A public authorization authentication method, system, storage medium and program product

By receiving and processing the registration information of the authorizing party and the authorized party on a public authorization and authentication platform, allocating software development kits and verifying the consistency of the login protocol, the problem of low complexity and security of single sign-on in the existing technology is solved, and an efficient and secure user authentication process is achieved.

CN119885142BActive Publication Date: 2025-11-25CLOUDCHAIN GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411954160.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-11-25
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

The lack of standardized and reusable single sign-on solutions in existing technologies leads to high development costs, complexity, and potential error rates for both the authorizing and authorized parties during integration. Furthermore, differences in login protocols make login integration difficult.

Method used

The system receives and processes batch-imported registration information of licensors and authorized parties on a public authorization and authentication platform, allocates preset software development kits, performs login protocol consistency verification and audit, and achieves seamless connection and data interaction through protocol conversion function.

Benefits of technology

It improves the efficiency and security of single sign-on, realizes an efficient, convenient and secure user authentication process between the authorizing party and the authorized party, and reduces repeated logins and potential security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885142B_ABST
    Figure CN119885142B_ABST
Patent Text Reader

Abstract

The application provides a public authorization authentication method, system, storage medium and program product, receives and processes the registration information of a plurality of authorized parties and a plurality of authorized parties in batch import, obtains the authorized party login protocol and the authorized party login protocol and distributes the preset software development kit to the authorized party and the authorized party; the authorized party initiates the authorization application to the authorized party, and after the authorized party audits the cooperation relationship between the authorized party and the authorized party, the authorized party identity and the authorized party security, sends the audit passing result to the authorized party; the authorization application passes the first interface called by the preset software development kit to encapsulate the application information, obtains and transmits to the public authorization authentication platform; the authorized party login protocol and the authorized party login protocol selected by the user need to be used are consistent; receive and store the login state information and confirmation information sent by the authorized party, and send to the authorized party to enable the user to successfully enter the user login success page.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of authorization authentication, and in particular to a public authorization authentication method, system, storage medium and program product. BACKGROUND

[0002] Single sign-on (SSO) technology is an identity verification mechanism, in which a user uses a set of credentials to log in to multiple systems or applications without having to repeatedly input the credentials for each system. The core idea of single sign-on is to seamlessly access multiple application systems after completing a single login through a unified identity verification process. This mechanism simplifies the login operation of the user and reduces the security risks that may be caused by multiple logins. Existing single sign-on is usually implemented based on an open standard, and common ones include Security Assertion Markup Language (SAML), Open Authorization (Oauth) and Central Authentication Service (CAS). The client of single sign-on usually refers to a browser, the service of the authorization party provides authentication functions, and the service of the authorized party receives authentication services. If the authorized party accesses the authorization party as a user of the authorization party, the authorized party can directly log in to the service of the authorized party.

[0003] In the prior art, the authorization party implements an open standard of single sign-on, provides a registration service and develops a software development kit (SDK) required for single sign-on. The authorization party issues a unique identifier and an authentication key to the authorized party that completes the registration, and provides the software development kit to the authorized party for use. After the authorized party performs corresponding secondary development work according to the standard of the authorization party, the authorized party can use the user information of the authorization party to perform a login operation. In the single sign-on process, both the provider of the authorization party and the integrator of the authorized party face a large amount of development tasks. When an authorization party is integrated with other authorized parties or an authorized party is integrated with multiple authorization parties, there is no ready-made and universal solution that can be directly reused. Each party starts from scratch to perform repeated development work, which increases the time cost of development and improves the complexity and potential error rate of the project. If there is a difference between the login protocols used by the authorization party and the authorized party, the two parties will not be able to implement login integration. Therefore, a big challenge in the current technical implementation is the lack of a standardized and reusable single sign-on solution to implement an efficient and secure user authentication process. SUMMARY

[0004] In view of this, the embodiments of the present application provide a public authorization authentication method, system, storage medium and program product to eliminate or improve one or more defects in the prior art, and solve the problem of low efficiency and security of the user authentication process in the prior art.

[0005] One aspect of the present application provides a public authorization authentication method, which is performed on a public authorization authentication platform. The method includes the following steps:

[0006] The system receives and processes registration information from multiple authorized parties and authorized users imported in batches, obtains the login agreements of the authorized parties and authorized users, and assigns a preset software development kit to the authorized parties and authorized users; the software development kit encapsulates various transmission interfaces and protocol specifications specified by the public authorization and authentication platform.

[0007] The authorization application initiated by the authorized party to request authorization from the authorizing party is sent to the authorizing party through the platform's internal information system, so that the authorizing party can review it and send the review result to the authorized party; the authorization application encapsulates the application information through the first interface called by the preset software development kit and transmits it to the public authorization authentication platform; the content reviewed by the authorizing party includes: the cooperative relationship between the authorized party and the authorizing party, the identity of the authorized party, and the security of the authorized party;

[0008] The consistency between the login protocol of the authorizing party selected by the user and the login protocol of the authorized party is verified.

[0009] The system receives and stores login status information indicating that the user has logged into the authorizing party and confirmation information indicating that the user agrees to use the authorizing party's account to log into the authorized party. The system then sends the login status information and the confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page.

[0010] In some embodiments, receiving and processing registration information of multiple licensors and multiple licensees imported in batches includes:

[0011] The system receives registration information from multiple authorized parties and multiple authorized parties, and reviews the format, completeness, and security of the registration information. When there are format errors, information defects, or warnings, the public authorization and authentication platform returns error messages to the authorized parties and authorized parties so that they can modify and resubmit the registration information.

[0012] The information of the authorized party and the authorized party that have passed the review is organized and uploaded in batches through a pre-set standardized interface and batch import template.

[0013] In some embodiments, receiving and processing registration information of multiple licensors and multiple licensees imported in batches further includes:

[0014] The registration information is encrypted using an advanced encryption standard or an asymmetric encryption algorithm;

[0015] The registration information of the authorizing party and the registration information of the authorized party are stored in different tablespaces of the public authorization and authentication platform.

[0016] In some embodiments, after receiving the authorization request initiated by the authorized party requesting authorization from the licensor, and sending it to the licensor through the platform's internal information system for review, the process further includes:

[0017] When the licensor fails to approve the authorization application, it receives the reason feedback information from the licensor and transmits the reason feedback information to the authorized party so that the authorized party can adjust the authorization application and resend it.

[0018] In some embodiments, verifying the consistency between the authorizing party login protocol and the authorized party login protocol includes:

[0019] The system compares the login protocol of the authorizing party selected by the user after logging in with the authorized party with the login protocol of the authorized party. If they are consistent, the protocol of both parties is used. If they are inconsistent, the protocol is automatically converted through the protocol conversion function of the public authorization and authentication platform.

[0020] In some embodiments, after receiving and storing login status information indicating that the user has logged into the authorizing party and confirmation information indicating that the user agrees to use the authorizing party's account to log into the authorized party, and sending the login status information and the confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page, the method further includes:

[0021] The login status information and the confirmation information are stored in the local storage module of the public authorization and authentication platform. When the user opens the user login address configured in the software development kit in the browser and enters the login page, the authorized party directly enters the user login success page based on the login status information and the confirmation information and maintains the user's login status.

[0022] On the other hand, the present invention also provides a public authorization and authentication system, the system comprising:

[0023] The authorization module is used to send the licensor's registration information and licensor's login agreement to the public authorization and authentication platform, receive the preset software development kit allocated by the public authorization and authentication platform, and review the authorization application;

[0024] The authorized module is used to send the authorized party's registration information and authorized login agreement to the public authorization and authentication platform, receive the preset software development kit allocated by the public authorization and authentication platform, initiate an authorization application to request authorization from the authorizing party, and receive the approval result.

[0025] The client module is used for users to access and log in to the authorized party and confirm the authorizing party that needs to initiate an authorization request;

[0026] A public authorization and authentication platform is used to execute the public authorization and authentication method described above, receiving and processing registration information of multiple licensors and multiple authorized parties imported in batches, obtaining licensor login agreements and authorized party login agreements, and distributing a preset software development kit to the licensor and the authorized party; sending authorization applications initiated by the authorized party to request authorization from the licensor to the licensor through the platform's internal information system, so that the licensor can review them and send the review result to the authorized party; verifying the consistency between the licensor login agreement selected by the user and the authorized party login agreement; receiving and storing login status information indicating that the user is logging into the licensor and confirmation information indicating that the user agrees to use the licensor's account to log into the authorized party, and sending the login status information and the confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page.

[0027] In some embodiments, the system further includes:

[0028] The cloud storage module is used to store the registration information, the authorizing party login agreement, the authorized party login agreement, the authorization application, the login status information, and the confirmation information during the public authorization authentication method process executed on the public authorization authentication platform.

[0029] On the other hand, the present invention also provides a computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implement the steps of any of the methods described above.

[0030] On the other hand, the present invention also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of any of the methods described above.

[0031] The beneficial effects of the present invention are at least as follows:

[0032] The public authorization authentication method, system, storage medium, and program product described in this invention improves work efficiency and ease of operation through batch access, making the interconnection of the entire public authorization authentication system more efficient and smooth. Pre-set software development kits, which encapsulate various transmission interfaces and protocol specifications defined by the public authorization authentication platform, are distributed to the authorizing party and the authorized party, achieving seamless connection and data interaction between them. The software development kits are publicly available, allowing developers to freely obtain and use them to integrate and develop related authentication functions for easier implementation of single sign-on and access control in applications or systems. When the authorizing party's login protocol differs from the authorized party's login protocol, the public authorization authentication platform's protocol conversion function automatically performs protocol conversion to smoothly complete the login integration. This process enables data exchange and information sharing, ensuring an efficient and convenient access process. Authorizing and authorized parties achieve high efficiency and security through the public authorization and authentication platform. Users only need to log in once to access all authorized resources without repeatedly entering credentials. Furthermore, this single sign-on solution eliminates the need for users to reuse the same password across multiple platforms, reducing potential security risks. Access to the public authorization and authentication platform provides both authorizing and authorized parties with a convenient, efficient, and secure single sign-on experience. The platform has the capability to extend to multiple single sign-on protocols, supporting various authentication protocols and achieving seamless integration between different systems and unified user identity verification. It adapts to various application scenarios and needs, ensuring smooth identity authentication and access control for users across multiple systems.

[0033] Additional advantages, objects, and features of the invention will be set forth in part in the description which follows, and will also become apparent in part to those skilled in the art upon studying the description, or may be learned by practice of the invention. The objects and other advantages of the invention can be realized and obtained by means of the structures specifically pointed out in the description and drawings.

[0034] Those skilled in the art will understand that the objectives and advantages achievable with the present invention are not limited to those specifically described above, and that the above and other objectives achievable with the present invention will become clearer from the following detailed description. Attached Figure Description

[0035] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, are not intended to limit the scope of the invention. In the drawings:

[0036] Figure 1 This is a flowchart illustrating a public authorization authentication method according to an embodiment of the present invention.

[0037] Figure 2This is a schematic diagram of the structure of a public authorization and authentication system according to an embodiment of the present invention. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and accompanying drawings. Here, the illustrative embodiments and descriptions of this invention are used to explain the invention, but are not intended to limit the invention.

[0039] It should also be noted that, in order to avoid obscuring the invention with unnecessary details, only the structures and / or processing steps closely related to the solution according to the invention are shown in the accompanying drawings, while other details that are not closely related to the invention are omitted.

[0040] It should be emphasized that the term "including / comprises" as used herein refers to the presence of a feature, element, step, or component, but does not exclude the presence or addition of one or more other features, elements, steps, or components.

[0041] It should also be noted that, unless otherwise specified, the term "connection" in this article can refer not only to a direct connection, but also to an indirect connection involving an intermediary.

[0042] In the following description, embodiments of the invention will be illustrated with reference to the accompanying drawings. In the drawings, the same reference numerals represent the same or similar parts, or the same or similar steps.

[0043] In existing technologies, the licensor implements an open standard for single sign-on, provides registration services, and develops the software development kit (SDK) required for single sign-on. The licensor issues a unique identifier and authentication key to the registered authorized party and provides the SSD to the authorized party. After the authorized party performs corresponding secondary development work according to the licensor's standard, the authorized party can use the licensor's user information to log in. This invention proposes a public authorization authentication method, system, storage medium, and program product. The public authorization authentication method is performed on a public authorization authentication platform, receiving and processing registration information from multiple licensors and authorized parties imported in batches, obtaining the licensor login protocol and the authorized party login protocol, and distributing a pre-set SSD containing various transmission interfaces and protocol specifications defined by the public authorization authentication platform to the licensor and authorized party. The method also includes a request from the authorized party. The authorization application submitted by the licensor is sent to the licensor through the platform's internal information system for review. Upon approval, the licensor sends the result to the authorized party. The authorization application encapsulates the application information through a first interface called by a pre-defined software development kit (SDK) and transmits it to the public authorization authentication platform. The licensor reviews the cooperation relationship between the authorized party and the licensor, the identity of the authorized party, and the security of the authorized party. The licensor confirms the consistency between the licensor's login protocol and the authorized party's login protocol selected by the user. The licensor receives and stores login status information indicating the user's login to the licensor and confirmation information indicating the user's agreement to use the licensor's account to log in to the authorized party. The licensor then sends the login status information and confirmation information to the authorized party through a second interface called by the pre-defined SSD, allowing the user to successfully log in to the authorized party and be redirected to a login success page.

[0044] Figure 1 This is a flowchart illustrating a public authorization authentication method according to an embodiment of the present invention. Specifically, this application provides a public authorization authentication method, which is performed on a public authorization authentication platform and includes the following steps S101-S104:

[0045] Step S101: Receive and process the registration information of multiple licensors and multiple authorized parties imported in batches, obtain the licensor login agreement and the authorized party login agreement, and allocate the preset software development kit to the licensor and the authorized party; the software development kit encapsulates various transmission interfaces and protocol specifications specified by the public authorization and authentication platform.

[0046] Step S102: The authorization application initiated by the authorized party to request authorization from the licensor is sent to the licensor through the platform's internal information system for review. The licensor then sends the review result to the authorized party. The authorization application encapsulates the application information through the first interface called by the preset software development kit and transmits it to the public authorization authentication platform. The content reviewed by the licensor includes the cooperative relationship between the authorized party and the licensor, the identity of the authorized party, and the security of the authorized party.

[0047] Step S103: Verify the consistency between the authorizing party's login agreement and the authorized party's login agreement selected by the user.

[0048] Step S104: Receive and store the login status information sent by the authorizing party to indicate that the user has logged into the authorizing party and the confirmation information sent by the authorizing party to indicate that the user agrees to use the authorizing party's account to log into the authorized party, and send the login status information and confirmation information to the authorized party through the second interface called by the preset software development kit so that the user can successfully log in to the authorized party and be redirected to the user login success page.

[0049] In step S101, various licensors and authorized parties are connected to the public authorization and authentication platform in batches at once, improving work efficiency and ease of operation; the format, completeness, and security of the registration information are reviewed to ensure the security of the connection process between licensors and authorized parties connecting to the public authorization and authentication platform; the public authorization and authentication platform reviews the registration information and generates detailed error messages and indicates the problems based on format errors, information defects, and danger warnings, and sends them to licensors and authorized parties through the public authorization and authentication platform's notification system, which includes, but is not limited to, email, in-site messages, and pop-ups; licensors and authorized parties organize and transmit their information in a structured manner according to the data format and transmission requirements of the preset standardized interface, with data formats including, but not limited to, JSON and XML; batch import templates, including but not limited to Excel and CSV file templates, are uploaded in batches according to the format matching the public authorization and authentication platform database, reducing operational errors and workload. In some embodiments, receiving and processing the batch-imported registration information of multiple licensors and multiple authorized parties includes steps S1011~S1012:

[0050] Step S1011: Receive registration information from multiple licensors and multiple authorized parties, and review the format, completeness, and security of the registration information; when there are format errors, information defects, or danger warnings, the public authorization and authentication platform returns error messages to the licensors and authorized parties so that they can modify and resubmit the registration information.

[0051] Step S1012: Organize and upload information of the approved authorizing party and authorized party in batches using the preset standardized interface and batch import template.

[0052] In some embodiments, receiving and processing the registration information of multiple licensors and multiple licensees imported in batches further includes steps S1-S2:

[0053] Step S1: Encrypt the registration information using Advanced Encryption Standard or asymmetric encryption algorithm.

[0054] Step S2: Store the registration information of the authorizing party and the registration information of the authorized party in different tablespaces of the public authorization and authentication platform.

[0055] Specifically, the Advanced Encryption Standard (AES) transforms registration information into ciphertext. Asymmetric encryption algorithms utilize a public-private key pairing mechanism; the public key is publicly used to encrypt data, and the corresponding private key is used for decryption, ensuring data confidentiality during storage and transmission. Both the authorizing and authorized party tablespaces contain multiple data tables. The authorizing party tablespace stores basic information, authorized resource information, and authorized history information for the authorizing party, while the authorized party tablespace stores the authorized party's identity information, authorized purpose description, and usage records. This clear tablespace partitioning ensures physical isolation of data and reduces interference between data. Indexes are created in each data table to quickly locate data storage locations in subsequent queries, improving response speed.

[0056] Furthermore, the default software development kit (SDK) is publicly available content provided by a public licensing and authentication platform for use by licensors and licensees. Licensors and licensees use the SSD to integrate and develop relevant authentication functions. The SSD is embedded into their respective projects, which are services deployed on the public licensing and authentication platform's server. This allows for seamless connection and data interaction between licensors and licensees through various transmission interfaces within the SSD. When a user opens the licensor's default login address in their browser, they are redirected to the licensee's login success page, maintaining their login status. If the user has already logged in with the licensor, the login is automatically successful, and the user is redirected back to the licensee's login success page.

[0057] In steps S102 and S103, the application information includes, but is not limited to, the authorized party's basic information, business scope, and purpose of intervention; the platform's internal information system includes, but is not limited to, email and in-site messages. After the authorizing party initiates the application, the authorized party reviews it. The key to the review is to ensure that each partner meets security and business requirements. After the review is passed, the connection relationship between the two parties is confirmed on the public authorization authentication platform. In some embodiments, after receiving the authorization application initiated by the authorized party to request authorization from the authorizing party, and sending it to the authorizing party through the platform's internal information system for the authorizing party to review, the process also includes: when the authorizing party fails to review the authorization application, receiving the reason feedback information issued by the authorizing party and transmitting the reason feedback information to the authorized party so that the authorized party can adjust the authorization application and resend it. Furthermore, both the authorized party and the authorizing party can act as the applicant to initiate an authorization application to the target party of the public authorization authentication platform, and the target party reviews it.

[0058] Furthermore, the user selects the account of the authorizing party to log in to the authorized party. The authorizing party's login protocol and the authorized party's login protocol are compared. In some embodiments, the consistency verification of the authorizing party's login protocol and the authorized party's login protocol includes comparing whether they are consistent. If they are consistent, the protocol of both parties is used; if they are inconsistent, the protocol conversion function of the public authorization authentication platform is used to automatically convert the protocol. The protocol conversion function ensures the security and privacy of users during the login process, thereby effectively preventing unauthorized access and data leakage. The public authorization authentication platform has the ability to extend multiple single sign-on protocols and supports multiple different authentication protocols, enabling seamless connection between different authorizing parties and authorized parties and unified verification of user identities.

[0059] In step S104, after the user logs in to the authorizing party and agrees to use the authorizing party's account to log in to the authorized party, the user sends confirmation information and login status information to the public authorization and authentication platform. The confirmation information indicates that the user agrees to use the authorizing party's account to log in to the authorized party, and the login status information indicates the user's relevant information when logging in to the authorizing party. The user logs in to the authorized party based on the confirmation information and login status information and is directly redirected to the user login success page. The confirmation information and login status information are stored in the public authorization and authentication platform, so the user does not need to log in to the authorizing party again to be directly redirected to the user login success page of the authorized party.

[0060] In some embodiments, after receiving and storing login status information indicating that the user is logging into the authorizing party and confirmation information indicating that the user agrees to use the authorizing party's account to log into the authorized party, and sending the login status information and confirmation information to the authorized party through a second interface called by a preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page, the method further includes:

[0061] Login status information and confirmation information are stored in the local storage module of the public authorization and authentication platform. When a user opens the user login address configured in the software development kit in the browser and enters the login page, the authorized party directly enters the user login success page based on the login status information and confirmation information and maintains the user's login status.

[0062] On the other hand, the present invention also provides a public authorization and authentication system, the system comprising:

[0063] The authorization module is used to send the licensor's registration information and login agreement to the public authorization and authentication platform, receive the preset software development kits allocated by the public authorization and authentication platform, and review authorization applications.

[0064] The authorized module is used to send the authorized party's registration information and authorized login agreement to the public authorization and authentication platform, receive the preset software development kit allocated by the public authorization and authentication platform, initiate an authorization application to request authorization from the licensor, and receive the approval result.

[0065] The client module is used for users to access and log in to the authorized party and confirm the authorizing party that needs to initiate an authorization request.

[0066] A public authorization and authentication platform is used to execute the public authorization and authentication methods described above, receive and process registration information of multiple licensors and authorized parties imported in batches, obtain the licensor login agreement and authorized party login agreement, and distribute a preset software development kit to the licensor and authorized party; send authorization applications initiated by the authorized party to the licensor through the platform's internal information system for review by the licensor, and then send the review result to the authorized party; confirm the consistency between the licensor login agreement and the authorized party login agreement of the licensor selected by the user; receive and store login status information indicating that the user is logging into the licensor and confirmation information indicating that the user agrees to use the licensor's account to log into the authorized party, and send the login status information and confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page.

[0067] In some embodiments, the system further includes:

[0068] The cloud storage module is used to store registration information, authorizing party login agreement, authorized party login agreement, authorization application, login status information and confirmation information during the public authorization and authentication process executed on the public authorization and authentication platform.

[0069] Specifically, storing registration information, authorizing party login agreement, authorized party login agreement, authorization application, login status information, and confirmation information in the cloud storage module enables efficient centralized data management and provides users with a more convenient and secure login experience.

[0070] On the other hand, the present invention also provides a computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implements the steps of any of the above methods.

[0071] On the other hand, the present invention also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of any of the above methods.

[0072] The present invention will now be described with reference to a specific embodiment:

[0073] This invention provides a public authorization authentication method, system, storage medium, and program product. The public authorization authentication method operates on a public authorization authentication platform, which constructs an efficient login authorization application system for users. Authorizers and authorized parties can easily view the information of all users connected to the platform. When one party needs to connect with another, they can submit an application through the platform, which is then reviewed by the other party. After the review process is completed and approved, both parties can log in through the platform, thus achieving a more efficient and secure user authentication process. Users can connect various different authorizers and authorized parties in batches at once, eliminating the need to manually add partners one by one, thereby greatly improving work efficiency and operational convenience. Both authorizers and authorized parties can join the public authorization authentication platform through this batch connection method, making the interconnection of the entire public authorization authentication system more efficient and smooth. The public authorization and authentication platform provides a universal software development kit (SDK) that can be used by both the licensor and the authorized party. Both parties need to embed this SDK into their respective projects, which utilize services deployed on the public authorization and authentication platform's server to achieve seamless connectivity and data exchange between the two systems. Specifically, the licensor needs to configure the user's login address and the authorized party's redirect address according to predetermined rules. When a user on the licensor's platform opens this configured login address in their browser, they will be directed to a login page. If the user has already logged in with the licensor, they do not need to log in again. After successful login, the system automatically redirects the user to the authorized party, which maintains the user's login status. The authorized party retrieves the user's relevant information from the licensor and uses this information for further business operations.

[0074] Figure 2This is a schematic diagram of the structure of a public authorization and authentication system according to an embodiment of the present invention. The specific working process of the public authorization and authentication system includes: the authorizing party of the authorization module and the authorized party of the authorized module register on the public authorization and authentication platform and confirm the authorizing party login protocol and the authorized party login protocol used; when the authorized party wants to log in using the authorizing party's user account, the authorized party applies for authorization from the authorizing party on the public authorization and authentication platform, and the platform notifies the authorizing party of the authorization via message; after the authorizing party approves the application in the review list, it provides the public authorization and authentication platform with notification of the review result to the authorized party; the user logs in on the authorized party's client module and selects the authorizing party to use; the authorized party confirms the protocol used by the authorizing party on the public authorization and authentication platform; the public authorization and authentication platform determines whether both parties use the same protocol; if not, it automatically performs protocol conversion; after redirecting to the authorizing party, the user authorizes the user, and the user agrees to log in to the authorized party using the authorizing party's account; after the user successfully logs in to the authorized party, they are redirected to the authorized party's login success page.

[0075] The authorizing and authorized parties can easily achieve single sign-on functionality by simply connecting to a public authorization and authentication platform. Both parties perform seamless identity verification and access control, simplifying the operation process and improving efficiency. In this way, users only need to log in once to access all authorized resources without having to repeatedly enter credentials, thereby improving the user experience. In addition, this single sign-on solution also enhances system security because users do not need to reuse the same password on multiple platforms, reducing potential security risks.

[0076] When there are inconsistencies in the login protocol between the authorizing party and the authorized party, the protocol conversion function is used to smoothly complete the entire login integration process; the two parties conduct seamless data exchange and information sharing to ensure that the entire access process is both efficient and convenient.

[0077] In summary, this invention provides a public authorization authentication method, system, storage medium, and program product. It receives and processes batch-imported registration information from multiple licensors and authorized parties, obtains licensor login protocols and authorized party login protocols, and distributes a preset software development kit (SDK) to the licensors and authorized parties. The SSD encapsulates various transmission interfaces and protocol specifications defined by the public authorization authentication platform. The authorization application initiated by the authorized party to request authorization from the licensor is sent to the licensor through the platform's internal information system for review. The licensor then sends the review result to the authorized party. The authorization application encapsulates the application information through a first interface called by the preset SSD. The data is transmitted to the public authorization and authentication platform. The content reviewed by the authorizing party includes: the cooperative relationship between the authorized party and the authorizing party, the identity of the authorized party, and the security of the authorized party; the consistency between the authorizing party's login protocol selected by the user and the authorized party's login protocol is confirmed; the authorizing party receives and stores login status information indicating that the user has logged into the authorizing party and confirmation information indicating that the user agrees to use the authorizing party's account to log into the authorized party, and sends the login status information and the confirmation information to the authorized party through the second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page.

[0078] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the aforementioned edge computing server deployment method. The computer-readable storage medium can be a tangible storage medium, such as random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, floppy disks, hard disks, removable storage disks, CD-ROMs, or any other form of storage medium known in the art.

[0079] Those skilled in the art will understand that the exemplary components, systems, and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Whether implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention. When implemented in hardware, it can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the desired tasks. The programs or code segments can be stored in a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried in a carrier wave.

[0080] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.

[0081] In this invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with or in place of features of other embodiments.

[0082] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, various modifications and variations of the embodiments of the present invention are possible. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A public authorization authentication method, characterized in that, The method is performed on a public authorized authentication platform, and the method includes: The system receives and processes registration information from multiple authorized parties and authorized users imported in batches, obtains the login agreements of the authorized parties and authorized users, and assigns a preset software development kit to the authorized parties and authorized users; the software development kit encapsulates various transmission interfaces and protocol specifications specified by the public authorization and authentication platform. The authorization application initiated by the authorized party to request authorization from the authorizing party is sent to the authorizing party through the platform's internal information system, so that the authorizing party can review it and send the review result to the authorized party; the authorization application encapsulates the application information through the first interface called by the preset software development kit and transmits it to the public authorization authentication platform; the content reviewed by the authorizing party includes: the cooperative relationship between the authorized party and the authorizing party, the identity of the authorized party, and the security of the authorized party; The consistency between the login protocol of the authorizing party selected by the user and the login protocol of the authorized party is verified. The system receives and stores login status information indicating that the user has logged into the authorizing party and confirmation information indicating that the user agrees to use the authorizing party's account to log into the authorized party. The system then sends the login status information and the confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page.

2. The public authorization authentication method according to claim 1, characterized in that, Receive and process batch imports of registration information from multiple licensors and multiple authorized parties, including: The system receives registration information from multiple authorized parties and multiple authorized parties, and reviews the format, completeness, and security of the registration information. When there are format errors, information defects, or warnings, the public authorization and authentication platform returns error messages to the authorized parties and authorized parties so that they can modify and resubmit the registration information. The information of the authorized party and the authorized party that have passed the review is organized and uploaded in batches through a pre-set standardized interface and batch import template.

3. The public authorization authentication method according to claim 2, characterized in that, Receiving and processing batch imports of registration information from multiple licensors and multiple authorized parties also includes: The registration information is encrypted using an advanced encryption standard or an asymmetric encryption algorithm; The registration information of the authorizing party and the registration information of the authorized party are stored in different tablespaces of the public authorization and authentication platform.

4. The public authorization authentication method according to claim 1, characterized in that, After receiving the authorization request initiated by the authorized party requesting authorization from the authorizing party, and sending it to the authorizing party through the platform's internal information system for review, the process further includes: When the licensor fails to approve the authorization application, it receives the reason feedback information from the licensor and transmits the reason feedback information to the authorized party so that the authorized party can adjust the authorization application and resend it.

5. The public authorization authentication method according to claim 1, characterized in that, The consistency verification between the authorizing party login protocol and the authorized party login protocol includes: The system compares the login protocol of the authorizing party selected by the user after logging in with the authorized party with the login protocol of the authorized party. If they are consistent, the protocol of both parties is used. If they are inconsistent, the protocol is automatically converted through the protocol conversion function of the public authorization and authentication platform.

6. The public authorization authentication method according to claim 1, characterized in that, After receiving and storing login status information indicating that the user has logged into the authorizing party and confirmation information indicating that the user agrees to use the authorizing party's account to log into the authorized party, and sending the login status information and the confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page, the method further includes: The login status information and the confirmation information are stored in the local storage module of the public authorization and authentication platform. When the user opens the user login address configured in the software development kit in the browser and enters the login page, the authorized party directly enters the user login success page based on the login status information and the confirmation information and maintains the user's login status.

7. A public authorization and authentication system, characterized in that, The system includes: The authorization module is used to send the licensor's registration information and licensor's login agreement to the public authorization and authentication platform, receive the preset software development kit allocated by the public authorization and authentication platform, and review the authorization application; The authorized module is used to send the authorized party's registration information and authorized login agreement to the public authorization and authentication platform, receive the preset software development kit allocated by the public authorization and authentication platform, initiate an authorization application to request authorization from the authorizing party, and receive the approval result. The client module is used for users to access and log in to the authorized party and confirm the authorizing party that needs to initiate an authorization request; A public authorization and authentication platform is configured to execute the public authorization and authentication method as described in any one of claims 1 to 6, receive and process registration information of multiple licensors and multiple authorized parties imported in batches, obtain licensor login agreements and authorized party login agreements, and allocate a preset software development kit to the licensor and the authorized party; send authorization applications initiated by the authorized party to the licensor for authorization through the platform's internal information system, so that the licensor can review them and send the review approval result to the authorized party; verify the consistency between the licensor login agreement selected by the user and the authorized party login agreement; receive and store login status information indicating that the user has logged into the licensor and confirmation information indicating that the user agrees to use the licensor's account to log into the authorized party, and send the login status information and the confirmation information to the authorized party through a second interface called by the preset software development kit so that the user can successfully log into the authorized party and be redirected to the user login success page.

8. The public authorization and authentication system according to claim 7, characterized in that, The system also includes: The cloud storage module is used to store the registration information, the authorizing party login agreement, the authorized party login agreement, the authorization application, the login status information, and the confirmation information during the public authorization authentication method process executed on the public authorization authentication platform.

9. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method as described in any one of claims 1 to 8.

10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and device for processing multi-protocol single sign-on request

    CN114499930A

  • Authentication server docking method and device, electronic equipment and storage medium

    CN117640121A