A single sign-on authentication method supporting cross-platform and multi-host operation

By implementing cross-platform single sign-on authentication in multi-machine heterogeneous systems, the problems of multiple authentications and inconvenient operating system logout are solved, providing an efficient and secure unified authentication and locking mechanism that supports multiple operating systems and architectures.

CN119743306BActive Publication Date: 2025-11-14BEIJING INST OF COMP TECH & APPL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411882478.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-11-14
Estimated Expiration
2044-12-19

AI Technical Summary

Technical Problem

In a multi-machine heterogeneous system environment, users need to authenticate the operating system and application system multiple times, resulting in low efficiency and inconvenience in logging out of the operating system, making it difficult to achieve unified authentication and synchronous locking.

Method used

By connecting multiple terminal computers to the authentication device, synchronous authentication and locking are achieved, authentication information is shared, and authentication agent software and authentication server system are used in conjunction with the operating system login module to achieve cross-platform single sign-on.

Benefits of technology

It improves the convenience and security of operating system login, ensures the consistency and continuity of the authentication process, supports multiple operating systems and architectures, reduces repeated authentication steps, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743306B_ABST
    Figure CN119743306B_ABST
Patent Text Reader

Abstract

This invention relates to a single sign-on authentication method supporting cross-platform, multi-host operation, belonging to the field of computer security. This invention connects multiple terminal computers in the same location to an authentication device via USB interfaces, enabling synchronous authentication and locking of multiple computers and sharing authentication information. After a user completes authentication with an authentication server on one host, the authentication information generated by the server is encrypted and stored in the authentication device. Other computers complete operating system authentication by reading the authentication information from the authentication device, thus ensuring the consistency and continuity of the authentication process between the host and backup machines. Furthermore, once one computer is locked, other computers are locked simultaneously. When the host machine fails, the backup machine can continue to process business without requiring re-authentication, ensuring system continuity and availability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer security, specifically relating to a single sign-on authentication method that supports cross-platform and multi-host operation. Background Technology

[0002] With the rapid development of information technology, enterprises and organizations are increasingly using multi-machine environments for work. Many tasks often require the collaboration of multiple computers with different operating systems. In this situation, operators face three main problems: first, operating system login authentication – multiple authentications are required when using a computer after logging in or out; second, operating system logout – for confidentiality reasons, operators must log out of each host sequentially when leaving, resulting in low efficiency; and third, application system authentication – users need to authenticate separately when using applications on each host, further reducing efficiency. With the accelerated popularization and application of domestically produced computers in my country, the diverse hardware architectures and different operating systems used in various scenarios further exacerbate the difficulties in using and maintaining login status.

[0003] How to integrate the authentication process with the operating system's login process to build a unified authentication method under multiple heterogeneous operating systems, and to achieve secure synchronous authentication and locking across multiple computers, is a problem that urgently needs to be solved by current technology. Summary of the Invention

[0004] (a) Technical problems to be solved

[0005] The technical problem to be solved by this invention is how to provide a single sign-on authentication method that supports cross-platform and multi-host systems, so as to solve the single sign-on problem in multi-machine heterogeneous system environments.

[0006] (II) Technical Solution

[0007] To address the aforementioned technical issues, this invention proposes a single sign-on authentication method supporting cross-platform multi-host operation. This method includes: connecting multiple terminal computers within the same location to an authentication device via USB interfaces to achieve synchronous authentication and locking of the multiple computers, and sharing authentication information; after a user completes authentication with an authentication server on one host, the authentication information generated by the authentication server is encrypted and stored in the authentication device. Other computers complete operating system authentication by reading the authentication information from the authentication device; thereby ensuring the consistency and continuity of the authentication process between the host and backup machines; and synchronously locking other computers after one computer is locked.

[0008] This method is implemented through a system consisting of authentication agent software, authentication device, and authentication server installed on the terminal computer. First, the authentication device is connected to the terminal computer via a USB interface to provide password services. Then, the user registers on the authentication server and enters their identity and biometric information. When authentication begins, the terminal computer calls the authentication device to establish a secure channel with the authentication server for authentication. After authentication, the authentication information is returned to the terminal computer. After the host completes identity authentication, the authentication information and the user's identity information are encrypted and stored in the authentication device. The backup machine reads this information to complete the authentication and subsequent interaction processes.

[0009] (III) Beneficial Effects

[0010] This invention proposes a single sign-on authentication method that supports cross-platform and multi-host operation. The multi-host single sign-on authentication method provided by this invention has the following significant technical advantages:

[0011] 1. High availability and fault tolerance: Through hot standby mode, when the primary machine fails, the backup machine can process business normally without re-authentication, ensuring the continuity and availability of the system.

[0012] 2. Enhanced Security: This invention employs encryption technology to protect the storage and transmission of authentication information, preventing data leakage or tampering. Simultaneously, the authentication device encrypts and stores authentication and personnel information, ensuring data security even if the device is compromised.

[0013] 3. Seamless Operating System Login Integration: By integrating with the operating system's login module (such as Windows CredentialProviders, Linux LightDM, etc.), other computers can automatically log in after the user completes authentication on the host computer, reducing the number of steps required for repeated authentication and improving the efficiency and convenience of operating system login.

[0014] 4. Synchronous clearing and locking after authentication information expires: When authentication information expires or the user actively locks the computer, the authentication device will promptly clear the authentication information and personnel information, and all computers will simultaneously lock the operating system to ensure the consistency and security of the entire system.

[0015] 5. Broad support for operating systems and architectures: The authentication device of this invention supports a variety of operating systems and computer architectures, which can meet the needs of different enterprises and organizations and adapt to diverse technological environments. Attached Figure Description

[0016] Figure 1 This is a system architecture diagram of the present invention;

[0017] Figure 2 System architecture diagram;

[0018] Figure 3 For deployment mode diagram;

[0019] Figure 4 This is a flowchart of the authentication process. Detailed Implementation

[0020] To make the objectives, contents, and advantages of the present invention clearer, the specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples.

[0021] This invention pertains to computer security authentication technology, specifically a cross-platform, multi-machine single sign-on authentication method designed to solve the single sign-on problem in heterogeneous multi-machine system environments. This invention effectively supports different operating systems and computer architectures, is tightly integrated with the operating system's login process, and enables authentication information sharing and synchronized login status management among multiple hosts, thereby ensuring the convenience and security of the system authentication process.

[0022] The purpose of this invention is to provide a single sign-on authentication method supporting cross-platform, multi-host authentication. The innovation of this method lies primarily in the authentication client, upgrading the existing authentication mode that binds the authentication process to the host to a cross-platform authentication mode that allows multiple computers to authenticate synchronously. This mode connects multiple terminal computers in the same location to the authentication device via USB interfaces, enabling synchronous authentication and locking of multiple computers and sharing authentication information. After a user completes authentication with the authentication server on one host, the authentication information generated by the authentication server is encrypted and stored in the authentication device. Other computers complete operating system authentication by reading the authentication information from the authentication device. This ensures the consistency and continuity of the authentication process between the host and backup machines. Furthermore, once one computer is locked, other computers are locked synchronously, improving system security. The specific technical solution is as follows:

[0023] 1. System Architecture: This invention's system includes authentication agent software, authentication device, and authentication server installed on the terminal computer. The main innovations lie in the authentication agent software and authentication device. First, the authentication device is connected to the terminal computer via a USB interface to provide password services. Then, the user registers on the authentication server, entering their identity and biometric information. Upon starting authentication, the terminal computer uses the authentication device to establish a secure channel with the authentication server for authentication. After authentication, the authentication information is returned to the terminal computer. After the host completes identity authentication, the authentication information and user identity information are encrypted and stored in the authentication device. The backup machine can read this information to complete the authentication and subsequent interaction processes.

[0024] 2. Binding the Authentication Process with Operating System Login: In this invention, the authentication process is integrated with the terminal operating system's login module (such as CredentialProviders for Windows, LightDM for Linux, etc.). It takes over the original operating system's authentication mode. Once the host completes the authentication process, it can log in to the operating system. Simultaneously, the backup machine reads the authentication information from the authentication device and can also log in and access the operating system desktop. In this way, the authentication process and the operating system login process are bound together. Users no longer need to enter credentials multiple times to access the operating system, greatly improving the user experience and system convenience.

[0025] 3. Authentication Information Expiration and Synchronous Locking: When authentication information expires or the user actively locks the computer, the authentication and personnel information stored in the authentication device will be immediately cleared. When the backup machine detects that the information in the authentication device has expired, it will synchronously lock the computer and exit the operating system desktop to ensure the system is in a secure state. Through integration with the operating system login module, the operating system will automatically trigger a locking operation when authentication information expires to prevent unauthorized access.

[0026] 4. Supports authentication access across multiple operating systems and architectures: This invention supports computers with different operating systems (such as Windows and Linux) and computer architectures (such as x86, x64, and ARM) connecting to the authentication device via USB interface. The authentication device is compatible with the operating system through its authentication module (such as CredentialProviders for Windows and LightDM for Linux), enabling the system to provide a unified authentication mode, operation process, and interface style on computers with various operating systems and architectures. This improves consistency when working collaboratively across multiple operating systems, reduces user awareness of different operating systems during the authentication process, and greatly enhances the user experience.

[0027] Example 1:

[0028] Figure 1 The diagram below shows the system architecture of this invention. The single sign-on authentication method for multiple hosts provided by this invention uses a front-end and back-end cooperation approach to complete the authentication operation.

[0029] The backend authentication server provides management and authentication functions. It manages user identity information, including biometrics and certificates; business information, including business application information and the roles and permissions of personnel in business applications; and terminal information, including terminal number, authentication policy, and operating system. The authentication functions include certificate authentication, biometric comparison, authentication information generation, and validity period management.

[0030] The front-end user terminal includes authentication devices and authentication agent software, mainly encompassing operating system authentication, password services, biometric data collection, and multi-machine information synchronization functions. It establishes a secure channel with the authentication server through password services to ensure secure and reliable transmission. Authentication is completed collaboratively with the authentication server using biometrics, personnel certificate information, and other data. It also manages operating system authentication for each platform, automatically enabling single sign-on based on the personnel information returned by the server. Finally, using the authentication device's password service, user information is encrypted and stored within the authentication device, allowing other devices to simultaneously log in to the operating system upon reading application information.

[0031] After the entire authentication process is completed, users can access the business application system through the authentication agent software, carrying authentication information. The authentication server verifies the authentication information to determine its validity and the user's role and permissions in the application, thus protecting the security of the business system. When users operate the business system on other slave devices, they can still use the authentication information stored in the authentication device to seamlessly access the business system with a single point of entry.

[0032] Figure 2 The diagram shows the client architecture of this invention, which uses authentication proxy software and authentication devices in combination to complete single sign-on authentication for multiple hosts.

[0033] The authentication agent software consists of a platform adaptation module, operating system login software, authentication agent service, device driver and call library, and authentication interface components. The authentication device includes authentication device software.

[0034] The platform adaptation modules include Gina, Credential Providers, and LightDM, which are adapted to Windows XP, Windows 7 / 10 / 11, and Linux systems, respectively. They take over the operating system authentication process and call the operating system login software to provide a unified operating system authentication function across the platforms.

[0035] The operating system login software is responsible for the human-computer interaction process during operating system login, and includes an authentication policy module and a system authentication management module. First, the authentication policy module interacts with the authentication server to obtain the authentication policy information corresponding to the terminal computer, such as certificate authentication or biometric authentication. Then, it calls the authentication proxy service to complete the entire authentication process for the user. Finally, the system authentication management module obtains information such as the desktop and operating system user information of the logged-in operating system, sends it to the platform adaptation module to complete the user's identity authentication and single sign-on to the operating system.

[0036] The authentication proxy service is the core software of the authentication proxy software, providing sub-modules for software upgrade, biometric authentication, certificate authentication, software system configuration, application authentication, device monitoring, and cryptographic service. This service primarily interacts with the authentication server and authentication devices, collects biometric or certificate information, and collaborates with the cryptographic service proxy module to establish a secure channel with the authentication server to complete user authentication. After authentication, the authentication information and user information are stored in the authentication device. The software upgrade sub-module is responsible for upgrading the proxy software and authentication device firmware. The software system configuration sub-module handles software configuration. The application authentication sub-module works with the authentication interface components to enable user access to the business system. The device detection sub-module detects the online status and authentication information of the authentication device. When an update to the authentication information is detected, it proactively notifies the operating system authentication software and logs into the operating system. When the authentication information is detected to be invalid or the device is offline, it proactively invokes the operating system login software to lock the computer system.

[0037] The device driver and interface call library provide software interfaces for the authentication agent service and drive the authentication device.

[0038] The application system client includes an authentication interface component, which provides a standard interface for the authentication system client. The application system can use this interface to interact with the application server through the authentication proxy service to complete secure system access.

[0039] The authentication device software includes a password module, a device certificate module, a biometric data acquisition module, and an authentication information management module. The authentication agent software communicates with the authentication device through the device driver and interface call library to complete authentication and multi-host single sign-on operations.

[0040] Example 2:

[0041] Figure 3 This is a deployment mode diagram in an embodiment of the present invention, illustrating the connection relationship between the authentication device, two terminal computers, and the operating system login module.

[0042] Figure 4 This is a flowchart of the authentication process in an embodiment of the present invention, illustrating the authentication between the host and the backup machine, the binding of the token storage and retrieval, the operating system login process, and the synchronization and locking process after the token expires.

[0043] This invention provides a cross-platform, multi-machine single sign-on authentication method, which, combined with the implementation method of the operating system login process, connects computers with different operating systems and architectures to the authentication device via USB, achieving cross-platform secure authentication. This invention features high availability, strong security, and multi-platform compatibility, making it suitable for the needs of various enterprises and organizations.

[0044] The single sign-on authentication method for multiple hosts provided by this invention has the following significant technical effects:

[0045] 1. High availability and fault tolerance: Through hot standby mode, when the primary machine fails, the backup machine can process business normally without re-authentication, ensuring the continuity and availability of the system.

[0046] 2. Enhanced Security: This invention employs encryption technology to protect the storage and transmission of authentication information, preventing data leakage or tampering. Simultaneously, the authentication device encrypts and stores authentication and personnel information, ensuring data security even if the device is compromised.

[0047] 3. Seamless Operating System Login Integration: By integrating with the operating system's login module (such as Windows CredentialProviders, Linux LightDM, etc.), other computers can automatically log in after the user completes authentication on the host computer, reducing the number of steps required for repeated authentication and improving the efficiency and convenience of operating system login.

[0048] 4. Synchronous clearing and locking after authentication information expires: When authentication information expires or the user actively locks the computer, the authentication device will promptly clear the authentication information and personnel information, and all computers will simultaneously lock the operating system to ensure the consistency and security of the entire system.

[0049] 5. Broad support for operating systems and architectures: The authentication device of this invention supports a variety of operating systems and computer architectures, which can meet the needs of different enterprises and organizations and adapt to diverse technological environments.

[0050] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A single sign-on authentication method supporting cross-platform and multi-host architecture, characterized in that, The method includes: connecting multiple terminal computers in the same location to an authentication device via a USB interface to achieve synchronous authentication and locking of multiple computers and share authentication information; after a user completes authentication with an authentication server on a host computer, the authentication information generated by the authentication server is encrypted and stored in the authentication device, and other computers complete operating system authentication by reading the authentication information in the authentication device; thereby ensuring the consistency and continuity of the authentication process between the host computer and the backup computer; and after one computer is locked, other computers are locked synchronously. This method is implemented through a system consisting of authentication agent software, authentication device, and authentication server installed on the terminal computer. First, the authentication device is connected to the terminal computer via a USB interface to provide password services. Then, the user registers on the authentication server and enters their identity and biometric information. When authentication begins, the terminal computer calls the authentication device to establish a secure channel with the authentication server for authentication. After authentication, the authentication information is returned to the terminal computer. After the host completes identity authentication, the authentication information and the user's identity information are encrypted and stored in the authentication device. The backup machine reads this information to complete the authentication and subsequent interaction processes.

2. The single sign-on authentication method supporting cross-platform and multi-host operation as described in claim 1, characterized in that, The authentication process is integrated with the login module of the terminal operating system, taking over the original operating system's authentication mode. Once the host completes the authentication operation, it can log in to the operating system. At the same time, the backup machine reads the authentication information from the authentication device, performs the login operation synchronously, and enters the operating system desktop. In this way, the authentication process and the operating system's login process are bound together, and users can enter the operating system without having to enter credentials multiple times.

3. The single sign-on authentication method supporting cross-platform and multi-host operation as described in claim 2, characterized in that, For Windows operating systems, the login module is CredentialProviders; for Linux operating systems, the login module is LightDM.

4. The single sign-on authentication method supporting cross-platform and multi-host operation as described in claim 1, characterized in that, When authentication information expires or the user actively locks the computer, the authentication information and personnel information stored in the authentication device will be immediately cleared. When the backup machine detects that the information in the authentication device has expired, it will lock the computer and exit the operating system desktop to ensure that the system is in a secure state. Through integration with the operating system login module, the operating system will automatically trigger a locking operation when the authentication information expires to prevent unauthorized access.

5. The single sign-on authentication method supporting cross-platform and multi-host operation as described in claim 1, characterized in that, Computers with different operating systems and architectures can be connected to the authentication device via a USB interface. The authentication device is compatible with the operating system through the operating system's authentication module, enabling the system to provide a unified authentication mode, operation process, and interface style on computers with various operating systems and architectures, thus improving consistency when working collaboratively across multiple operating systems.

6. The single sign-on authentication method supporting cross-platform and multi-host operation as described in claim 1, characterized in that, The authentication server is located in the backend and provides management and authentication functions. It manages user identity information, including biometrics, certificate information, business information, including business application information and the role and permission information of personnel in business applications, and terminal information, including terminal number authentication policy and operating system information. The authentication functions include certificate authentication, biometric comparison, authentication information generation, and validity period management.

7. The single sign-on authentication method supporting cross-platform multi-hosts as described in claim 1, characterized in that, The authentication device and authentication agent software are located at the front end, including operating system authentication, password services, biometric data collection, and multi-machine information synchronization functions. It establishes a secure channel with the authentication server through the password service to ensure secure and reliable transmission. It collaborates with the authentication server to complete the authentication operation using biometrics, personnel certificate information, and other data. It also takes over the authentication of various platform operating systems, automatically performing single sign-on based on the personnel information returned by the server. Finally, using the authentication device's password service, it encrypts and stores user information within the authentication device, allowing other devices to simultaneously log in to the operating system when they read the application information. After the entire authentication process is completed, users can access the business application system through the authentication agent software, carrying authentication information. The authentication server verifies the authentication information to determine its validity and the user's role and permissions in the application, thus protecting the security of the business system. When users operate the business system on other slave devices, they still use the authentication information stored in the authentication device, enabling seamless single-point access to the business system.

8. The single sign-on authentication method supporting cross-platform and multi-host operation as described in claim 1, characterized in that, The authentication agent software includes: platform adaptation module, operating system login software, authentication agent service, device driver and call library, and authentication interface component; The platform adaptation modules include Gina, CredentialProviders, and LightDM, which are adapted to Windows XP, Windows 7 / 10 / 11, and Linux systems respectively. They take over the operating system authentication process and call the operating system login software to provide a unified operating system authentication function across the platforms. The operating system login software is responsible for the human-computer interaction process during operating system login, including an authentication policy module and a system authentication management module. First, the authentication policy module interacts with the authentication server to obtain the authentication policy information corresponding to the terminal computer. Then, it calls the authentication proxy service to complete the entire authentication process for the user. Finally, the system authentication management module obtains the desktop and operating system user information of the logged-in operating system, sends it to the platform adaptation module, completes the user's identity authentication, and enables single sign-on to the operating system. The authentication agent service is the core software of the authentication agent software, providing sub-modules for software upgrade, biometric authentication, certificate authentication, software system configuration, application authentication, device monitoring, and cryptographic service. This service is responsible for interacting with the authentication server and authentication devices, collecting biometric or certificate information, and collaborating with the cryptographic service agent module to establish a secure channel with the authentication server to complete personnel authentication. After authentication, the authentication and personnel information are stored in the authentication device. The software upgrade sub-module is responsible for upgrading the agent software and authentication device firmware. The software system configuration sub-module is responsible for the software configuration function. The application authentication sub-module is responsible for cooperating with the authentication interface component to enable user access to the business system. The device detection sub-module is used to detect the online status and authentication information of the authentication device. When an update to the authentication information is detected, it actively notifies the operating system authentication software and logs into the operating system. When an invalid authentication information or an offline device is detected, it actively calls the operating system login software to lock the computer system. The device driver and interface call library provide software interfaces for the authentication agent service and drive the authentication device.

9. The single sign-on authentication method supporting cross-platform multi-hosts as described in claim 8, characterized in that, The application system client includes an authentication interface component, which provides a standard interface for the authentication system client. The application system interacts with the application server through this interface using the authentication proxy service to complete secure system access.

10. The single sign-on authentication method supporting cross-platform multi-hosts as described in claim 8, characterized in that, The authentication device includes authentication device software, which includes a password module, a device certificate module, a biometric data acquisition module, and an authentication information management module. The authentication agent software communicates with the authentication device through the device driver and interface call library to complete authentication and multi-host single sign-on operations.

Citation Information

Patent Citations

  • Method and system for realizing multi-system single sign-on based on user synchronization

    CN112153041A

  • Synchronizing Configuration Information Among Multiple Clients

    US20070283011A1