Application access method, system and device and computer readable storage medium
Through the communication between computer equipment and the identity authentication server and application server, verify and obtain identity credentials to access the target application, the problems of long access time, low efficiency and low success rate in the prior art are solved, and more efficient and reliable application access is achieved.
Patent Information
- Application Number
- CN202411265566.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-09-10
AI Technical Summary
In the prior art, users need to enter the login password of the operating system and the access password of the target application respectively, resulting in a long time to access the application, low efficiency, and easy to reduce the access success rate due to forgetting the password.
Through the computer device, the login request is obtained and sent to the identity authentication server. After verifying the identity credentials of the target user, the identity credentials are sent directly to the application server to obtain authorized access information, thereby displaying the interface of the target application.
No user needs to enter the target application's login account and login password, which saves time to access the application, improves access efficiency, and reduces the risk of inaccessibility due to forgetting your password, and improves access success rate.
Smart Images

Figure CN119989310A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer technology, and in particular to an application access method, system, device, and computer-readable storage medium. Background Art
[0002] With the continuous development of computer technology, the importance of the content stored in the computer is also increasing, and more and more people will set the login password of the operating system of the computer device. When the user wants to access the target application in the computer device, the user needs to enter the login password of the operating system first, log in to the operating system, and then enter the correct access password before accessing the target application.
[0003] This requires the user to remember the operating system login password and the target application access password, which places high demands on the user, making it take a long time to access the application and reducing the access efficiency. When the user forgets the operating system login password or forgets the target application access password, the user cannot access the target application, thereby reducing the access success rate of the target application. Summary of the invention
[0004] The embodiments of the present application provide an application access method, system, device and computer-readable storage medium, which can be used to solve the problems of long time required to access applications, low access efficiency and low access success rate in related technologies. The technical solution is as follows.
[0005] On the one hand, an embodiment of the present application provides an application access method, the method is applied to a computer device, the computer device is in communication connection with an identity authentication server and an application server, the method includes:
[0006] The computer device obtains a login request and sends the login request to the identity authentication server, wherein the login request includes a login account and a login password of a target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system;
[0007] The computer device receives the identity credential returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, wherein the identity credential is used to indicate the identity information of the target user;
[0008] The computer device sends the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application;
[0009] The computer device receives the authorization access information returned by the application server when it is determined that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
[0010] In a possible implementation, the computer device includes an operating system authentication module and a local security authorization module;
[0011] The computer device obtains a login request and sends the login request to the identity authentication server, including:
[0012] The operating system authentication module obtains the login request and sends the login request to the local security authorization module;
[0013] The local security authorization module receives the login request and sends the login request to the identity authentication server;
[0014] The computer device receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, including:
[0015] The local security authorization module receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and sends authentication success information to the operating system authentication module according to the identity credentials, wherein the authentication success information is used to indicate that the target user can log in to the operating system;
[0016] The operating system authentication module receives the authentication success information and logs into the operating system.
[0017] In a possible implementation, the computer device includes a browser;
[0018] The computer device sending the identity credential to the application server includes:
[0019] The browser sends the identity credential to the application server;
[0020] The computer device receives the authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information, including:
[0021] The browser receives the authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
[0022] In a possible implementation, before the browser sends the identity credential to the application server, the method further includes:
[0023] The browser sends an acquisition request to the local security authorization module of the computer device, wherein the acquisition request is used to acquire the identity credential;
[0024] The browser receives the identity credential sent by the local security authorization module.
[0025] In a possible implementation, the method further includes:
[0026] The local security authorization module stores the identity credentials.
[0027] In a possible implementation, the method further includes:
[0028] The computer device receives the target information returned by the identity authentication server when determining that the target user cannot log in to the operating system, and displays the target information, where the target information is used to indicate that the target user cannot log in to the operating system.
[0029] In a possible implementation, the method further includes:
[0030] The computer device receives the access prohibition information returned by the application server when determining that the target user cannot access the target application, and displays the access prohibition information, where the access prohibition information is used to indicate that the target user cannot access the target application.
[0031] On the other hand, an embodiment of the present application provides an application access system, the system comprising a computer device, an identity authentication server and an application server, wherein:
[0032] The computer device is used to obtain a login request and send the login request to the identity authentication server, wherein the login request includes a login account and a login password of a target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system;
[0033] The identity authentication server is used to send an identity credential to the computer device when determining that the target user can log in to the operating system, wherein the identity credential is used to indicate the identity information of the target user;
[0034] The computer device is further used to receive the identity credential and log into the operating system;
[0035] The computer device is further used to send the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application;
[0036] The application server is used to send authorization access information to the computer device when determining that the target user can access the target application, wherein the authorization access information is used to indicate that the target user can access the target application;
[0037] The computer device is further used to receive the authorized access information and display the interface corresponding to the target application according to the authorized access information.
[0038] On the other hand, an embodiment of the present application provides a computer device, which includes a processor and a memory, wherein the memory stores at least one program code, and the at least one program code is loaded and executed by the processor so that the computer device implements any of the above-mentioned application access methods.
[0039] On the other hand, a computer-readable storage medium is provided, in which at least one program code is stored. The at least one program code is loaded and executed by a processor so that a computer implements any of the above-mentioned application access methods.
[0040] On the other hand, a computer program or a computer program product is also provided, wherein at least one computer instruction is stored in the computer program or the computer program product, and the at least one computer instruction is loaded and executed by a processor so that the computer implements any of the above-mentioned application access methods.
[0041] The technical solution provided by the embodiments of the present application brings at least the following beneficial effects:
[0042] The technical solution provided by the embodiment of the present application directly sends the target user's identity credentials to the application server after the target user logs into the operating system, if the target user still wants to access the target application, so that the application server returns the authorization access information when determining that the target user can access the target application, thereby displaying the interface corresponding to the target application to enable the target user to access the target application. In this way, when accessing the target application, the target user does not need to enter the login account and login password of the target application, which saves the time required to access the application and improves the access efficiency of the target application. Moreover, since there is no need to enter the login account and login password of the target application, there is no need for the target user to remember the login account and login password, thereby avoiding the situation where the target user forgets the login password of the target application and the target user cannot access the target application, thereby improving the access success rate of the target application. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0044] Figure 1 It is a structural diagram of an application access system provided in an embodiment of the present application;
[0045] Figure 2 is a flow chart of an application access method provided by an embodiment of the present application;
[0046] Figure 3 is a flow chart of an application access method provided by an embodiment of the present application;
[0047] Figure 4 is a flow chart of an application access method provided by an embodiment of the present application;
[0048] Figure 5 It is a structural diagram of a terminal device provided in an embodiment of the present application;
[0049] Figure 6 It is a structural diagram of a server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0050] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0051] Figure 1 is a schematic diagram of the structure of an application access system provided in an embodiment of the present application, such as Figure 1 As shown, the system includes: a computer device 101, an identity authentication server 102 and an application server 103.
[0052] Among them, the computer device 101 includes an operating system authentication module 104, a local security authorization module 105 and a browser 106. Optionally, the operating system authentication module is an authentication module developed based on the Windows Credential Provider (a credential provider for an operating system) standard, and the operating system authentication module can perform identity authentication through the local security authorization module 105 (that is, the Local Security Authority Subsystem Service, LSASS) of Windows (an operating system). The computer device 101 is pre-configured with kbr5.conf / kbr5.ini (a configuration file), and the configuration includes the address of the identity authentication server. The browser 106 is configured to use the Windows IWA authentication mode (an authentication mode for an operating system) and needs to use an internal domain name range for unified authentication. Exemplarily, the browser can be a Chrome browser (a browser), a Firefox browser (a browser), or an Edge browser (a browser), which is not limited in the embodiments of the present application. For example, the internal domain name range configured in the Chrome browser is "example.com".
[0053] The computer device 101 and the identity authentication server 102 are communicatively connected via a wired network or a wireless network, and the computer device 101 and the application server 103 are communicatively connected via a wired network or a wireless network.
[0054] Optionally, the computer device 101 is any electronic device product that can interact with a user through one or more methods such as a keyboard, a touch pad, a remote controller, voice interaction, or a handwriting device, for example, a PC (Personal Computer), a mobile phone, a smart phone, a PDA (Personal Digital Assistant), a wearable device, a PPC (Pocket PC), a tablet computer, a smart car machine, a smart TV, a smart speaker, a smart watch, etc.
[0055] The computer device 101 may generally refer to one of a plurality of computer devices, and this embodiment is only illustrated by taking the computer device 101 as an example. Those skilled in the art may know that the number of the computer devices 101 may be more or less. For example, the computer device 101 may be only one, or the computer devices 101 may be dozens or hundreds, or more. The embodiment of the present application does not limit the number and device type of the computer devices 101.
[0056] The identity authentication server 102 may be a single server, or a server cluster consisting of multiple servers, or any one of a cloud computing platform and a virtualization center, which is not limited in the embodiments of the present application. The application server 103 may be a single server, or a server cluster consisting of multiple servers, or any one of a cloud computing platform and a virtualization center, which is not limited in the embodiments of the present application.
[0057] Those skilled in the art should understand that the above-mentioned computer device 101, identity authentication server 102 and application server 103 are merely examples, and other existing or future computer devices or servers, if applicable to the present application, should also be included in the scope of protection of the present application and are incorporated herein by reference.
[0058] The present application embodiment provides an application access method, which can be applied to the above Figure 1 The implementation environment shown is Figure 2 As an example, the flowchart of an application access method provided in the embodiment of the present application is shown in FIG. Figure 1 The interaction between the computer device 101, the identity authentication server 102 and the application server 103 is implemented. Figure 2 As shown, the method comprises the following steps:
[0059] In step 201, the computer device obtains a login request and sends the login request to an identity authentication server.
[0060] In a possible implementation, the computer device includes an operating system authentication module and a local security authorization module. The process of the computer device obtaining a login request and sending the login request to the identity authentication server includes: the operating system authentication module obtains the login request and sends the login request to the local security authorization module; the local security authorization module receives the login request and sends the login request to the identity authentication server.
[0061] The login request includes the login account and login password of the target user who requests to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system.
[0062] Optionally, before obtaining a login request, the operating system authentication module needs to first obtain the target user's login account and the target user's login password. The embodiment of the present application does not limit the method for obtaining the target user's login account and the target user's login password. Optionally, the process of obtaining the target user's login account and the target user's login password includes: in response to the operation of turning on the computer device, displaying an account box and a password box; according to the account box, obtaining the target user's login account, and according to the password box, obtaining the target user's login password.
[0063] After obtaining the target user's login account and login password, in response to the operation of logging into the computer device, the operating system authentication module generates a login request based on the target user's login account and login password, and the login request includes the target user's login account and login password requesting to log into the operating system.
[0064] Optionally, the computer device includes a power-on control, and in response to a trigger operation on the power-on control, receives an operation to turn on the computer device.
[0065] According to the account box, the process of obtaining the login account of the target user includes: in response to an input operation in the account box, using the content input in the account box as the login account of the target user. Alternatively, in response to a trigger operation on the account box, displaying candidate accounts, and in response to a trigger operation on any account in the candidate accounts, determining any account as the login account of the target user.
[0066] According to the password box, the process of obtaining the login password of the target user includes: in response to an input operation in the password box, taking the content input in the password box as the login password of the target user.
[0067] In a possible implementation, the operating system authentication module cannot directly contact the identity authentication server. Therefore, after obtaining the login request, the operating system authentication module sends the login request to the local security authorization module, so that the local security authorization module sends the login request to the identity authentication server.
[0068] After receiving the login request sent by the operating system authentication module, the local security authorization module sends a login request to the identity authentication server, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system. The identity authentication server is the identity authentication server corresponding to the target group. The target group can be an enterprise, a company under an enterprise, a department within a company, or other groups. The embodiment of the present application does not limit the target group.
[0069] The local security authorization module can send a login request to the identity authentication server immediately after receiving the login request, or it can send a login request to the identity authentication server after staying for a target time. The embodiment of the present application does not limit the timing of sending the login request to the identity authentication server by the local security authorization module. Among them, the target time is set based on experience or adjusted according to the implementation environment, and the embodiment of the present application does not limit this.
[0070] In step 202, the identity authentication server receives a login request and determines whether the target user can log in to the operating system.
[0071] In a possible implementation manner, the identity authentication server stores the object accounts of various objects included in the target group, and the corresponding relationship between the object accounts of various objects and the object passwords of various objects.
[0072] Optionally, after receiving the login request sent by the local security authorization module, the identity authentication server parses the login request to obtain the login account and login password of the target user, and then determines whether the target user can log in to the operating system based on the login account and login password of the target user.
[0073] If the login account belongs to the target group and the login account and login password match, it is determined that the target user can log in to the operating system. If the login account does not belong to the target group, it is determined that the target user cannot log in to the operating system. If the login account belongs to the target group and the login account and login password do not match, it is determined that the target user cannot log in to the operating system.
[0074] Optionally, the process of determining whether the login account belongs to the target group includes: if the object accounts stored in the identity authentication server include the login account, determining that the login account belongs to the target group. If the object accounts stored in the identity authentication server do not include the login account, determining that the login account does not belong to the target group.
[0075] The process of determining whether the login account and the login password match includes: obtaining the object password corresponding to the login account; if the login password and the object password match, determining that the login account and the login password match; if the login password and the object password do not match, determining that the login account and the login password do not match.
[0076] The matching of the login password and the object password means that the login password and the object password are consistent, or the contents corresponding to the login password and the object password are consistent.
[0077] In step 203, the identity authentication server sends the identity credentials to the computer device when determining that the target user can log in to the operating system.
[0078] The identity certificate is used to indicate the identity information of the target user, that is, the identity certificate is used to indicate that the target user is an object included in the target group, and the target user can successfully log in to the operating system.
[0079] In a possible implementation, the identity authentication server sends the identity credentials to the local security authorization module when determining that the target user can log in to the operating system. The local security authorization module receives the identity credentials and sends authentication success information to the operating system authentication module. The operating system authentication module receives the authentication success information and logs in to the operating system.
[0080] Optionally, the local security authorization module may send a successful authentication message to the operating system authentication module immediately after receiving the identity credentials, or may send a successful authentication message to the operating system authentication module after staying for a reference time. The embodiment of the present application does not limit the timing of the local security authorization module sending the successful authentication message to the operating system authentication module. The reference time is set based on experience or adjusted according to the implementation environment, which is not limited in the embodiment of the present application. Exemplarily, the reference time is 2 seconds.
[0081] Optionally, after receiving the identity credential, the local security authorization module may also store the identity credential so that the browser can subsequently obtain the identity credential from the local security authorization module.
[0082] In another possible implementation, when the identity authentication server determines that the target user cannot log in to the operating system, the identity authentication server sends target information to the computer device, where the target information is used to indicate that the target user cannot log in to the operating system. The computer device receives the target information returned by the identity authentication server when it determines that the target user cannot log in to the operating system, and displays the target information.
[0083] Optionally, the identity authentication server sends the target information to the local security authorization module, the local security authorization module receives the target information and sends the target information to the operating system authentication module, the operating system authentication module receives the target information and displays the target information.
[0084] There are two reasons why the target user cannot log in to the operating system. The first is that the login account does not belong to the target group, and the second is that the login account belongs to the target group, but the login account and login password do not match. When the reason why the target user cannot log in to the operating system is that the login account does not belong to the target group, the target information sent by the identity authentication server is the first information, which means that the target user cannot log in to the operating system because the login account does not belong to the target group. When the reason why the target user cannot log in to the operating system is that the login account belongs to the target group, but the login account and login password do not match, the target information sent by the identity authentication server is the second information, which means that the target user cannot log in to the operating system because the login account and login password do not match.
[0085] In step 204, the computer device receives the identity credentials and logs into the operating system.
[0086] In a possible implementation, the local security authorization module receives the identity credentials and sends authentication success information to the operating system authentication module. After receiving the authentication success information, the operating system authentication module logs into the operating system. The way of logging into the operating system includes but is not limited to displaying the desktop of the computer device.
[0087] In step 205, the computer device sends the identity credentials to the application server.
[0088] In one possible implementation, after the desktop of the computer device is displayed, relevant information of the browser is displayed on the desktop of the computer device. The relevant information of the browser may be the name of the browser, the icon of the browser, or any other information of the browser. The embodiment of the present application does not limit the relevant information of the browser.
[0089] When the target user wants to access the target application, the target user triggers the relevant information of the browser, and the computer device displays the homepage of the browser, in which a search box and a search control are displayed. The target user can enter the address of the target application in the search box, and the browser obtains the address of the target application. In response to the target user's triggering operation on the search control, the computer device sends the target user's identity credentials to the application server. Among them, the target user's identity credentials are used by the application server to determine whether the target user can access the target application. The application server is the server corresponding to the target application, that is, the application server is a server that provides background support for the target application. Optionally, the computer device includes a browser, and the browser sends the target user's identity credentials to the application server.
[0090] In a possible implementation, before the browser sends the identity credential to the application server, the browser needs to first obtain the identity credential. Optionally, the browser obtains the identity credential from a local security authorization module.
[0091] The process of the browser obtaining the identity credential from the local security authorization module includes: the browser sends a request to the local security authorization module, the request is used to obtain the identity credential. The local security authorization module receives the request and returns the identity credential to the browser, so that the browser obtains the identity credential.
[0092] In step 206, the application server receives the identity credentials and determines whether the target user can access the target application based on the identity credentials.
[0093] In a possible implementation, an object credential that can access an object of a target application is stored in an application server. After the application server receives the identity credential, the process of determining whether the target user can access the target application according to the identity credential includes: if the object credential stored in the application server includes the identity credential, determining that the target user can access the target application. If the object credential stored in the application server does not include the identity credential, determining that the target user cannot access the target application.
[0094] In step 207, when determining that the target user can access the target application, the application server sends authorization access information to the computer device.
[0095] In a possible implementation, after determining whether the target user can access the target application in the above step 206, if the target user can access the target application, the authorization access information is sent to the computer device. The authorization access information can be any information used to indicate that the target user can access the target application, and this embodiment of the application is not limited to this. Optionally, the authorization access information is sent to the browser.
[0096] In another possible implementation, when it is determined that the target user cannot access the target application, the application server sends access prohibition information to the computer device, where the access prohibition information is used to indicate that the target user cannot access the target application. Optionally, the application server sends access prohibition information to the browser.
[0097] In step 208, the computer device receives the authorized access information and displays the interface corresponding to the target application according to the authorized access information.
[0098] In a possible implementation, after receiving the authorization access information sent by the application server, the computer device displays the interface corresponding to the target application according to the authorization access information. Optionally, after receiving the authorization access information sent by the application server, the browser displays the interface corresponding to the target application according to the authorization access information.
[0099] In another possible implementation, after receiving the access prohibition information sent by the application server, the computer device displays the access prohibition information. Optionally, after receiving the access prohibition information sent by the application server, the browser displays the access prohibition information.
[0100] After the target user logs into the operating system, if the target user still wants to access the target application, the above method directly sends the target user's identity credentials to the application server, so that the application server returns the authorization access information when it is determined that the target user can access the target application, thereby displaying the interface corresponding to the target application to enable the target user to access the target application. In this way, when accessing the target application, the target user does not need to enter the login account and login password of the target application, which saves the time required to access the application and improves the access efficiency of the target application. Moreover, since there is no need to enter the login account and login password of the target application, there is no need for the target user to remember the login account and login password, thereby avoiding the situation where the target user forgets the login password of the target application and cannot access the target application, thereby improving the access success rate of the target application.
[0101] Figure 3 It is a flowchart of an application access method provided in an embodiment of the present application. The method is executed by a computer device 101 and includes the following steps.
[0102] In step 301, the computer device obtains a login request and sends the login request to the identity authentication server. The login request includes the login account and login password of the target user requesting to log in to the operating system. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system.
[0103] In a possible implementation, the process of the computer device obtaining a login request and sending the login request to the identity authentication server has been described in the above step 201 and will not be repeated here.
[0104] In step 302, the computer device receives the identity credential returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, where the identity credential is used to indicate the identity information of the target user.
[0105] In a possible implementation, the computer device receives the identity credentials returned by the identity authentication server when it is determined that the target user can log in to the operating system. The process of logging in to the operating system has been described in the above step 204 and will not be repeated here.
[0106] In step 303, the computer device sends the identity credential to the application server, and the identity credential is used by the application server to determine whether the target user can access the target application.
[0107] In a possible implementation, the process of the computer device sending the identity credential to the application server has been described in the above step 205 and will not be repeated here.
[0108] In step 304, the computer device receives the authorization access information returned by the application server when it is determined that the target user can access the target application, and displays the interface corresponding to the target application according to the authorization access information.
[0109] In a possible implementation, the computer device receives the authorization access information returned by the application server when it is determined that the target user can access the target application. The process of displaying the interface corresponding to the target application has been described in the above step 208 and will not be repeated here.
[0110] The embodiment of the present application provides an application access system, which includes a computer device, an identity authentication server and an application server, wherein:
[0111] The computer device is used to obtain a login request and send the login request to the identity authentication server. The login request includes the login account and login password of the target user who requests to log in to the operating system. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system.
[0112] The identity authentication server is used to send an identity credential to the computer device when it is determined that the target user can log in to the operating system, and the identity credential is used to indicate the identity information of the target user;
[0113] Computer equipment, also used to receive identity credentials and log into the operating system;
[0114] The computer device is further used to send an identity credential to the application server, and the identity credential is used by the application server to determine whether the target user can access the target application;
[0115] The application server is used to send authorization access information to the computer device when it is determined that the target user can access the target application, and the authorization access information is used to indicate that the target user can access the target application;
[0116] The computer device is also used to receive authorized access information and display an interface corresponding to the target application according to the authorized access information.
[0117] In one possible implementation, the computer device includes an operating system authentication module and a local security authorization module;
[0118] The operating system authentication module is used to obtain the login request and send the login request to the local security authorization module;
[0119] A local security authorization module is used to receive a login request and send the login request to an identity authentication server;
[0120] The local security authorization module is further used to receive the identity credentials returned by the identity authentication server when it is determined that the target user can log in to the operating system, and send authentication success information to the operating system authentication module according to the identity credentials, and the authentication success information is used to indicate that the target user can log in to the operating system;
[0121] The operating system authentication module is also used to receive authentication success information and log in to the operating system.
[0122] In one possible implementation, the computer device includes a browser;
[0123] The browser sends the identity credentials to the application server;
[0124] The browser is also used to receive the authorization access information returned by the application server when it is determined that the target user can access the target application, and display the interface corresponding to the target application according to the authorization access information.
[0125] In a possible implementation, the browser is further used to send an acquisition request to a local security authorization module of the computer device, where the acquisition request is used to acquire the identity credential;
[0126] The browser is also used to receive identity credentials sent by the local security authorization module.
[0127] In a possible implementation, the local security authorization module is also used to store identity credentials.
[0128] In a possible implementation, the computer device is further used to receive target information returned by the identity authentication server when it is determined that the target user cannot log in to the operating system, and display the target information, where the target information is used to indicate that the target user cannot log in to the operating system.
[0129] In a possible implementation, the computer device is further used to receive access prohibition information returned by the application server when it is determined that the target user cannot access the target application, and display the access prohibition information, where the access prohibition information is used to indicate that the target user cannot access the target application.
[0130] Figure 4 A flowchart of an application access method provided in an embodiment of the present application, such as Figure 4 As shown, the method includes the following steps.
[0131] 1. The target user logs into the operating system.
[0132] 2. The operating system authentication module generates a login request.
[0133] The login request includes the login account and login password of the target user who requests to log in to the operating system.
[0134] 3. The operating system authentication module sends a login request to the local security authorization module.
[0135] 4. The local security authorization module sends a login request to the identity authentication server.
[0136] 5. The identity authentication server determines whether the target user can log in to the operating system.
[0137] 6. When the identity authentication server determines that the target user can log in to the operating system, it sends the identity credentials to the local security authorization module.
[0138] The identity credential is used to indicate the identity information of the target user.
[0139] 7. The local security authorization module sends authentication success information to the operating system authentication module.
[0140] The local security authorization module stores identity credentials.
[0141] 8. The operating system authentication module logs into the operating system.
[0142] 9. The target user logs in to the target application.
[0143] 10. The browser sends a request to the local security authorization module.
[0144] 11. The local security authorization module sends the user credentials to the browser.
[0145] 12. The browser sends the user credentials to the application server.
[0146] 13. The application server determines whether the target user can access the target application.
[0147] 14. When the application server determines that the target user can access the target application, it sends authorization access information to the browser.
[0148] 15. The browser displays the interface corresponding to the target application.
[0149] The computer device may be a terminal device, Figure 5 The structural block diagram of a terminal device 500 provided by an exemplary embodiment of the present application is shown. The terminal device 500 may be any electronic device product that can perform human-computer interaction with a user through one or more methods such as a keyboard, a touchpad, a remote controller, voice interaction, or a handwriting device. For example, a PC (Personal Computer), a mobile phone, a smart phone, a PDA (Personal Digital Assistant), a wearable device, a PPC (Pocket PC), a tablet computer, a smart car machine, a smart TV, a smart speaker, a smart watch, etc.
[0150] Typically, the terminal device 500 includes: a processor 501 and a memory 502 .
[0151] The processor 501 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 501 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 501 may also include a main processor and a coprocessor. The main processor is a processor for processing data in an awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in a standby state. In some embodiments, the processor 501 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 501 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0152] The memory 502 may include one or more computer-readable storage media, which may be non-transitory. The memory 502 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 502 is used to store at least one instruction, which is used to be executed by the processor 501 to implement the application access method provided in the method embodiment of the present application.
[0153] In some embodiments, the terminal device 500 may further optionally include: a peripheral device interface 503 and at least one peripheral device. The processor 501, the memory 502 and the peripheral device interface 503 may be connected via a bus or a signal line. Each peripheral device may be connected to the peripheral device interface 503 via a bus, a signal line or a circuit board. Specifically, the peripheral device includes: at least one of a radio frequency circuit 504, a display screen 505, a camera assembly 506, an audio circuit 507 and a power supply 508.
[0154] The peripheral device interface 503 may be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 501 and the memory 502. In some embodiments, the processor 501, the memory 502, and the peripheral device interface 503 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 501, the memory 502, and the peripheral device interface 503 may be implemented on a separate chip or circuit board, which is not limited in this embodiment.
[0155] The radio frequency circuit 504 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 504 communicates with the communication network and other communication devices through electromagnetic signals. The radio frequency circuit 504 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals into electrical signals. Optionally, the radio frequency circuit 504 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The radio frequency circuit 504 can communicate with other terminal devices through at least one wireless communication protocol. The wireless communication protocol includes but is not limited to: the World Wide Web, a metropolitan area network, an intranet, various generations of mobile communication networks (2G, 3G, 4G and 5G), a wireless local area network and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 504 may also include circuits related to NFC (Near Field Communication), which is not limited in this application.
[0156] The display screen 505 is used to display a UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 505 is a touch display screen, the display screen 505 also has the ability to collect touch signals on the surface or above the surface of the display screen 505. The touch signal can be input to the processor 501 as a control signal for processing. At this time, the display screen 505 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, the display screen 505 can be one, set on the front panel of the terminal device 500; in other embodiments, the display screen 505 can be at least two, respectively set on different surfaces of the terminal device 500 or in a folding design; in other embodiments, the display screen 505 can be a flexible display screen, set on a curved surface or a folding surface of the terminal device 500. Even, the display screen 505 can also be set to a non-rectangular irregular shape, that is, a special-shaped screen. The display screen 505 can be made of materials such as LCD (Liquid Crystal Display), OLED (Organic Light-Emitting Diode), etc.
[0157] The camera assembly 506 is used to capture images or videos. Optionally, the camera assembly 506 includes a front camera and a rear camera. Typically, the front camera is arranged on the front panel of the terminal device 500, and the rear camera is arranged on the back of the terminal device 500. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth of field camera, a wide-angle camera, and a telephoto camera, so as to realize the fusion of the main camera and the depth of field camera to realize the background blur function, the fusion of the main camera and the wide-angle camera to realize the panoramic shooting and VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera assembly 506 may also include a flash. The flash can be a monochrome temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation at different color temperatures.
[0158] The audio circuit 507 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals and input them into the processor 501 for processing, or input them into the radio frequency circuit 504 to achieve voice communication. For the purpose of stereo acquisition or noise reduction, there may be multiple microphones, which are respectively arranged at different parts of the terminal device 500. The microphone may also be an array microphone or an omnidirectional acquisition microphone. The speaker is used to convert the electrical signal from the processor 501 or the radio frequency circuit 504 into sound waves. The speaker may be a traditional film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio circuit 507 may also include a headphone jack.
[0159] The power supply 508 is used to power various components in the terminal device 500. The power supply 508 can be an alternating current, a direct current, a disposable battery, or a rechargeable battery. When the power supply 508 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery charged through a wired line, and a wireless rechargeable battery is a battery charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.
[0160] In some embodiments, the terminal device 500 further includes one or more sensors 509 . The one or more sensors 509 include, but are not limited to: an acceleration sensor 510 , a gyroscope sensor 511 , a pressure sensor 512 , an optical sensor 513 , and a proximity sensor 514 .
[0161] The acceleration sensor 510 can detect the magnitude of acceleration on the three coordinate axes of the coordinate system established by the terminal device 500. For example, the acceleration sensor 510 can be used to detect the components of gravity acceleration on the three coordinate axes. The processor 501 can control the display screen 505 to display the user interface in a horizontal view or a vertical view according to the gravity acceleration signal collected by the acceleration sensor 510. The acceleration sensor 510 can also be used to collect game or user motion data.
[0162] The gyro sensor 511 can detect the body direction and rotation angle of the terminal device 500, and the gyro sensor 511 can cooperate with the acceleration sensor 510 to collect the user's 3D actions on the terminal device 500. The processor 501 can implement the following functions based on the data collected by the gyro sensor 511: motion sensing (such as changing the UI according to the user's tilt operation), image stabilization during shooting, game control, and inertial navigation.
[0163] The pressure sensor 512 can be set on the side frame of the terminal device 500 and / or the lower layer of the display screen 505. When the pressure sensor 512 is set on the side frame of the terminal device 500, it can detect the user's holding signal of the terminal device 500, and the processor 501 performs left and right hand recognition or shortcut operation according to the holding signal collected by the pressure sensor 512. When the pressure sensor 512 is set on the lower layer of the display screen 505, the processor 501 controls the operability controls on the UI interface according to the user's pressure operation on the display screen 505. The operability controls include at least one of a button control, a scroll bar control, an icon control, and a menu control.
[0164] The optical sensor 513 is used to collect the ambient light intensity. In one embodiment, the processor 501 can control the display brightness of the display screen 505 according to the ambient light intensity collected by the optical sensor 513. Specifically, when the ambient light intensity is high, the display brightness of the display screen 505 is increased; when the ambient light intensity is low, the display brightness of the display screen 505 is reduced. In another embodiment, the processor 501 can also dynamically adjust the shooting parameters of the camera component 506 according to the ambient light intensity collected by the optical sensor 513.
[0165] The proximity sensor 514, also called a distance sensor, is usually arranged on the front panel of the terminal device 500. The proximity sensor 514 is used to collect the distance between the user and the front of the terminal device 500. In one embodiment, when the proximity sensor 514 detects that the distance between the user and the front of the terminal device 500 is gradually decreasing, the processor 501 controls the display screen 505 to switch from the screen-on state to the screen-off state; when the proximity sensor 514 detects that the distance between the user and the front of the terminal device 500 is gradually increasing, the processor 501 controls the display screen 505 to switch from the screen-off state to the screen-on state.
[0166] Those skilled in the art will understand that Figure 5 The structure shown in the figure does not constitute a limitation on the terminal device 500, and may include more or fewer components than shown in the figure, or combine certain components, or adopt a different component arrangement.
[0167] The computer device may be a server, Figure 6The schematic diagram of the structure of the server provided in the embodiment of the present application, the server 600 may have relatively large differences due to different configurations or performances, and may include one or more processors (Central Processing Units, CPU) 601 and one or more memories 602, wherein the one or more memories 602 store at least one program code, and the at least one program code is loaded and executed by the one or more processors 601 to implement the application access method provided by the above-mentioned various method embodiments. Of course, the server 600 may also have components such as a wired or wireless network interface, a keyboard, and an input and output interface for input and output, and the server 600 may also include other components for implementing device functions, which will not be described in detail here.
[0168] In an exemplary embodiment, a computer-readable storage medium is further provided, in which at least one program code is stored. The at least one program code is loaded and executed by a processor to enable a computer to implement any of the above-mentioned application access methods.
[0169] Optionally, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc (CD-ROM), a magnetic tape, a floppy disk, an optical data storage device, etc.
[0170] In an exemplary embodiment, a computer program or a computer program product is also provided. The computer program or the computer program product stores at least one computer instruction, and the at least one computer instruction is loaded and executed by a processor to enable a computer to implement any of the above-mentioned application access methods.
[0171] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0172] It should be understood that the "plurality" mentioned in this article refers to two or more. "And / or" describes the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship.
[0173] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0174] The above description is only an exemplary embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the principles of the present application shall be included in the protection scope of the present application.
Claims
1. An application access method, characterized in that: The method is applied to a computer device, the computer device is in communication connection with an identity authentication server and an application server, and the method comprises: The computer device obtains a login request and sends the login request to the identity authentication server, wherein the login request includes a login account and a login password of a target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system; The computer device receives the identity credential returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, wherein the identity credential is used to indicate the identity information of the target user; The computer device sends the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application; The computer device receives the authorization access information returned by the application server when it is determined that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
2. The method according to claim 1, characterized in that The computer device includes an operating system authentication module and a local security authorization module; The computer device obtains a login request and sends the login request to the identity authentication server, including: The operating system authentication module obtains the login request and sends the login request to the local security authorization module; The local security authorization module receives the login request and sends the login request to the identity authentication server; The computer device receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, including: The local security authorization module receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and sends authentication success information to the operating system authentication module according to the identity credentials, wherein the authentication success information is used to indicate that the target user can log in to the operating system; The operating system authentication module receives the authentication success information and logs into the operating system.
3. The method according to claim 1, characterized in that The computer device includes a browser; The computer device sending the identity credential to the application server includes: The browser sends the identity credential to the application server; The computer device receives the authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information, including: The browser receives the authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
4. The method according to claim 3, characterized in that Before the browser sends the identity credential to the application server, the method further includes: The browser sends an acquisition request to the local security authorization module of the computer device, wherein the acquisition request is used to acquire the identity credential; The browser receives the identity credential sent by the local security authorization module.
5. The method according to claim 4, characterized in that The method further comprises: The local security authorization module stores the identity credentials.
6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: The computer device receives the target information returned by the identity authentication server when determining that the target user cannot log in to the operating system, and displays the target information, where the target information is used to indicate that the target user cannot log in to the operating system.
7. The method according to any one of claims 1 to 5, characterized in that: The method also includes: The computer device receives the access prohibition information returned by the application server when determining that the target user cannot access the target application, and displays the access prohibition information, where the access prohibition information is used to indicate that the target user cannot access the target application.
8. An application access system, characterized in that: The system includes a computer device, an identity authentication server and an application server; wherein, The computer device is used to obtain a login request and send the login request to the identity authentication server, wherein the login request includes a login account and a login password of a target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system; The identity authentication server is used to send an identity credential to the computer device when determining that the target user can log in to the operating system, wherein the identity credential is used to indicate the identity information of the target user; The computer device is further used to receive the identity credential and log into the operating system; The computer device is further used to send the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application; The application server is used to send authorization access information to the computer device when determining that the target user can access the target application, wherein the authorization access information is used to indicate that the target user can access the target application; The computer device is further used to receive the authorized access information and display the interface corresponding to the target application according to the authorized access information.
9. A computer device, characterized in that: The computer device includes a processor and a memory, wherein at least one program code is stored in the memory, and the at least one program code is loaded and executed by the processor, so that the computer device implements the application access method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores at least one program code, and the at least one program code is loaded and executed by a processor so that a computer implements the application access method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Request response method and device, electronic device and storage medium
CN112632521A
Single sign-on method and device, electronic equipment and storage medium
CN116208376A
Access control method and device, desktop operating system login platform and processor
CN116756776A
Interoperable credential gathering and access modularity
US20050091213A1