embodiment of the present invention;
[0026] Figure 6 This is a schematic diagram of a process for changing an account according to an embodiment of the present invention;
[0027] Figure 7 This is a structural block diagram of a cross-domain account management device according to an embodiment of the present invention;
[0028] Figure 8 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0029] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0030] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0031] Furthermore, it should be noted that the acquisition, storage, use, and processing of data in the embodiments of this application all comply with the relevant provisions of national laws and regulations. It should also be noted that certain software, components, models, and other existing industry solutions may be mentioned in the embodiments of this application. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.
[0032] To address the problems in the existing technology, this application provides a method for cross-domain account management. Figure 1 This is a flowchart illustrating a cross-domain account management method according to an embodiment of the present invention, as shown below. Figure 1 As shown, this cross-domain account management method may include the following steps:
[0033] S110, upon receiving a centralized authentication request, determines the account information corresponding to the first network terminal currently logged in by the user.
[0034] In S110, a centralized authentication request can be used to instruct a user to access a second network terminal from a first network terminal. The first and second network terminals can be any one of the user management system, data domain, and business system. The centralized authentication request enables a user to switch from the currently logged-in first network terminal to another network terminal.
[0035] In this embodiment, the relationship between the user management system, data domains, and business systems can be as follows: the user management system is associated with multiple data domains, and each data domain includes multiple business systems.
[0036] For example, a user management system can be a unified authentication system, a single data domain can be a data platform representing a unit or organization, and a single business system can be an application system within the data platform.
[0037] Understandably, by tracing the request port of the centralized authentication request, it is possible to determine the first network terminal currently logged in by the user who sent the centralized authentication request, and further determine the account information corresponding to the user's first network terminal.
[0038] S120: Based on the account information corresponding to the first network terminal, match the account information corresponding to the second network terminal in the account model.
[0039] In S120, the account model can be an account model constructed according to preset rules, used to assign an account to each legally registered user. Figure 2 This is a schematic diagram of an account model according to an embodiment of the present invention, such as... Figure 2 As shown, the account model can include primary account information, secondary account information, and secondary account information. Each user can be associated with one primary account, each primary account can be associated with m secondary accounts, and each secondary account can be associated with n secondary accounts, where m and n are positive integers.
[0040] The account information can correspond to the web interface. The primary account information is the account information corresponding to the user management system, the secondary account information is the account information corresponding to the data domain, and the auxiliary account information is the account information corresponding to the business system. It can be understood that, depending on the maturity of the data domain construction, the data domain can be divided into newly built data domains and already built data domains. In the case of a data domain that has been built, the secondary account information can be the self-coded information that each data domain already has. It can also be understood that a data domain that has been built can include multiple already built business systems, and the auxiliary account information can be the business system accounts that have been uniformly managed by each business system.
[0041] For example, in the scenario of assigning an account to a new user, Figure 3 This is a flowchart illustrating the creation of an account model according to an embodiment of the present invention, such as... Figure 3 As shown, the user management system can obtain the employee number from the group's centralized human resources management system as the main account information of the new user. For example, the main account information of the user with employee number E0000000001 is E0000000001.
[0042] The management terminal of the data domain can associate the original account information of the data domain with the primary account information to obtain the secondary account information. For example, the account number of the user with employee number E0000000001 in the original account information of data domain B is B0000000001. After associating the primary account information with the original account information, the secondary account information obtained is BE0000000001.
[0043] The management terminal of the data domain can also obtain slave account information based on the original account of the application system in the data domain according to the preset coding rules. For example, the original account of the user with employee number E0000000001 in business system A of data domain B is BE0000000001A, and the obtained slave account information is BE0000000001AC.
[0044] In this way, by constructing the account model, it is possible to match the account information corresponding to the second network from the account information corresponding to the first network, thereby enabling users to switch from the first network to the second network and achieve cross-domain access to data.
[0045] S130, Log in to the second network terminal based on the account information corresponding to the second network terminal.
[0046] In S130, after obtaining the account information of the second network terminal, you can log in to the second network terminal based on the account information corresponding to the second network terminal.
[0047] In this embodiment, if the first network terminal is a business system, when a user logs into the second network terminal from the first network terminal, the system can first determine whether the account information status is locked. If the account information status is locked, the system can return information that the user's account is locked to the business system.
[0048] If the account information is not in a locked state and the account information is correct, the number of times the account has successfully logged in can be counted. If the number of times exceeds this count, the account information is invalid, and a message indicating that the user account information has expired can be returned to the business system.
[0049] If the account information is not locked, the account information is correct, and the account information is not expired, it can be analyzed whether the account information is low-security level. If the account information is low-security level, a message to modify the account information can be returned to the business system.
[0050] After logging into the second network terminal based on the account information corresponding to the second network terminal, the user management system can record login logs to achieve single sign-on for users.
[0051] In this embodiment, upon receiving a centralized authentication request, the account information corresponding to the user's currently logged-in first network terminal is determined. Based on the account information corresponding to the first network terminal, the account information corresponding to the second network terminal is matched in the account model. Then, the user logs into the second network terminal based on the account information corresponding to the second network terminal. This application constructs an account model with interconnected primary, secondary, and secondary account information for users, and establishes a correspondence between account information and the user management system. This enables switching between different data domains and different business systems, ensuring unified authentication and cross-domain data access without requiring modifications to the interfaces of each unit.
[0052] In some embodiments, account information includes username and password. Logging into the second network terminal based on the account information corresponding to the second network terminal includes:
[0053] If the password and account do not match, and the number of times the password and account do not match exceeds a preset threshold, an account lockout request is generated. The account lockout request is used to request the lockout of the account information corresponding to the second network terminal.
[0054] Send the account lockout request to the management terminal of the user management system;
[0055] Receive the first approval result from the management terminal of the user management system;
[0056] If the first approval is successful, execute the account lockout request.
[0057] In this embodiment, the account lockout request can also be made based on the user's request. For example, if a user leaves the company or changes positions, the user can make an account lockout request for the account information corresponding to the second network terminal that is no longer in use.
[0058] Thus, by locking the account information corresponding to the second network terminal when the account and password do not match, the data security of the user management system, data domain and business system can be improved.
[0059] In some embodiments, when the account information corresponding to the locked second network terminal is slave account information, upon approval of the first approval result, the account lock request is executed, including:
[0060] If the first approval result is passed, determine whether the business type of the business system corresponding to the account information conforms to the preset business type;
[0061] If the business type of the business system corresponding to the account information matches the preset business type, determine whether the task in the business system has been completed; if the task in the business system has been completed, lock the account information.
[0062] In this embodiment, the business types of the business system can be divided into two categories: one is a business system that is of high importance and requires monitoring and approval by the administrator of the data domain management terminal, and the other is a business system that does not require monitoring and approval by the data domain administrator. The preset business type can be a business system that is of high importance and requires monitoring and approval by the administrator of the data domain management terminal. When the business type of the business system corresponding to the account information meets the preset business type, the data domain administrator needs to monitor whether the task of the slave account in the business system has been completed. When the task in the business system has been completed, the administrator of the data domain management terminal can lock the slave account information.
[0063] Figure 4 This is a schematic diagram of a process for locking an account according to an embodiment of the present invention, such as... Figure 4 As shown in S410, the user management system initiates an account lockout process internally;
[0064] S420, determine the application type. If the application type is push to do, then execute S430. If the application type is direct locking, then execute S460.
[0065] In this embodiment, the application type is also the business type; push-to-handle means that the locking process is handled by the administrator of the data domain management terminal; direct locking means that the locking process can be directly executed by the user management system.
[0066] S430, pushes account lock-up agency information;
[0067] The user management system pushes the errand information to the data domain management terminal.
[0068] S440, asynchronous processing by application administrators in the data domain;
[0069] The application administrator of the data domain is the same as the administrator of the data domain management terminal. The administrator of the data domain management terminal can manage the approval of the data domain and the approval of the business systems associated with the data domain.
[0070] S450, Application Administrator of Data Domain Ends Delegation;
[0071] S460, the system has locked the account;
[0072] S470, the lock was successfully marked.
[0073] The business management system records information about locked accounts.
[0074] In this way, by executing different binding processes on the account information corresponding to business systems with different business types, for business systems of high importance, the administrator of the data domain management terminal monitors and reviews the task execution status of the account in the business system, ensuring that the account is locked only after the task is fully completed and approved. This can effectively prevent account locking due to misoperation or failure to complete important tasks, and improve the security and stability of the business system.
[0075] In some embodiments, the method further includes:
[0076] If all secondary accounts associated with the primary account information have been locked, then the primary account information will be locked.
[0077] If all secondary accounts associated with the primary account have been locked, then the primary account will be locked.
[0078] In this embodiment, a user's account can be locked according to the scope of the account lock request. The account lock request can lock all of the user's accounts, including primary account information, secondary account information, and secondary account information, or it can lock only some of the user's accounts.
[0079] Understandably, an account lockout request cannot lock a sub-account information without locking all the sub-account information associated with it, nor can it lock a master account information without locking all the sub-account information associated with it. Otherwise, it will be impossible to switch to an unlocked sub-account information associated with the sub-account information or an unlocked sub-account information associated with the master account information based on the centralized authentication request.
[0080] This avoids locking conflicts or confusion caused by improper account locking order. Furthermore, the layered locking mechanism (from account information to sub-account information to main account information) ensures the overall security of the user management system.
[0081] In some embodiments, the method further includes:
[0082] Upon receiving an account operation request, the account operation request is sent to the management terminal of the user management system. The account operation request includes at least one of an account change request and an account creation request.
[0083] Receive the second approval result from the management terminal of the user management system;
[0084] If the second approval result is approved, execute the account operation request.
[0085] In this embodiment, the user management system can approve account operation requests based on the following constraints. If an account operation request does not meet the following constraints, the management terminal of the user management system can provide a second approval result indicating disapproval:
[0086] First, a request to change or create a sub-account cannot be mutually exclusive with existing sub-account attributes. For example, if the data domain is Finance Department, the sub-accounts have two attributes: Accountant and Auditor. These two attributes are mutually exclusive, and a user cannot have sub-accounts with both attributes simultaneously through a request to change or create a sub-account.
[0087] Secondly, a user's account change request or account creation request cannot cause the number of sub-accounts to exceed the preset limit. For example, if the system stipulates that a user's main account information can be associated with 5 sub-accounts, and each sub-account information can be associated with 10 sub-accounts, then the user cannot use an account change request or account creation request to cause a single sub-account information to be associated with more than 10 sub-accounts.
[0088] Finally, requests to change or create a sub-account must meet certain prerequisites. For example, there are hierarchical relationships between different sub-accounts. If a user wants to change or create a higher-level sub-account, they need to obtain a lower-level sub-account first.
[0089] In this way, by setting constraints on account operation requests, the rationality of user account permissions and account structure can be controlled, ensuring the security and stability of the system. These constraints not only prevent potential resource abuse and misconfiguration but also promote the standardization and automation of the account management system.
[0090] In some embodiments, if the second approval result is passed, executing an account operation request includes:
[0091] In the case of account operation requests including account creation requests, account information is generated according to preset encoding rules;
[0092] Parse the account creation request to obtain the target sub-account information to be associated with the account information;
[0093] The account information will be linked with the target sub-account information.
[0094] If the account operation request includes an account change request, parse the account change request to obtain the initial account information;
[0095] Based on the change request from the initial slave account information, the target slave account information is obtained.
[0096] Figure 5This is a schematic diagram of a process for creating a new account according to an embodiment of the present invention, such as... Figure 5 As shown, S510 initiates the account creation process;
[0097] If the request to create an account is received as a request to create a new account, the request to create an account is sent to the management terminal of the user management system, and the second approval result is received from the management terminal of the user management system; if the second approval result is approved, the request to create an account is executed.
[0098] S520, complete account creation;
[0099] Sub-account information can be generated according to preset coding rules, where the preset coding rules can be set to obtain sub-account information based on the coding combination of the business system corresponding to the sub-account information and the sub-account information.
[0100] S530, storage binding relationship;
[0101] Parse the account creation request to obtain the target sub-account information to be associated with the account information; then associate the account information with the target sub-account information.
[0102] S540, push account information.
[0103] After completing the request to create a new account, the newly created account information can be returned to the client that the user is using.
[0104] Figure 6 This is a schematic diagram of a process for changing an account according to an embodiment of the present invention, such as... Figure 6 As shown, S610 initiates the account change process;
[0105] If the request to operate from an account is a request to change an account, the request to change an account is sent to the management terminal of the user management system, and the second approval result is received from the management terminal of the user management system; if the second approval result is approved, the request to operate from an account is executed.
[0106] S620, complete the account information change;
[0107] The initial slave account information can be obtained by parsing the slave account change request; then, the initial slave account information can be changed according to the slave account change request to obtain the target slave account information.
[0108] S630, stores changed data;
[0109] S640, push account information.
[0110] After completing the account change request, the target of the change can be returned from the account information to the web application that the user is currently using.
[0111] It is understandable that the above methods for changing and creating accounts can also be applied to changing and creating secondary account information and primary account information.
[0112] In this way, by setting the methods for changing and creating primary account information, secondary account information, and secondary account information in the account model, flexible control over the user's account model is achieved.
[0113] Figure 7 A schematic diagram of the structure of a cross-domain account management device provided in another embodiment of this application is shown. For ease of explanation, only the parts related to the embodiments of this application are shown.
[0114] Reference Figure 7 The cross-domain account management device 700 may include:
[0115] The determination module 701 is used to determine the account information corresponding to the first network terminal currently logged in by the user when a centralized authentication request is received. The centralized authentication request is used to instruct the user to access the second network terminal from the first network terminal. Both the first network terminal and the second network terminal include any one of the user management system, data domain and business system.
[0116] The matching module 702 is used to match the account information of the second network terminal in the account model based on the account information of the first network terminal. The account model includes the user's main account information, sub-account information and slave account information. The main account information is associated with at least one sub-account information and the sub-account information is associated with at least one slave account information. The main account information is the account information corresponding to the user management system, the sub-account information is the account information corresponding to the data domain, and the slave account information is the account information corresponding to the business system.
[0117] The login module 703 is used to log in to the second network terminal based on the account information corresponding to the second network terminal.
[0118] In some embodiments, the login module 703 may include the following units:
[0119] The generation unit is used to generate an account lock request when the password and account do not match, and the number of times the password and account do not match exceeds a preset threshold. The account lock request is used to request the lock of the account information corresponding to the second network terminal.
[0120] The sending unit is used to send the account lockout request to the management terminal of the user management system;
[0121] The receiving unit is used to receive the first approval result from the management terminal of the user management system;
[0122] The execution unit is used to execute the account lockout request if the first approval result is passed.
[0123] In some embodiments, the execution unit described above may include the following units:
[0124] The sub-unit is used to determine whether the business type of the business system corresponding to the secondary account information conforms to the preset business type when the account information corresponding to the secondary network terminal is locked as secondary account information and the first approval result is passed.
[0125] The sub-unit is also used to determine whether the task in the business system has been completed if the business type of the business system corresponding to the account information matches the preset business type.
[0126] The locking subunit is used to lock account information after the task in the business system has been completed.
[0127] In some embodiments, the locking subunit described above can also be used for:
[0128] If all secondary accounts associated with the primary account information have been locked, then the primary account information will be locked.
[0129] If all secondary accounts associated with the primary account have been locked, then the primary account will be locked.
[0130] In some embodiments, the cross-domain account management device described above may further include the following modules:
[0131] The sending module is used to send an account operation request to the management terminal of the user management system for approval when an account operation request is received. The account operation request includes at least one of an account change request and an account creation request.
[0132] The receiving module is used to receive the second approval result from the management terminal of the user management system;
[0133] The execution module is used to execute account operation requests if the second approval result is passed.
[0134] In some embodiments, the execution module described above may include the following units:
[0135] The generation unit is used to generate slave account information according to preset encoding rules when slave account operation requests include slave account creation requests;
[0136] The parsing unit is used to parse the account creation request to obtain the target sub-account information to be associated with the sub-account information;
[0137] The association unit is used to associate account information with target sub-account information.
[0138] The parsing unit is also used to parse the sub-account change request to obtain the initial sub-account information when the sub-account operation request includes a sub-account change request;
[0139] The change unit is used to change the initial slave account information according to the slave account change request to obtain the target slave account information.
[0140] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. They are devices corresponding to the above-mentioned cross-domain account management method. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of this device. For details on its specific functions and the technical effects it brings, please refer to the method embodiment section. It will not be repeated here.
[0141] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0142] Figure 8 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention, such as... Figure 8 As shown:
[0143] The device may include a processor 801 and a memory 802 storing programs or instructions.
[0144] When processor 801 executes the program, it implements the steps in any of the above method embodiments.
[0145] For example, the program can be divided into one or more modules / units, one or more of which are stored in memory 802 and executed by processor 801 to complete this application. The one or more modules / units can be a series of program instruction segments capable of performing a specific function, which describe the execution process of the program in the device.
[0146] Specifically, the processor 801 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0147] Memory 802 may include mass storage for data or instructions. For example, and not limitingly, memory 802 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 802 may include removable or non-removable (or fixed) media. Where appropriate, memory 802 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 802 is non-volatile solid-state memory.
[0148] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) machine-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.
[0149] The processor 801 implements any of the methods described in the above embodiments by reading and executing programs or instructions stored in the memory 802.
[0150] In one example, the electronic device may also include a communication interface 803 and a bus 804. The processor 801, memory 802, and communication interface 803 are connected via the bus 804 and communicate with each other.
[0151] The communication interface 803 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0152] Bus 804 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 804 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0153] Furthermore, in conjunction with the methods in the above embodiments, this application embodiment can provide a machine-readable storage medium for implementation. This machine-readable storage medium stores a program or instructions; when executed by a processor, the program or instructions implement any of the methods in the above embodiments. This machine-readable storage medium can be read by a machine such as a computer.
[0154] This application also provides a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled. The processor is used to run programs or instructions to implement the various processes of the above method embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0155] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0156] This application provides a computer program product stored in a machine-readable storage medium. The program product is executed by at least one processor to implement the various processes of the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be described again here.
[0157] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0158] The functional modules shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on machine-readable media or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable media" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer grids such as the Internet, intranets, etc.
[0159] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0160] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by a computer program or instructions. These programs or instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0161] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for cross-domain account management, characterized in that, Applied to a user management system, which is associated with multiple data domains, each data domain including multiple business systems, the method includes: Upon receiving a centralized authentication request, the account information corresponding to the first network terminal currently logged in by the user is determined. The centralized authentication request is used to instruct the user to access the second network terminal from the first network terminal. Based on the account information corresponding to the first network terminal, the account information corresponding to the second network terminal is matched in the account model. The account model includes the user's main account information, secondary account information, and secondary account information. The main account information is associated with at least one of the secondary account information, and the secondary account information is associated with at least one secondary account information. The main account information is the account information corresponding to the user management system, the secondary account information is the account information corresponding to the data domain, and the secondary account information is the account information corresponding to the business system. Log in to the second network client based on the account information corresponding to the second network client.
2. The method according to claim 1, characterized in that, The account information includes a username and password. Logging into the second network terminal based on the account information corresponding to the second network terminal includes: If the password does not match the account and the number of times the password does not match the account exceeds a preset threshold, an account lock request is generated. The account lock request is used to request the lock of the account information corresponding to the second network terminal. Send the account lockout request to the management terminal of the user management system; Receive the first approval result from the management terminal of the user management system; If the first approval result is passed, the account lockout request is executed.
3. The method according to claim 2, characterized in that, When the account information corresponding to the second network terminal is secondary account information, the step of executing the account lock request after the first approval result is passed includes: If the first approval result is passed, determine whether the business type of the business system corresponding to the account information conforms to the preset business type; If the business type of the business system corresponding to the slave account information matches the preset business type, determine whether the task in the business system has been completed; if the task in the business system has been completed, lock the slave account information.
4. The method according to claim 3, characterized in that, The method further includes: If all secondary accounts associated with the first secondary account information have been locked, then the first secondary account information will be locked. If all sub-accounts associated with the primary account information have been locked, then the primary account information will be locked.
5. The method according to claim 1, characterized in that, The method further includes: Upon receiving an account operation request, the account operation request is sent to the management terminal of the user management system. The account operation request includes at least one of an account change request and an account creation request. Receive the second approval result from the management terminal of the user management system; If the second approval result is approved, the account operation request is executed.
6. The method according to claim 5, characterized in that, If the second approval result is passed, executing the account operation request includes: If the sub-account operation request includes the sub-account creation request, sub-account information is generated according to a preset encoding rule; Parse the new account creation request to obtain the target sub-account information to be associated with the sub-account information; Associate the sub-account information with the target sub-account information; If the sub-account operation request includes the sub-account change request, the sub-account change request is parsed to obtain the initial sub-account information; The initial slave account information is changed according to the slave account change request to obtain the target slave account information.
7. A cross-domain account management device, characterized in that, The device includes: The determination module is used to determine the account information corresponding to the first network terminal currently logged in by the user when a centralized authentication request is received. The centralized authentication request is used to instruct the user to access the second network terminal from the first network terminal. The first network terminal and the second network terminal both include any one of the user management system, data domain and business system. The matching module is used to match the account information corresponding to the second network terminal in the account model based on the account information corresponding to the first network terminal. The account model includes the user's main account information, secondary account information, and secondary account information. The main account information is associated with at least one of the secondary account information, and the secondary account information is associated with at least one secondary account information. The main account information is the account information corresponding to the user management system, the secondary account information is the account information corresponding to the data domain, and the secondary account information is the account information corresponding to the business system. The login module is used to log in to the second network terminal based on the account information corresponding to the second network terminal.
8. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the method as described in any one of claims 1-6.
10. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-6.
Citation Information
Patent Citations
Cross-domain single point login system and method based on SAML
CN104301418A
Method, device and equipment for cross-domain single sign-on
CN114692118A