Keep-alive method and device based on single-point login system

By setting a timing task in the single sign-in system, the token is invalid when the user has not used it for a long time and the user's business operation efficiency is improved.

CN119995919APending Publication Date: 2025-05-13AISINO CORPORATION
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411860372.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When the existing single sign-in system is not used for a long time, the token will automatically expire, causing the user to log in again, affecting the business process.

Method used

Set up background timing tasks in single sign-in system to automatically extend the validity period of user login tokens to ensure that the token is still valid when the user needs it.

Benefits of technology

It extends the use time of user login tokens, reduces duplicate login authentication, and improves the efficiency of users in handling business processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995919A_ABST
    Figure CN119995919A_ABST
Patent Text Reader

Abstract

The invention provides a keep-alive method and device based on a single-point login system, and the method comprises the steps: generating a user login token of a user through the single-point login system, and automatically prolonging the limited period of the user login token of the user according to a set background timing task; when the user skips to the service system to execute the current service to be handled, the single-point login system generates a first service token according to the user login token; when the user calls a service interface of the current to-be-handled service, the service system verifies the first service token to generate a verification result; and when the verification result is that the service token is valid, the user executes the current to-be-handled service. According to the method and the device, by setting the timed task for keeping the validity of the user login token alive, when the user logs in and uses the service system, the token can be automatically kept alive, the use time of the login token is prolonged, the use of the user service system is ensured, repeated login authentication is reduced, and the efficiency of processing the service process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of user authentication, and more specifically, to a method and device for keeping alive based on a single sign-on system. Background Art

[0002] Most single sign-on system methods are aimed at achieving single sign-on, single sign-off, switching between different business systems, user identity authentication, and user token issuance. In general, the single sign-on process is relatively complicated, and users are reluctant to operate multiple times. There is no special treatment for the length of time a user's token is used in the business system. When a user does not perform business operations for a period of time, the user token will automatically expire, which may cause the user to need to re-perform single sign-on when performing business operations, affecting the user's business process. Summary of the invention

[0003] In order to solve the technical problem that the single sign-on system in the prior art has no special processing for the usage time of the user's token in the business system, the present invention provides a keep-alive method and device based on the single sign-on system.

[0004] According to one aspect of the present invention, the present invention provides a method for keeping alive based on a single sign-on system, comprising:

[0005] The single sign-on system performs authentication based on the identity authentication information input by the user and generates an authentication result, wherein the authentication result includes authentication passed and information error;

[0006] When the authentication result is authentication passed, the single sign-on system generates a user login token for the user, and automatically extends the user login token for the user according to the set background timing task;

[0007] When the user jumps to the business system to execute the current pending business, the single sign-on system generates a first business token according to the user login token of the user;

[0008] When the user calls the service interface of the current pending service, the service system verifies the first service token and generates a verification result, wherein the verification result includes whether the service token is valid or invalid;

[0009] When the verification result shows that the service token is valid, the user executes the current pending service.

[0010] Optionally, when the verification result is that the business token is invalid, the single sign-on system generates a second business token according to the user login token of the user, and outputs a generation result, wherein the generation result includes generation success and generation failure.

[0011] Optionally, when the generation result is successful, when the verification result is that the business token is valid, the user changes the current pending business to be performed to:

[0012] The user executes the current pending service based on the second service token.

[0013] Optionally, when the generation result is generation failure, the single sign-on system updates the user login token of the user.

[0014] Optionally, the method further comprises, after the user completes the current to-do business, if there is a next to-do task, updating the next to-do task as the current to-do task.

[0015] According to another aspect of the present invention, the present invention provides a keep-alive device based on a single sign-on system, the device comprising:

[0016] The identity authentication module is used for the single sign-on system to perform authentication according to the identity authentication information input by the user and generate an authentication result, wherein the authentication result includes authentication pass and information error;

[0017] A user token module, which is used for the single sign-on system to generate a user login token for the user when the authentication result is authentication passed, and automatically extend the user login token of the user according to the set background timing task;

[0018] A business token module, used for generating a first business token according to the user login token of the user by the single sign-on system when the user jumps to the business system to execute the current pending business;

[0019] A token verification module, used for, when the user calls the service interface of the current pending service, the service system verifies the first service token and generates a verification result, wherein the verification result includes whether the service token is valid or invalid;

[0020] The task execution module is used for the user to execute the current pending business when the verification result shows that the business token is valid.

[0021] Optionally, the business token module is also used to generate a second business token based on the user login token of the user when the verification result of the token verification module is that the business token is invalid, and output the generation result, wherein the generation result includes generation success and generation failure.

[0022] Optionally, the task execution module is further configured to, when the generation result output by the business token module is generation success, enable the user to execute the current pending business based on the second business token.

[0023] Optionally, the user token module is further configured to, when the generation result output by the business token module is generation failure, enable the single sign-on system to update the user login token of the user.

[0024] Optionally, the business token module is further configured to update the next to-do task to the current to-do task when the user completes the current to-do business and there is a next to-do task.

[0025] According to another aspect of the present invention, the present invention provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program is used to execute the method described in any one of the above aspects of the present invention.

[0026] According to another aspect of the present invention, an electronic device is provided, comprising: a processor; a memory for storing instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of the above aspects of the present invention.

[0027] The method and device for keeping alive based on the single sign-on system of the present invention include: the single sign-on system performs authentication according to the identity authentication information input by the user and generates an authentication result; when the authentication result is authentication passed, the single sign-on system generates a user login token for the user, and automatically extends the user login token of the user for a limited period according to the set background timing task; when the user jumps to the business system to execute the current pending business, the single sign-on system generates a first business token according to the user login token of the user; when the user calls the business interface of the current pending business, the business system verifies the first business token and generates a verification result; when the verification result is that the business token is valid, the user executes the current pending business. The method and device can automatically keep the token alive when the user logs in to use the business system by setting a timing task for keeping alive the validity of the user login token, extending the use time of the login token, ensuring the use of the user business system, reducing repeated login authentication, and improving the efficiency of processing business processes. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:

[0029] Figure 1 It is a flow chart of a method for keeping alive based on a single sign-on system according to a preferred embodiment of the present invention;

[0030] Figure 2 It is a structural schematic diagram of a keep-alive device based on a single sign-on system according to a preferred embodiment of the present invention;

[0031] Figure 3 Schematic diagram of the structure of an electronic device according to a preferred embodiment of the present invention. DETAILED DESCRIPTION

[0032] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.

[0033] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.

[0034] Exemplary Methods

[0035] Figure 1 FIG. 1 is a flow chart of a method for keeping alive based on a single sign-on system according to a preferred embodiment of the present invention. Figure 1 As shown, the keep-alive method based on the single sign-on system described in this preferred embodiment starts from step 101.

[0036] In step 101, the single sign-on system performs authentication according to the identity authentication information input by the user and generates an authentication result, wherein the authentication result includes authentication passed and information error.

[0037] In step 102, when the authentication result is authentication passed, the single sign-on system generates a user login token for the user, and automatically extends the user login token of the user according to the set background timing task.

[0038] In step 103, when the user jumps to the service system to execute the current pending service, the single sign-on system generates a first service token according to the user login token of the user.

[0039] In step 104, when the user calls the service interface of the current pending service, the service system verifies the first service token and generates a verification result, wherein the verification result includes whether the service token is valid or invalid.

[0040] In step 105, when the verification result shows that the service token is valid, the user executes the current pending service.

[0041] Preferably, when the verification result is that the business token is invalid, the single sign-on system generates a second business token according to the user login token of the user, and outputs a generation result, wherein the generation result includes generation success and generation failure.

[0042] Preferably, when the generation result is successful, when the verification result is that the business token is valid, the user changes the current pending business to be performed to:

[0043] The user executes the current pending service based on the second service token.

[0044] Preferably, when the generation result is generation failure, the single sign-on system updates the user login token of the user.

[0045] Preferably, the method further comprises, after the user completes the current to-do business, if there is a next to-do task, updating the next to-do task to the current to-do task.

[0046] The keep-alive method based on the single sign-on system described in this preferred embodiment sets a timed task to keep the validity of the user's login token alive, so that when the user logs in to use the business system, the token can be automatically kept alive, the usage time of the user's login token can be extended, the user's business system use can be guaranteed, repeated login authentication can be reduced, the user's use can be facilitated, and the efficiency of the user in handling business processes can be improved.

[0047] Exemplary Devices

[0048] Figure 2 FIG. 1 is a schematic diagram of a structure of a keep-alive device based on a single sign-on system according to a preferred embodiment of the present invention. Figure 2 As shown, the keep-alive device 200 based on the single sign-on system described in this preferred embodiment includes:

[0049] The identity authentication module 201 is used for the single sign-on system to perform authentication according to the identity authentication information input by the user and generate an authentication result, wherein the authentication result includes authentication pass and information error;

[0050] The user token module 202 is used for the single sign-on system to generate a user login token for the user when the authentication result is authentication passed, and automatically extend the user login token of the user according to the set background timing task;

[0051] The business token module 203 is used for the single sign-on system to generate a first business token according to the user login token of the user when the user jumps to the business system to execute the current pending business;

[0052] The token verification module 204 is used for, when the user calls the service interface of the current pending service, the service system verifies the first service token and generates a verification result, wherein the verification result includes whether the service token is valid or invalid;

[0053] The task execution module 205 is used for the user to execute the current pending business when the verification result shows that the business token is valid.

[0054] Preferably, the business token module is also used for generating a second business token based on the user login token of the user and outputting the generation result when the verification result of the token verification module is that the business token is invalid, wherein the generation result includes generation success and generation failure.

[0055] Preferably, the task execution module is also used for, when the generation result output by the business token module is generation success, the user executes the current pending business based on the second business token.

[0056] Preferably, the user token module is also used for the single sign-on system to update the user login token of the user when the generation result output by the business token module is generation failure.

[0057] Preferably, the business token module is also used for updating the next to-do task as the current to-do task when the user completes the current to-do business and there is a next to-do task.

[0058] The steps of the keep-alive device based on the single sign-on system described in this preferred embodiment, which extends the usage time of the login token by setting a timed task to keep the validity of the user's login token alive, thereby enabling the user to quickly switch between multiple pending services, are the same as the steps of the keep-alive method based on the single sign-on system described in the present invention, and the technical effects achieved are also the same, which will not be repeated here.

[0059] Exemplary Electronic Devices

[0060] Figure 3 The electronic device according to the preferred embodiment of the present invention is a schematic diagram of the structure of the electronic device. The electronic device can be any one or both of the first device and the second device, or a stand-alone device independent of them, and the stand-alone device can communicate with the first device and the second device to receive the collected input signal from them. Figure 3 FIG. 1 is a block diagram of an electronic device according to an embodiment of the present disclosure. Figure 3 As shown, the electronic device includes one or more processors 301 and a memory 302 .

[0061] The processor 301 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.

[0062] The memory 302 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 301 may run the program instructions to implement the energy consumption anomaly diagnosis method based on the enterprise energy consumption space of each disclosed embodiment described above and / or other desired functions. In one example, the electronic device may also include: an input device 303 and an output device 304, which are interconnected via a bus system and / or other forms of connection mechanisms (not shown).

[0063] In addition, the input device 303 may also include, for example, a keyboard, a mouse, and the like.

[0064] The output device 304 can output various information to the outside. The output device 305 can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto.

[0065] Of course, to simplify, Figure 3 Only some of the components related to the present disclosure in the electronic device are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, according to specific application situations, the electronic device may further include any other appropriate components.

[0066] Exemplary computer program products and computer-readable storage media

[0067] In addition to the above-mentioned methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the single sign-on system-based keep-alive method according to various embodiments of the present disclosure described in the above-mentioned "Exemplary Method" section of this specification.

[0068] The computer program product may be written in any combination of one or more programming languages ​​to write program code for performing the operations of the disclosed embodiments, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0069] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, causes the processor to execute the steps of a method for maintaining a single sign-on system based on various embodiments of the present disclosure described in the above “Exemplary Method” section of this specification.

[0070] The computer readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but is not limited to, a system, device or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0071] The basic principles of the present disclosure are described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, strengths, effects, etc. are required by each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purpose of illustration and ease of understanding, and are not limitations. The above details do not limit the present disclosure to the necessity of adopting the above specific details to be implemented.

[0072] Each embodiment in this specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0073] The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including," "comprising," "having," and the like are open words, referring to "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or," and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.

[0074] The apparatus and method of the present disclosure may be implemented in many ways. For example, the apparatus and method of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above, unless otherwise specifically stated. In addition, in some embodiments, the present disclosure may also be implemented as a program recorded in a recording medium, which includes machine-readable instructions for implementing the method according to the present disclosure. Therefore, the present disclosure also covers a recording medium storing a program for executing the method according to the present disclosure.

[0075] It should also be noted that in the apparatus, equipment and method of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present disclosure. The above description of the disclosed aspects is provided to enable any technician in the field to make or use the present disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown here, but to the widest scope consistent with the principles and novel features disclosed herein.

[0076] The above description has been given for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.

Claims

1. A method for keeping alive based on a single sign-on system, characterized in that: The method comprises: The single sign-on system performs authentication based on the identity authentication information input by the user and generates an authentication result, wherein the authentication result includes authentication passed and information error; When the authentication result is authentication passed, the single sign-on system generates a user login token for the user, and automatically extends the user login token for the user according to the set background timing task; When the user jumps to the business system to execute the current pending business, the single sign-on system generates a first business token according to the user login token of the user; When the user calls the service interface of the current pending service, the service system verifies the first service token and generates a verification result, wherein the verification result includes whether the service token is valid or invalid; When the verification result shows that the service token is valid, the user executes the current pending service.

2. The method according to claim 1, characterized in that When the verification result is that the business token is invalid, the single sign-on system generates a second business token according to the user login token of the user, and outputs a generation result, wherein the generation result includes generation success and generation failure.

3. The method according to claim 2, characterized in that When the generation result is successful, when the verification result is that the business token is valid, the user changes the current pending business to be performed to: The user executes the current pending service based on the second service token.

4. The method according to claim 2, characterized in that: When the generation result is generation failure, the single sign-on system updates the user login token of the user.

5. The method according to claim 1, characterized in that The method further includes updating the next to-do task as the current to-do task when the user completes the current to-do business and there is a next to-do task.

6. A keep-alive device based on a single sign-on system, characterized in that: The device comprises: The identity authentication module is used for the single sign-on system to perform authentication according to the identity authentication information input by the user and generate an authentication result, wherein the authentication result includes authentication pass and information error; A user token module, which is used for the single sign-on system to generate a user login token for the user when the authentication result is authentication passed, and automatically extend the user login token of the user according to the set background timing task; A business token module, used for generating a first business token according to the user login token of the user by the single sign-on system when the user jumps to the business system to execute the current pending business; A token verification module, used for, when the user calls the service interface of the current pending service, the service system verifies the first service token and generates a verification result, wherein the verification result includes whether the service token is valid or invalid; The task execution module is used for the user to execute the current pending business when the verification result shows that the business token is valid.

7. The device according to claim 6, characterized in that The business token module is also used for generating a second business token based on the user login token of the user and outputting the generation result when the verification result of the token verification module is that the business token is invalid, wherein the generation result includes generation success and generation failure.

8. The device according to claim 6, characterized in that The task execution module is also used for, when the generation result output by the business token module is generation success, the user to execute the current pending business based on the second business token.

9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to execute the method according to any one of claims 1 to 5.

10. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is used to read the executable instructions from the memory and execute the instructions to implement the method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Browser kernel based multi-service integration system

    CN104461537A

  • Method and system for conducting authentication on third-party application

    CN104734849A

  • Single sign-on method, single sign-on terminal and single sign-on system

    CN107294916A

  • User login authentication method

    CN113591059A

  • Single sign-on method and system, electronic equipment and storage medium

    CN118013499A