Login method, device and system integrated with ubiquitous terminal application entry

By analyzing and verifying the public parameters in the redirect address in the client on the server, and calling the user authentication conversion interface to obtain the user authentication login state, it solves the problems of complexity and high technical requirements of the user authorization system when the software system is integrated into the user's existing system platform terminal in the existing technology, and realizes convenient and fast access to the pan-terminal application and support for multiple terminal applications.

CN119921954APending Publication Date: 2025-05-02RICHFIT INFORMATION TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311426304.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

When the prior art integrates the functional portal of the software system into the user's existing system platform terminal, the complexity and technical requirements of the user authorization system are high, and it is difficult to support the differences in diversified terminal forms and customer technical capabilities.

Method used

By receiving the login request for redirecting pages in the client on the server, analyzing the redirect page address in the client to obtain public parameters, verifying the legitimacy of the client signature information, and calling the user authentication conversion interface according to the authorized login type of the target terminal application, obtaining the user authentication login state, and returning it to the client to realize the authorized login of the target terminal application.

Benefits of technology

It realizes convenient and fast access to the pan-terminal application portal, lowers the technical threshold of the client, supports the access to multiple terminal applications, and supports dynamic expansion of terminal applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921954A_ABST
    Figure CN119921954A_ABST
Patent Text Reader

Abstract

The invention discloses a login method, device and system of an integrated ubiquitous terminal application entry. The method comprises the following steps: receiving a login request of a transit page of any client; the login request comprises a transfer page address of the client; analyzing the client transit page address to obtain a public parameter; the public parameters comprise a terminal ID, a timestamp, client signature information, an authorized login type of a target terminal application and a unique identifier of a user; determining whether the client signature information is legal or not according to the terminal ID, the timestamp and the client signature information; and if yes, determining to call a user authentication conversion interface according to the authorized login type of the target terminal application and the unique identifier of the user to obtain a user authentication login state, and returning the user authentication login state to the client. According to the method, convenience is provided for a client to realize flexible and rapid access of the multi-terminal application, and dynamic infinite extension of the access terminal application is supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a login method, device and system for integrating a pan-terminal application portal. Background Art

[0002] In today's digital age, cloud computing and cloud services have become one of the key drivers in the field of information technology. A core component of the cloud computing model is SaaS (Software as a Service), a service model that provides software applications on a subscription basis. SaaS provides users with flexibility, cost-effectiveness and convenience, allowing them to easily access and use a variety of applications without having to worry about tedious installation and maintenance.

[0003] As the number of customers of software system SaaS services continues to grow, some customers will have their own independent software system platforms. After purchasing software services, customers need to integrate the functional entrance of the software system into the user's existing system platform terminal so that users can use the business function services provided by the software system in the existing platform terminal. Due to the large number of customers, uneven technical capabilities, and various terminal forms (H5, App, mini-programs, etc.), it is necessary to provide a unified set of integration standards and simple implementation plans to support various types of customer system terminals, thereby improving the efficiency of system integration. At present, software systems mostly use the OAuth protocol to implement unified user identity authentication across systems. Summary of the invention

[0004] In order to achieve more convenient and faster access to a pan-terminal application portal, an embodiment of the present invention provides a login method, device and system for an integrated pan-terminal application portal.

[0005] In a first aspect, an embodiment of the present invention provides a login method for an integrated pan-terminal application portal, which is applied to a server, and the method includes:

[0006] Receive a login request from any client transfer page; the login request includes the client transfer page address;

[0007] Parsing the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier;

[0008] Determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information;

[0009] If so, determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain the user authentication login state, obtain the user authentication login state, and return the user authentication login state to the client.

[0010] In one or some optional implementations of the embodiments of the present application, the determining of calling a user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtaining a user authentication login state, obtaining a user authentication login state, and returning the user authentication login state to the client includes:

[0011] Obtaining a user information query interface of the target terminal application according to the authorized login type of the target terminal application;

[0012] A query is performed based on the user unique identifier and the user information query interface. If it is confirmed that the user corresponding to the user unique identifier exists in the user information of the target terminal application, the user authentication login state is obtained and returned to the client.

[0013] In one or some optional implementations of the embodiments of the present application, the determining of calling a user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtaining a user authentication login state, obtaining a user authentication login state, and returning the user authentication login state to the client includes:

[0014] Obtaining an access token for the target terminal application according to the authorized login type of the target terminal application;

[0015] The target terminal application obtains a user information query interface of the target terminal application according to the access token;

[0016] A query is performed based on the user unique identifier and the user information query interface. If it is confirmed that the user corresponding to the user unique identifier exists in the user information of the target terminal application, the user authentication login state is obtained and returned to the client.

[0017] In one or some optional implementations of the embodiment of the present application, determining whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information includes:

[0018] Find the corresponding key according to the terminal ID;

[0019] Encrypt according to the timestamp, the terminal ID and the corresponding key to obtain the server signature information;

[0020] Confirm whether the server signature information is the same as the client signature information;

[0021] If yes, confirm that the client signature information is legal;

[0022] If not, return an error message.

[0023] In one or some optional implementations of the embodiment of the present application, after parsing the client transfer page address to obtain the public parameters, the process further includes:

[0024] Determine whether the common parameters are missing, and if so, return an error message.

[0025] In a second aspect, an embodiment of the present invention provides a login method for an integrated pan-terminal application portal, which is applied to a client, and the method includes:

[0026] Obtain the user's terminal information and encrypt it to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp;

[0027] Obtain transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the url parameters carried by the function page routing address;

[0028] Combining the terminal ID, the client signature information and the transfer page parameter, splicing to obtain the client transfer page address;

[0029] Load the transfer page according to the client transfer page address and send a login request to the server;

[0030] Receive the information returned by the server and determine whether the information returned by the server is the user authentication login state:

[0031] If so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameter carried by the function page routing address.

[0032] In one or some optional implementations of the embodiments of the present application, the user's terminal information is obtained and encrypted to obtain the client signature information, and the terminal information includes a terminal ID, a key and a timestamp, including:

[0033] Concatenate the terminal ID, the key and the timestamp to obtain a character string to be encrypted;

[0034] The key is used as an encryption factor and an encryption algorithm is used to encrypt the character string to obtain the client signature information.

[0035] In a third aspect, an embodiment of the present invention provides a login method for an integrated pan-terminal application portal, the method comprising:

[0036] The client obtains the user's terminal information and encrypts it to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp;

[0037] Obtain transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the url parameters carried by the function page routing address;

[0038] Combining the terminal ID, the client signature information and the transfer page parameter, splicing to obtain the client transfer page address;

[0039] Load the transfer page according to the client transfer page address and send a login request to the server;

[0040] The server receives a login request sent by the client transfer page; the login request includes the client transfer page address;

[0041] Parsing the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier;

[0042] Determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information;

[0043] If yes, determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain the user authentication login state, and return the user authentication login state to the client;

[0044] The client receives the information returned by the server and determines whether the information returned by the server is the user authentication login state:

[0045] If so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameter carried by the function page routing address.

[0046] In a fourth aspect, an embodiment of the present invention provides a login device with an integrated pan-terminal application portal, which is applied to a server, and the device includes:

[0047] A first acquisition module is used to receive a login request of any client transfer page; the login request includes the client transfer page address;

[0048] A first parsing module, used to parse the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier;

[0049] A first judgment module, used to determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information;

[0050] The second acquisition module is used to determine the call of the user authentication conversion interface according to the authorized login type of the target terminal application and the user's unique identifier if the first judgment module determines that the client signature information is legal, obtain the user authentication login state, and return the user authentication login state to the client.

[0051] In a fifth aspect, an embodiment of the present invention provides a login device integrated with a pan-terminal application portal, which is applied to a client, and the device includes:

[0052] The first encryption module is used to obtain the user's terminal information for encryption to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp;

[0053] The first acquisition module is used to acquire transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the URL parameters carried by the function page routing address;

[0054] A first splicing module, used for combining the terminal ID, the client signature information and the transfer page parameter to obtain a client transfer page address;

[0055] A first sending module, used for loading a transfer page according to the client transfer page address, and sending a login request to the server;

[0056] The first judgment module is used to receive the information returned by the server and judge whether the information returned by the server is the user authentication login state;

[0057] The first display module is used to jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the url parameters carried by the function page routing address if the first judgment module determines that the information returned by the server is the user authentication login state.

[0058] In a sixth aspect, an embodiment of the present invention provides a login system integrating a pan-terminal application portal, the system comprising: a server and a client;

[0059] The server is used to receive a login request from any client transfer page; the login request includes the client transfer page address; the client transfer page address is parsed to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier; according to the terminal ID, the timestamp and the client signature information, it is determined whether the client signature information is legal; if so, according to the authorized login type and user unique identifier of the target terminal application, it is determined to call the user authentication conversion interface to obtain the user authentication login state, obtain the user authentication login state, and return the user authentication login state to the client;

[0060] The client is used to obtain the user's terminal information and encrypt it to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp; obtain the transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application and the url parameters carried by the function page routing address; combine the terminal ID, the client signature information and the transfer page parameters to obtain the client transfer page address; load the transfer page according to the client transfer page address, and send a login request to the server; receive the information returned by the server, and determine whether the information returned by the server is a user authentication login state: if so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the url parameters carried by the function page routing address.

[0061] In a seventh aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed on a computer device, implements the above-mentioned integrated ubiquitous terminal application portal login method.

[0062] In an eighth aspect, an embodiment of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the login method for the integrated pan-terminal application portal as described above is implemented.

[0063] In a ninth aspect, an embodiment of the present invention provides a computer program product comprising instructions, which, when executed on a computer device, enables the computer device to execute the above-mentioned integrated pan-terminal application portal login method.

[0064] In the tenth aspect, an embodiment of the present invention provides a chip, the chip includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a computer program or instruction to implement the login method of the integrated pan-terminal application portal as mentioned above.

[0065] The beneficial effects of the above technical solution provided by the embodiment of the present invention include at least:

[0066] The login method for integrated pan-terminal application portal provided by the embodiment of the present invention encrypts the user's terminal information, and splices it with the authorized login type of the target terminal application, the user's unique identifier, the function page routing address and the corresponding parameters into the client transfer page address. In the transfer page, the user authentication conversion interface is called to obtain the user authentication login state, realize the authorized login of the target terminal application, and jump from the transfer page to the function page of the target terminal application. A method for realizing the integrated pan-terminal application portal is established. By obtaining the authorized login type and other parameters of the target terminal application set by the user, the corresponding type of target terminal application is accessed according to the different authorized login types, which provides convenience for the rapid access of software system customers, can support the access of multiple terminal application systems of customers, and support dynamic and unlimited expansion of access terminal applications.

[0067] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.

[0068] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0069] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0070] Figure 1 A schematic diagram of the steps of applying the login method of the integrated universal terminal application portal provided by the embodiment of the present invention to the server;

[0071] Figure 2 A schematic diagram of a process for a server to call a user authentication conversion interface provided by an embodiment of the present invention;

[0072] Figure 3 A schematic diagram of the steps of applying the login method of the integrated universal terminal application portal provided by an embodiment of the present invention to a client;

[0073] Figure 4 A schematic diagram of a process of a client client initiating a request for transfer login provided in an embodiment of the present invention;

[0074] Figure 5 A schematic diagram of the steps of a login method for an integrated ubiquitous terminal application portal provided by an embodiment of the present invention;

[0075] Figure 6 A schematic diagram of the structure of a login device for an integrated universal terminal application portal applied to a server provided in an embodiment of the present application;

[0076] Figure 7 A schematic diagram of the structure of a login device for an integrated universal terminal application portal applied to a client provided in an embodiment of the present application;

[0077] Figure 8 A schematic diagram of the structure of a login system with an integrated pan-terminal application portal provided in an embodiment of the present application. DETAILED DESCRIPTION

[0078] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.

[0079] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.

[0080] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0081] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.

[0082] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0083] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0084] It should be understood that the size of the serial numbers of the steps in the following embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0085] In order to illustrate the technical solution of the present application, a specific embodiment is provided below for illustration.

[0086] The inventors found that in the prior art, when it is necessary to integrate the functional entrance of the software system into the existing system platform terminal, the software system often uses the OAuth protocol to implement unified user identity authentication across systems. This solution requires the integrated software system to implement user authorization, which has high requirements for customers. Customers need to have certain technical capabilities to implement and maintain their own user authorization system, which may require professional developers and security experts to handle the complexity of authentication and authorization, and it is difficult to implement. Based on this, the inventors have made the present invention after further research and development, providing a login method, device, equipment and medium for integrating a pan-terminal application entrance.

[0087] Embodiment 1

[0088] An embodiment of the present invention provides a login method for an integrated pan-terminal application portal. The method calls the user authentication conversion interface of the target terminal application on the server side based on the public parameters provided by the client, obtains the user authentication login state, and then returns the user authentication login state to the client. The client jumps to the function page of the target terminal application to complete the user login.

[0089] The following is a detailed introduction to the implementation process of the login method integrating the pan-terminal application entrance in the server and client:

[0090] In the present application, refer to Figure 2 As shown, the server will perform the following steps:

[0091] S101: receiving a login request of any client transfer page; the login request includes the client transfer page address.

[0092] S102: Parse the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier.

[0093] In an embodiment of the present application, in the above step S101, the server receives a login request sent by the client transfer page, which contains the address of the client transfer page. The client transfer page address is parsed according to fixed rules to obtain public parameters in the address, which include terminal ID, timestamp, client signature information, authorized login type of the target terminal application, and user unique identifier.

[0094] The client transfer page address is obtained by concatenating the client URL, the user's terminal ID, timestamp, client signature information, the authorized login type of the target terminal application, and the user's unique identifier according to fixed rules.

[0095] In a specific embodiment, the client transfer page address can be expressed as "https: / / domain.com / login?app_id=×tamp=&sign=&page=&utype=&utypevalue=&pageparams=", "https: / / domain.com" is the client URL, "login" indicates that the current page is the login page, "app_id", "timestamp", "sign", "utype" and "utypevalue" respectively represent the terminal ID, timestamp, client signature information, authorized login type of the target terminal application and user unique identifier, the client transfer page address also includes "page" and "pageparams", which are the function page routing address of the target terminal application and the url parameters carried by the function page routing address. These two parameters are used when the client jumps to the function page of the target terminal application after the client receives the user authentication login state.

[0096] In an embodiment of the present application, after parsing the client transfer page address to obtain the above-mentioned public parameters, it is necessary to determine whether the obtained public parameters are missing. If there are any missing, an error message is returned to the client, and the client page prompts parameter abnormality information. If there are no missing, continue with the following steps.

[0097] S103: Determine whether the client signature information is legal based on the terminal ID, the timestamp and the client signature information; if so, execute step S104; if not, execute step S105.

[0098] In the embodiment of the present application, the above step S103 includes:

[0099] Find the corresponding key according to the terminal ID;

[0100] Encrypt according to the timestamp, the terminal ID and the corresponding key to obtain the server signature information;

[0101] Confirm whether the server signature information is the same as the client signature information;

[0102] If yes, confirm that the client signature information is legal; if no, judge that it is illegal

[0103] In the embodiment of the present application, the corresponding key stored in the server can be found according to the terminal ID. The server signature information generated by the terminal ID, timestamp and key according to the fixed signature generation rule is compared with the client signature information obtained in step S102 to confirm whether the two are the same. If they are not the same, it is considered that the login request initiated by the client this time is an illegally tampered and counterfeit request, and the server returns an error message to the client. If they are the same, it is confirmed that the verification is successful, the client signature information is legal, and it is a normal login request, and the following steps continue.

[0104] In the embodiment of the present application, the key of each customer is stored and used separately on the server and the client, and cannot be used as an interface parameter for network transmission to prevent data security leakage. The server and the client use the same signature information generation rules to obtain the server signature information and the client signature information. Only when the two are exactly the same, it means that the keys of the server and the client are also the same, indicating that the login request is a secure login request, thereby ensuring the confidentiality of customer information.

[0105] S104: Determine to call a user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain a user authentication login state, and return the user authentication login state to the client.

[0106] S105: Return error information.

[0107] In the embodiment of the present application, the flow chart of calling the user authentication conversion interface to obtain the user authentication login state is shown in FIG. Figure 2 After parsing the public parameters and verifying the legality of the client signature information, different corresponding methods in the user authentication conversion interface need to be used according to the different authorized login types of the target terminal application obtained in step S102. The methods corresponding to different authorized login types can be divided into two categories. In a specific embodiment, Figure 2As shown, "utype" indicates the authorized login method. The parameters of the authorized login type show four types: "sap", "idnum", "djtoken" and "rxtoken". "utype=sap" and "utype=idnum" respectively indicate the situation where the user's employee number and ID card are used as the authorized login type. In this case, the corresponding user unique identifier is the user's employee number and ID card; "utype=djtoken" and "utype=rxtoken" respectively indicate that the authorized login type is two different terminal systems. In this case, the user unique identifier is the access token corresponding to the authorized login type.

[0108] The methods corresponding to the first authorization login type include:

[0109] Obtaining a user information query interface of the target terminal application according to the authorized login type of the target terminal application;

[0110] A query is performed based on the user unique identifier and the user information query interface. If it is confirmed that the user corresponding to the user unique identifier exists in the user information of the target terminal application, the user authentication login state is obtained and returned to the client.

[0111] The methods corresponding to the second type of authorized login include:

[0112] Obtaining an access token for the target terminal application according to the authorized login type of the target terminal application;

[0113] The target terminal application obtains a user information query interface of the target terminal application according to the access token;

[0114] A query is performed based on the user unique identifier and the user information query interface. If it is confirmed that the user corresponding to the user unique identifier exists in the user information of the target terminal application, the user authentication login state is obtained and returned to the client.

[0115] In the embodiment of the present application, when the authorization login type is the first authorization login type, the corresponding user information query interface will be directly obtained from the server, and then the user information query interface will be used according to the user unique identifier to obtain the user authentication login state in the user information corresponding to the authorization login type, and the user authentication login state will be returned to the client. In a specific embodiment, when the authorization login type is "utype=sap" or "utype=idnum", the first authorization login method is called, which represents the authorization login type as sap employee number and ID number respectively. For example, when the authorization login type is idnum, the parameter of the user unique identifier is the user ID number, and the user information is queried through the ID number query interface according to the ID number. If the user's ID number exists in the user information corresponding to the ID number, the user information query interface generates the corresponding user authentication login state, and returns the user authentication login state and other information of the customer (such as user name, gender, avatar, etc.) to the client. If the user's ID number does not exist in the user information corresponding to the ID number, an error message is returned.

[0116] In an embodiment of the present application, when the authorized login type is the second authorized login type, it means that the server needs to connect to other terminal applications externally to obtain an access token (JSON Web Token) corresponding to the target terminal application, and use the access token to obtain user information through an external user information query interface provided by the target terminal application. The information returned by the external user information query interface contains a new user unique identifier. The new user unique identifier is then used to search for user information corresponding to the new user unique identifier in the user information query interface of the server to obtain the user authentication login state, and the user authentication login state and other information of the customer (such as user name, gender, avatar, etc.) are returned to the client. If the user does not exist, an error message is returned.

[0117] Among them, the user authentication login state is a token or credential that indicates that the user or application has been authorized to perform certain operations or access certain resources. Although only four parameter situations are described here, corresponding to two authorization login methods, as long as the server can provide compatible extension support, it can meet the access of more different terminal applications, and different authorization login methods can be added accordingly.

[0118] In the embodiment of the present application, by setting corresponding authorization login types according to different target terminal applications, convenience is provided for the rapid access of software system customers, which can support the access of multiple terminal application systems of customers and support dynamic and unlimited expansion of access terminal applications.

[0119] In the present application, refer to Figure 3 As shown, the client will perform the following steps:

[0120] S201: Obtain the user's terminal information and encrypt it to obtain client signature information; the terminal information includes a terminal ID, a key and a timestamp.

[0121] In the embodiment of the present application, the above step S201 includes:

[0122] Concatenate the terminal ID, the key and the timestamp to obtain a character string to be encrypted;

[0123] The key is used as an encryption factor and an encryption algorithm is used to encrypt the character string to obtain the client signature information.

[0124] In the embodiment of the present application, in order to ensure the uniqueness of each customer information, the client needs to configure non-repetitive terminal information for each customer, and the terminal information includes a terminal ID and a key, wherein the terminal ID is used to distinguish different terminal applications used by different users, and the key is an encryption / decryption key. When the client needs to initiate a login request, the client splices the terminal ID, the key and the current timestamp into a string to be encrypted according to a fixed rule, and then uses the key as the encryption factor, and uses the encryption algorithm to encrypt the string to be encrypted to obtain the client signature information. In a specific embodiment, the string to be encrypted str = 'app_id = '+AID+'×tamp'+TS+'&app_secret = '+AST, wherein AID is the terminal ID, TS is the current timestamp, and AST is the key content value saved by the client. The key is used as the encryption factor key, and the string to be encrypted str is encrypted using the AES256 encryption algorithm to obtain the client signature information sign = AESEncrypt (key, str).

[0125] S202: Obtain transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the url parameters carried by the function page routing address.

[0126] S203: Combine the terminal ID, the client signature information and the transfer page parameter to obtain a client transfer page address.

[0127] S204: Load the transfer page according to the client transfer page address, and send a login request to the server.

[0128] In an embodiment of the present application, after obtaining the client signature information, it is also necessary to obtain the authorized login type of the customer's target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the URL parameters carried by the function page routing address. After the customer completes the filling of the above-mentioned transfer page parameter information on the client and clicks to log in, the client transfer page address is obtained by combining the terminal ID, client signature information and transfer page parameters according to fixed rules.

[0129] In a specific embodiment, the client transfer page address can be expressed as "https: / / domain.com / login?app_id=×tamp=&sign=&page=&utype=&utypevalue=&pageparams=", "https: / / domain.com" is the client URL, "login" indicates that the current page is the login page, "app_id", "timestamp", "sign", "utype" and "utypevalue" respectively represent the terminal ID, timestamp, client signature information, authorized login type of the target terminal application and user unique identification, and "page" and "pageparams" respectively represent the function page routing address of the target terminal application and the url parameters carried by the function page routing address.

[0130] In an embodiment of the present application, the customer completes filling in the above-mentioned transfer page parameter information on the client, and clicks to log in. After obtaining the client transfer page address, the webview loads the client transfer page h5 page and sends a login request to the server.

[0131] S205: Receive the information returned by the server, and determine whether the information returned by the server is the user authentication login state: if so, execute step S206; if not, execute step S207.

[0132] S206: Jumping from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameter carried in the function page routing address.

[0133] S207: Return error information.

[0134] In the present application, refer to Figure 4 As shown, the client ( Figure 4The client (the client terminal application side shown in the figure) loads the transfer page and sends a login request to the server. Referring to the server steps S101-S104, the client receives the information returned by the server and determines whether the information returned by the server is a user authentication login state or an error message. If the returned information is an error message, the client displays the error message to the customer on the transfer page; if the returned information is a user authentication login state, the localstore (client storage mechanism, which stores data on the customer's local browser) saves the user authentication login state and other customer information (such as user name, gender, avatar, etc.). The client reloads the interface from the transfer page to the routing address of the target terminal application (composed of the function page routing address of the target terminal application and the url parameters carried by the function page routing address), completes the jump and display of the function page of the target terminal application in the client, and the customer can use the corresponding functions provided by the target terminal application, thereby completing the customer login.

[0135] In the embodiment of the present application, the server and the client interact to complete the login process of the integrated pan-terminal application portal, refer to Figure 5 As shown, the overall execution steps of the integrated pan-terminal application portal login are as follows:

[0136] S301: The client obtains the user's terminal information and encrypts it to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp;

[0137] S302: Acquire transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the url parameters carried by the function page routing address;

[0138] S303: combining the terminal ID, the client signature information and the transfer page parameter to obtain a transfer page address;

[0139] S304: Loading the transfer page according to the transfer page address, and sending a login request to the server;

[0140] S305: The server receives a login request sent by the client transfer page; the login request includes the client transfer page address;

[0141] S306: Parse the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier;

[0142] S307: Determine whether the client signature information is legal based on the terminal ID, the timestamp and the client signature information: if so, execute step S308; if not, execute S309;

[0143] S308: Determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain the user authentication login state, and return the user authentication login state to the client;

[0144] S309: return error information;

[0145] S310: The client receives the information returned by the server and determines whether the information returned by the server is a user authentication login state: if so, execute step S311; if not, execute S312;

[0146] S311: Jumping from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameter carried in the function page routing address;

[0147] S312: Return error information.

[0148] In the embodiment of the present application, the specific implementation process of the above steps S301 to S304 and S309 to S310 can refer to the detailed description of the login method for the client-integrated pan-terminal application portal of the above steps S201 to S204 and S205 to S206; the specific implementation process of the above steps S304 to S308 can refer to the detailed description of the login method for the server-integrated pan-terminal application portal of the above steps S101 to S104, and the repeated parts of the above processes will not be repeated here.

[0149] The login method for an integrated pan-terminal application portal provided in an embodiment of the present invention encrypts the user's terminal information, and then splices it with the authorized login type of the target terminal application, the user's unique identifier, the function page routing address, and the corresponding parameters into a client transfer page address. In the transfer page, the user authentication conversion interface is called to obtain the user authentication login state and other information of the customer, to achieve the authorized login of the target terminal application, and jump from the transfer page to the function page of the target terminal application. A method for implementing an integrated pan-terminal application portal has been established, which provides convenience to customers by obtaining the authorized login type and other parameters of the target terminal application set by the customer, so that customers can quickly access multiple terminal application systems. In addition, this method also supports the dynamic expansion of terminal applications, allowing new terminal applications to be continuously added, thereby meeting the growing needs of the system.

[0150] Embodiment 2

[0151] Based on the same inventive concept, the embodiment of the present invention also provides a login device integrating a pan-terminal application portal, which is applied to the server, referring to Figure 6 As shown, the device comprises:

[0152] The first acquisition module 101 is used to receive a login request of any client transfer page; the login request includes the client transfer page address;

[0153] The first parsing module 102 is used to parse the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier;

[0154] A first judgment module 103 is used to determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information;

[0155] The second acquisition module 104 is used to determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user's unique identifier if the first judgment module determines that the client signature information is legal, obtain the user authentication login state, and return the user authentication login state to the client.

[0156] Embodiment 3

[0157] Based on the same inventive concept, the embodiment of the present invention also provides a login device integrating a pan-terminal application portal, which is applied to a client, referring to Figure 7 As shown, the device comprises:

[0158] The first encryption module 201 is used to obtain the user's terminal information for encryption to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp;

[0159] The first acquisition module 202 is used to acquire transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the URL parameters carried by the function page routing address;

[0160] A first splicing module 203, used to combine the terminal ID, the client signature information and the transfer page parameter to obtain a transfer page address;

[0161] A first sending module 204, configured to load a transfer page according to the transfer page address and send a login request to the server;

[0162] The first judgment module 205 is used to receive the information returned by the server and judge whether the information returned by the server is a user authentication login state;

[0163] The first display module 206 is used to jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameters carried by the function page routing address if the first judgment module determines that the information returned by the server is the user authentication login state.

[0164] Embodiment 4

[0165] Based on the same inventive concept, the embodiment of the present invention also provides a login system integrating a pan-terminal application portal, referring to Figure 8 As shown, the system includes a server 1 and a client 2, wherein:

[0166] The server 1 is used to receive a login request from any client transfer page; the login request includes the client transfer page address; the client transfer page address is parsed to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier; according to the terminal ID, the timestamp and the client signature information, it is determined whether the client signature information is legal; if so, according to the authorized login type and user unique identifier of the target terminal application, it is determined to call the user authentication conversion interface to obtain the user authentication login state, obtain the user authentication login state, and return the user authentication login state to the client;

[0167] The client 2 is used to obtain the user's terminal information and encrypt it to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp; obtain the transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application and the url parameters carried by the function page routing address; combine the terminal ID, the client signature information and the transfer page parameters to obtain the transfer page address; load the transfer page according to the transfer page address, and send a login request to the server; receive the information returned by the server, and determine whether the information returned by the server is the user authentication login state: if so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the url parameters carried by the function page routing address.

[0168] It should be noted that the information interaction, execution process and other contents between the server 1 and the client 2 in the above-mentioned system are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0169] Embodiment 5

[0170] Based on the same inventive concept, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a computer device, the login method of the integrated universal terminal application portal as described in the above embodiment 1 is implemented.

[0171] Embodiment 6

[0172] Based on the same inventive concept, an embodiment of the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the login method for the integrated pan-terminal application portal as described in the above-mentioned embodiment 1 is implemented.

[0173] Embodiment 7

[0174] Based on the same inventive concept, an embodiment of the present invention also provides a computer program product containing instructions. When the computer program product is run on a computer device, the computer device executes the login method of the integrated pan-terminal application portal as described in the above embodiment 1.

[0175] Embodiment 8

[0176] Based on the same inventive concept, an embodiment of the present invention also provides a chip, the chip includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a computer program or instruction to implement the login method of the integrated pan-terminal application portal as described in the above embodiment one.

[0177] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.

[0178] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0179] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0180] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0181] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A login method integrating a pan-terminal application portal, characterized in that: Applied to the server, including: Receive a login request from any client transfer page; the login request includes the client transfer page address; Parsing the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier; Determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information; If so, determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain the user authentication login state, and return the user authentication login state to the client.

2. The method according to claim 1, characterized in that The method of determining to call a user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtaining a user authentication login state, obtaining a user authentication login state, and returning the user authentication login state to the client includes: Obtaining a user information query interface of the target terminal application according to the authorized login type of the target terminal application; A query is performed based on the user unique identifier and the user information query interface. If it is confirmed that the user corresponding to the user unique identifier exists in the user information of the target terminal application, the user authentication login state is obtained and returned to the client.

3. The method according to claim 1, characterized in that The method of determining to call a user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtaining a user authentication login state, obtaining a user authentication login state, and returning the user authentication login state to the client includes: Obtaining an access token for the target terminal application according to the authorized login type of the target terminal application; The target terminal application obtains a user information query interface of the target terminal application according to the access token; A query is performed based on the user unique identifier and the user information query interface. If it is confirmed that the user corresponding to the user unique identifier exists in the user information of the target terminal application, the user authentication login state is obtained and returned to the client.

4. The method according to claim 1, characterized in that The determining whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information includes: Find the corresponding key according to the terminal ID; Encrypt according to the timestamp, the terminal ID and the corresponding key to obtain the server signature information; Confirm whether the server signature information is the same as the client signature information; If yes, confirm that the client signature information is legal; If not, return an error message.

5. The method according to claim 1, characterized in that After parsing the client transfer page address and obtaining the public parameters, the method further includes: Determine whether the common parameters are missing, and if so, return an error message.

6. A login method integrating a pan-terminal application portal, characterized in that: Applied to the client, including: Obtain the user's terminal information and encrypt it to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp; Obtain transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the url parameters carried by the function page routing address; Combining the terminal ID, the client signature information and the transfer page parameter, splicing to obtain the client transfer page address; Load the transfer page according to the client transfer page address and send a login request to the server; Receive the information returned by the server and determine whether the information returned by the server is the user authentication login state: If so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameter carried by the function page routing address.

7. The method according to claim 6, characterized in that The user's terminal information is obtained and encrypted to obtain the client signature information, wherein the terminal information includes a terminal ID, a key and a timestamp, including: Concatenate the terminal ID, the key and the timestamp to obtain a character string to be encrypted; The key is used as an encryption factor and an encryption algorithm is used to encrypt the character string to obtain the client signature information.

8. A login method integrating a pan-terminal application portal, characterized in that: include: The client obtains the user's terminal information, encrypts it, and obtains the client signature information; The terminal information includes a terminal ID, a key and a timestamp; Get the transfer page parameters; The transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the URL parameters carried by the function page routing address; Combining the terminal ID, the client signature information and the transfer page parameter, splicing to obtain the client transfer page address; Load the transfer page according to the client transfer page address and send a login request to the server; The server receives the login request sent by the client transfer page; The login request includes the client transfer page address; Parsing the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier; Determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information; If yes, determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain the user authentication login state, and return the user authentication login state to the client; The client receives the information returned by the server and determines whether the information returned by the server is the user authentication login state: If so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the URL parameter carried by the function page routing address.

9. A login device integrated with a pan-terminal application portal, characterized in that: Applied to the server, including: A first acquisition module is used to receive a login request of any client transfer page; the login request includes the client transfer page address; A first parsing module, used to parse the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier; A first judgment module, used to determine whether the client signature information is legal according to the terminal ID, the timestamp and the client signature information; The second acquisition module is used to determine the call of the user authentication conversion interface according to the authorized login type of the target terminal application and the user's unique identifier if the first judgment module determines that the client signature information is legal, obtain the user authentication login state, and return the user authentication login state to the client.

10. A login device integrated with a pan-terminal application portal, characterized in that: Applied to the client, including: The first encryption module is used to obtain the user's terminal information for encryption to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp; The first acquisition module is used to acquire transfer page parameters; the transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the URL parameters carried by the function page routing address; A first splicing module, used for combining the terminal ID, the client signature information and the transfer page parameter to obtain a client transfer page address; A first sending module, used for loading a transfer page according to the client transfer page address, and sending a login request to the server; The first judgment module is used to receive the information returned by the server and judge whether the information returned by the server is the user authentication login state; The first display module is used to jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the url parameters carried by the function page routing address if the first judgment module determines that the information returned by the server is the user authentication login state.

11. A login system integrating a pan-terminal application portal, characterized in that: include: Server and client; The server is used to receive a login request from any client transfer page; The login request includes the client transfer page address; Parse the client transfer page address to obtain public parameters; the public parameters include terminal ID, timestamp, client signature information, authorized login type of target terminal application and user unique identifier; determine whether the client signature information is legal according to the terminal ID, timestamp and client signature information; if so, determine to call the user authentication conversion interface according to the authorized login type of the target terminal application and the user unique identifier, obtain the user authentication login state, and return the user authentication login state to the client; The client is used to obtain the user's terminal information for encryption to obtain the client signature information; the terminal information includes the terminal ID, key and timestamp; Get the transfer page parameters; The transfer page parameters include the authorized login type of the target terminal application, the user unique identifier of the target terminal application, the function page routing address of the target terminal application, and the url parameters carried by the function page routing address; the client transfer page address is obtained by combining the terminal ID, the client signature information and the transfer page parameters; Load the transfer page according to the client transfer page address, and send a login request to the server; receive the information returned by the server, and determine whether the information returned by the server is the user authentication login state: if so, jump from the transfer page to the function page of the target terminal application according to the function page routing address of the target terminal application and the url parameters carried by the function page routing address.

12. A computer-readable storage medium storing instructions, which, when executed on a computer device, cause the computer device to execute a login method for an integrated pan-terminal application portal as described in any one of claims 1-5 or 6-7.

13. A computer device, characterized in that: It includes a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements a login method for an integrated pan-terminal application portal as described in any one of claims 1-5 or 6-7.

14. A computer program product comprising instructions, which, when executed on a computer device, enables the computer device to execute a login method for an integrated pan-terminal application portal as described in any one of claims 1-5 or 6-7.

15. A chip, comprising a processor and a communication interface, wherein the communication interface and the processor are coupled, and the processor is used to run a computer program or instruction to implement a login method for an integrated pan-terminal application portal as described in any one of claims 1-5 or 6-7.