Cloud application access control method, device, equipment, storage medium and program product

By integrating cloud application authentication information and controlling access based on authentication results, the low efficiency and complexity of cloud applications when connecting to the authentication systems of license holders in different provinces were solved, and an efficient and secure authentication process was achieved.

CN119520024BActive Publication Date: 2025-10-03CHINA MOBILE COMM GRP TERMINAL +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411465608.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-21
Publication Date
2025-10-03
Estimated Expiration
2044-10-21

AI Technical Summary

Technical Problem

When existing cloud applications connect to the license authentication systems of different provinces, they face problems such as cumbersome authentication processes, low efficiency, high complexity, great compliance challenges, interface compatibility issues, and limited scalability.

Method used

By integrating and processing cloud application authentication information and sending the integrated and processed authentication information to at least one authentication system, access to the target cloud application is controlled according to the authentication result, thereby reducing multiple authentication requests.

Benefits of technology

It improves the certification efficiency of cloud applications, reduces development and maintenance costs, simplifies the certification process, and enhances security and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520024B_ABST
    Figure CN119520024B_ABST
Patent Text Reader

Abstract

This application discloses a cloud application access control method, apparatus, device, storage medium, and program product, belonging to the field of communication security technology. The method comprises: in response to a target cloud application startup operation, obtaining an identity authentication request sent by the target cloud application; integrating and processing cloud application authentication information corresponding to the identity authentication request, sending the integrated and processed cloud application authentication information to at least one authentication system corresponding to the target cloud application, obtaining a cloud application authentication result returned by the at least one authentication system; and controlling access to the target cloud application based on the cloud application authentication result. This approach can reduce multiple authentication requests between different authentication systems and improve cloud application authentication efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication security technology, and in particular to a cloud application access control method, apparatus, device, storage medium, and program product. Background Art

[0002] With the advancement of internet technology, the widespread adoption of fiber-optic home internet access, and the continued maturity of end-to-end cloud technology, more and more cloud applications are being launched in various provinces. However, with the expansion of cloud applications, the demand for certification services tailored to each province is also increasing. Because each province has its own unique licensing schemes and certification methods, cloud applications must adapt to the schemes provided by each licensing scheme when integrating with certification services.

[0003] To meet the certification requirements of these licensees, the existing technical model requires the licensee to provide an authentication interface, and the cloud application to directly connect with the licensee's authentication system. Whenever a new province goes online, the cloud application must follow the province's licensee's authentication process, undergoing development, testing, and acceptance. However, as the number of provinces online increases, especially in some provinces with multiple licensees, the authentication connection becomes increasingly complex, the authentication process becomes cumbersome, and the authentication efficiency becomes low. Summary of the Invention

[0004] The embodiments of the present application provide a cloud application access control method, apparatus, device, storage medium and program product to at least solve the problems of cumbersome authentication process and low authentication efficiency in the process of docking authentication of existing cloud applications.

[0005] In order to solve the above technical problems, this application is implemented as follows:

[0006] In a first aspect, an embodiment of the present application provides a cloud application access control method, comprising: in response to a startup operation of a target cloud application, obtaining an identity authentication request sent by the target cloud application; integrating and processing the cloud application authentication information corresponding to the identity authentication request, sending the integrated and processed cloud application authentication information to at least one authentication system corresponding to the target cloud application, and obtaining a cloud application authentication result returned by the at least one authentication system; and controlling access to the target cloud application based on the cloud application authentication result.

[0007] In the second aspect, an embodiment of the present application provides a cloud application access control device, including: an acquisition module, used to obtain an identity authentication request sent by the target cloud application in response to the startup operation of the target cloud application; an authentication module, used to integrate and process the cloud application authentication information corresponding to the identity authentication request, and send the integrated and processed cloud application authentication information to at least one authentication system corresponding to the target cloud application, and obtain the cloud application authentication result returned by the at least one authentication system; a control module, used to control access to the target cloud application based on the cloud application authentication result.

[0008] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect above are implemented.

[0009] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect above are implemented.

[0010] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer performs the steps of the method described in the first aspect above.

[0011] In an embodiment of the present application, in response to a startup operation of a target cloud application, an identity authentication request sent by the target cloud application is obtained; cloud application authentication information corresponding to the identity authentication request is integrated and processed, and the integrated and processed cloud application authentication information is sent to at least one authentication system corresponding to the target cloud application, and a cloud application authentication result returned by the at least one authentication system is obtained; and access to the target cloud application is controlled based on the cloud application authentication result. In this way, by integrating and processing the cloud application authentication information, sending the integrated and processed cloud application authentication information to at least one authentication system, and controlling access to the target cloud application based on the returned cloud application authentication result, multiple authentication requests between different authentication systems can be reduced, thereby improving the authentication efficiency of cloud applications.

[0012] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0014] Figure 1 A schematic diagram of the authentication architecture provided in an embodiment of the present application is shown;

[0015] Figure 2 A schematic diagram of a process for cloud application access control provided by an embodiment of the present application is shown;

[0016] Figure 3 A schematic diagram of instruction interaction of a cloud application access control method provided by an embodiment of the present application is shown;

[0017] Figure 4 A schematic diagram of a process for obtaining an encryption key according to an embodiment of the present invention is shown;

[0018] Figure 5 A schematic diagram of the information transmission process provided by an embodiment of the present application is shown;

[0019] Figure 6 A schematic diagram of the structure of a cloud application access control device provided in an embodiment of the present application is shown;

[0020] Figure 7 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0021] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0022] With the increasing number of cloud applications and the number of provinces where cloud applications are deployed, each time a cloud application is launched in a new province, it needs to connect with the license holder's certification process. According to the license holder's certification plan, targeted development, testing, and acceptance procedures must be carried out. However, as cloud applications are launched in more and more provinces, and some provinces have more than one license holder, the certification process has become more diverse, and at least the following problems exist:

[0023] (1) Increased complexity. Different licensees may have different requirements and implementation methods, which makes unified management and coordination impossible, increasing the difficulty of development and maintenance.

[0024] (2) Increased compliance challenges. Different licensees often follow their own unique regulations and standards in terms of data protection and privacy, which leads to huge compliance challenges when cloud applications are connected.

[0025] (3) There are compatibility issues with the docking interface. Different authentication systems often have different API interfaces and protocol standards, which requires a lot of interface adaptation and conversion work during the docking process. This requires developers to be familiar with and understand the interface specifications of each authentication system to ensure the correct transmission and processing of data.

[0026] (4) Complex security authentication. Each authentication system may have a unique security authentication mechanism, such as certificates and tokens, which increases the difficulty of security management.

[0027] (5) Limited scalability. Connecting to the license holder's authentication system may limit the scalability of the application. If the interface or functions provided by the license holder's authentication system are not flexible enough, it may affect the development and expansion of the application.

[0028] (6) The testing workload has increased significantly. Due to the existence of targeted development, it is necessary to conduct comprehensive testing on the connection between each authentication system and application, including normal processes and various abnormal situations, which has significantly increased the testing workload.

[0029] In response to the above-mentioned problems existing in the process of cloud application docking and authentication, an embodiment of the present application provides a cloud application access control method. This method integrates and processes cloud application authentication information, and sends the integrated and processed cloud application authentication information to at least one authentication system. Access to the target cloud application is controlled based on the returned cloud application authentication result. This can reduce multiple authentication requests between different authentication systems and improve the authentication efficiency of cloud applications.

[0030] Figure 1 A schematic diagram of the authentication architecture provided by an embodiment of the present application is shown. As shown in the figure, a user requests access to a cloud application 130 through a cloud HD client 110, and the cloud application interacts with the cloud HD client 110 for data through a cloud platform 120. The cloud HD client 110 integrates authentication interfaces of multiple authentication systems 140. When the same cloud application faces different authentication systems, it can connect to multiple authentication systems 140 through the cloud HD client 110 without the need to develop the authentication process multiple times, thereby improving the authentication efficiency of the cloud application and reducing the time and economic costs of development.

[0031] Figure 2The flowchart of the cloud application access control method provided by the embodiment of the present application is shown. The execution subject of the method can be a terminal device or a server, wherein the terminal device can be a device such as a personal computer, or a mobile terminal device such as a mobile phone, a tablet computer, a cloud HD client, etc. The terminal device can be a terminal device used by the user. The server can be an independent server or a server cluster composed of multiple servers. Moreover, the server can be a background server of a certain business or a background server of a certain platform or application (for example, a cloud HD application, etc.). In the embodiment of the present application, the execution subject is the above-mentioned Figure 1 The cloud HD client 110 in the example is used for explanation. For the server, the following related content can be used for processing, which will not be repeated here. As shown in the figure, the cloud application access control method 200 can include the following steps:

[0032] Step 201: In response to a startup operation of a target cloud application, obtain an identity authentication request sent by the target cloud application.

[0033] In a specific implementation, the user starts the target cloud application through the cloud HD client 110. After receiving the cloud application startup request initiated by the user, the HD client 110 starts the target cloud application through the cloud platform 120 and obtains the identity authentication request sent by the target cloud application. The identity authentication request may include the cloud application authentication parameters of the target cloud application, such as application name, application ID, user ID, credentials, etc.

[0034] Step 202: Integrate and process the cloud application authentication information corresponding to the identity authentication request, send the integrated cloud application authentication information to at least one authentication system corresponding to the target cloud application, and obtain the cloud application authentication result returned by the at least one authentication system.

[0035] In the specific implementation, the cloud HD client 110 integrates and processes the cloud application authentication information corresponding to the identity authentication request. The cloud application authentication information includes the authentication information, device information, timestamp, version number, encryption algorithm, etc. of the target cloud application, and then sends the integrated and processed cloud application authentication information to at least one authentication system corresponding to the target cloud application. The corresponding authentication process is executed through at least one authentication system. After the authentication process is completed, the cloud application authentication result is returned.

[0036] Step 203: Control access to the target cloud application based on the cloud application authentication result.

[0037] In a specific implementation, access to the target cloud application is controlled based on the cloud application authentication result. For example, when it is determined that the authentication is passed based on the cloud application authentication result, an indication message is sent to the target cloud application to instruct the target cloud application to execute the business corresponding to the startup operation; when it is determined that the authentication fails based on the cloud application authentication result, an indication message is sent to the target cloud application to instruct the target cloud application to execute exit processing.

[0038] In this way, by integrating and processing cloud application authentication information and sending the integrated and processed cloud application authentication information to at least one authentication system, access to the target cloud application is controlled based on the returned cloud application authentication result, multiple authentication requests between different authentication systems can be reduced, and the authentication efficiency of cloud applications can be improved.

[0039] In one possible implementation, in step 201, in response to a startup operation of a target cloud application, obtaining an identity authentication request initiated by the target cloud application includes:

[0040] In response to the startup operation of the target cloud application, the cloud application identification information of the target cloud application is obtained; the cloud application identification information is sent to the cloud platform, and the target cloud platform indicated by the cloud application identification information is started through the cloud platform to obtain the identity authentication request sent by the target cloud application.

[0041] In an embodiment of the present application, a user clicks on the entrance of the cloud HD client 110 and starts the cloud HD client 110 with cloud application identification information, wherein the cloud application identification information includes cloud application package name parameters, etc. In response to the start operation of the target cloud application, the cloud HD client 110 obtains the cloud application identification information of the target cloud application and sends the cloud application identification information to the cloud platform 120 to notify the cloud platform 120 to start the target cloud application. The cloud platform 120 starts the target cloud application indicated by the cloud application identification information in the virtual machine. When the target cloud application starts, the identity authentication request carrying the cloud application authentication parameters is passed to the cloud platform 120 through the ContentProvider. The cloud platform 120 transparently transmits the identity authentication request to the cloud HD client 110 through the end-cloud communication technology, thereby obtaining the identity authentication request sent by the target cloud application, which includes the cloud application authentication parameters of the target cloud application.

[0042] In one possible implementation, in step 203, controlling access to the target cloud application according to the cloud application authentication result includes:

[0043] When the identity authentication is successful according to the cloud application authentication result, a first indication message is sent to the target cloud application, and cloud application content is generated according to the interface flow corresponding to the startup operation returned by the target cloud application;

[0044] When it is determined that the identity authentication has failed based on the cloud application authentication result, an authentication failure page is displayed, and a second indication message is sent to the target cloud application to cause the target cloud application to execute an exit process; wherein, the first indication message is used to indicate that the identity authentication of the target cloud application is successful, and the second indication message is used to indicate that the identity authentication of the target cloud application has failed.

[0045] In an exemplary embodiment, Figure 3 As shown in , the above cloud application access control method may include the following steps:

[0046] Step 301: The user clicks on the entrance of the cloud HD client 110 and starts the cloud HD client 110 with the cloud application identification information, wherein the cloud application identification information includes cloud application package name parameters, etc.;

[0047] Step 302: The cloud HD client notifies the cloud platform 120 to start the target cloud application through the end-cloud communication technology;

[0048] Step 303: The cloud platform 120 starts the target cloud application indicated by the cloud application identification information in the virtual machine;

[0049] Step 304: When the target cloud application is started, its cloud application authentication parameters are passed to the cloud platform 120 via ContentProvider;

[0050] Step 305: The cloud platform 120 transparently transmits the cloud application authentication parameters to the cloud HD client 110 via the end-cloud communication technology;

[0051] Step 306: The cloud HD client 110 integrates the cloud application authentication information and initiates a cloud application authentication request to the authentication system based on the license holder version;

[0052] Step 307: The authentication system returns the cloud application authentication result to the cloud HD client 110;

[0053] Step 308: After receiving the cloud application authentication result, the cloud HD client 110 determines whether the authentication is successful or failed;

[0054] Step 309: If the cloud application authentication fails, the cloud HD client 110 displays an authentication failure page and transparently transmits a second indication message through the end-cloud communication technology, where the second indication message is used to indicate that the identity authentication of the target cloud application has failed.

[0055] Step 310: The cloud platform 120 notifies the target cloud application of the second indication message through ContentProvider;

[0056] Step 311: The target cloud application automatically exits after receiving the second instruction message;

[0057] Step 312: If the cloud application authentication is successful, the cloud HD client 110 transparently transmits a first indication message via the end-cloud communication technology; the first indication message is used to indicate that the identity authentication of the target cloud application is successful;

[0058] Step 313: The cloud platform 120 notifies the target cloud application of the first indication message through the ContentProvider;

[0059] Step 314: After receiving the first instruction message, the target cloud application normally enters the service corresponding to the startup operation and returns to the interface flow;

[0060] Step 315: The cloud platform 120 loads the interface flow returned by the target cloud application;

[0061] Step 316: The cloud platform 120 transmits the interface stream to the cloud HD client 110;

[0062] Step 317: The cloud HD client 110 displays the cloud application content.

[0063] In a possible implementation, in step 202, sending the integrated cloud application authentication information to at least one authentication system corresponding to the target cloud application includes:

[0064] The integrated cloud application authentication information is encrypted using a preset encryption key to obtain authentication encrypted data; and the authentication encrypted data is sent to the at least one authentication system.

[0065] In an embodiment of the present application, in order to ensure the security of the target cloud application during the authentication process, the cloud HD client 110 encrypts the integrated cloud application authentication information using a preset encryption key to obtain authentication encrypted data; and sends the authentication encrypted data to at least one authentication system.

[0066] Before encrypting the integrated cloud application authentication information using a preset encryption key to obtain authentication encrypted data, the method further includes:

[0067] Establish a communication link with at least one authentication system corresponding to the target cloud application; send the identity information corresponding to the identity authentication request to the at least one authentication system through the communication link; when it is determined that the identity information verification is successful, send the service authorization certificate corresponding to the identity information to obtain the encryption key of the at least one authentication system.

[0068] In the embodiment of the present application, during the cloud application authentication process between the cloud HD client 110 and the authentication system, a communication link is established between the cloud HD client 110 and at least one authentication system corresponding to the target cloud application; an encryption key of at least one authentication system is obtained through the communication link, wherein, Figure 4 As shown, the method for obtaining the encryption key includes the following steps:

[0069] Step 401: After receiving the identity authentication request from the target cloud application, the cloud HD client 110 establishes a communication link with at least one authentication system corresponding to the target cloud application. Specifically, the cloud HD client 110 sends a network connection establishment request to the authentication system and responds to the communication channel establishment success message returned by the authentication system to establish the communication link between the two.

[0070] Step 402: The cloud HD client 110 sends the identity information corresponding to the identity authentication request to the authentication system via the communication link;

[0071] Step 403: The authentication system verifies the identity information;

[0072] Step 404: If the identity information verification is successful, the service authorization certificate corresponding to the identity information is sent;

[0073] Step 405: The authentication system verifies the validity of the service authorization certificate, returns the cloud application verification result, and obtains the encryption key of the authentication system.

[0074] Furthermore, after the authorization is completed, the preset encryption key between the cloud HD client and the authentication system is used to establish an encrypted secure communication channel, and subsequent data transmission and interaction are carried out on the secure communication channel.

[0075] The above-mentioned methods for obtaining the encryption key include:

[0076] Obtain an initial key sent by the at least one authentication system; send an encryption request to the at least one authentication system, and obtain an encrypted encryption key returned by the at least one authentication system; decrypt the encrypted encryption key using the initial key to obtain the encryption key.

[0077] In the embodiment of this application, Figure 5 As shown, the method for obtaining the encryption key includes the following steps:

[0078] Step 501: When the Cloud HD client initially establishes a communication connection with the authentication system, the client exchanges necessary authentication parameters and information and agrees on an initial key.

[0079] Step 502: The Cloud HD client sends an encryption request to the authentication system using a communication protocol. The encryption request includes a message encrypted using an initial key, which is used to represent the application for the encryption key.

[0080] Step 503: After receiving the encryption request, the authentication system uses the initial key to decrypt the message, verify the validity of the encryption request, and generate an encryption key. It then encrypts the encryption key using the initial key and sends the encrypted encryption key to the Cloud HD client.

[0081] Step 504: The cloud HD client uses the initial key to decrypt the encrypted encryption key to obtain the encryption key.

[0082] Furthermore, the cloud HD client and the authentication system both have the same encryption key, completing the data communication link. Subsequent data interactions will also be encrypted and decrypted using the same communication key.

[0083] Optionally, during secure communication between Cloud HD and the authentication system, a two-phase key agreement method is implemented for mutual authentication, effectively preventing man-in-the-middle attacks. Key agreement and key verification are used to mitigate malicious man-in-the-middle attacks. During the key agreement phase, the Elliptic Curve Diffie-Hellman (ECDH)-based key exchange protocol is used to exchange public keys to negotiate a shared key. During the key verification phase, both parties perform mutual authentication to ensure a secure and reliable man-in-the-middle attack.

[0084] Specifically, a short secret key H is first shared. A collective authentication key H is obtained through methods such as device writes or OTA downloads. Two inverse values, z and -z, are then derived from the secret key H. During the key agreement phase, Cloud HD randomly selects a private key Ry and then calculates the corresponding public key Py based on the selected private key, namely, Py = (Ry + z)G, and sends it to the authentication system. The authentication system then selects a private key Rr and calculates the corresponding public key Pr, where Pr = (Rr + z)G, and sends it to the Cloud HD client. After receiving the public keys sent by both parties, X is calculated, namely, X = Pr + (-t)G = RrG. The corresponding session key Kyr is then calculated from X. The session key Kry is obtained using the same steps, where Kyr = RyX = RyRrG and Kry = RrX = RrRyG. During the key authentication phase, Cloud HD and the authentication system calculate the corresponding intermediate values ​​Ty and Tr and send them to each other for verification. The authenticity of the identity is determined by comparing the intermediate values ​​to see if they are equal. Here, Ty = zKyr = rRyRrG, and Tr = zKry = tRrRy. After both parties complete identity authentication, they have obtained the same session key. At this point, if a malicious attacker eavesdrops on the public key, without the corresponding identity password S, they will be unable to obtain the corresponding value of t and thus cannot impersonate the Cloud HD client or any party in the authentication system to cause damage, thus ensuring data security. In the above data processing, G is a public parameter, representing a base point of order n, a large prime number, and is a point on a public elliptic curve.

[0085] In a further embodiment, in order to improve the security during data transmission, compared with the inherent encryption methods in the prior art, the embodiment of the present application adopts a dynamic encryption method for encryption during data transmission. In the stage facing data encryption needs, data encryption is achieved by randomly calling the encryption method, thereby avoiding others' malicious speculation and tampering with the data during transmission, and effectively ensuring the security of data transmission.

[0086] Specifically, within the Cloud HD client, different encryption methods are integrated through program encapsulation. Functional programs are named and ranked using an encryption + numerical ranking method. When data encryption is required, the encryption module is called by first calling a random generation function to generate a random number. Then, based on the random value, the corresponding encryption module is called to encrypt the data being transmitted. In a further embodiment, to ensure secure interaction between the Cloud HD client and the authentication system, a preset update time period can be set, with both parties regularly updating and maintaining their digital certificates and keys after a certain period of time.

[0087] Figure 6The structure diagram of the cloud application access control device provided by the embodiment of the present application is shown. The cloud application access control device can implement the following Figure 2 In the embodiment shown, all or part of the contents, the cloud application access control device 600 includes:

[0088] An acquisition module 610 is configured to acquire an identity authentication request sent by a target cloud application in response to a startup operation of the target cloud application;

[0089] The authentication module 620 is configured to integrate the cloud application authentication information corresponding to the identity authentication request, send the integrated cloud application authentication information to at least one authentication system corresponding to the target cloud application, and obtain a cloud application authentication result returned by the at least one authentication system;

[0090] The control module 630 is used to control access to the target cloud application according to the cloud application authentication result.

[0091] In one possible implementation, the obtaining module 610, when used to obtain the identity authentication request sent by the target cloud application in response to the startup operation of the target cloud application, is specifically configured to:

[0092] In response to a start-up operation of a target cloud application, obtaining cloud application identification information of the target cloud application;

[0093] The cloud application identification information is sent to the cloud platform, and the target cloud platform indicated by the cloud application identification information is started through the cloud platform to obtain the identity authentication request sent by the target cloud application.

[0094] In one possible implementation, the authentication module 620, when used to send the integrated cloud application authentication information to at least one authentication system corresponding to the target cloud application, is specifically configured to:

[0095] The integrated cloud application authentication information is encrypted using a preset encryption key to obtain authentication encrypted data;

[0096] The authentication encrypted data is sent to the at least one authentication system.

[0097] In one possible implementation, the authentication module 620 is further configured to:

[0098] Establishing a communication link with at least one authentication system corresponding to the target cloud application;

[0099] sending the identity information corresponding to the identity authentication request to the at least one authentication system via the communication link;

[0100] When it is determined that the identity information verification is passed, a service authorization certificate corresponding to the identity information is sent, and an encryption key of the at least one authentication system is obtained.

[0101] In one possible implementation, the authentication module 620 is configured to obtain the encryption key by:

[0102] obtaining an initial key sent by the at least one authentication system;

[0103] Sending an encryption request to the at least one authentication system, and obtaining an encrypted encryption key returned by the at least one authentication system;

[0104] The encrypted encryption key is decrypted using the initial key to obtain the encryption key.

[0105] In one possible implementation, the control module 630, when used to control access to the target cloud application based on the cloud application authentication result, is specifically configured to:

[0106] When the identity authentication is successful according to the cloud application authentication result, a first indication message is sent to the target cloud application, and cloud application content is generated according to the interface flow corresponding to the startup operation returned by the target cloud application;

[0107] When it is determined that the identity authentication has failed based on the cloud application authentication result, an authentication failure page is displayed, and a second indication message is sent to the target cloud application to cause the target cloud application to execute an exit process; wherein, the first indication message is used to indicate that the identity authentication of the target cloud application is successful, and the second indication message is used to indicate that the identity authentication of the target cloud application has failed.

[0108] An embodiment of the present application provides a cloud application access control device, comprising an acquisition module, an authentication module, and a control module; the acquisition module, in response to a startup operation of a target cloud application, acquires an identity authentication request sent by the target cloud application; the authentication module integrates and processes the cloud application authentication information corresponding to the identity authentication request, sends the integrated and processed cloud application authentication information to at least one authentication system corresponding to the target cloud application, and acquires a cloud application authentication result returned by the at least one authentication system; the control module controls access to the target cloud application based on the cloud application authentication result. In this way, by integrating and processing the cloud application authentication information, sending the integrated and processed cloud application authentication information to at least one authentication system, and controlling access to the target cloud application based on the returned cloud application authentication result, multiple authentication requests between different authentication systems can be reduced, thereby improving the authentication efficiency of cloud applications.

[0109] Figure 7A schematic diagram of the hardware structure of an electronic device that implements the embodiments of the present application is shown. Referring to this figure, at the hardware level, the electronic device 700 includes a processor 710, and optionally includes an internal bus 720, a network interface 730, and a memory 740. The memory 740 may include a memory 741, such as a high-speed random-access memory (RAM), and may also include a non-volatile memory 742, such as at least one disk storage device. Of course, the electronic device 700 may also include hardware required for other services.

[0110] The processor 710, network interface 730, and memory can be interconnected via an internal bus 720. This internal bus 720 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Such buses can be classified as address buses, data buses, control buses, and the like. For ease of illustration, only one bidirectional arrow is used in this figure, but this does not imply that there is only one bus or only one type of bus.

[0111] The memory 740 stores programs. Specifically, the programs may include program codes, which include computer operating instructions. The memory 740 may include a memory 741 and a non-volatile memory 742, and provides instructions and data to the processor 710.

[0112] The processor 710 reads the corresponding computer program from the non-volatile memory 742 into the memory and then runs it, forming a device for locating the target user at the logical level. The processor 710 executes the program stored in the memory and specifically performs the following: Figure 2 The methods disclosed in the illustrated embodiments implement the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be described in detail here.

[0113] The above application Figure 2The methods disclosed in the illustrated embodiments can be applied to or implemented by processor 710. Processor 710 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be performed by hardware integrated logic circuits or software instructions within processor 710. The processor 710 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules within the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0114] The computer device can also execute the methods described in the above method embodiments and realize the functions and beneficial effects of the methods described in the above method embodiments, which will not be repeated here.

[0115] Of course, in addition to software implementation, the electronic device 700 of the present application does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0116] The embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, which, when executed by an electronic device including a plurality of application programs, enables the electronic device to execute Figure 2 The methods disclosed in the illustrated embodiments implement the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be described in detail here.

[0117] The computer-readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0118] Furthermore, an embodiment of the present application provides a computer program product, comprising a computer program stored on a non-transitory computer-readable storage medium, wherein the computer program comprises program instructions. When the program instructions are executed by a computer, the following process is implemented: Figure 2 The methods disclosed in the illustrated embodiments implement the functions and beneficial effects of the various methods described in the foregoing method embodiments, which will not be described in detail here.

[0119] The embodiments of the present application can be applied to various electronic device collaboration or interconnection scenarios, including: collaboration and interconnection between mobile phones and laptops / tablets; collaboration and interconnection between mobile terminals and smart TVs / displays; collaboration and interconnection between mobile phones or tablets and in-car entertainment systems; collaboration and interconnection between mobile terminals and smart conference systems, etc., thereby meeting the diverse needs of users in scenarios such as smart homes, smart offices, and smart travel.

[0120] In short, the above description is only a preferred embodiment of the present application and does not limit the scope of protection of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

[0121] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0122] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0123] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0124] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

Claims

1. A cloud application access control method, characterized in that: include: In response to a start-up operation of a target cloud application, obtaining an identity authentication request sent by the target cloud application; Integrate and process the cloud application authentication information corresponding to the identity authentication request, send the integrated cloud application authentication information to at least one authentication system corresponding to the target cloud application, and obtain a cloud application authentication result returned by the at least one authentication system; Access to the target cloud application is controlled based on the cloud application authentication result.

2. The method according to claim 1, characterized in that The step of obtaining an identity authentication request initiated by the target cloud application in response to a startup operation of the target cloud application includes: In response to a start-up operation of a target cloud application, obtaining cloud application identification information of the target cloud application; The cloud application identification information is sent to the cloud platform, and the target cloud platform indicated by the cloud application identification information is started through the cloud platform to obtain the identity authentication request sent by the target cloud application.

3. The method according to claim 1, characterized in that The step of sending the integrated cloud application authentication information to at least one authentication system corresponding to the target cloud application includes: The integrated cloud application authentication information is encrypted using a preset encryption key to obtain authentication encrypted data; The authentication encrypted data is sent to the at least one authentication system.

4. The method according to claim 3, characterized in that Before encrypting the integrated cloud application authentication information using a preset encryption key to obtain authentication encrypted data, the method further includes: Establishing a communication link with at least one authentication system corresponding to the target cloud application; sending the identity information corresponding to the identity authentication request to the at least one authentication system via the communication link; When it is determined that the identity information verification is passed, a service authorization certificate corresponding to the identity information is sent, and an encryption key of the at least one authentication system is obtained.

5. The method according to claim 3, characterized in that The method for obtaining the encryption key includes: obtaining an initial key sent by the at least one authentication system; Sending an encryption request to the at least one authentication system, and obtaining an encrypted encryption key returned by the at least one authentication system; The encrypted encryption key is decrypted using the initial key to obtain the encryption key.

6. The method according to claim 1, characterized in that The controlling access to the target cloud application according to the cloud application authentication result includes: When the identity authentication is successful according to the cloud application authentication result, a first indication message is sent to the target cloud application, and cloud application content is generated according to the interface flow corresponding to the startup operation returned by the target cloud application; When it is determined that the identity authentication has failed based on the cloud application authentication result, an authentication failure page is displayed, and a second indication message is sent to the target cloud application to cause the target cloud application to execute an exit process; wherein, the first indication message is used to indicate that the identity authentication of the target cloud application is successful, and the second indication message is used to indicate that the identity authentication of the target cloud application has failed.

7. A cloud application access control device, characterized in that: include: an acquisition module, configured to acquire, in response to a startup operation of a target cloud application, an identity authentication request sent by the target cloud application; an authentication module, configured to integrate and process the cloud application authentication information corresponding to the identity authentication request, send the integrated and processed cloud application authentication information to at least one authentication system corresponding to the target cloud application, and obtain a cloud application authentication result returned by the at least one authentication system; A control module is used to control access to the target cloud application based on the cloud application authentication result.

8. An electronic device, characterized in that: The electronic device includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A readable storage medium, characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that The computer program product comprises a computer program stored on a non-transitory computer-readable storage medium, wherein the computer program comprises a program or instructions, and when the program or instructions are executed, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Identity authentication method, device and system and electronic equipment

    CN112559993A

  • Cloud application access control method and device and computer readable storage medium

    CN118214571A