Application access method, system, device and computer readable storage medium
By working in concert with computer equipment, identity authentication servers, and application servers, and using identity credentials to authenticate the target user, the problem of long access time, low efficiency, and low success rate in existing technologies for accessing applications is solved, and fast and convenient application access is achieved.
Patent Information
- Application Number
- CN202411265566.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-10
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-09-10
AI Technical Summary
In existing technologies, users need to remember the passwords for the operating system and applications, resulting in long access times, low efficiency, and low success rates when accessing applications.
By working in conjunction with computer equipment, identity authentication servers, and application servers, identity credentials are used to authenticate the target user. The identity credentials are sent directly to the application server to determine whether the target application can be accessed, eliminating the need to enter the login account and password for the target application.
It saves time accessing applications, improves access efficiency, avoids access failures caused by users forgetting their passwords, and increases the access success rate.
Smart Images

Figure CN119989310B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer technology, and in particular to an application access method, system, device, and computer-readable storage medium. Background Art
[0002] With the continuous development of computer technology, the importance of computer storage content is also increasing. More and more people are setting login passwords for their computer operating systems. When a user wants to access a target application on a computer device, they must first enter the operating system login password, log in to the operating system, and then enter the correct access password before accessing the target application.
[0003] This requires the user to remember the operating system login password and the target application access password, which places high demands on the user, making it take longer to access the application and reducing access efficiency. When the user forgets the operating system login password or the target application access password, the user cannot access the target application, thereby reducing the access success rate of the target application. Summary of the Invention
[0004] The embodiments of the present application provide an application access method, system, device, and computer-readable storage medium, which can be used to solve the problems of long application access time, low access efficiency, and low access success rate in related technologies. The technical solution is as follows.
[0005] In one aspect, an embodiment of the present application provides an application access method, which is applied to a computer device, wherein the computer device is in communication with an identity authentication server and an application server, and the method includes:
[0006] The computer device obtains a login request and sends the login request to the identity authentication server, wherein the login request includes a login account and a login password of a target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system;
[0007] The computer device receives the identity credential returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, wherein the identity credential is used to indicate the identity information of the target user;
[0008] The computer device sends the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application;
[0009] The computer device receives the authorization access information returned by the application server when it is determined that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
[0010] In one possible implementation, the computer device includes an operating system authentication module and a local security authorization module;
[0011] The computer device obtains a login request and sends the login request to the identity authentication server, including:
[0012] The operating system authentication module obtains the login request and sends the login request to the local security authorization module;
[0013] The local security authorization module receives the login request and sends the login request to the identity authentication server;
[0014] The computer device receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system, including:
[0015] The local security authorization module receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and sends authentication success information to the operating system authentication module based on the identity credentials, wherein the authentication success information is used to indicate that the target user can log in to the operating system;
[0016] The operating system authentication module receives the authentication success information and logs into the operating system.
[0017] In one possible implementation, the computer device includes a browser;
[0018] The computer device sending the identity credential to the application server includes:
[0019] The browser sends the identity credential to the application server;
[0020] The computer device receives authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information, including:
[0021] The browser receives the authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
[0022] In a possible implementation, before the browser sends the identity credential to the application server, the method further includes:
[0023] The browser sends an acquisition request to the local security authorization module of the computer device, wherein the acquisition request is used to acquire the identity credential;
[0024] The browser receives the identity credential sent by the local security authorization module.
[0025] In a possible implementation, the method further includes:
[0026] The local security authorization module stores the identity credentials.
[0027] In a possible implementation, the method further includes:
[0028] The computer device receives target information returned by the identity authentication server when determining that the target user cannot log in to the operating system, and displays the target information, where the target information is used to indicate that the target user cannot log in to the operating system.
[0029] In one possible implementation, the method further includes:
[0030] The computer device receives access prohibition information returned by the application server when determining that the target user cannot access the target application, and displays the access prohibition information, where the access prohibition information is used to indicate that the target user cannot access the target application.
[0031] On the other hand, an embodiment of the present application provides an application access system, which includes a computer device, an identity authentication server, and an application server, wherein:
[0032] The computer device is configured to obtain a login request and send the login request to the identity authentication server, wherein the login request includes a login account and a login password of a target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system;
[0033] The identity authentication server is configured to send an identity credential to the computer device when determining that the target user can log in to the operating system, wherein the identity credential is used to indicate identity information of the target user;
[0034] The computer device is further configured to receive the identity credentials and log into the operating system;
[0035] The computer device is further configured to send the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application;
[0036] The application server is configured to, if determining that the target user can access the target application, send authorization access information to the computer device, wherein the authorization access information is used to indicate that the target user can access the target application;
[0037] The computer device is further configured to receive the authorized access information and display an interface corresponding to the target application according to the authorized access information.
[0038] On the other hand, an embodiment of the present application provides a computer device, which includes a processor and a memory, wherein the memory stores at least one program code, and the at least one program code is loaded and executed by the processor so that the computer device implements any of the above-mentioned application access methods.
[0039] On the other hand, a computer-readable storage medium is provided, in which at least one program code is stored. The at least one program code is loaded and executed by a processor to enable a computer to implement any of the above-mentioned application access methods.
[0040] On the other hand, a computer program or a computer program product is also provided, wherein the computer program or the computer program product stores at least one computer instruction, and the at least one computer instruction is loaded and executed by a processor to enable a computer to implement any of the above-mentioned application access methods.
[0041] The technical solutions provided by the embodiments of the present application bring at least the following beneficial effects:
[0042] The technical solution provided by the embodiment of the present application is that after the target user logs into the operating system, if the target user still wants to access the target application, the target user's identity credentials are directly sent to the application server, so that the application server returns the authorization access information when it determines that the target user can access the target application, thereby displaying the interface corresponding to the target application to enable the target user to access the target application. In this way, when accessing the target application, the target user does not need to enter the login account and login password of the target application, which saves the time required to access the application and improves the access efficiency of the target application. Moreover, since there is no need to enter the login account and login password of the target application, there is no need for the target user to remember the login account and login password, thereby avoiding the situation where the target user forgets the login password of the target application and the target user cannot access the target application, thereby improving the access success rate of the target application. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0044] Figure 1 This is a schematic diagram of the structure of an application access system provided by an embodiment of the present application;
[0045] Figure 2 This is a flowchart of an application access method provided by an embodiment of the present application;
[0046] Figure 3 This is a flowchart of an application access method provided by an embodiment of the present application;
[0047] Figure 4 This is a flowchart of an application access method provided by an embodiment of the present application;
[0048] Figure 5 This is a schematic diagram of the structure of a terminal device provided in an embodiment of the present application;
[0049] Figure 6 This is a structural diagram of a server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0050] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0051] Figure 1 This is a schematic diagram of the structure of an application access system provided by an embodiment of the present application. Figure 1 As shown, the system includes: a computer device 101 , an identity authentication server 102 and an application server 103 .
[0052] Among them, the computer device 101 includes an operating system authentication module 104, a local security authorization module 105 and a browser 106. Optionally, the operating system authentication module is an authentication module developed based on the Windows Credential Provider (a credential provider for an operating system) standard, and the operating system authentication module can perform identity authentication through the local security authorization module 105 (also known as the Local Security Authority Subsystem Service, LSASS) of Windows (an operating system). The computer device 101 is pre-configured with kbr5.conf / kbr5.ini (a configuration file), and the configuration includes the address of the identity authentication server. The browser 106 is configured to use the Windows IWA authentication mode (an authentication mode for an operating system) and needs to use a unified authentication internal domain name range. Exemplarily, the browser can be a Chrome browser (a browser), a Firefox browser (a browser), or an Edge browser (a browser), and this embodiment of the application does not limit this. For example, the internal domain name range configured in the Chrome browser is "example.com".
[0053] The computer device 101 and the identity authentication server 102 are communicatively connected via a wired network or a wireless network, and the computer device 101 and the application server 103 are communicatively connected via a wired network or a wireless network.
[0054] Optionally, the computer device 101 is any electronic device that can interact with a user through one or more methods such as a keyboard, a touchpad, a remote control, voice interaction, or a handwriting device. For example, a PC (Personal Computer), a mobile phone, a smart phone, a PDA (Personal Digital Assistant), a wearable device, a PPC (Pocket PC), a tablet computer, a smart car computer, a smart TV, a smart speaker, a smart watch, etc.
[0055] Computer device 101 may generally refer to one of multiple computer devices. This embodiment uses computer device 101 as an example. Those skilled in the art will appreciate that the number of computer devices 101 may be greater or lesser. For example, there may be only one computer device 101, or there may be dozens, hundreds, or even more computer devices 101. This embodiment of the application does not limit the number or type of computer devices 101.
[0056] The identity authentication server 102 can be a single server, a server cluster consisting of multiple servers, or any one of a cloud computing platform and a virtualization center, and this embodiment of the application does not limit this. The application server 103 can be a single server, a server cluster consisting of multiple servers, or any one of a cloud computing platform and a virtualization center, and this embodiment of the application does not limit this.
[0057] Those skilled in the art should understand that the above-mentioned computer device 101, identity authentication server 102 and application server 103 are merely examples, and other existing or future computer devices or servers, if applicable to this application, should also be included in the scope of protection of this application and are included here by reference.
[0058] The present application embodiment provides an application access method, which can be applied to the above Figure 1 The implementation environment shown is Figure 2 As an example, the flowchart of an application access method provided in the embodiment of the present application is shown in FIG. Figure 1 The interaction between the computer device 101, the identity authentication server 102 and the application server 103 is realized. Figure 2 As shown, the method includes the following steps:
[0059] In step 201, the computer device obtains a login request and sends the login request to the identity authentication server.
[0060] In one possible implementation, a computer device includes an operating system authentication module and a local security authorization module. The process of the computer device receiving a login request and sending the login request to an identity authentication server includes: the operating system authentication module receiving the login request and sending the login request to the local security authorization module; and the local security authorization module receiving the login request and sending the login request to the identity authentication server.
[0061] The login request includes the login account and login password of the target user who requests to log in to the operating system. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system.
[0062] Optionally, before receiving a login request, the operating system authentication module needs to first obtain the target user's login account and the target user's login password. The present embodiment of the application does not limit the method for obtaining the target user's login account and the target user's login password. Optionally, the process of obtaining the target user's login account and the target user's login password includes: displaying an account box and a password box in response to turning on the computer device; obtaining the target user's login account based on the account box, and obtaining the target user's login password based on the password box.
[0063] After obtaining the target user's login account and login password, in response to the operation of logging into the computer device, the operating system authentication module generates a login request based on the target user's login account and login password, and the login request includes the target user's login account and login password requesting to log into the operating system.
[0064] Optionally, the computer device includes a power-on control, and receives an operation to turn on the computer device in response to a triggering operation on the power-on control.
[0065] The process of obtaining the target user's login account from the account box includes: responding to an input operation in the account box, using the content entered in the account box as the target user's login account. Alternatively, responding to a trigger operation on the account box, displaying candidate accounts, and responding to a trigger operation on any of the candidate accounts, determining any of the candidate accounts as the target user's login account.
[0066] According to the password box, the process of obtaining the target user's login password includes: responding to an input operation in the password box, using the content input in the password box as the target user's login password.
[0067] In one possible implementation, the operating system authentication module cannot directly contact the identity authentication server. Therefore, after receiving the login request, the operating system authentication module sends the login request to the local security authorization module, so that the local security authorization module sends the login request to the identity authentication server.
[0068] After receiving the login request from the operating system authentication module, the local security authorization module sends the login request to the identity authentication server. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system. The identity authentication server is the identity authentication server corresponding to the target group. The target group can be an enterprise, a company within an enterprise, a department within a company, or other groups. This embodiment of the application does not limit the target group.
[0069] The local security authorization module may send a login request to the identity authentication server immediately after receiving the login request, or may wait for a target duration before sending the login request to the identity authentication server. The embodiments of the present application do not limit the timing of when the local security authorization module sends the login request to the identity authentication server. The target duration may be set based on experience or adjusted according to the implementation environment, and the embodiments of the present application do not limit this either.
[0070] In step 202, the identity authentication server receives the login request and determines whether the target user can log in to the operating system.
[0071] In a possible implementation, the identity authentication server stores the object accounts of the various objects included in the target group, and the corresponding relationship between the object accounts of the various objects and the object passwords of the various objects.
[0072] Optionally, after receiving the login request sent by the local security authorization module, the identity authentication server parses the login request to obtain the login account and login password of the target user, and then determines whether the target user can log in to the operating system based on the login account and login password of the target user.
[0073] If the login account belongs to the target group and the login account and login password match, the target user is determined to be allowed to log in to the operating system. If the login account does not belong to the target group, the target user is determined to be unable to log in to the operating system. If the login account belongs to the target group and the login account and login password do not match, the target user is determined to be unable to log in to the operating system.
[0074] Optionally, the process of determining whether the login account belongs to the target group includes: if the object accounts stored in the identity authentication server include the login account, determining that the login account belongs to the target group; if the object accounts stored in the identity authentication server do not include the login account, determining that the login account does not belong to the target group.
[0075] The process of determining whether the login account and the login password match includes: obtaining the object password corresponding to the login account; if the login password and the object password match, determining that the login account and the login password match; if the login password and the object password do not match, determining that the login account and the login password do not match.
[0076] The matching of the login password and the object password means that the login password and the object password are the same, or the contents corresponding to the login password and the object password are the same.
[0077] In step 203, the identity authentication server sends the identity credentials to the computer device if it is determined that the target user can log in to the operating system.
[0078] The identity certificate is used to indicate the identity information of the target user, that is, the identity certificate is used to indicate that the target user is included in the target group and that the target user can successfully log in to the operating system.
[0079] In one possible implementation, upon determining that the target user is authorized to log into the operating system, the identity authentication server sends the identity credentials to the local security authorization module. The local security authorization module receives the identity credentials and sends a successful authentication message to the operating system authentication module. The operating system authentication module receives the successful authentication message and logs into the operating system.
[0080] Optionally, the local security authorization module may immediately send a successful authentication message to the operating system authentication module after receiving the identity credentials, or may wait for a reference time before sending the successful authentication message to the operating system authentication module. The present embodiment of the application does not limit the timing of when the local security authorization module sends the successful authentication message to the operating system authentication module. The reference time is set based on experience or adjusted according to the implementation environment, and the present embodiment of the application does not limit this. For example, the reference time is 2 seconds.
[0081] Optionally, after receiving the identity credential, the local security authorization module may further store the identity credential so that the browser can subsequently obtain the identity credential from the local security authorization module.
[0082] In another possible implementation, when the identity authentication server determines that the target user is not allowed to log in to the operating system, the identity authentication server sends target information to the computer device, where the target information indicates that the target user is not allowed to log in to the operating system. The computer device receives the target information returned by the identity authentication server when the target user is determined to be not allowed to log in to the operating system, and displays the target information.
[0083] Optionally, the identity authentication server sends the target information to the local security authorization module, the local security authorization module receives the target information and sends the target information to the operating system authentication module, the operating system authentication module receives the target information and displays the target information.
[0084] There are two reasons why the target user cannot log in to the operating system. The first is that the login account does not belong to the target group, and the second is that the login account belongs to the target group, but the login account and login password do not match. When the target user cannot log in to the operating system because the login account does not belong to the target group, the target information sent by the identity authentication server is the first information. The first information means that the target user cannot log in to the operating system because the login account does not belong to the target group. When the target user cannot log in to the operating system because the login account belongs to the target group, but the login account and login password do not match, the target information sent by the identity authentication server is the second information. The second information means that the target user cannot log in to the operating system because the login account and login password do not match.
[0085] In step 204 , the computer device receives the identity credentials and logs into the operating system.
[0086] In one possible implementation, the local security authorization module receives the identity credentials and sends a successful authentication message to the operating system authentication module. After receiving the successful authentication message, the operating system authentication module logs into the operating system. The method of logging into the operating system includes, but is not limited to, displaying the desktop of the computer device.
[0087] In step 205 , the computer device sends the identity credentials to the application server.
[0088] In one possible implementation, after the desktop of the computer device is displayed, browser-related information is displayed on the desktop of the computer device. The browser-related information may be the name of the browser, the icon of the browser, or any other information of the browser. The embodiment of the present application does not limit the browser-related information.
[0089] When the target user wants to access the target application, the target user triggers the relevant information of the browser, and the computer device displays the homepage of the browser, which displays a search box and a search control. The target user can enter the address of the target application in the search box, and the browser obtains the address of the target application. In response to the target user's triggering operation on the search control, the computer device sends the target user's identity credentials to the application server. The target user's identity credentials are used by the application server to determine whether the target user can access the target application. The application server is the server corresponding to the target application, that is, the application server is the server that provides background support for the target application. Optionally, the computer device includes a browser, and the browser sends the target user's identity credentials to the application server.
[0090] In a possible implementation, before the browser sends the identity credential to the application server, the browser needs to first obtain the identity credential. Optionally, the browser obtains the identity credential from a local security authorization module.
[0091] The process of the browser obtaining the identity credential from the local security authorization module includes: the browser sends a request to the local security authorization module to obtain the identity credential. The local security authorization module receives the request and returns the identity credential to the browser, so that the browser obtains the identity credential.
[0092] In step 206 , the application server receives the identity credentials and determines whether the target user can access the target application based on the identity credentials.
[0093] In one possible implementation, an application server stores object credentials that allow access to an object of a target application. After receiving the identity credentials, the application server determines, based on the identity credentials, whether a target user can access the target application. This includes: if the object credentials stored in the application server include the identity credentials, determining that the target user can access the target application. If the object credentials stored in the application server do not include the identity credentials, determining that the target user cannot access the target application.
[0094] In step 207 , when determining that the target user can access the target application, the application server sends authorization access information to the computer device.
[0095] In one possible implementation, after determining whether the target user can access the target application in step 206, if the target user can access the target application, authorization access information is sent to the computer device. The authorization access information can be any information indicating that the target user can access the target application, and this embodiment of the application is not limited thereto. Optionally, the authorization access information is sent to the browser.
[0096] In another possible implementation, when determining that the target user cannot access the target application, the application server sends access prohibition information to the computer device, where the access prohibition information is used to indicate that the target user cannot access the target application. Optionally, the application server sends access prohibition information to the browser.
[0097] In step 208, the computer device receives the authorized access information and displays the interface corresponding to the target application according to the authorized access information.
[0098] In one possible implementation, after receiving the authorization access information sent by the application server, the computer device displays the interface corresponding to the target application according to the authorization access information. Optionally, after receiving the authorization access information sent by the application server, the browser displays the interface corresponding to the target application according to the authorization access information.
[0099] In another possible implementation, after receiving the access prohibition information sent by the application server, the computer device displays the access prohibition information. Optionally, after receiving the access prohibition information sent by the application server, the browser displays the access prohibition information.
[0100] After the target user logs into the operating system, if the target user still wants to access the target application, the above method directly sends the target user's identity credentials to the application server, so that the application server returns the authorization access information when it determines that the target user can access the target application, thereby displaying the interface corresponding to the target application to enable the target user to access the target application. In this way, when accessing the target application, the target user does not need to enter the login account and login password of the target application, which saves the time required to access the application and improves the access efficiency of the target application. Moreover, since there is no need to enter the login account and login password of the target application, there is no need for the target user to remember the login account and login password, thereby avoiding the situation where the target user forgets the login password of the target application and is unable to access the target application, thereby improving the access success rate of the target application.
[0101] Figure 3 This is a flowchart of an application access method provided in an embodiment of the present application. The method is executed by a computer device 101 and includes the following steps.
[0102] In step 301, the computer device obtains a login request and sends the login request to the identity authentication server. The login request includes the login account and login password of the target user requesting to log in to the operating system. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system.
[0103] In a possible implementation, the process of the computer device obtaining a login request and sending the login request to the identity authentication server has been described in the above step 201 and will not be repeated here.
[0104] In step 302, the computer device receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and logs in to the operating system. The identity credentials are used to indicate the identity information of the target user.
[0105] In one possible implementation, the computer device receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system. The process of logging in to the operating system has been described in the above step 204 and will not be repeated here.
[0106] In step 303, the computer device sends the identity credential to the application server, and the identity credential is used by the application server to determine whether the target user can access the target application.
[0107] In a possible implementation, the process of the computer device sending the identity credentials to the application server has been described in the above step 205 and will not be repeated here.
[0108] In step 304 , the computer device receives the authorization access information returned by the application server when it is determined that the target user can access the target application, and displays the interface corresponding to the target application according to the authorization access information.
[0109] In one possible implementation, the computer device receives the authorization access information returned by the application server when it determines that the target user can access the target application. The process of displaying the interface corresponding to the target application has been described in the above step 208 and will not be repeated here.
[0110] The embodiment of the present application provides an application access system, which includes a computer device, an identity authentication server and an application server, wherein:
[0111] The computer device is used to obtain a login request and send the login request to the identity authentication server. The login request includes the login account and login password of the target user requesting to log in to the operating system. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system;
[0112] The identity authentication server is used to send an identity credential to the computer device when it is determined that the target user can log in to the operating system. The identity credential is used to indicate the identity information of the target user;
[0113] Computer equipment is also used to receive identity credentials and log into the operating system;
[0114] The computer device is further configured to send an identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application;
[0115] The application server is configured to send authorization access information to the computer device when determining that the target user can access the target application, wherein the authorization access information is used to indicate that the target user can access the target application;
[0116] The computer device is further used to receive authorized access information and display the interface corresponding to the target application according to the authorized access information.
[0117] In one possible implementation, the computer device includes an operating system authentication module and a local security authorization module;
[0118] The operating system authentication module is used to obtain the login request and send the login request to the local security authorization module;
[0119] The local security authorization module is used to receive login requests and send login requests to the identity authentication server;
[0120] The local security authorization module is further configured to receive the identity credentials returned by the identity authentication server when it is determined that the target user can log in to the operating system, and send an authentication success message to the operating system authentication module based on the identity credentials, wherein the authentication success message is used to indicate that the target user can log in to the operating system;
[0121] The operating system authentication module is also used to receive authentication success information and log in to the operating system.
[0122] In one possible implementation, the computer device includes a browser;
[0123] The browser sends the identity credentials to the application server;
[0124] The browser is further configured to receive authorization access information returned by the application server when it is determined that the target user can access the target application, and display the interface corresponding to the target application according to the authorization access information.
[0125] In a possible implementation, the browser is further configured to send an acquisition request to a local security authorization module of the computer device, where the acquisition request is used to acquire the identity credential;
[0126] The browser is also used to receive identity credentials sent by the local security authorization module.
[0127] In a possible implementation, the local security authorization module is also used to store identity credentials.
[0128] In a possible implementation, the computer device is further configured to receive target information returned by the identity authentication server when it is determined that the target user cannot log in to the operating system, and display the target information, where the target information is used to indicate that the target user cannot log in to the operating system.
[0129] In a possible implementation, the computer device is further configured to receive access prohibition information returned by the application server when it is determined that the target user cannot access the target application, and display the access prohibition information, where the access prohibition information is used to indicate that the target user cannot access the target application.
[0130] Figure 4 A flowchart of an application access method provided in an embodiment of the present application is shown in FIG. Figure 4 As shown, the method includes the following steps.
[0131] 1. The target user logs into the operating system.
[0132] 2. The operating system authentication module generates a login request.
[0133] The login request includes the login account and login password of the target user who requests to log in to the operating system.
[0134] 3. The operating system authentication module sends a login request to the local security authorization module.
[0135] 4. The local security authorization module sends a login request to the identity authentication server.
[0136] 5. The identity authentication server determines whether the target user can log in to the operating system.
[0137] 6. When the identity authentication server determines that the target user can log in to the operating system, it sends the identity credentials to the local security authorization module.
[0138] The identity credential is used to indicate the identity information of the target user.
[0139] 7. The local security authorization module sends authentication success information to the operating system authentication module.
[0140] The local security authorization module stores identity credentials.
[0141] 8. The operating system authentication module logs into the operating system.
[0142] 9. The target user logs in to the target application.
[0143] 10. The browser sends a request to the local security authorization module.
[0144] 11. The local security authorization module sends the user credentials to the browser.
[0145] 12. The browser sends the user credentials to the application server.
[0146] 13. The application server determines whether the target user can access the target application.
[0147] 14. When the application server determines that the target user can access the target application, it sends authorization access information to the browser.
[0148] 15. The browser displays the interface corresponding to the target application.
[0149] The computer device may be a terminal device, Figure 5 The following is a block diagram of a terminal device 500 provided in accordance with an exemplary embodiment of the present application. The terminal device 500 may be any electronic device capable of human-computer interaction with a user through one or more methods, such as a keyboard, touchpad, remote control, voice interaction, or handwriting device. Examples include a PC (Personal Computer), mobile phone, smartphone, PDA (Personal Digital Assistant), wearable device, Pocket PC (PPC), tablet computer, smart car computer, smart TV, smart speaker, smart watch, and the like.
[0150] Typically, the terminal device 500 includes a processor 501 and a memory 502 .
[0151] The processor 501 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 501 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 501 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 501 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 501 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0152] The memory 502 may include one or more computer-readable storage media, which may be non-transitory. The memory 502 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 502 is used to store at least one instruction, which is executed by the processor 501 to implement the application access method provided in the method embodiment of the present application.
[0153] In some embodiments, terminal device 500 may optionally include a peripheral device interface 503 and at least one peripheral device. Processor 501, memory 502, and peripheral device interface 503 may be connected via a bus or signal lines. Each peripheral device may be connected to peripheral device interface 503 via a bus, signal lines, or circuit boards. Specifically, the peripheral device may include at least one of a radio frequency circuit 504, a display screen 505, a camera assembly 506, an audio circuit 507, and a power supply 508.
[0154] The peripheral device interface 503 can be used to connect at least one I / O (Input / Output)-related peripheral device to the processor 501 and the memory 502. In some embodiments, the processor 501, the memory 502, and the peripheral device interface 503 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 501, the memory 502, and the peripheral device interface 503 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.
[0155] The radio frequency circuit 504 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 504 communicates with communication networks and other communication devices via electromagnetic signals. The radio frequency circuit 504 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals into electrical signals. Optionally, the radio frequency circuit 504 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The radio frequency circuit 504 can communicate with other terminal devices via at least one wireless communication protocol. Such wireless communication protocols include, but are not limited to, the World Wide Web, a metropolitan area network, an intranet, various generations of mobile communication networks (2G, 3G, 4G, and 5G), a wireless local area network, and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 504 may also include circuits related to NFC (Near Field Communication), which is not limited in this application.
[0156] The display screen 505 is used to display a user interface (UI). This UI may include graphics, text, icons, videos, or any combination thereof. When the display screen 505 is a touch screen, it is also capable of collecting touch signals on or above the surface of the display screen 505. These touch signals can be input as control signals to the processor 501 for processing. In this case, the display screen 505 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there can be one display screen 505, located on the front panel of the terminal device 500. In other embodiments, there can be at least two display screens 505, located on different surfaces of the terminal device 500 or in a foldable design. In other embodiments, the display screen 505 can be a flexible display, located on a curved or foldable surface of the terminal device 500. Furthermore, the display screen 505 can be configured as a non-rectangular irregular shape, i.e., a special-shaped screen. The display screen 505 can be made of materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).
[0157] The camera assembly 506 is used to capture images or videos. Optionally, the camera assembly 506 includes a front camera and a rear camera. Typically, the front camera is arranged on the front panel of the terminal device 500, and the rear camera is arranged on the back of the terminal device 500. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth of field camera, a wide-angle camera, and a telephoto camera, so as to realize the fusion of the main camera and the depth of field camera to realize the background blur function, the fusion of the main camera and the wide-angle camera to realize panoramic shooting and VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera assembly 506 may also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation at different color temperatures.
[0158] The audio circuit 507 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals to be input into the processor 501 for processing, or input into the radio frequency circuit 504 to achieve voice communication. For the purpose of stereo sound collection or noise reduction, there can be multiple microphones, which are respectively arranged in different parts of the terminal device 500. The microphone can also be an array microphone or an omnidirectional collection microphone. The speaker is used to convert the electrical signals from the processor 501 or the radio frequency circuit 504 into sound waves. The speaker can be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signals into sound waves audible to humans, but also convert the electrical signals into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio circuit 507 may also include a headphone jack.
[0159] Power supply 508 is used to power various components in terminal device 500. Power supply 508 can be AC power, DC power, a disposable battery, or a rechargeable battery. When power supply 508 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged via a wired line, while a wireless rechargeable battery is a battery that is charged via a wireless coil. The rechargeable battery can also be used to support fast charging technology.
[0160] In some embodiments, the terminal device 500 further includes one or more sensors 509 , including but not limited to: an acceleration sensor 510 , a gyroscope sensor 511 , a pressure sensor 512 , an optical sensor 513 , and a proximity sensor 514 .
[0161] The accelerometer 510 can detect the magnitude of acceleration along the three coordinate axes of the coordinate system established by the terminal device 500. For example, the accelerometer 510 can be used to detect the components of gravity acceleration along the three coordinate axes. The processor 501 can control the display screen 505 to display the user interface in a landscape or portrait view based on the gravity acceleration signal collected by the accelerometer 510. The accelerometer 510 can also be used to collect game or user motion data.
[0162] The gyroscope sensor 511 can detect the body orientation and rotation angle of the terminal device 500. The gyroscope sensor 511 can work with the acceleration sensor 510 to collect the user's 3D movements of the terminal device 500. Based on the data collected by the gyroscope sensor 511, the processor 501 can implement the following functions: motion sensing (such as changing the UI based on the user's tilt operation), image stabilization during shooting, game control, and inertial navigation.
[0163] The pressure sensor 512 can be set on the side frame of the terminal device 500 and / or the lower layer of the display screen 505. When the pressure sensor 512 is set on the side frame of the terminal device 500, it can detect the user's grip signal of the terminal device 500, and the processor 501 performs left and right hand recognition or shortcut operations based on the grip signal collected by the pressure sensor 512. When the pressure sensor 512 is set on the lower layer of the display screen 505, the processor 501 controls the operable controls on the UI interface based on the user's pressure operation on the display screen 505. The operable controls include at least one of a button control, a scroll bar control, an icon control, and a menu control.
[0164] The optical sensor 513 is used to detect ambient light intensity. In one embodiment, the processor 501 can control the display brightness of the display screen 505 based on the ambient light intensity detected by the optical sensor 513. Specifically, when the ambient light intensity is high, the display brightness of the display screen 505 is increased; when the ambient light intensity is low, the display brightness of the display screen 505 is decreased. In another embodiment, the processor 501 can also dynamically adjust the shooting parameters of the camera assembly 506 based on the ambient light intensity detected by the optical sensor 513.
[0165] The proximity sensor 514, also known as a distance sensor, is typically located on the front panel of the terminal device 500. The proximity sensor 514 is used to detect the distance between the user and the front of the terminal device 500. In one embodiment, when the proximity sensor 514 detects that the distance between the user and the front of the terminal device 500 is gradually decreasing, the processor 501 controls the display screen 505 to switch from the screen-on state to the screen-off state. When the proximity sensor 514 detects that the distance between the user and the front of the terminal device 500 is gradually increasing, the processor 501 controls the display screen 505 to switch from the screen-off state to the screen-on state.
[0166] Those skilled in the art will understand that Figure 5 The structure shown in the figure does not constitute a limitation on the terminal device 500, and the terminal device 500 may include more or fewer components than shown in the figure, or combine certain components, or adopt a different component arrangement.
[0167] The computer device may be a server, Figure 6This is a schematic diagram of the structure of the server provided in the embodiment of the present application. The server 600 may have relatively large differences due to different configurations or performances, and may include one or more processors (Central Processing Units, CPU) 601 and one or more memories 602, wherein the one or more memories 602 store at least one program code, and the at least one program code is loaded and executed by the one or more processors 601 to implement the application access method provided by the above-mentioned various method embodiments. Of course, the server 600 may also have components such as a wired or wireless network interface, a keyboard, and an input and output interface for input and output. The server 600 may also include other components for implementing device functions, which will not be described in detail here.
[0168] In an exemplary embodiment, a computer-readable storage medium is further provided. The storage medium stores at least one program code. The at least one program code is loaded and executed by a processor to enable a computer to implement any of the above-mentioned application access methods.
[0169] Optionally, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc (CD-ROM), a magnetic tape, a floppy disk, an optical data storage device, or the like.
[0170] In an exemplary embodiment, a computer program or a computer program product is further provided. The computer program or the computer program product stores at least one computer instruction, and the at least one computer instruction is loaded and executed by a processor to enable a computer to implement any of the above-mentioned application access methods.
[0171] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0172] It should be understood that the term "plurality" used herein refers to two or more. "And / or" describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. The character " / " generally indicates an "or" relationship between the associated objects.
[0173] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0174] The above description is merely an exemplary embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall be included in the scope of protection of the present application.
Claims
1. An application access method, characterized in that: The method is applied to a computer device, the computer device being in communication with an identity authentication server and an application server, the computer device including an operating system authentication module, a local security authorization module, and a browser, the browser being configured with an internal domain name range for unified authentication, and the method comprising: The operating system authentication module obtains a login request and sends the login request to the local security authorization module; The local security authorization module receives the login request and sends the login request to the identity authentication server, where the identity authentication server is the identity authentication server corresponding to the target group. The login request includes the login account and login password of the target user requesting to log in to the operating system. The login request is used by the identity authentication server to determine whether the target user can log in to the operating system; The local security authorization module receives the identity credentials returned by the identity authentication server when determining that the target user can log in to the operating system, and sends authentication success information to the operating system authentication module based on the identity credentials, wherein the authentication success information is used to indicate that the target user can log in to the operating system; the operating system authentication module receives the authentication success information and logs in to the operating system, wherein the identity credentials are used to indicate that the target user is included in the target group and that the target user can successfully log in to the operating system; The browser sends the identity credential to the application server, where the identity credential is used by the application server to determine whether the target user can access the target application; The browser receives the authorization access information returned by the application server when determining that the target user can access the target application, and displays an interface corresponding to the target application according to the authorization access information.
2. The method according to claim 1, characterized in that Before the browser sends the identity credential to the application server, the method further includes: The browser sends an acquisition request to the local security authorization module of the computer device, wherein the acquisition request is used to acquire the identity credential; The browser receives the identity credential sent by the local security authorization module.
3. The method according to claim 2, characterized in that The method further comprises: The local security authorization module stores the identity credentials.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: The computer device receives target information returned by the identity authentication server when determining that the target user cannot log in to the operating system, and displays the target information, where the target information is used to indicate that the target user cannot log in to the operating system.
5. The method according to any one of claims 1 to 3, characterized in that: The method also includes: The computer device receives access prohibition information returned by the application server when determining that the target user cannot access the target application, and displays the access prohibition information, where the access prohibition information is used to indicate that the target user cannot access the target application.
6. An application access system, characterized in that: The system includes a computer device, an identity authentication server and an application server, wherein the computer device is in communication with the identity authentication server and the application server, and the computer device includes an operating system authentication module, a local security authorization module and a browser, wherein the browser is configured with an internal domain name range of unified authentication; wherein, The computer device includes an operating system authentication module, which is used to obtain a login request and send the login request to the local security authorization module; The computer device includes a local security authorization module, which is used to receive the login request and send the login request to the identity authentication server, where the identity authentication server is the identity authentication server corresponding to the target group, wherein the login request includes the login account and login password of the target user requesting to log in to the operating system, and the login request is used by the identity authentication server to determine whether the target user can log in to the operating system; The identity authentication server is configured to send an identity credential to the computer device when determining that the target user can log in to the operating system, wherein the identity credential is used to indicate identity information of the target user; The local security authorization module included in the computer device is further used to receive the identity credential and send authentication success information to the operating system authentication module based on the identity credential, wherein the authentication success information is used to indicate that the target user can log in to the operating system; The computer device includes an operating system authentication module, which is used to receive the authentication success information and log in to the operating system, wherein the identity credential is used to indicate that the target user is included in the target group and that the target user can successfully log in to the operating system; The browser included in the computer device is further used to send the identity credential to the application server, and the identity credential is used by the application server to determine whether the target user can access the target application; The application server is configured to, if determining that the target user can access the target application, send authorization access information to the computer device, wherein the authorization access information is used to indicate that the target user can access the target application; The browser included in the computer device is further used to receive the authorized access information and display the interface corresponding to the target application according to the authorized access information.
7. A computer device, characterized in that: The computer device includes a processor and a memory, wherein the memory stores at least one program code, and the at least one program code is loaded and executed by the processor, so that the computer device implements the application access method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores at least one program code, and the at least one program code is loaded and executed by a processor to enable a computer to implement the application access method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Request response method and device, electronic device and storage medium
CN112632521A
Single sign-on method and device, electronic equipment and storage medium
CN116208376A