A dynamically adaptive identity authentication integrated controller
By using a dynamic and adaptive identity authentication integration controller, and combining a login gatekeeper plugin and a plugin server, multi-factor authentication is achieved, which solves the problem of insufficient security of traditional identity authentication. It is applicable to various information systems and improves the security and applicability of information systems.
Patent Information
- Application Number
- CN202411703585.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-26
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-11-26
AI Technical Summary
Traditional identity authentication methods are not secure enough, and implementing two-factor authentication in information systems requires redesigning the login authentication framework, making it difficult to promote.
A dynamic and adaptive identity authentication integration controller is adopted. By combining the login gatekeeper plugin with the plugin server, it adapts to the system framework of the target information system and uses the user client mapping table maintained by the plugin server to realize the access of the multi-factor authentication process, thus avoiding the need to redesign the underlying login authentication framework of the target information system.
Without altering the login authentication framework of the target information system, this solution implements multi-factor authentication, enhances the security of the information system, and provides a simple yet effective identity verification solution applicable to various operating systems and application systems.
Smart Images

Figure CN119520130B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of identity authentication technology, and in particular to a dynamic adaptive identity authentication integrated controller. Background Technology
[0002] With the development of information technology and network informatization, people's work, study, and lifestyles are undergoing tremendous changes, greatly improving efficiency and maximizing the sharing of information resources. At the same time, information security has gradually become one of the most pressing concerns. The leakage of personal privacy information is becoming increasingly serious, and personal data in cyberspace urgently needs protection.
[0003] To ensure information security, cryptographic techniques must be used to protect various sensitive data in information systems.
[0004] Traditional authentication methods involve users inputting a username and password into an information system. The system then verifies the user's identity by comparing this information with the user's existing registration data. However, this traditional method encapsulates the username and password within the data packet, making it vulnerable to theft and thus lacking sufficient security. Therefore, information systems with higher security requirements may consider adding two-factor authentication methods such as digital certificates. However, this necessitates a complete redesign of the system's login authentication framework, which is difficult to implement and thus hinders its widespread adoption. Summary of the Invention
[0005] This application addresses the aforementioned problems and technical requirements by proposing a dynamic adaptive identity authentication integrated controller. The technical solution of this application is as follows:
[0006] A dynamic adaptive identity authentication integration controller includes a login gatekeeper plugin and a plugin server. The login gatekeeper plugin and the plugin server establish a connection. The login gatekeeper plugin matches the system framework of the target information system. The identity authentication integration controller interfaces with the target information system and the identity authentication system through the login gatekeeper plugin. The plugin server stores a user client mapping table of the target information system, which records the mapping relationship between the legitimate login accounts of the target information system and their corresponding legitimate identity identifiers.
[0007] The login gatekeeper plugin obtains the account to be logged in from the login request sent to the target information system and determines the identity identifier to be authenticated corresponding to the account to be logged in;
[0008] The login gatekeeper plugin confirms that the identity authentication of the account to be logged in has been passed when the identity authentication system verifies the identity identifier to be authenticated, when the login response returned by the intercepted target information system confirms that the account to be logged in is a legitimate login account of the target information system, and when the user client mapping table of the target information system stored on the plugin server contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated.
[0009] The further technical solution is that the login gatekeeper plugin obtains the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated, and sends a mapping verification request containing the identity identifier to be authenticated and the account to be logged in to the plugin server;
[0010] When the plugin server finds that the user client mapping table of the target information system contains the mapping relationship between the identity identifier to be authenticated and the account to be logged in in the mapping verification request, it returns a mapping verification pass response to the login gatekeeper plugin.
[0011] When the login gatekeeper plugin receives a mapping verification successful response, it determines that the user client mapping table of the target information system stored on the plugin server contains the mapping relationship between the account to be logged in and the identity to be authenticated.
[0012] The further technical solution is that the login gatekeeper plugin sends a mapping verification request containing the account to be logged in to the plugin server;
[0013] When the plugin server finds that the user client mapping table of the target information system contains the mapping relationship of the account to be logged in in the mapping verification request, it returns a mapping verification pass response containing the legitimate identity identifier corresponding to the account to be logged in to the login gatekeeper plugin.
[0014] The login gatekeeper plugin obtains the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated. When it detects that the identity identifier to be authenticated matches the legitimate identity identifier in the received mapping verification pass response, it determines that the target information system's user client mapping table contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated.
[0015] Its further technical solution is that after the login gatekeeper plugin obtains the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated, it sends an identifier verification request containing the identity identifier to be authenticated to the identity authentication system and receives the challenge code returned by the identity authentication system.
[0016] The login gatekeeper plugin returns the challenge code to the account to be logged in, and receives the signature result sent by the account to be logged in after signing the challenge code with the identity identifier to be authenticated;
[0017] The login gatekeeper plugin sends the signature result to the identity authentication system, and upon receiving a response from the identity authentication system confirming that the identity authentication system has verified the identity of the person to be authenticated based on the signature result.
[0018] The further technical solution is that the login gatekeeper plugin sends a mapping verification request containing the account to be logged in to the plugin server;
[0019] When the plugin server finds that the user client mapping table of the target information system contains the mapping relationship of the account to be logged in in the mapping verification request, it returns a mapping verification pass response containing the legitimate identity identifier corresponding to the account to be logged in to the login gatekeeper plugin.
[0020] When the login gatekeeper plugin receives a mapping verification pass response from the plugin server, it determines that the user client mapping table of the target information system contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated, and uses the legitimate identity identifier corresponding to the account to be logged in contained in the mapping verification pass response as the identity identifier to be authenticated.
[0021] The further technical solution is that after the login gatekeeper plugin receives the mapping verification pass response returned by the plugin server and obtains the legal identity identifier corresponding to the account to be logged in as the identity identifier to be authenticated, it sends an identifier verification request containing the identity identifier to be authenticated to the identity authentication system. The identifier verification request is used to instruct the identity authentication system to verify the identity identifier to be authenticated.
[0022] The login gatekeeper plugin receives a verification success response from the identity authentication system, indicating that the identity authentication system has successfully verified the identity of the person to be authenticated.
[0023] A further technical solution is that when the plugin server finds that the user client mapping table of the target information system does not contain the mapping relationship of the account to be logged in, it returns a binding prompt response to the login gatekeeper plugin;
[0024] When the login gatekeeper plugin receives the binding prompt response from the plugin server, it redirects to prompt the user to bind a valid identity identifier to the login account.
[0025] The further technical solution is to obtain an identity binding request by logging into the gatekeeper plugin. The identity binding request includes the account to be bound and the identity identifier to be bound.
[0026] When the login gatekeeper plugin confirms that the identity authentication system has verified the identity identifier to be bound, and confirms that the account to be bound is a legitimate login account of the target information system based on the login response returned by the intercepted target information system, and confirms that the user client mapping table of the target information system stored on the plugin server does not contain a mapping relationship between the account to be bound and other legitimate identity identifiers, it generates a mapping establishment request containing the account to be bound and the identity identifier to be bound and sends it to the plugin server.
[0027] The plugin server establishes a mapping relationship between the account to be bound and the identity to be bound in the received mapping request and stores it in the user client mapping table of the target information system.
[0028] The further technical solution is that the target information system is a web application system, and the login gatekeeper plugin is a network proxy module developed for the web application system;
[0029] Alternatively, the target information system is a Linux operating system, and the login gatekeeper plugin is a Linux shared library developed for local or remote user login on the Linux operating system;
[0030] Alternatively, the target information system is a Windows operating system, and the login gatekeeper plugin is a Windows dynamic link library developed for local or domain users of the Windows operating system to log in locally or remotely.
[0031] Alternatively, the target information system is a database, and the login security plugin is a database sharing library developed for the database.
[0032] A further technical solution is that when the login security plugin detects that the target information system has exited, or that the login account has exited, or that the trusted session between the target information system and the login account has expired, it deletes the trusted session and redirects the user to the initialization page.
[0033] The further technical solution is that the login gatekeeper plugin intercepts the response value of the target interface returned by the target information system to the login account. When a corresponding modification policy is detected for the target interface, the response value of the target interface is modified according to the corresponding modification policy and then returned to the login account; otherwise, the response value of the target interface is directly returned to the login account.
[0034] Its further technical solution is that the login gatekeeper plugin obtains the access request sent by the login account to the target information system, and intercepts the redirection request returned by the target information system to the login account;
[0035] The login gatekeeper plugin checks whether the URL path carried in the redirect request matches the URL path in the access request;
[0036] When the login gatekeeper plugin detects that the URL path carried in the redirect request does not match the URL path in the access request, it rewrites and repairs the URL path carried in the redirect request according to the URL path in the access request before redirecting.
[0037] When the login gatekeeper plugin detects that the URL path carried in the redirect request matches the URL path in the access request, it directly redirects the user according to the URL path carried in the redirect request.
[0038] The beneficial technical effects of this application are:
[0039] This application discloses a dynamic adaptive identity authentication integration controller, which includes a login gatekeeper plugin adapted to the system framework of the target information system. The login gatekeeper plugin interfaces with and calls the functions of the identity authentication system, and combined with the user client mapping table maintained by the plugin server, it can integrate the multi-factor authentication process into the target information system without redesigning the underlying login authentication framework of the target information system. In the national promotion of commercial cryptography application security transformation, it provides a simple and effective systematic identity authentication solution for device and computing security as well as application and data security.
[0040] This identity authentication integrated controller is applicable to various operating systems and application systems, including user login for various web application systems such as banking or healthcare applications, user login for various databases, local or remote user login for various Windows systems, and user login for various Linux systems, making it widely applicable. Attached Figure Description
[0041] Figure 1 This is a schematic diagram of the structure of the identity authentication integrated controller of this application.
[0042] Figure 2 This is a flowchart illustrating the identity authentication process implemented by the identity authentication integration controller in one embodiment of this application.
[0043] Figure 3 This is a flowchart illustrating the identity authentication process implemented by the identity authentication integration controller in another embodiment of this application.
[0044] Figure 4 This is a flowchart illustrating the identity authentication process implemented by the identity authentication integration controller in another embodiment of this application.
[0045] Figure 5 This is a flowchart illustrating the process of implementing the modified interface response function by the identity authentication integration controller in another embodiment of this application.
[0046] Figure 6 This is a flowchart illustrating the process of implementing external jump protection function in the identity authentication integrated controller in one embodiment of this application. Detailed Implementation
[0047] The specific embodiments of this application will be further described below with reference to the accompanying drawings.
[0048] This application discloses a dynamic adaptive identity authentication integrated controller. Please refer to [link / reference]. Figure 1 The identity authentication integration controller 100 includes a login gatekeeper plugin 110 and a plugin server 120, wherein:
[0049] (1) The identity authentication integration controller 100 interfaces with the target information system 200 through the login gatekeeper plugin 110, and the login gatekeeper plugin 110 matches the system framework of the target information system 200. When the system framework of the target information system 200 is different, the specific implementation of the login gatekeeper plugin 110 in the identity authentication integration controller 100 is also different, so that the identity authentication integration controller 100 can adapt to different target information systems 200 and achieve dynamic self-adaptation.
[0050] The target information system 200 in this application includes various operating systems and application systems. When the system framework of the target information system 200 is different, the implementation method of the login gatekeeper plugin 110 will also be different:
[0051] In one embodiment, if the target information system 200 is a web application system, then the login gatekeeper plugin 110 that matches the system framework of the target information system 200 is a network proxy module or web service plugin developed for the web application system.
[0052] In one embodiment, if the target information system 200 is a Linux operating system, then the login gatekeeper plugin 110 that matches the system framework of the target information system 200 is a Linux Plug and Play Authentication Module (PAM), also known as a Linux shared library, developed for local or remote user login on the Linux operating system.
[0053] In another embodiment, if the target information system 200 is a Windows operating system, then the login gatekeeper plugin 110 that matches the system framework of the target information system 200 is a Windows authentication module plugin (WAM), i.e., a Windows dynamic link library, developed for local or domain users of the Windows operating system to log in locally or remotely.
[0054] In another embodiment, if the target information system 200 is a database, then the login gatekeeper plugin 110 that matches the system framework of the target information system 200 is a database plug-and-play authentication module (DAM) developed for the database, i.e., a database shared library, such as a MySQL database shared library.
[0055] Regardless of the system framework adopted by the target information system 200, it is only necessary to ensure that the login gatekeeper plugin 110 is compatible with the underlying framework of the target information system 200 and can be connected to the target information system 200. When the target information system 200 is a distributed information system, multiple login gatekeeper plugins 110 need to be deployed on the same target information system.
[0056] (2) In the identity authentication integration controller 100, the login gatekeeper plugin 110 and the plugin server 120 establish a connection. In actual implementation, the identity authentication integration controller 100 of this application often contains multiple login gatekeeper plugins 110, which respectively interface with different target information systems 200, and each login gatekeeper plugin 110 is matched with the system framework of its respective interfaced target information system. For example Figure 1 Taking the identity authentication integration controller 100, which includes N login gatekeeper plugins 110, as an example, these N login gatekeeper plugins 110 are respectively connected to target information systems 1 to N. Each login gatekeeper plugin 110 matches the system framework of its respective connected information system, where N is an integer parameter. Each login gatekeeper plugin 110 is connected to a plugin server 120, and the plugin server 120 provides services to the login gatekeeper plugins 110 connected to different target information systems 200.
[0057] The plug-in server 120 in the identity authentication integration controller 100 of this application stores a user client mapping table of the target information system to which the login gatekeeper plug-in is connected. The user client mapping table of the target information system records the mapping relationship between the legitimate login accounts and their corresponding legitimate identity identifiers. A legitimate login account is a login account registered in the target information system. The mapping relationship between a legitimate login account and a legitimate identity identifier is established and added to the user client mapping table of the target information system after the legitimate login account and legitimate identity identifier are bound together in the target information system. The process of establishing this mapping relationship will be described later. When the identity authentication integration controller 100 includes multiple login gatekeeper plug-ins connected to different target information systems, the plug-in server 120 stores the respective user client mapping tables of each target information system. For example, in... Figure 1 In the example, the plug-in server 120 stores the user client mapping tables for each of the target information systems 1 to N.
[0058] (3) The identity authentication integration controller 100 also connects to an external identity authentication system 300 through a login gatekeeper plugin 110. The legitimate identity identifier of the target information system 200 is carried in the identity authentication client containing the digital certificate. The identity authentication system 300 connected to by the login gatekeeper plugin 110 is a digital certificate management and verification system used to provide services to the identity authentication client carrying the legitimate identity identifier of the target information system 200. The two need to match. For example, commonly, the identity authentication client carrying the legitimate identity identifier of the target information system 200 is a ukey, and the corresponding identity authentication system 300 is a signature verification server. Another common example is that the identity authentication client carrying the legitimate identity identifier of the target information system 200 is an application with a digital certificate installed, and the corresponding identity authentication system 300 is the self-developed identity authentication system 300 corresponding to the application. Regardless of which identity authentication system 300 is connected, after the identity authentication integration controller 100 connects to the identity authentication system 300 through the login gatekeeper plugin 110, it can call the digital certificate management and verification functions provided by the identity authentication system 300. When the identity authentication integration controller 100 includes multiple login gatekeeper plug-ins 110, the login gatekeeper plug-in 110 that interfaces with each target information system 200 interfaces with the identity authentication system 300 respectively. Any two login gatekeeper plug-ins 110 can interface with the same or different identity authentication systems 300.
[0059] After the identity authentication integration controller 100 connects to the target information system 200 and the identity authentication system 300 through the login gatekeeper plugin 110, it can integrate the multi-factor authentication process into the target information system 200 without modifying the login authentication framework of the target information system 200, thereby improving the security of the target information system 200. When the identity authentication integration controller 100 of this application is not connected, the identity authentication process implemented by the target information system 200 according to its own login authentication framework is as follows: The information system client corresponding to the target information system 200 sends a login request to the target information system 200. This login request contains the account to be logged in and the login password used. The target information system 200 checks whether the account to be logged in and the login password in the login request match. If it determines that the account to be logged in and the login password match, it determines that the account to be logged in is a legitimate account, and returns a login response indicating that the account to be logged in is a legitimate account to the information system client, redirecting to login. If it determines that the account to be logged in and the login password do not match, it determines that the account to be logged in is not a legitimate account, and returns a login response indicating that the account to be logged in is not a legitimate account to the information system client, refusing login. However, this conventional method of identity authentication is not very reliable.
[0060] After the identity authentication integration controller 100 of this application is connected to the target information system 200, the multi-factor authentication process for the target information system 200 based on the identity authentication integration controller 100 is as follows:
[0061] The login gatekeeper plugin 110 obtains the account to be logged in from the login request sent to the target information system 200, and the login gatekeeper plugin 110 also determines the identity identifier to be authenticated corresponding to the account to be logged in.
[0062] The login request will still be sent to the target information system 200 normally. The target information system 200 will authenticate the login request according to its own login authentication framework and return the corresponding login response. While the target information system 200 is authenticating the login request according to its own login authentication framework, the login gatekeeper plugin 110 will call the identity authentication system 300 to verify the identity identifier to be authenticated corresponding to the login account. The login gatekeeper plugin 110 will also verify the mapping relationship between the login account and its corresponding identity identifier according to the user client mapping table of the target information system stored on the plugin server 120.
[0063] When the target information system 200 completes the authentication of the login request according to its own login authentication framework and returns a login response, the login gatekeeper plugin 110 will also intercept the login response returned by the target information system.
[0064] The login gatekeeper plugin 110 determines that the identity authentication of the account to be logged in has been successful when the identity authentication system 300 verifies the identity identifier to be authenticated corresponding to the account to be logged in, the plugin server 120 stores a mapping relationship between the account to be logged in and the identity identifier to be authenticated in the user client mapping table of the target information system, and the login response returned by the intercepted target information system 200 confirms that the account to be logged in is a legitimate login account of the target information system 200. This indicates that the account to be logged in is a legitimate login account of the target information system, and the identity identifier used by the account to be logged in is a legitimate identity identifier of the target information system 200. Furthermore, the account to be logged in and the identity identifier used by the account to be logged in are pre-bound and have a mapping relationship, thus achieving multi-factor authentication.
[0065] Within the framework of the above identity authentication process, the specific implementation methods will differ depending on the identity authentication client, and can be mainly divided into two categories:
[0066] In the first scenario, the login security plugin 110 can directly obtain the identity identifier currently used by the account to be logged in, such as when the identity identifier is carried in the ukey. In this case, the login security plugin 110 will directly use the currently used identity identifier as the identity identifier to be authenticated for the account to be logged in. The identity authentication system mainly verifies the legitimacy of the identity identifier to be authenticated, that is, whether the identity identifier to be authenticated is legitimate. Therefore, the overall framework for multi-factor authentication in this scenario is: first, verify whether the currently used identity identifier is a legitimate identity identifier, and verify whether the account to be logged in is a legitimate login account; then, verify whether there is a mapping relationship between the account to be logged in and the currently used identity identifier. Under this authentication framework:
[0067] 1. The method for verifying whether the currently used identity is a valid identity is as follows:
[0068] After obtaining the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated, the login gatekeeper plugin 110 sends an identifier verification request containing the identity identifier to be authenticated to the identity authentication system 300. Upon receiving the identifier verification request, the identity authentication system 300 returns a challenge code to the login gatekeeper plugin 110. The login gatekeeper plugin 110 receives the challenge code returned by the identity authentication system 300 and returns it to the account to be logged in. Upon receiving the challenge code, the account to be logged in signs the challenge code using its currently used identity identifier (i.e., the identity identifier to be authenticated) and sends it to the login gatekeeper plugin 110. The login gatekeeper plugin 110 receives the signature result sent by the account to be logged in, showing the challenge code signed using the identity identifier to be authenticated.
[0069] The login gatekeeper plugin 110 sends the signature result to the identity authentication system 300. The identity authentication system 300 verifies the signature result using the identity identifier to be authenticated in the identity verification request. If the identity identifier to be authenticated is verified successfully based on the signature result, the identity authentication system 300 returns an identity verification success response to the login gatekeeper plugin 110; otherwise, it returns an identity verification failure response to the login gatekeeper plugin 110.
[0070] When the login gatekeeper plugin 110 receives a successful identity verification response from the identity authentication system 300, it determines that the identity authentication system 300 has successfully verified the identity identifier to be authenticated based on the signature result, thus confirming that the identity identifier currently used by the account to be logged in is a legitimate identity identifier. Conversely, when the login gatekeeper plugin 110 receives a failed identity verification response from the identity authentication system 300, it determines that the identity authentication system 300 has failed to verify the identity identifier to be authenticated, thus confirming that the identity identifier currently used by the account to be logged in is not a legitimate identity identifier, and in this case, it can directly determine that the identity authentication of the account to be logged in has failed.
[0071] 2. The method to verify whether the account to be logged in is a legitimate account is as follows:
[0072] Based on the login response returned by the intercepted target information system 200, determine whether the account to be logged in is a legitimate login account of the target information system 200.
[0073] 3. There are two different methods for verifying whether there is a mapping relationship between the account to be logged in and the currently used identity:
[0074] (1) The plugin server 120 verifies whether there is a mapping relationship between the account to be logged in and the currently used identity:
[0075] After confirming that the identity authentication system 300 has successfully verified the identity identifier to be authenticated, and after determining that the account to be logged in is a legitimate login account of the target information system 200 based on the login response returned by the intercepted target information system 200, the login gatekeeper plugin 110 sends a mapping verification request containing the identity identifier to be authenticated and the account to be logged in to the plugin server 120.
[0076] The plugin server 120 receives the mapping verification request and parses it to obtain the identity identifier to be authenticated and the account to be logged in. Then, the plugin server 120 queries the user client mapping table of the target information system 200, which is connected to the login gatekeeper plugin 110, to see if it contains a mapping relationship between the identity identifier to be authenticated and the account to be logged in from the mapping verification request. If the plugin server 120 determines that the user client mapping table of the target information system 200 contains a mapping relationship between the identity identifier to be authenticated and the account to be logged in from the mapping verification request, it returns a mapping verification successful response to the login gatekeeper plugin 110. If the plugin server 120 determines that the user client mapping table of the target information system 200 contains a mapping relationship between the account to be logged in from the mapping verification request and other legitimate identity identifiers, it returns a mapping verification failed response to the login gatekeeper plugin 110.
[0077] When the login gatekeeper plugin 110 receives the mapping verification successful response returned by the plugin server 120, it determines that the user client mapping table of the target information system stored by the plugin server 120 contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated. This indicates that the account to be logged in is a legitimate login account, and the identity identifier currently used by the account to be logged in is a legitimate identity identifier that is bound to the account to be logged in, thus confirming that the identity authentication of the account to be logged in has been successful.
[0078] (2) The login gatekeeper plugin 110 verifies whether there is a mapping relationship between the account to be logged in and the currently used identity:
[0079] After confirming that the identity authentication system 300 has successfully verified the identity identifier to be authenticated, and after determining that the account to be logged in is a legitimate login account of the target information system 200 based on the login response returned by the intercepted target information system 200, the login gatekeeper plugin 110 sends a mapping verification request containing the account to be logged in to the plugin server 120.
[0080] The plugin server 120 receives the mapping verification request and parses it to obtain the account to be logged in. Then, the plugin server 120 queries the user client mapping table of the target information system 200, which is connected to the login gatekeeper plugin 110, to see if it contains a mapping relationship between the account to be logged in and its legitimate identity identifier. If the plugin server 120 determines that the user client mapping table of the target information system 200 contains the mapping relationship for the account to be logged in, it returns a mapping verification successful response containing the legitimate identity identifier corresponding to the account to be logged in to the login gatekeeper plugin 110.
[0081] On the other hand, the login gatekeeper plugin 110 obtains the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated. When it detects that the identity identifier to be authenticated is consistent with the legitimate identity identifier in the received mapping verification pass response, it determines that the user client mapping table of the target information system 200 contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated. This indicates that the account to be logged in is a legitimate login account at this time, and the identity identifier currently used by the account to be logged in is the legitimate identity identifier that is bound to the account to be logged in, thereby determining that the identity authentication of the account to be logged in has passed.
[0082] Under this authentication framework, the steps of verifying whether the currently used identity is a valid identity and verifying whether the account to be logged in is a valid login account are implemented differently in different business scenarios. Two implementation examples are given below:
[0083] Example 1: First, obtain the identity currently used by the account to be logged in and verify whether it is a valid identity. Then, obtain the account to be logged in and verify whether it is a valid login account. Please refer to [link / reference]. Figure 2 The flowchart shown below:
[0084] Step 201: Log in to the gatekeeper plugin 110 to establish a session and obtain the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated.
[0085] Step 202: Login gatekeeper plugin 110 sends an identity verification request containing the identity identifier to be authenticated to identity authentication system 300.
[0086] Step 203: The identity authentication system 300 returns a challenge code to the login gatekeeper plugin 110.
[0087] Step 204: The login gatekeeper plugin 110 returns the challenge code to the account to be logged in. The account to be logged in signs the challenge code using the identity identifier to be authenticated and then sends it to the login gatekeeper plugin 110.
[0088] Step 205: Login gatekeeper plugin 110 receives the signature result sent by the account to be logged in, which is the result of signing the challenge code using the identity identifier to be authenticated.
[0089] Step 206: Log in to the gatekeeper plugin 110 and send the signature result to the identity authentication system 300.
[0090] Step 207: The identity authentication system 300 verifies the identity identifier to be authenticated based on the signature result and returns a verification pass or verification fail response to the login gatekeeper plugin 110.
[0091] Step 208: After receiving the identity verification pass response returned by the identity authentication system 300, the login gatekeeper plugin 110 converts the session into a UK session and binds it to the identity identifier to be authenticated. It also obtains the account to be logged in corresponding to the UK session from the login request sent to the target information system 200, and intercepts the login response returned by the target information system 200 in response to the login request.
[0092] After receiving the authentication failure response from the identity authentication system 300, the login gatekeeper plugin 110 determines that the identity authentication of the account to be logged in has failed.
[0093] Step 209: After the login gatekeeper plugin 110 determines that the account to be logged in is a legitimate login account based on the intercepted login response, it sends a mapping verification request to the plugin server 120. The mapping verification request includes the account to be logged in corresponding to the UK session and the identity identifier to be authenticated bound to the UK session.
[0094] Step 210: Plugin server 120 queries the user client mapping table of target information system 200 to see if it contains a mapping relationship between the identity identifier to be authenticated and the account to be logged in in the mapping verification request, and returns a mapping verification pass response or a mapping verification fail response to login gatekeeper plugin 110.
[0095] In step 212, when the login gatekeeper plugin 110 receives a mapping verification success response, it determines that the authentication of the account to be logged in has passed and converts the UK session into a trusted session. When the login gatekeeper plugin 110 receives a mapping verification failure response, it determines that the authentication of the account to be logged in has failed.
[0096] Example 2: First, obtain the account to be logged in and verify if it is a legitimate account. Then, obtain the identity currently being used by the account to be logged in and verify if it is a legitimate identity. Please refer to [link / reference]. Figure 3 The flowchart shown below:
[0097] Step 301: Login gatekeeper plugin 110 establishes a session and obtains the account to be logged in from the login request sent to the target information system. The target information system 200 verifies the login request and returns a login response.
[0098] Step 302: The login gatekeeper plugin 110 intercepts the login response returned by the target information system 200 in response to the login request.
[0099] Step 303: When the login gatekeeper plugin 110 determines that the account to be logged in is a legitimate login account of the target information system based on the login response returned by the intercepted target information system, it converts the session into an account session and saves the account to be logged in in the account session.
[0100] Step 304: Log in to the gatekeeper plugin 110 to obtain the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated.
[0101] Step 305: Login gatekeeper plugin 110 sends an identity verification request containing the identity identifier to be authenticated to identity authentication system 300.
[0102] Step 306: The identity authentication system 300 returns a challenge code to the login gatekeeper plugin 110.
[0103] Step 307: The login gatekeeper plugin 110 returns the challenge code to the account to be logged in. The account to be logged in signs the challenge code using the identity identifier to be authenticated and then sends it to the login gatekeeper plugin 110.
[0104] Step 308: Login gatekeeper plugin 110 receives the signature result sent by the account to be logged in, which is the result of signing the challenge code using the identity identifier to be authenticated.
[0105] Step 309: Log in to the gatekeeper plugin 110 and send the signature result to the identity authentication system 300.
[0106] Step 310: The identity authentication system 300 verifies the identity identifier to be authenticated based on the signature result and returns a verification pass or verification fail response to the login gatekeeper plugin 110.
[0107] In step 311, after receiving the authentication system 300's response indicating successful identity verification, the login gatekeeper plugin 110 sends a mapping verification request containing the account to be logged in from the account session to the plugin server 120. If the login gatekeeper plugin 110 receives the authentication system 300's response indicating failed identity verification, it directly determines that the authentication of the account to be logged in has failed.
[0108] In step 312, when the plugin server 120 finds that the user client mapping table of the target information system 200 contains the mapping relationship between the login account and the legitimate identity identifier in the mapping verification request, it returns a mapping verification pass response containing the legitimate identity identifier of the login account to the login gatekeeper plugin 110.
[0109] Step 313: When the login gatekeeper plugin 110 receives a mapping verification success response and determines that the valid identity identifier in the mapping verification success response matches the identity identifier to be authenticated, it determines that the identity authentication of the account to be logged in has passed and converts the account session into a trusted session. When the login gatekeeper plugin 110 receives a mapping verification failure response, it determines that the identity authentication of the account to be logged in has failed.
[0110] In the second scenario, the login plugin 110 does not directly obtain the identity identifier currently used by the account to be logged in. This occurs when the identity identifier used by the account to be logged in is carried within the application. In this case, the overall framework for multi-factor authentication is as follows: First, verify whether the account to be logged in is a legitimate account and determine if there is a legitimate identity identifier that has a mapping relationship with the account. Then, verify whether this legitimate identity identifier is the identity identifier currently used by the account to be logged in. In this case, the authentication system's verification of the identity identifier to be authenticated is mainly an authorization verification, that is, verifying whether the identity identifier to be authenticated is the identity identifier currently used by the account to be logged in. Under this authentication framework, please refer to... Figure 4 The flowchart shown below:
[0111] When the login gatekeeper plugin 110 determines that the account to be logged in is a legitimate login account of the target information system based on the login response returned by the intercepted target information system, it sends a mapping verification request containing the account to be logged in to the plugin server 120.
[0112] The plugin server 120 receives the mapping verification request and parses it to obtain the account to be logged in. Then, the plugin server 120 queries the user client mapping table of the target information system 200, which is connected to the login gatekeeper plugin 110, to see if it contains a mapping relationship between the account to be logged in and its legitimate identity identifier. If the plugin server 120 determines that the user client mapping table of the target information system 200 contains the mapping relationship for the account to be logged in, it returns a mapping verification successful response containing the legitimate identity identifier corresponding to the account to be logged in to the login gatekeeper plugin 110.
[0113] When the login gatekeeper plugin 110 receives the mapping verification pass response returned by the plugin server, it determines that the user client mapping table of the target information system contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated, and uses the legitimate identity identifier corresponding to the account to be logged in contained in the mapping verification pass response as the identity identifier to be authenticated.
[0114] After receiving the mapping verification successful response from the plugin server 120 and obtaining the legitimate identity identifier corresponding to the account to be logged in as the identity identifier to be authenticated, the login gatekeeper plugin 110 sends an identifier verification request containing the identity identifier to be authenticated to the identity authentication system 300. This identifier verification request instructs the identity authentication system to verify the identity identifier to be authenticated. Upon receiving the identifier verification request, the identity authentication system 300 verifies the identity identifier to be authenticated according to the adopted verification mechanism, including: the identity authentication system 300 sends a challenge code to the identity identifier to be authenticated; if the identity identifier currently used by the account to be logged in is the identity identifier to be authenticated and authorization is confirmed, the account to be logged in will use the identity identifier to sign the challenge code and return the signature result to the identity authentication system 300. The identity authentication system 300 verifies the signature result using the identity identifier to be authenticated; if the signature result verification is successful, it returns an identifier verification successful response to the login gatekeeper plugin 110. If the signature result verification fails or the signature result is not received within the timeout period, the identity authentication system 300 returns an identifier verification failed response to the login gatekeeper plugin 110.
[0115] When the login gatekeeper plugin 110 receives a successful authentication response from the identity authentication system 300, it determines that the identity authentication system 300 has successfully verified the identity identifier to be authenticated, meaning that the identity identifier to be authenticated is the identity identifier currently used by the account to be logged in. Conversely, when the login gatekeeper plugin 110 receives a failed authentication response from the identity authentication system 300, it determines that the identity authentication system 300 has failed to verify the identity identifier to be authenticated, indicating that the identity identifier to be authenticated is not the identity identifier currently used by the account to be logged in. This could be due to the identity identifier not responding within a timeout period or the account not being authorized. In this case, the login gatekeeper plugin 110 determines that the authentication of the account to be logged in has failed.
[0116] Regardless of the scenario described above, when the plugin server 120 queries the user client mapping table of the target information system, it may encounter a situation where the mapping relationship for the account to be logged in is not included in the user client mapping table. This means that the account to be logged in, which is a legitimate login account, has not yet been bound to a corresponding legitimate identity identifier. In this case, the plugin server 120 will return a binding prompt response to the login gatekeeper plugin 110. Upon receiving the binding prompt response from the plugin server 120, the login gatekeeper plugin 110 will redirect the user to the binding process to bind a legitimate identity identifier, thereby adding the corresponding mapping relationship to the user client mapping table.
[0117] During the binding process, the login gatekeeper plugin 110 receives an identity binding request, which includes the account to be bound and the identity identifier to be bound. The login gatekeeper plugin 110 only generates a mapping establishment request containing the account to be bound and the identity identifier to be bound and sends it to the plugin server 120 when it confirms that the identity authentication system 300 has successfully verified the identity identifier to be bound, when it determines from the intercepted login response returned by the target information system 200 that the account to be bound is a legitimate login account of the target information system, and when it confirms that the user client mapping table of the target information system stored by the plugin server 120 does not contain a mapping relationship between the account to be bound and other legitimate identity identifiers. Then, the plugin server 120 establishes a mapping relationship between the account to be bound and the identity identifier to be bound in the received mapping establishment request and stores it in the user client mapping table of the target information system, thereby establishing a binding relationship between the account to be bound and the identity identifier to be bound. At this point, the account to be bound is a legitimate login account of the target information system, and the identity identifier to be bound is a legitimate identity identifier that has a mapping relationship with the account to be bound. There are also different specific implementation methods in the first and second types of cases mentioned above:
[0118] In the first scenario described above, the account to be bound initiates a login request as the account to be logged in, and the identity identifier to be bound is the identity identifier currently used by the account to be logged in. After the above verification process, in step 210 of the first scenario described above, or step 312 of the first scenario described above, when the plugin server 120 queries the user client mapping table of the target information system 200 and finds that it does not contain the mapping relationship of the account to be logged in, it will return a binding prompt response to the login gatekeeper plugin 110. The login gatekeeper plugin 110 receives the binding prompt response returned by the plugin server 120 and redirects to prompt the account to be logged in to enter the binding process. When the account to be bound is confirmed to be bound to the identity identifier to be bound, due to the verification mechanism of the first type, it has been verified that the account to be logged in is a legitimate login account, and it has also been verified that the identity identifier currently used by the account to be logged in is a legitimate identity identifier. It has also been determined that the account to be logged in has not established a mapping relationship with other identity identifiers. Therefore, the login gatekeeper plugin 110 will directly generate a mapping establishment request containing the account to be bound and the identity identifier to be bound and send it to the plugin server 120 to establish the mapping relationship between the account to be logged in and the identity identifier currently used, and confirm that the identity authentication of the account to be logged in has passed.
[0119] In the second scenario described above, during the login request process initiated by the account to be bound as the account to be logged in, when the plugin server 120 queries the user client mapping table of the target information system 200 and finds that it does not contain a mapping relationship for the account to be logged in, it will return a binding prompt response to the login gatekeeper plugin 110. Upon receiving the binding prompt response from the plugin server 120, the login gatekeeper plugin 110 will redirect the account to be logged in to enter the binding process and request a challenge code from the identity authentication system 300 to send to the account to be bound. The account to be bound uses the identity identifier to sign the challenge code and sends the signature result to the identity authentication system 300. After the identity authentication system 300 verifies the signature result, it sends a verification response containing the identity identifier to be bound to the login gatekeeper plugin 110. When the login gatekeeper plugin 110 receives the verification response containing the identity identifier to be bound from the identity authentication system 300, it determines that the identity identifier to be bound is a legitimate identity identifier. Due to the verification mechanism of the second type, it has been determined that the account to be logged in is a legitimate login account and that it has not established a mapping relationship with other identity identifiers. Therefore, the login gatekeeper plugin 110 will generate a mapping establishment request containing the account to be bound and the identity identifier to be bound and send it to the plugin server 120 to establish a mapping relationship between the account to be logged in and the identity identifier currently used.
[0120] In one embodiment, after the identity authentication integration controller of this application completes the above-mentioned multi-factor authentication process, the login gatekeeper plugin 110 deletes the trusted session to exit the session when it detects that the target information system 200 has exited, or the login account has exited, or the trusted session between the target information system 200 and the login account has expired, and then redirects to the initialization page. The initialization page can be a custom page that does not require login.
[0121] In another embodiment, the login gatekeeper plugin 110 of the identity authentication integrated controller also supports the function of modifying the interface response; please refer to [reference needed]. Figure 5 The logged-in account accesses the target information system 200 normally. The target information system 200 returns its own webpage to the logged-in account for display. Currently, most websites retrieve data via asynchronous interfaces to display page content. The login security plugin 110 intercepts the response values of the target interface returned by the target information system 200 to the logged-in account. When a corresponding modification policy is detected for that target interface, the plugin modifies the response value according to the corresponding modification policy and returns it to the logged-in account; otherwise, it directly returns the response value of the target interface to the logged-in account. The modification policies for different interfaces can be customized.
[0122] There are three common implementation scenarios for the above-mentioned function of modifying the interface response:
[0123] Scenario 1: Modern web application development is quite flexible. When some web applications use WebSockets, cross-origin access issues may arise. If the host for the WebSocket connection is returned through another interface, this feature to modify the interface response can unify the host and avoid cross-origin access problems.
[0124] Scenario 2: Some application systems obtain the content and even the link addresses of their page rendering components from an interface. The application system itself knows that it is host_A, but the address proxied by the login gatekeeper plugin 110 may be host_B. If the application system returns a link address through its own interface, it is very likely that it is its own host_A. Since host_A is internally forwarded to the login gatekeeper plugin 110 and cannot be exposed, the login gatekeeper plugin 110 can use this interface to respond with the modification function to change host_A to host_B.
[0125] Scenario 3: Some application systems require personalized displays after logging into the 110 agent security plugin, such as displaying an identity authentication icon. In this case, this method can also be used to modify the interface to complete the personalized display content.
[0126] In another embodiment, the login gatekeeper plugin 110 of the identity authentication integrated controller 100 also supports external jump protection function, please refer to Figure 6 When a logged-in account accesses the application system normally, manually entering the URL or saving the URL in the browser can lead to a situation where the application system is accessed correctly but the request path is incorrect. For example, in most cases, the login account directly enters https: / / www.example.com, but the actual address is https: / / www.example.com / console / admin. When the application system detects the incorrect URL path entered by the login account, it sends a redirect request (301 / 302 redirect request) to the browser. At this time, the login gatekeeper plugin 110 retrieves the access request sent by the login account to the target information system 200 and intercepts the redirect request returned by the information system to the login account. Then, the login gatekeeper plugin 110 checks whether the URL path carried in the redirect request matches the URL path in the login account's access request. When the login gatekeeper plugin detects a mismatch between the URL path carried in the redirect request and the URL path in the access request, it rewrites and corrects the URL path carried in the redirect request according to the URL path in the access request sent by the login account before redirecting. When the login gatekeeper plugin detects that the URL path carried in the redirect request matches the URL path in the access request, it directly redirects the user according to the URL path carried in the redirect request.
[0127] In another embodiment, the multi-factor authentication service provided by the identity authentication integration controller 100 can also work with a data integrity monitoring engine to monitor critical and sensitive data of the information system. In this case, the identity authentication integration controller 100 also interfaces with the data integrity monitoring engine through a login gatekeeper plugin 110. The user client mapping table of the target information system stored in the plugin server 120 also stores the modification permissions of each legitimate login account. The login gatekeeper plugin 110 obtains data modification requests sent by legitimate login accounts from the target information system 200 and sends the legitimate login account and data modification request to the plugin server 120. The plugin server 120 queries whether the data modification request matches the modification permissions of the corresponding legitimate login account in the user client mapping table, and returns the modification permission query result to the login gatekeeper plugin 110, which then sends it to the data integrity monitoring engine. The data integrity monitoring engine monitors and provides feedback on the data modification operations of the login accounts based on the modification permission query result. This allows it to provide prompts, alerts, or even block access when data is tampered with by certain login accounts, while simultaneously supporting the legitimate modification of data by specifically authorized login accounts. This type of security protection is particularly meaningful for application data in scenarios such as banking or healthcare systems, because it can effectively protect the integrity of important financial or medical data, thereby effectively preventing fraud, ensuring compliance, supporting decision-making, and maintaining trust. It can also support the operation and maintenance of data under legal circumstances, and realize the demand for safeguarding the data security of important application systems for the national economy and people's livelihood with hardware-level cryptographic security.
[0128] In another embodiment, the multi-factor authentication service provided by the identity authentication integrated controller 100 can also work with a data encryption / decryption engine to protect critical sensitive data from leakage. Under data encryption, normal users are allowed to use the data, while all unknown users are prohibited from using the data. For example, for database data, when a normal application system login account accesses the database data, a data decryption service is automatically provided. However, for abnormal application system login accounts, such as users of the operating system, even superusers of the operating system, no data decryption service is provided. Thus, the confidentiality of application system data is protected to the maximum extent without affecting the normal use of the data.
[0129] While the foregoing description provides one or more examples of processes, devices, or systems, it should be understood that other processes, devices, or systems may fall within the scope of the appended claims. It should be understood that the embodiments described herein can be implemented in a variety of computing devices, including, but not limited to, servers, suitably programmed general-purpose computers, cameras, sensors, audio / video encoding and playback devices, set-top boxes, television broadcasting equipment, mobile devices, and autonomous vehicles. The embodiments described herein can be implemented by hardware or software comprising instructions for configuring one or more processors to perform the functions described herein. The software instructions may be stored on any suitable non-transitory computer-readable storage medium, including CDs, RAM, ROM, flash memory, etc.
[0130] It should be understood that the embodiments described in this application, as well as the modules, routines, processes, threads, or other software components that implement the described methods / processes / frameworks, can be implemented using standard computer programming techniques and languages. This application is not limited to specific processors, computer languages, computer programming conventions, data structures, or other such implementation details. Those skilled in the art will recognize that the described methods / processes can be implemented as part of computer-executable code stored in volatile or non-volatile memory, as part of an application-specific integrated circuit (ASIC), etc. It will be apparent to those skilled in the art that certain adaptations and modifications can be made to the described methods / processes / frameworks, and the embodiments discussed above should be considered illustrative rather than restrictive.
[0131] The above descriptions are merely preferred embodiments of this application, and this application is not limited to the above embodiments. It is understood that other improvements and variations that can be directly derived or conceived by those skilled in the art without departing from the spirit and concept of this application should be considered to be included within the protection scope of this application.
Claims
1. A dynamic adaptive identity authentication integrated controller, characterized in that, The identity authentication integration controller includes a login gatekeeper plugin and a plugin server. The login gatekeeper plugin and the plugin server establish a connection. The login gatekeeper plugin matches the system framework of the target information system. The identity authentication integration controller connects to the target information system and the identity authentication system respectively through the login gatekeeper plugin. The plug-in server stores a user client mapping table of the target information system, which records the mapping relationship between the legitimate login accounts of the target information system and their corresponding legitimate identity identifiers. The login gatekeeper plugin obtains the account to be logged in from the login request sent to the target information system, and determines the identity identifier to be authenticated corresponding to the account to be logged in; The login gatekeeper plugin confirms successful identity authentication for the account to be logged in when it determines that the identity authentication system has verified the identity identifier to be authenticated, and when it determines that the account to be logged in is a legitimate login account of the target information system based on the login response returned by the intercepted target information system, and when it determines that the user client mapping table of the target information system stored on the plugin server contains a mapping relationship between the account to be logged in and the identity identifier to be authenticated. At this time, it means that the account to be logged in is a legitimate login account of the target information system, and the identity identifier used by the account to be logged in is a legitimate identity identifier of the target information system. Furthermore, the account to be logged in and the identity identifier used by it have been pre-bound and have a mapping relationship, thereby realizing multi-factor authentication.
2. The identity authentication integrated controller according to claim 1, characterized in that, The login gatekeeper plugin obtains the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated, and sends a mapping verification request containing the identity identifier to be authenticated and the account to be logged in to the plugin server; When the plugin server finds that the user client mapping table of the target information system contains the mapping relationship between the identity identifier to be authenticated and the account to be logged in in the mapping verification request, it returns a mapping verification pass response to the login gatekeeper plugin. When the login gatekeeper plugin receives a mapping verification success response, it determines that the user client mapping table of the target information system stored on the plugin server contains a mapping relationship between the account to be logged in and the identity identifier to be authenticated.
3. The identity authentication integrated controller according to claim 1, characterized in that, The login gatekeeper plugin sends a mapping verification request containing the account to be logged in to the plugin server; When the plugin server finds that the user client mapping table of the target information system contains the mapping relationship of the account to be logged in in the mapping verification request, it returns a mapping verification pass response containing the legitimate identity identifier corresponding to the account to be logged in to the login gatekeeper plugin. The login gatekeeper plugin obtains the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated, and when it detects that the identity identifier to be authenticated is consistent with the legitimate identity identifier in the received mapping verification pass response, it determines that the user client mapping table of the target information system contains the mapping relationship between the account to be logged in and the identity identifier to be authenticated.
4. The identity authentication integrated controller according to claim 2 or 3, characterized in that, After obtaining the identity identifier currently used by the account to be logged in as the identity identifier to be authenticated, the login gatekeeper plugin sends an identifier verification request containing the identity identifier to be authenticated to the identity authentication system and receives the challenge code returned by the identity authentication system. The login gatekeeper plugin returns the challenge code to the account to be logged in, and receives the signature result sent by the account to be logged in, which is a signature of the challenge code using the identity identifier to be authenticated; The login gatekeeper plugin sends the signature result to the identity authentication system, and upon receiving a verification response from the identity authentication system indicating that the identity authentication system has verified the identity identifier to be authenticated based on the signature result.
5. The identity authentication integrated controller according to claim 1, characterized in that, The login gatekeeper plugin sends a mapping verification request containing the account to be logged in to the plugin server; When the plugin server finds that the user client mapping table of the target information system contains the mapping relationship of the account to be logged in in the mapping verification request, it returns a mapping verification pass response containing the legitimate identity identifier corresponding to the account to be logged in to the login gatekeeper plugin. When the login gatekeeper plugin receives a mapping verification pass response from the plugin server, it determines that the user client mapping table of the target information system contains a mapping relationship between the account to be logged in and the identity identifier to be authenticated, and uses the legitimate identity identifier corresponding to the account to be logged in contained in the mapping verification pass response as the identity identifier to be authenticated.
6. The identity authentication integrated controller according to claim 5, characterized in that, After receiving the mapping verification pass response returned by the plugin server and obtaining the legal identity identifier corresponding to the account to be logged in as the identity identifier to be authenticated, the login gatekeeper plugin sends an identifier verification request containing the identity identifier to be authenticated to the identity authentication system. The identifier verification request is used to instruct the identity authentication system to verify the identity identifier to be authenticated. When the login gatekeeper plugin receives a verification response from the identity authentication system, it determines that the identity authentication system has verified the identity identifier to be authenticated.
7. The identity authentication integrated controller according to claim 2, 3, or 5, characterized in that, When the plugin server finds that the user client mapping table of the target information system does not contain the mapping relationship of the account to be logged in, it returns a binding prompt response to the login gatekeeper plugin. When the login gatekeeper plugin receives the binding prompt response returned by the plugin server, it redirects to prompt the account to be logged in to bind a valid identity identifier.
8. The identity authentication integrated controller according to claim 7, characterized in that, The login security plugin obtains an identity binding request, which includes the account to be bound and the identity identifier to be bound. When the login gatekeeper plugin determines that the identity authentication system has verified the identity identifier to be bound, and determines that the account to be bound is a legitimate login account of the target information system based on the login response returned by the intercepted target information system, and determines that the user client mapping table of the target information system stored on the plugin server does not contain a mapping relationship between the account to be bound and other legitimate identity identifiers, the plugin generates a mapping establishment request containing the account to be bound and the identity identifier to be bound and sends it to the plugin server. The plugin server establishes a mapping relationship between the account to be bound and the identity identifier to be bound in the received mapping establishment request and stores it in the user client mapping table of the target information system.
9. The identity authentication system according to claim 1, characterized in that, The target information system is a web application system, and the login gatekeeper plugin is a network proxy module developed for the web application system. Alternatively, the target information system is a Linux operating system, and the login gatekeeper plugin is a Linux shared library developed for local or remote user login on the Linux operating system; Alternatively, the target information system is a Windows operating system, and the login gatekeeper plugin is a Windows dynamic link library developed for local or domain users of the Windows operating system to log in locally or remotely. Alternatively, the target information system may be a database, and the login security guard plugin may be a database sharing library developed for the database.
10. The identity authentication integrated controller according to claim 1, characterized in that, When the login gatekeeper plugin detects that the target information system has logged out, or that the login account has logged out, or that the trusted session between the target information system and the login account has expired, it deletes the trusted session and redirects the user to the initialization page.
11. The identity authentication integrated controller according to claim 1, characterized in that, The login security plugin intercepts the response value of the target interface returned by the target information system to the login account. When it detects that the target interface has a corresponding modification policy, it modifies the response value of the target interface according to the modification policy and returns it to the login account; otherwise, it directly returns the response value of the target interface to the login account.
12. The identity authentication integrated controller according to claim 1, characterized in that, The login security plugin obtains the access request sent by the login account to the target information system, and intercepts the redirection request returned by the target information system to the login account; The login gatekeeper plugin detects whether the URL path carried in the redirection request matches the URL path in the access request; When the login gatekeeper plugin detects that the URL path carried in the redirect request does not match the URL path in the access request, it rewrites and repairs the URL path carried in the redirect request according to the URL path in the access request before redirecting. When the login gatekeeper plugin detects that the URL path carried in the redirection request matches the URL path in the access request, it directly redirects the user according to the URL path carried in the redirection request.
Citation Information
Patent Citations
Single sign-on integrated method for Form identity authentication in single login system
CN102624737A
Identity verifying system
CN105827624A
Terminal security login method and device
CN115913743A