A dual session verification method, device, terminal and medium
By setting up global users and local users in the single sign-in architecture and integrating dual session verification methods in the application system, the problems such as organizational structure redundancy and user status synchronization difficulties in the existing single sign-in architecture are solved, and higher system stability and user experience are achieved.
Patent Information
- Application Number
- CN202510387034.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-03-31
AI Technical Summary
The existing single sign-in architecture has redundant organizational structures, user association problems, difficulty in synchronizing user status, low fault tolerance, and the ability to not share local sessions.
By simplifying the organizational structure, setting up global users and local users, avoiding redundant organizational structures, and integrating its own authentication and authentication center session verification and authentication methods in the application system to achieve dual session verification.
It reduces the system failure rate, supports independent session authentication and authentication of local users, avoids frequent synchronization and alignment processes between the authentication center and the application system, and improves user experience and system stability.
Smart Images

Figure CN119892524B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of session verification, and in particular relates to a dual session verification method, device, terminal and medium. Background Art
[0002] For the same organization, there may be many application systems, each with its own organizational structure and session management functions. The session authentication between different organizations is not the same, which results in the same user having to frequently authenticate when using different application systems under the organization, which is a very unfriendly user experience. Therefore, many organizations have adopted a single sign-on solution to solve this problem. Single sign-on means that all applications under the same organization share the authentication status. When you log in to a certain application, other applications also have the login status. Correspondingly, when you log out of a certain application, other applications will also log out of the system accordingly.
[0003] Common single sign-on solutions include: parent domain cookie solution, session sharing solution, distributed session solution, token (jwt+cookie) solution, etc. Cookie+session related solutions may cause CSRF attacks and have security issues, so they are not commonly used. Currently, the more common solution is to implement single sign-on based on the authentication center. This method generally deploys a unified authentication center to manage the single sign-on function of the application system, and the general implementation method is also based on the jwt+cookie method. The above unified authentication center solution has the following problems:
[0004] 1. Redundant organizational structure. Generally speaking, the authentication center has its own independent organizational structure, and each business system has its own organizational structure. However, users of different applications and authentication centers can be considered the same user under the single sign-on architecture.
[0005] 2. User association problem. The organizational structures between different applications and authentication centers are independent. Therefore, the association between the users of the application system and the users of the authentication center must be maintained manually. This strong binding relationship is not conducive to user changes and expansions.
[0006] 3. User status synchronization problem. There is a manually maintained correspondence between the authentication center and the users of each application system. When the user status of the authentication center changes, all application system users must be notified to change their status at the same time. When the user status of an application system changes, the authentication center and other application system users must also be notified to change their status at the same time. In other words, under this single sign-on architecture, an undirected connected graph structure is formed between the authentication center and all application systems, which is very inconvenient to maintain and expand.
[0007] 4. As in the above-mentioned "undirected connected graph" structure, if the synchronization between any two vertices fails, it will cause the problem of user mismatch between the authentication center or the application system. However, there are many synchronization processes in this structure. Therefore, under this architecture, the fault tolerance rate of user synchronization is very low and the error rate is high.
[0008] 5. It destroys the ability to not share local sessions. Once the application system implements the above single sign-on solution, all users must "force sharing". If some users do not need to share sessions, it cannot be implemented. Summary of the invention
[0009] To solve the above problems, the present invention provides a dual session verification method, device, terminal and medium, which simplifies the organizational structure, sets global users and local users, avoids redundant organizational structure, and also avoids the tedious process of frequent synchronization and alignment between the authentication center and users of each application system, reduces the system failure rate, and also supports the ability of local users to perform independent session authentication and authorization.
[0010] In a first aspect, the technical solution of the present invention provides a dual session verification method, comprising the following steps:
[0011] Identify and label user types, including global users and local users;
[0012] Integrate the self-authentication and authentication methods and the authentication center session verification and authentication methods in the application system;
[0013] Register the application system to the target organization of the unified authentication center, re-register the global users of the application system to the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system;
[0014] The application system determines the type of accessing user. If it is a local user of the application system itself, it uses its own authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, it uses the authentication center's session verification and authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources.
[0015] In an optional implementation, identifying the user type and marking it specifically includes:
[0016] Build a user information table;
[0017] Receive a user registration request including user information, where the user information includes a user login password and a user name named in a standard format;
[0018] Fill the user information into the user information table, detect the user name information, determine the user type according to the user name information, and fill the determined user type into the user information table; wherein there is no intersection between the global user set and the local user set of the same application system.
[0019] In an optional implementation, the application system determines the type of the accessing user, specifically including:
[0020] Receive a user login request containing user information;
[0021] Extract the user name from the user information of the user login request;
[0022] Extract a type identifier from the user name, and determine the user type based on the type identifier;
[0023] If the user type is a global user, the global user will use the authentication center session verification authentication method to perform resource request verification after successfully logging in through the unified authentication center;
[0024] If the user type is a local user, the user name is matched with all the user names in the user information table;
[0025] If a consistent user name is matched, the current user is judged to be a local user of the application system itself. After the current user logs in successfully, the subsequent resource request verification is performed using its own authentication method. Otherwise, the login failure is fed back to the user.
[0026] In an optional implementation, if the application system is a local user, the application system uses its own authentication method to verify the resource request, and the verification authorizes the user to access the corresponding interface resources, specifically including:
[0027] A local user logs into the application system, establishes a local session with the application system, and stores the local session;
[0028] Receive a resource access request carrying a local session sent by a local user;
[0029] Retrieve the local session corresponding to the resource access request and verify the validity and integrity of the local session;
[0030] If the local session is valid and complete, confirm that the permissions match, and determine whether the target resource of the local user's current resource access request can be accessed based on the resource access policy and local session permissions;
[0031] If access is possible, authorize the corresponding interface resources to the local user.
[0032] In an optional implementation, if the user is a global user, the authentication center session verification authentication method is used to verify the resource request, and the verification authorizes the user to authorize the corresponding interface resources, specifically including:
[0033] Check whether the global session of the current global user is saved in the browser;
[0034] If it has been saved, the accessed application system uses the authentication center session verification authentication method to verify the resource access request of the global user based on the global session saved in the browser. If the verification passes, the user is authorized to access the corresponding interface resources;
[0035] If not saved, check whether the global session of the current global user is saved in the unified authentication center;
[0036] If saved, the global session is obtained from the unified authentication center and saved in the browser. The authentication center session verification authentication method is used later to verify the resource access request of the global user based on the global session saved by the browser. If the verification passes, the user is authorized to access the corresponding interface resources.
[0037] If it is not saved, the accessed application system jumps to the unified authentication center for global users to log in. After the global user successfully logs in to the unified authentication center, the unified authentication center records the global session and carries the global session to jump to the accessed application system. The accessed application system records the global session in the browser and subsequently uses the authentication center session verification authentication method to verify the resource access request of the global user based on the global session recorded by the browser. If the verification passes, the user is authorized to use the corresponding interface resources.
[0038] In an optional implementation, the authentication center session verification authentication method is used to verify the resource access request of the global user based on the global session saved by the browser. The verification is performed by authorizing the user to access the corresponding interface resource, specifically including:
[0039] Receive resource access requests sent by global users;
[0040] Retrieve the corresponding global session information from the browser and verify the global session information using the authentication center session verification authentication method;
[0041] If the verification passes, the corresponding interface resources are authorized to the global user.
[0042] In an optional embodiment, the method further comprises the following steps:
[0043] The application system detects whether a global user has logged out;
[0044] If the global user logs out, the application system notifies the unified authentication center to delete the global session information of the logged out global user;
[0045] The application system deletes the global session information of the global user who has logged out in the browser.
[0046] In a second aspect, the technical solution of the present invention provides a dual session verification device, comprising:
[0047] User registration module, used to identify and label user types, including global users and local users;
[0048] Authentication method integration module, used to integrate the self-authentication authentication method and the authentication center session verification authentication method in the application system;
[0049] The global user registration module is used to register the application system with the target organization of the unified authentication center, re-register the global users of the application system with the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system;
[0050] The verification module is used by the application system to judge the type of accessing user. If it is a local user, the request is verified using its own authentication method. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, the authentication center session verification method is used to verify the request. If the verification passes, the user is authorized to use the corresponding interface resources.
[0051] In a third aspect, the technical solution of the present invention provides a terminal, including:
[0052] A memory, used for storing a dual session verification program;
[0053] A processor is used to implement the steps of the dual session verification method as described in any one of the above items when executing the dual session verification program.
[0054] In a fourth aspect, the technical solution of the present invention provides a computer-readable storage medium, on which a dual-session verification program is stored. When the dual-session verification program is executed by a processor, the steps of the dual-session verification method as described in any one of the above items are implemented.
[0055] A dual session verification method, device, terminal and medium provided by the present invention have the following beneficial effects compared with the prior art: users register with the application system now, and global users and local users are divided. At the same time, the application system integrates two authentication methods: its own authentication and authorization method and the authentication center session verification authentication method. Then, when the application system registers with the unified authentication center, the global user is re-registered under the target organization of the unified authentication center to form a global user pool, and the global user is cancelled or deleted on the application system side. Finally, the application system uses different authentication methods to authenticate the two users, and then provides the requested resources. The present invention divides the application system users into two types: global users and local users. The global user is unique in the whole domain and is only reserved in the authentication center. The application system no longer reserves the global user; and the local user is also only reserved in each application system. Although the local user and the global user belong to the same application, the two users are respectively given global authentication and local authentication methods. The two users are completely independent in the authentication authorization and access authentication process, thus avoiding the cumbersome process of frequent synchronization and alignment between the authentication center and the users of each application system, and also supports the ability of local users to independently authenticate and authenticate sessions, thereby supporting the ability of local users not to share sessions. The authentication and status change capabilities of global users are concentrated in the authentication center. Business systems are not allowed to change the global user status. There are no copies of global users. All systems share a global user pool, so that changes in user status can be instantly perceived by each application system. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the technical solution of the present invention, the accompanying drawings required for use in the description will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0057] Figure 1 A schematic diagram of a dual session verification method flow chart provided by an embodiment of the present invention.
[0058] Figure 2 Schematic diagram of the user registration process in the application system.
[0059] Figure 3 Schematic diagram of the process of determining the access user type for the application system.
[0060] Figure 4 A flowchart for verifying resource requests of local users of the application system using its own authentication method.
[0061] Figure 5 A flow chart showing the resource request verification process for global users using the authentication center session verification authentication method.
[0062] Figure 6 A schematic block diagram of the structure of a dual session verification device provided by an embodiment of the present invention.
[0063] Figure 7 A schematic diagram of the structure of a terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0064] In order to make the purpose, features and advantages of the present invention more obvious and easy to understand, the technical scheme of the present invention will be clearly and completely described below in conjunction with the drawings in this specific embodiment. Obviously, the embodiments described below are only part of the embodiments of the present invention, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0065] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used in the specification of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention.
[0066] Figure 1 A schematic diagram of a dual session verification method provided by an embodiment of the present invention. Figure 1 The execution subject may be a dual session verification device. The dual session verification method provided in the embodiment of the present invention is executed by a computer device, and accordingly, the dual session verification device runs in the computer device. According to different requirements, the order of the steps in the flowchart may be changed, and some may be omitted.
[0067] like Figure 1 As shown, the method includes the following steps.
[0068] S1, identify and label user types, which include global users and local users.
[0069] During user registration in the application system, the user type is identified during the registration process. For example, user types are distinguished by user names. Different user types have different user name naming rules or representations, and are clearly divided into global users and local users, laying the foundation for subsequent differentiated authentication and authorization processes. It should be noted that all application systems use the same rules to identify user types, which improves the convenience of classification and identification.
[0070] S2, integrates its own authentication method and the authentication center's session verification authentication method into the application system.
[0071] The application system integrates two authentication methods, namely its own authentication method and the authentication center session verification authentication method, to provide technical support for verification of different types of users. The dual session authentication scheme means that the application system can adopt the authentication method of the authentication center + the authentication method of the application system itself. Specifically, the application system needs to integrate the session verification and authentication capabilities of the unified authentication center, while retaining the session authentication method of the application system itself. When the session needs to be authenticated, first determine whether the session belongs to a global session or a local session. The global session is verified by the authentication method of the authentication center, and the local session is verified by the authentication method of the application system itself.
[0072] S3, register the application system to the target organization of the unified authentication center, re-register the global users of the application system to the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system.
[0073] The application system is connected to the target organization of the unified authentication center. During this process, the global users in the application system are re-registered under the target organization of the authentication center, so that all users under the target organization can share the application system. At the same time, the global users in the application system that have been registered with the authentication center are cleaned up, so that the global users are unique in the entire domain and are only retained in the authentication center. The application system no longer retains global users; and local users are only retained in each application system. The authentication and status change capabilities of global users are concentrated in the authentication center. Each business system is not allowed to change the status of global users. There are no copies of global users. All systems share a global user pool, so that changes in user status will be instantly perceived by each application system.
[0074] The global user domain-wide unique design of this solution makes the session status between the authentication center and each application system form a star structure with the authentication center as the origin. The current session status of each application system only depends on the status recorded by the authentication center.
[0075] S4, the application system determines the type of accessing user. If it is a local user of the application system itself, it uses its own authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, it uses the authentication center's session verification and authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources.
[0076] The application system determines the type of the accessed user. The local users of the application system use their own authentication and authorization methods to verify the request, and the global users use the authentication center session verification and authorization methods to verify the request. It can be understood that global users refer to users managed by a unified authentication center and shared by different applications under a unified organization, and local users refer to users who can only access the application system where they are registered. Local users can only log in and request resources in the application system where they are registered, and cannot log in and retrieve resources in other application systems. The advantage of this dual session combined verification method is that after the application system integrates the session verification capability of the authentication center itself, it can verify the token information from the authentication center itself in this way, without the need to maintain global users in the application system itself, and the global user is unique in the entire domain and only exists in the organizational structure of the authentication center. The design breaks the "undirected connection graph" structure formed between different copies of the same user in the traditional single sign-on architecture, and can avoid the cumbersome status synchronization process of users between various application systems and the authentication center.
[0077] This embodiment divides the application system users into two types: global users and local users. Global users are unique in the entire domain and are only retained in the authentication center. The application system no longer retains global users; local users are also only retained in each application system. Although local users and global users belong to the same application, they are authenticated by global authentication and local authentication respectively. These two types of users are completely independent in the authentication authorization and access authentication process, thus avoiding the tedious process of frequent synchronization and alignment between the authentication center and the users of each application system. At the same time, it also supports the ability of local users to authenticate and authorize independent sessions, and further supports the ability of local users not to share sessions. The authentication and status change capabilities of global users are concentrated in the authentication center. Each business system is not allowed to change the status of global users. There is no copy of global users. All systems share a global user pool, so that changes in user status can be instantly perceived by each application system.
[0078] In some optional embodiments, such as Figure 2 As shown, identifying the user type and marking it specifically includes the following steps.
[0079] S1.1, construct a user information table.
[0080] S1.2, receiving a user registration request including user information, where the user information includes a user login password and a user name named in a standard format.
[0081] S1.3, fill the user information into the user information table, detect the user name information, determine the user type according to the user name information, and fill the determined user type into the user information table; wherein there is no intersection between the global user set and the local user set of the same application system.
[0082] In these implementations, the user registers on the application system side, and the application system pre-builds a user information table to facilitate centralized and orderly storage of user information, provide data convenience for subsequent authentication, authorization, and user data analysis, improve the efficiency of querying, updating, and maintaining user information, and help improve the overall user management efficiency. The user sends a user registration request through the registration result, and the user registration request carries user information. The user information includes the user login password and the user name named in the standard format. The application system fills the user information into the user information table, detects the user name information, determines the user type based on the user name information, and fills the determined user type into the user information table. It should be noted that for the same application system, it must be ensured that there is no intersection between the global user set and the local user set. In other words, a user cannot belong to both a global user and a local user at the same time.
[0083] When a user requests resources from an application system, he or she first logs in to the application system. The application system determines the type of user requesting login. If the user is a local user of the application system, the application system uses its own authentication method to verify the request. If the verification succeeds, the user is authorized to use the corresponding interface resources. If the user is a global user, the application system uses the authentication center's session verification method to verify the resource request. If the verification succeeds, the user is authorized to use the corresponding interface resources.
[0084] like Figure 3 As shown, the application system determines the type of the accessing user, which specifically includes the following steps.
[0085] S4.1, receiving a user login request including user information.
[0086] S4.2, extracting the user name from the user information of the user login request.
[0087] S4.3, extract the type identifier from the user name, and determine the user type based on the type identifier. If it is a global user, execute step S4.4; if it is a local user, execute step S4.5.
[0088] S4.4, after the global user successfully logs in through the unified authentication center, the subsequent authentication method of the authentication center session verification is used to verify the resource request.
[0089] S4.5, match the user name with all the user names in the user information table. If a consistent user name is matched, execute step S4.6, otherwise execute step S4.7.
[0090] S4.6, determine that the current user is a local user of the application system itself, and after the current user successfully logs in, perform subsequent resource request verification using its own authentication method.
[0091] S4.7, feedback to the user that the login failed.
[0092] After receiving the user login request, the application system will extract the user name from the request information, and then determine the user type by the type identifier in the user name. If it is a global user, after successfully logging in to the unified authentication center, the authentication center session verification authentication method is used to verify the resource request; if it is a local user, the user name is matched with the user name in the user information table of the application system one by one. If the match is successful, it is determined to be a local user of the application system itself, and the resource request is verified using its own authentication method after successful login; if the match fails, the login failure is fed back to the user. In these implementation methods, the user type is determined by multiple steps and multiple methods, and the type identifier in the user name and the match with the user information table are comprehensively utilized to accurately distinguish between global users and local users, lay the foundation for subsequent accurate authentication and authorization, avoid erroneous authorization, and ensure system security. At the same time, the authentication process is clear and convenient, and users can quickly know the login results. For legal users, the system can quickly determine their type and guide them to the corresponding authentication and authorization process, quickly complete the login and obtain resource access rights; for illegal users, timely feedback login failure information, avoid users waiting for a long time or performing invalid operations, and improve the convenience and satisfaction of users using the application system. The user type judgment and authentication process is strict, which effectively prevents illegal users from accessing system resources and improves data security.
[0093] After a local user logs in to the registered application system, the application system uses its integrated authentication method to verify the local user's resource request, such as Figure 4 As shown, if it is a local user of the application system itself, it uses its own authentication method to verify the resource request, and the verification is performed by authorizing the user to access the corresponding interface resources, which specifically includes the following steps.
[0094] S101, a local user logs in to an application system, establishes a local session with the application system, and stores the local session.
[0095] S102: Receive a resource access request carrying a local session sent by a local user.
[0096] S103, calling the local session corresponding to the resource access request, and verifying the validity and integrity of the local session.
[0097] S104: If the local session is valid and complete, confirm that the permissions match, and determine whether the target resource of the local user's current resource access request can be accessed based on the resource access policy and the local session permissions.
[0098] S105: If the access is possible, authorize the corresponding interface resources to the local user.
[0099] It should be noted that local user authentication and authorization are completely in each application system itself, and there is no intersection between local authentication and global authentication, and they are completely isolated. In other words, the authentication and session authentication methods of local users remain unchanged. The dual session authentication design retains the ability of local sessions not to be shared. In these optional implementations, local user authentication and authorization are only performed in the application system itself, isolated from global authentication, and the ability of local sessions not to be shared is retained, so that the application system can formulate personalized access policies for different local users. Local users of different departments or roles can flexibly set different permissions according to business needs, without being restricted by global session sharing rules, and improve the adaptability of the system to complex business scenarios. Local authentication and authorization are completed independently in each application system, and the management boundaries are clear. The application system can independently upgrade and optimize its own authentication and authorization mechanism without coordinating with other systems, reducing management complexity and maintenance costs, and improving system iteration efficiency. Since local authentication and authorization run independently, the response speed is faster. Local users can quickly obtain resource access rights and reduce waiting time. At the same time, personalized permission settings meet the diverse needs of users and improve user satisfaction with the system and ease of use.
[0100] For global users, since global users only exist in the unified authentication center, the authentication of unified global users needs to be performed in the authentication center. After the unified authentication is successful, the authentication center session is returned to the application system. When the application system determines that the current session is a global user session, it uses the unified authentication center global session authentication method for authentication.
[0101] like Figure 5 As shown, if it is a global user, the authentication center session verification authentication method is used to verify the resource request. The verification is performed by authorizing the user to access the corresponding interface resources, which specifically includes the following steps.
[0102] S201, detecting whether the global session of the current global user is saved in the browser, if so, executing step S202, otherwise executing step S203.
[0103] S202, the accessed application system uses the authentication center session verification authentication method to verify the resource access request of the global user based on the global session saved in the browser, and authorizes the corresponding interface resource to the user if the verification passes.
[0104] S203, check whether the global session of the current global user is saved in the unified authentication center, if so, execute step S204, otherwise execute step S205.
[0105] S204, obtain the global session from the unified authentication center and save it in the browser. Subsequently, use the authentication center session verification authentication method to verify the resource access request of the global user based on the global session saved by the browser. After verification, authorize the user to the corresponding interface resources.
[0106] S205, the accessed application system jumps to the unified authentication center for global users to log in. After the global user successfully logs in to the unified authentication center, the unified authentication center records the global session and carries the global session to jump to the accessed application system. The accessed application system records the global session in the browser and subsequently uses the authentication center session verification authentication method to verify the resource access request of the global user based on the global session recorded by the browser. The verification authorizes the user to the corresponding interface resources.
[0107] In these optional implementations, the application system obtains the global session from the unified authentication center and saves it in the browser, and then performs authentication based on the global session saved in the browser. Since the global user's session is directly accessed and obtained from the authentication center of each application system and then saved in the browser storage of the respective domain name, session propagation does not involve cross-domain issues.
[0108] Among them, the authentication center session verification authentication method is used to verify the resource access request of the global user based on the global session saved by the browser. The verification is performed by authorizing the corresponding interface resources to the user, which specifically includes the following steps.
[0109] Step 1: Receive a resource access request sent by a global user.
[0110] Step 2, retrieve the corresponding global session information from the browser, and verify the global session information using the authentication center session verification authentication method.
[0111] Step 3: If the verification passes, authorize the corresponding interface resources to the global user.
[0112] In some optional implementations, the global session information is verified using the authentication center session verification authentication method, including verification of the integrity, validity, and access rights of the global session information. The application system provides feedback to the user based on the verification results. If the verification passes, the corresponding interface resources are authorized to the user. If the verification fails, feedback to the user is given that the resource request failed.
[0113] The above process can quickly complete verification and authorization for users who have logged in and whose sessions are valid by giving priority to detecting the global session in the browser, thus reducing the waiting time for users. When there is no session in the browser, the user login is automatically obtained or guided from the authentication center. The whole process is highly automated and does not require too much operation by the user, which can improve the convenience of users using the system. At the same time, the unified authentication center is the core of global user authentication and session management. All global user authentication is carried out here. Centralized management ensures the consistency and authority of authentication standards. In the process of session verification, whether it is based on the browser session or the session obtained from the authentication center, the verification and authentication method of the authentication center is used. The strict verification mechanism can effectively prevent illegal users from accessing resources and ensure the security of system and user data. This verification and authentication process is independent of the specific application system. The application system only needs to integrate the session verification and authentication method of the authentication center to access the single sign-on system. When a new application system is connected, it can be connected more conveniently without complex development and configuration, reducing the system expansion cost and improving the system's compatibility with different applications. In addition, the global session is recorded and managed by the unified authentication center, and each application system verifies based on the session of the authentication center. When the global user status changes, such as password modification, permission change, etc., the authentication center can update the session information in time, and each application system can synchronously obtain the latest session status to ensure the consistency of the global user's session in different application systems and avoid the confusion of permissions caused by asynchronous sessions. Furthermore, by caching the global session in the browser, when the user frequently accesses resources in different application systems, the number of interactions with the authentication center is reduced, improving resource access efficiency. At the same time, when there is no session in the browser, the mechanism of quickly obtaining the session from the authentication center can also ensure that the user obtains the latest session in time when needed, ensuring the continuity of resource access and improving the overall performance of the system.
[0114] The following provides an example of global user session authentication.
[0115] ① Global user 1 wants to access system A. At this time, he is not logged in and the authentication center has not saved the user's session. In this case, he will jump to the unified authentication center to log in. After the login is successful, the unified authentication center records the session of user 1 and jumps to system A with the session. The browser records the session, and user 1 needs to carry the session for authentication when accessing system A thereafter.
[0116] ② System A detects that user 1 is a global user and uses the global session verification method to verify the current session. After the verification passes, the corresponding interface resources are authorized.
[0117] ③ User 1 visits system B under the same organization again. System B obtains the user's login status through the unified authentication center and finds that user 1 has logged in. System B then directly obtains the saved session information from the unified authentication center and saves it in the browser.
[0118] ④ User 1 uses the session information obtained from the unified authentication center to access system B. System B checks that user 1 is a global user and verifies the current session using the global session verification method. After the verification passes, the corresponding interface resources are authorized.
[0119] It should be noted that there is a difference between the way user 1 obtains the session when accessing system B and the way user 1 obtains the session when accessing system A. Although both are session information obtained by the application system from the authentication center, the former first performs user authentication to generate a session and saves it when the user 1 session does not exist, while the latter directly obtains the existing session information of user 1.
[0120] For global user logout, global users support logout from various application systems or authentication centers. When an application logs out a user, the system notifies the authentication center to delete the user's session information and deletes the session information saved in the browser by various application systems. In this way, when the logged-in user accesses other applications, the session information will not exist in the browser and the authentication center, and re-login and authentication are required to access. Specifically, the application system detects whether a global user has logged out. If a global user has logged out, the application system notifies the unified authentication center to delete the global session information of the logged-out global user, and the application system deletes the global session information of the logged-out global user in the browser.
[0121] An embodiment of a dual session verification method is described in detail above. Based on the dual session verification method described in the above embodiment, an embodiment of the present invention further provides a dual session verification device corresponding to the method.
[0122] Figure 6 A schematic block diagram of the structure of a dual session verification device provided in an embodiment of the present invention. In this embodiment, the dual session verification system 600 can be divided into multiple functional modules according to the functions it performs. The module referred to in the present invention refers to a series of computer program segments that can be executed by at least one processor and can perform fixed functions, which are stored in a memory.
[0123] The user registration module 610 is used to identify and label user types, where user types include global users and local users.
[0124] The authentication method integration module 620 is used to integrate the self-authentication authentication method and the authentication center session verification authentication method in the application system.
[0125] The global user registration module 630 is used to register the application system to the target organization of the unified authentication center, re-register the global users of the application system to the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system.
[0126] Verification module 640 is used by the application system to determine the type of accessing user. If it is a local user, the request is verified using its own authentication method. After the verification, the user is authorized with corresponding interface resources. If it is a global user, the request is verified using the authentication center session verification method. After the verification, the user is authorized with corresponding interface resources.
[0127] The dual session verification device of this embodiment is used to implement the aforementioned dual session verification method. Therefore, the specific implementation method of the device can be seen in the embodiment part of the dual session verification method in the previous text. Therefore, its specific implementation method can refer to the description of the corresponding embodiments of each part, which will not be introduced in detail here.
[0128] In addition, since the dual session verification device of this embodiment is used to implement the aforementioned dual session verification method, its function corresponds to that of the aforementioned method and will not be repeated here.
[0129] Figure 7 A schematic diagram of the structure of a terminal 700 provided in an embodiment of the present invention includes: a processor 710, a memory 720 and a communication unit 730. The processor 710 is used to implement the following steps when implementing the dual session verification program stored in the memory 720:
[0130] Identify and label user types, including global users and local users;
[0131] Integrate the self-authentication and authentication methods and the authentication center session verification and authentication methods in the application system;
[0132] Register the application system to the target organization of the unified authentication center, re-register the global users of the application system to the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system;
[0133] The application system determines the type of accessing user. If it is a local user of the application system itself, it uses its own authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, it uses the authentication center's session verification and authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources.
[0134] The present invention also provides a computer storage medium, wherein the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM).
[0135] The computer storage medium stores a dual session verification program, and when the dual session verification program is executed by the processor, the following steps are implemented:
[0136] Identify and label user types, including global users and local users;
[0137] Integrate the self-authentication and authentication methods and the authentication center session verification and authentication methods in the application system;
[0138] Register the application system to the target organization of the unified authentication center, re-register the global users of the application system to the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system;
[0139] The application system determines the type of accessing user. If it is a local user of the application system itself, it uses its own authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, it uses the authentication center's session verification and authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources.
[0140] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A dual session verification method, characterized in that: The following steps are involved: Identify and label user types, including global users and local users; Integrate the self-authentication and authentication methods and the authentication center session verification and authentication methods in the application system; Register the application system to the target organization of the unified authentication center, re-register the global users of the application system to the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system; The application system determines the type of accessing user. If it is a local user of the application system itself, it uses its own authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, it uses the authentication center's session verification and authentication method to verify the resource request. If the verification passes, the user is authorized to use the corresponding interface resources.
2. The dual session verification method according to claim 1, characterized in that: Identify and label user types, including: Build a user information table; Receive a user registration request including user information, where the user information includes a user login password and a user name named in a standard format; Fill the user information into the user information table, detect the user name information, determine the user type according to the user name information, and fill the determined user type into the user information table; wherein there is no intersection between the global user set and the local user set of the same application system.
3. The dual session verification method according to claim 2, characterized in that: The application system determines the type of accessing user, including: Receive a user login request containing user information; Extract the user name from the user information of the user login request; Extract a type identifier from the user name, and determine the user type based on the type identifier; If the user type is a global user, the global user will use the authentication center session verification authentication method to perform resource request verification after successfully logging in through the unified authentication center; If the user type is a local user, the user name is matched with all the user names in the user information table; If a consistent user name is matched, the current user is judged to be a local user of the application system itself. After the current user logs in successfully, the subsequent resource request verification is performed using its own authentication method. Otherwise, the login failure is fed back to the user.
4. The dual session verification method according to claim 3, characterized in that: If the application system is a local user, it uses its own authentication method to verify the resource request. The verification authorizes the user to use the corresponding interface resources, including: A local user logs into the application system, establishes a local session with the application system, and stores the local session; Receive a resource access request carrying a local session sent by a local user; Retrieve the local session corresponding to the resource access request and verify the validity and integrity of the local session; If the local session is valid and complete, confirm that the permissions match, and determine whether the target resource of the local user's current resource access request can be accessed based on the resource access policy and local session permissions; If access is possible, authorize the corresponding interface resources to the local user.
5. The dual session verification method according to claim 4, characterized in that: If it is a global user, the authentication center session verification authentication method is used to verify the resource request. The verification authorizes the user to use the corresponding interface resources, including: Check whether the global session of the current global user is saved in the browser; If it has been saved, the accessed application system uses the authentication center session verification authentication method to verify the resource access request of the global user based on the global session saved in the browser. If the verification passes, the user is authorized to access the corresponding interface resources; If not saved, check whether the global session of the current global user is saved in the unified authentication center; If saved, the global session is obtained from the unified authentication center and saved in the browser. The authentication center session verification authentication method is used later to verify the resource access request of the global user based on the global session saved by the browser. If the verification passes, the user is authorized to access the corresponding interface resources. If it is not saved, the accessed application system jumps to the unified authentication center for global users to log in. After the global user successfully logs in to the unified authentication center, the unified authentication center records the global session and carries the global session to jump to the accessed application system. The accessed application system records the global session in the browser and subsequently uses the authentication center session verification authentication method to verify the resource access request of the global user based on the global session recorded by the browser. If the verification passes, the user is authorized to use the corresponding interface resources.
6. The dual session verification method according to claim 5, characterized in that: The authentication center session verification authentication method is used to verify the resource access request of global users based on the global session saved by the browser. The verification is performed by authorizing the user to the corresponding interface resources, including: Receive resource access requests sent by global users; Retrieve the corresponding global session information from the browser and verify the global session information using the authentication center session verification authentication method; If the verification passes, the corresponding interface resources are authorized to the global user.
7. The dual session verification method according to claim 6, characterized in that: The method further comprises the following steps: The application system detects whether a global user has logged out; If the global user logs out, the application system notifies the unified authentication center to delete the global session information of the logged out global user; The application system deletes the global session information of the global user who has logged out in the browser.
8. A dual session verification device, characterized in that: include, User registration module, used to identify and label user types, including global users and local users; Authentication method integration module, used to integrate the self-authentication authentication method and the authentication center session verification authentication method in the application system; The global user registration module is used to register the application system with the target organization of the unified authentication center, re-register the global users of the application system with the target organization of the unified authentication center, and deregister or delete the global users registered with the unified authentication center from the application system; The verification module is used by the application system to judge the type of accessing user. If it is a local user, the request is verified using its own authentication method. If the verification passes, the user is authorized to use the corresponding interface resources. If it is a global user, the authentication center session verification method is used to verify the request. If the verification passes, the user is authorized to use the corresponding interface resources.
9. A terminal, characterized in that: include: A memory, used for storing a dual session verification program; A processor, configured to implement the steps of the dual session verification method as claimed in any one of claims 1 to 7 when executing the dual session verification program.
10. A computer-readable storage medium, characterized in that: The readable storage medium stores a dual session verification program, and when the dual session verification program is executed by the processor, the steps of the dual session verification method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
One-point entry and access system based on authentication service acting information facing to service architecture
CN101277193A
Login verification methods and devices, computer equipment and memory medium
CN109547458A