Unified authentication method based on Oauth authorization framework and computer equipment

By adopting a unified authentication method based on the Oauth authorization framework in enterprise information construction, and using the unified identity authentication system to connect with the front-end system of the portal system, the complex password leakage and management problems of traditional identity authentication methods are solved, and unified authentication for multiple systems, multiple applications, and multiple clients is realized, and authentication efficiency and security level are improved.

CN120034367APending Publication Date: 2025-05-23BEIJING HUADIAN TIANREN ELECTRIC POWER CONTROL TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510124362.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the construction of enterprise informationization, traditional identity verification methods have complex password leakage and management problems. At the same time, the portal system needs to implement unified authentication of multiple systems, multiple applications, and multiple clients.

Method used

The unified authentication method based on the Oauth authorization framework is adopted, and the unified authentication system is connected to the front-end system of the portal system through the unified identity authentication system, and the unified authorization code is used to achieve unified authentication for multiple systems, multiple applications, and multiple clients.

Benefits of technology

It realizes unified authentication for multiple systems, multiple applications, and multiple clients, avoids repeated input of accounts and passwords multiple times, improves authentication efficiency, and improves the security level of enterprise information construction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034367A_ABST
    Figure CN120034367A_ABST
Patent Text Reader

Abstract

The invention provides a unified authentication method based on an Oauth authorization framework and computer equipment, and belongs to the technical field of computers. The method comprises the following steps: in response to a portal system access request, judging whether a portal system session of a user exists or not; if not, skipping to a unified identity authentication system login page to obtain login information of the user, and calling a service interface of the unified identity authentication system to enable the unified identity authentication system to generate session information containing a unified authorization code; in response to an operation request which is triggered by a user through a portal system and contains a unified authorization code, judging whether a target application system session of the user exists or not; and if the unified authorization code bound with the current session is not matched with the unified authorization code in the operation request, or the user target application system session does not exist, calling a service interface to obtain user information according to the unified authorization code, and then creating the target application system session based on the user information. According to the method, unified authentication of multiple systems, multiple clients and multiple applications is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of computer technology, and specifically relates to a unified authentication method based on an Oauth authorization framework, a front-end system of a portal system, a unified identity authentication system, a computer device, and a machine-readable storage medium. Background Art

[0002] In the process of informatization development of enterprises and institutions, more and more application systems have emerged. In the decentralized construction process of each application system, each of them plans its user authentication and access control function modules. With the continuous increase of application systems, on the one hand, traditional identity authentication methods (such as user name and password) have many problems, such as password leakage and complex management. On the other hand, portal systems, as an integration platform for various information resources within the enterprise, have gradually become an important part of enterprise informatization construction. Therefore, how to achieve unified authentication of multiple systems, multiple applications, and multiple clients has become an important issue facing the current enterprise informatization construction. Summary of the invention

[0003] The purpose of the embodiments of the present application is to provide a unified authentication method based on the Oauth authorization framework, a front-end system of a portal system, a unified identity authentication system, a computer device and a machine-readable storage medium to achieve unified authentication of multiple systems, multiple applications and multiple clients.

[0004] To achieve the above-mentioned purpose, the first aspect of the present application provides a unified authentication method based on the Oauth authorization framework, which is applied to the front-end system of a portal system. The portal system includes a unified identity authentication system. The service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published. The page of the front-end system integrates link entrances of multiple application systems. The method includes:

[0005] In response to a portal system access request initiated by a user, determining whether there is a portal system session of the user;

[0006] If there is no portal system session for the user, jump to the login page of the unified identity authentication system to obtain the user's login information, and call the service interface to enable the unified identity authentication system to verify the login information, generate session information for establishing a session required for the user to access the application system after the verification is passed, and return a unified authorization code based on the Oauth authorization framework in the session information, and then display the page of the front-end system;

[0007] In response to an operation request containing the unified authorization code triggered by the user through a link entry of the target application system, determining whether there is a target application system session of the user;

[0008] If there is a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or there is no target application system session of the user, the service interface is called. If user information obtained by the unified identity authentication system based on the unified authorization code contained in the operation request is returned by the service interface, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

[0009] In a specific embodiment of the present application, after verification is passed, session information for establishing a session required for the user to access the application system is generated, including:

[0010] According to the user's login information and the user information registered by the user when registering on the login page of the unified identity authentication system, a unified authorization code based on the Oauth authorization framework is generated using a preset password mode;

[0011] Generate session information for establishing a session required for the user to access the application system, wherein the session information includes the unified authorization code, the access token, and the refresh token.

[0012] In a specific embodiment of the present application, the method further includes:

[0013] If there is a target application system session of the user, and the unified authorization code bound to the current session matches the unified authorization code contained in the operation request, then jump to the operation page of the target application system.

[0014] In a specific embodiment of the present application, the method further includes:

[0015] If the user information returned by the service interface and obtained by the unified identity authentication system according to the unified authorization code contained in the operation request is not received or the session times out, the process jumps to the login page of the unified identity authentication system.

[0016] A second aspect of the present application provides a unified authentication method based on the Oauth authorization framework, which is applied to a unified identity authentication system of a portal system, wherein a service interface provided by the unified identity authentication system is pre-registered with a service gateway of the portal system and published, wherein the portal system includes a front-end system, wherein a page of the front-end system integrates link entrances of multiple application systems, and wherein the method includes:

[0017] Receiving login information of a user transmitted through an internal login page when the front-end system responds to a portal system access request initiated by a user and does not have a portal system session of the user;

[0018] Receiving a request for calling the service interface sent by the front-end system;

[0019] Verify the login information. If the verification is successful, generate session information for establishing a session required for the user to access the application system, and pass the unified authorization code based on the Oauth authorization framework in the session information to the front-end system, so that the front-end system can display its own page, receive the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a session with the target application system of the user;

[0020] Receiving a request for calling the service interface sent by the front-end system when the front-end system has a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or does not have a target application system session of the user;

[0021] The user information is obtained according to the unified authorization code contained in the operation request, and the user information is transmitted to the front-end system so that the front-end system performs the following processing based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

[0022] In a specific embodiment of the present application, generating session information for establishing a session required for the user to access the application system includes:

[0023] According to the user's login information and the user information registered by the user when registering on the login page of the unified identity authentication system, a unified authorization code based on the Oauth authorization framework is generated using a preset password mode;

[0024] Generate session information for establishing a session required for the user to access the application system, wherein the session information includes the unified authorization code, the access token, and the refresh token.

[0025] A third aspect of the present application provides a front-end system of a portal system, the portal system includes a unified identity authentication system, a service interface provided by the unified identity authentication system is pre-registered with a service gateway of the portal system and published, a page of the front-end system integrates link entrances of multiple application systems, and the front-end system includes:

[0026] The first module is used to respond to a portal system access request initiated by a user and determine whether there is a portal system session of the user;

[0027] The second module is used to jump to the login page of the unified identity authentication system to obtain the user's login information when there is no portal system session of the user, and call the service interface to enable the unified identity authentication system to verify the login information, generate session information for establishing a session required for the user to access the application system after the verification is passed, and return a unified authorization code based on the Oauth authorization framework in the session information, and then display the page of the front-end system;

[0028] The third module is used to respond to the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a target application system session of the user;

[0029] The fourth module is used to call the service interface when there is a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or there is no target application system session of the user. If user information obtained by the unified identity authentication system according to the unified authorization code contained in the operation request is returned by the service interface, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

[0030] A fourth aspect of the present application provides a unified identity authentication system, wherein a service interface provided by the unified identity authentication system is pre-registered with a service gateway of a portal system and published, wherein the portal system includes a front-end system, wherein a page of the front-end system integrates link entrances of multiple application systems, and wherein the unified identity authentication system includes:

[0031] A fifth module is used to receive the user's login information transmitted by the user through the internal login page when the front-end system responds to the portal system access request initiated by the user and does not have the portal system session of the user;

[0032] The sixth module receives a request for calling the service interface sent by the front-end system;

[0033] The seventh module is used to verify the login information. If the verification is successful, session information for establishing a session required for the user to access the application system is generated, and the unified authorization code based on the Oauth authorization framework in the session information is passed to the front-end system, so that the front-end system can display its own page, receive the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a session with the target application system of the user;

[0034] An eighth module is used to receive a request for calling the service interface sent by the front-end system when the front-end system has a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request or does not have the target application system session of the user;

[0035] The ninth module is used to obtain user information according to the unified authorization code contained in the operation request, and transmit the user information to the front-end system, so that the front-end system performs the following processing based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

[0036] A fifth aspect of the present application provides a computer device, comprising:

[0037] a memory configured to store instructions; and

[0038] The processor is configured to call the instructions from the memory and implement the unified authentication method based on the Oauth authorization framework according to the first aspect or the second aspect of the present application when executing the instructions.

[0039] The sixth aspect of the present application provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to enable a machine to execute the unified authentication method based on the Oauth authorization framework according to the first aspect or the second aspect of the present application.

[0040] The above technical solution establishes a unified authentication mechanism based on the Oauth authorization framework when a portal system integrating multiple application systems is connected to a unified identity authentication system. Among them, the unified authorization code based on the Oauth authorization framework is used as a symbol to uniformly identify the user identity for application system session identification, application system session establishment, etc., thereby realizing unified authentication of multiple systems, multiple applications, and multiple clients. Compared with the decentralized construction and separate authentication of multiple application systems, it avoids repeated input of account numbers and passwords, and improves authentication efficiency.

[0041] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The accompanying drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present application, but do not constitute a limitation on the embodiments of the present application. In the accompanying drawings:

[0043] Figure 1 A first flow chart of a unified authentication method based on the Oauth authorization framework according to an embodiment of the present application is schematically shown;

[0044] Figure 2 A second flow chart of a unified authentication method based on the Oauth authorization framework according to an embodiment of the present application is schematically shown;

[0045] Figure 3 A third flow chart of a unified authentication method based on the Oauth authorization framework according to an embodiment of the present application is schematically shown;

[0046] Figure 4 A fourth flow chart of a unified authentication method based on the Oauth authorization framework according to an embodiment of the present application is schematically shown;

[0047] Figure 5 A fifth flow chart of a unified authentication method based on the Oauth authorization framework according to an embodiment of the present application is schematically shown;

[0048] Figure 6 The following is a schematic diagram of a unified authentication method based on the Oauth authorization framework in a specific application example;

[0049] Figure 7 The technical architecture diagram of the portal system in a specific application example is schematically shown;

[0050] Figure 8 The structural block diagram of a computer device according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION

[0051] The specific implementation of the embodiment of the present application is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described here is only used to illustrate and explain the embodiment of the present application, and is not used to limit the embodiment of the present application.

[0052] If there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or suggesting their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0053] Oauth authorization framework, such as Oauth2.0, is an industrial-level authorization protocol that allows Internet users to authorize third-party websites or application services to access their information on specific websites without having to provide login accounts and passwords to third-party websites or application services. In the Oauth authorization framework, an "authorization server" is proposed. After user authorization, the authorization server issues an access token to the third-party application, so that the user can access the resources stored on a specific resource server within a specific time through the token without providing the login account and password to the third-party application.

[0054] In order to achieve unified authentication of multiple systems, multiple applications, and multiple clients, this application proposes a unified authentication method, the unified authentication process of which is implemented based on the Oauth authorization framework.

[0055] Embodiment 1

[0056] Specifically, a unified authentication method based on the Oauth authorization framework is applied to the front-end system of a portal system. The portal system includes a unified identity authentication system. The service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published. The page of the front-end system integrates link entrances of multiple application systems. The portal system can be an enterprise portal system, etc. The unified authentication method includes the following contents:

[0057] In response to a portal system access request initiated by a user, determining whether there is a portal system session of the user;

[0058] If there is no portal system session for the user, jump to the login page of the unified identity authentication system to obtain the user's login information, and call the service interface provided by the unified identity authentication system to enable the unified identity authentication system to verify the user's login information, generate session information for establishing a session required for the user to access the application system after the verification is passed, and return a unified authorization code based on the Oauth authorization framework in the session information, and then display the page of the front-end system;

[0059] In response to an operation request for the target application system triggered by the user through a link entry of the target application system, determining whether there is a target application system session of the user, the operation request containing the unified authorization code returned in the previous step;

[0060] If there is a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or there is no target application system session of the user, the service interface of the unified identity authentication system is called. If the user information obtained by the unified identity authentication system according to the unified authorization code contained in the operation request is returned by the service interface, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, and creating a session between the user and the target application system (the user's target application system session).

[0061] Specifically, the unified authorization code is generated based on the Oauth authorization framework, which is different from the standard Oauth2.0 authorization code method used when the application system is connected to the unified identity authentication system alone. When multiple application systems are integrated through the portal system, the portal system is connected to the unified identity authentication system. The standard Oauth2.0 and other methods are not applicable. The authorization code under the Oauth authorization framework used in this application is defined as a unified authorization code, which indicates the uniformity of access authorization for each application system under the portal system. The target application system is the application system that the user currently plans to access. The session information generated by the unified identity authentication system refers to the session information used to establish the session required for the user to access the application system resources. Under the Oauth authorization framework, the session information includes a unified authorization code, access token, and refresh token.

[0062] In the above embodiment of the present application, the service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published, and the link entrances of multiple application systems are integrated on the page of the front-end system of the portal system, and a unified authentication mechanism for multiple systems, multiple applications and multiple clients is established based on the Oauth authorization framework, wherein: the unified authorization code generated by the unified identity authentication system after verification of the user's login information is used as a mark to identify the user's identity for application system session identification, application system session establishment, etc., and if the access token in the session information is used as an identity identification mark, it will be inconvenient to transmit because the access token is too long. Based on the above, the present application realizes unified authentication of multiple systems, multiple applications and multiple clients, and provides effective identity support and security authentication protection for enterprise informatization construction, business system interconnection, etc., which greatly improves the work efficiency of employees while improving the security level, and reduces the enterprise management cost accordingly.

[0063] As an example, the user may trigger a portal system access request by inputting the portal system address in a browser or clicking a portal system link on a page displayed on a client.

[0064] As an example, the user may trigger an operation request for the target application system containing a unified authorization code by clicking a link entry of the target application system on the front-end system page.

[0065] Optionally, after determining whether there is a portal system session of the user, the method further includes the following steps:

[0066] If there is a portal system session of the user, the page of the front-end system is displayed.

[0067] Optionally, the login page of the unified identity authentication system includes operation entrances for account registration, password modification and password retrieval. After jumping to the login page of the unified identity authentication system, if the user has not registered an account, the user information is saved after the user registers the account, and then the user's login information is obtained after the user enters the account and password to log in, scans the code to log in, or logs in via SMS.

[0068] Optionally, after determining whether there is a target application system session of the user, the following steps are further included:

[0069] If there is a target application system session of the user, and the unified authorization code bound to the current session matches the unified authorization code contained in the operation request, then jump to the operation page of the target application system so that the user can operate the target application system and access the resources of the target application system.

[0070] Optionally, after calling the service interface, if the user information obtained by the unified identity authentication system according to the unified authorization code contained in the operation request is not received or the session times out, the system jumps to the login page of the unified identity authentication system.

[0071] Figure 1 The following schematically shows a flow chart of a unified authentication method based on the Oauth authorization framework applied to a front-end system of a portal system according to an embodiment of the present application. Figure 1 As shown, the method may include steps 100 to 106 .

[0072] Step 100: receiving a portal system access request initiated by a user.

[0073] In this application, the user triggers a portal system access request by inputting the portal system address in the browser or clicking the portal system link on the display page of the client.

[0074] Step 102, when the portal system session with the user is established, the page of the front-end system is displayed, that is, the user directly enters the page of the front-end system.

[0075] Step 104: Receive an operation request for the target application system containing a unified authorization code triggered by the user through the link entry of the target application system. The user's unified authorization code is generated by the unified identity authentication system after verifying the login information transmitted through the login page of the unified identity authentication system before the user's current session starts.

[0076] As an example, the user may trigger an operation request for the target application system containing a unified authorization code by clicking a link entry of the target application system on a page of the front-end system.

[0077] As an example, the operation request header includes a unified authorization code.

[0078] As an example, the unified authorization code is generated in the following manner: based on the user's login information and the user information registered by the user when registering on the login page of the unified identity authentication system, the unified authorization code is generated using a preset password mode. Preferably, the unified authorization code is of UUID type, that is, the unified authorization code is a unique identification code generated by a UUID generator.

[0079] As another example of generating a unified authorization code, a unified authorization code is generated in the following way: based on the user's account, password, client id, client key, tenant id, authorization type and authorization parameter range, a preset password mode is used to generate a unified authorization code of the UUID type. For example, the application service is based on the Spring framework, and the preset password mode is SpringSecurity+Jwt+Oauth2. Among them: SpringSecurity refers to the SpringSecurity security framework; the full name of Jwt is JSON WEB Token, which is a cross-domain authentication solution; Oauth2 refers to the Oauth2.0 protocol. As mentioned above, the authorization type refers to the authorization type corresponding to the application system resource access rights open to the user, and the authorization parameter range refers to the authorization parameter range corresponding to the application system resource access rights open to the user.

[0080] Step 106, when there is a target application system session of the user and the unified authorization code bound to the current session matches the unified authorization code contained in the operation request received in step 104, jump to the operation page of the target application system, thereby completing the user's access authentication to the target application system.

[0081] As an example, in order to determine whether there is a target application system session of the user, the target application system intercepts the operation request to obtain the unified authorization code in the operation request header. In addition, this application also proposes a unified authorization code acquisition method when the application system cannot intercept the operation request, specifically: when the application system is integrated into the portal system, the URL is added with a fixed prefix, and redirection is performed after jumping to the application system.

[0082] Figure 2 The following schematically shows a flow chart of a unified authentication method based on the Oauth authorization framework applied to a front-end system of a portal system according to another embodiment of the present application. Figure 2As shown, the method may include steps 200 to 206 .

[0083] Step 200: receiving a portal system access request initiated by a user.

[0084] Step 202: If there is no portal system session for the user, jump to the login page of the unified identity authentication system to obtain the user's login information, and call the service interface provided by the unified identity authentication system to enable the unified identity authentication system to verify the user's login information, generate session information for the user to access the application system after the verification is passed, and return the unified authorization code based on the Oauth authorization framework and the preset security mechanism in the session information, and then display the page of the front-end system. The generation mechanism of the unified authorization code can be found in Figure 1 The contents described in the illustrated embodiment.

[0085] Step 204: receiving an operation request for the target application system containing a unified authorization code, which is triggered by the user through a link entry of the target application system.

[0086] Step 206, when there is no target application system session with the user, or when there is a target application system session with the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request received in step 204, call the service interface of the unified identity authentication system, and after receiving the user information returned by the service interface and obtained by the unified identity authentication system according to the unified authorization code contained in the operation request, perform the following processing based on the received user information: identity authentication, respond to the user's login request, create the user's target application system session, and then jump to the operation page of the target application system, thereby completing the user's access authentication to the target application system.

[0087] Figure 3 The following schematically shows a flow chart of a unified authentication method based on the Oauth authorization framework applied to a front-end system of a portal system according to another embodiment of the present application. Figure 3 As shown, the method may include steps 300 to 306 .

[0088] Step 300: receiving a portal system access request initiated by a user.

[0089] Step 302: When the portal system session with the user is established, the page of the front-end system is displayed, that is, the user directly enters the page of the front-end system.

[0090] Step 304: Receive an operation request for the target application system containing a unified authorization code triggered by the user through the link entry of the target application system. The user's unified authorization code is generated by the unified identity authentication system after verifying the login information transmitted through the login page of the statistical identity authentication system before the user's current session starts.

[0091] Step 306, when there is no target application system session with the user, or when there is a target application system session with the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request received in step 304, the service interface of the unified identity authentication system is called, and when the user information obtained by the unified identity authentication system according to the unified authorization code contained in the operation request and returned by the service interface is received, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, creating the user's target application system session, and then jumping to the operation page of the target application system, thereby completing the user's access authentication to the target application system.

[0092] Figure 4 The following schematically shows a flow chart of a unified authentication method based on the Oauth authorization framework applied to a front-end system of a portal system according to another embodiment of the present application. Figure 4 As shown, the method may include steps 400 to 406 .

[0093] Step 400: receiving a portal system access request initiated by a user.

[0094] Step 402: If there is no portal system session for the user, jump to the login page of the unified identity authentication system to obtain the user's login information, and call the service interface provided by the unified identity authentication system to enable the unified identity authentication system to verify the user's login information, generate session information for the user to access the application system after the verification is passed, and return the unified authorization code based on the Oauth authorization framework and the preset security mechanism in the session information, and then display the page of the front-end system. The generation mechanism of the unified authorization code can be found in Figure 1 The contents described in the illustrated embodiment.

[0095] Step 404: receiving an operation request for the target application system containing a unified authorization code, which is triggered by the user through a link entry of the target application system.

[0096] Step 406, when there is a target application system session of the user and the unified authorization code bound to the current session matches the unified authorization code contained in the operation request received in step 404, jump to the operation page of the target application system, thereby completing the user's access authentication to the target application system.

[0097] Embodiment 2

[0098] Specifically, a unified authentication method based on the Oauth authorization framework is applied to the unified identity authentication system of the portal system. The service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published. The portal system includes a front-end system, and the page of the front-end system integrates the link entrances of multiple application systems. Figure 5 As shown, the unified authentication method includes the following steps 500 to 508.

[0099] Step 500 : receiving the user's login information transmitted by the user through the internal login page when the front-end system responds to the portal system access request initiated by the user and does not have the portal system session of the user.

[0100] Step 502: Receive a request from the front-end system to call a service interface of the unified identity authentication system.

[0101] Step 504, verify the received login information. If the verification passes, generate session information for establishing the session required for the user to access the application system, and pass the unified authorization code based on the Oauth authorization framework in the session information to the front-end system, so that the front-end system can display its own page, receive the operation request containing the unified authorization code as mentioned above triggered by the user through the link entrance of the target application system, and determine whether there is a session with the target application system of the user.

[0102] Step 506, receiving a request for calling a service interface of a unified identity authentication system sent by the front-end system when the front-end system has the target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or does not have the target application system session of the user.

[0103] Step 508, obtain user information according to the unified authorization code contained in the operation request, and pass the user information to the front-end system, so that the front-end system performs the following processing based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

[0104] As an example, the session information includes a unified authorization code, an access token, and a refresh token, wherein the process of generating a unified authorization code based on the Oauth authorization framework is as follows: according to the user's login information and the user information registered by the user when registering on the login page of the unified identity authentication system, a unified authorization code is generated using a preset password mode. Preferably, the unified authorization code is of UUID type, that is, the unified authorization code is a unique identification code generated by a UUID generator.

[0105] As another example of the unified authorization code generation process, a unified authorization code is generated in the following manner: based on the user's account, password, client id, client key, tenant id, authorization type and authorization parameter range, a preset password mode is used to generate a unified authorization code of the UUID type. For example, when the application service is based on the Spring framework and the Oauth authorization framework adopts Oauth2.0, the preset password mode is SpringSecurity+Jwt+Oauth2. Among them: SpringSecurity refers to the SpringSecurity security framework; Jwt's full name is JSON WEB Token, which is a cross-domain authentication solution; Oauth2 refers to the Oauth2.0 protocol. As mentioned above, the authorization type refers to the authorization type corresponding to the application system resource access rights open to the user, and the authorization parameter range refers to the authorization parameter range corresponding to the application system resource access rights open to the user.

[0106] Optionally, the unified authorization code and access token are persisted to a database, and the session information is stored locally, for example, in local storage for subsequent use.

[0107] Optionally, the unified authorization code is passed to the front-end system in the following manner: the unified authorization code is passed to the front-end system in a get / post manner. For example, in an actual application, the post manner may be used by default.

[0108] Embodiment 3

[0109] The embodiment of the present application provides a unified authentication method based on the Oauth authorization framework, and the unified authentication method includes the following steps:

[0110] Step S1, the user enters the portal system address in the browser and jumps to the login page of the unified identity authentication system. The user registers an account, changes the password, and retrieves the password on the login page.

[0111] In an actual application, when redirecting to the unified identity authentication system, the redirect_url encoded in base64, way=href (used to establish a connection between the current document and the referenced resource), and exitFlag=true (exit flag) are concatenated after the url. The redirect_url defaults to the url address of the portal system. If there is no exitFlag=true parameter, the unified identity authentication system checks whether there is session information in its own cookies or local storage. If there is, it jumps to the redirect_url. If not, it jumps to the login page of the unified identity authentication system.

[0112] Step S2: The user enters login information such as account number and password on the login page of the unified identity authentication system to log in, or scans a code to log in, or logs in via SMS, etc.

[0113] Step S3, the unified identity authentication system verifies the user's login information, and generates session information containing unified authorization code, access token and refresh token after verification. In this embodiment, the unified authorization code is named iamCode, the access token is recorded as access_token, and the refresh token is recorded as refresh_token. The iamCode and access_token are persisted in the database one by one, and the session information is stored in the local storage for subsequent use. Then the unified identity authentication system uses the get / post method to pass the iamCode to the front-end system of the portal system. The default method can be set to post. The post method is submitted in the form form. The get method transmission means directly splicing iamCode after the decoded redirect_url, that is, splicing iamCode=xxx after the decoded redirect_url. The front-end system of the portal system stores the obtained iamCode and cannot display it in the url.

[0114] Step S4, click the link entry of the target application system on the page of the front-end system. For example, each link entry is displayed with the module name of each defined application system, or all menus of each application system can be displayed in the left menu bar of the front-end system page. After clicking the link entry of the target application system, an operation request for the target application system with iamCode in the request header is generated, and the request is redirected to the target application system. Preferably, the iamCode in the request header can be transmitted via a key-value pair, where the key is iamCode and the value is the corresponding value of iamCode.

[0115] Step S5: The target application system intercepts the operation request, obtains the iamCode in the request header, and determines whether there is an application system session corresponding to the user. If there is an application system session corresponding to the user, determine whether the iamCode bound to the current session id of the application system matches the operation request. If they match, jump to the operation page of the target application system and display it. If they do not match, clear the session, obtain user information based on the iamCode, use the service gateway to authenticate the user information, and jump to the login page of the unified identity authentication system after the authentication is passed. The user logs in on the login page of the unified identity authentication system. The front-end system creates a session between the user and the target application system, and binds the session id of the created session to the iamCode and stores it in local storage, or cookies, or session storage. If there is no application system session corresponding to the user, the user information is obtained according to the iamCode, and the user information is authenticated by the service gateway. After the authentication is passed, it jumps to the login page of the unified identity authentication system. The user logs in on the login page of the unified identity authentication system. The front-end system creates a session between the user and the target application system, and binds the session id of the created session with the iamCode and stores it in local storage, or cookies, or session storage. If the acquisition of user information fails or the session times out, the existing session is cleared, and the login page of the unified identity authentication system is jumped to, and then the execution of step S2 is returned. Among them, when jumping to the login page of the unified identity authentication system after the authentication is passed, there is no need to splice parameters such as redirect_url after the url.

[0116] Figure 6 FIG. 1 is a practical implementation of the above-mentioned embodiment 3. Figure 6 The workbench shown in the figure is the front-end system of the portal system, the business system represents the application system integrated with the portal system, and IAM represents the unified identity authentication system.

[0117] Corresponding to the unified authentication method based on the Oauth authorization framework in the above embodiment, the present application also provides a front-end system of a portal system, the portal system includes a unified identity authentication system, the service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published, the page of the front-end system integrates link entrances of multiple application systems, and the front-end system includes:

[0118] The first module is used to respond to a portal system access request initiated by a user and determine whether there is a portal system session of the user;

[0119] The second module is used to jump to the login page of the unified identity authentication system to obtain the user's login information when there is no portal system session of the user, and call the service interface to enable the unified identity authentication system to verify the login information, generate session information for establishing a session required for the user to access the application system after the verification is passed, and return a unified authorization code based on the Oauth authorization framework in the session information, and then display the page of the front-end system;

[0120] The third module is used to respond to the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a target application system session of the user;

[0121] The fourth module is used to call the service interface when there is a target application system session with the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or there is no target application system session with the user. If user information obtained by the unified identity authentication system based on the unified authorization code contained in the operation request is returned by the service interface, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, and creating a session between the user and the target application system.

[0122] As an embodiment of the present application, the front-end system of the portal system can be implemented as follows: Figure 1 The illustrated embodiments and other related method embodiments in this application.

[0123] The process of each module in the front-end system of the portal system provided in the embodiment of the present application realizing its own function can be specifically referred to the aforementioned Figure 1 The description of the illustrated embodiment and other related method embodiments will not be repeated here.

[0124] It should be noted that the information interaction, execution process and other contents between the above modules are based on the same concept as the method embodiment of the present application, and their specific functions and technical effects can be found in the method embodiment section, which will not be repeated here. In addition, the above modules can be applied to a computing device including a memory and a processor.

[0125] Corresponding to the unified authentication method based on the Oauth authorization framework in the above embodiment, the present application also provides a unified identity authentication system, wherein the service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published, wherein the portal system includes a front-end system, wherein the page of the front-end system integrates link entrances of multiple application systems, and the unified identity authentication system includes:

[0126] The sixth module receives a request for calling the service interface sent by the front-end system;

[0127] The seventh module is used to verify the login information. If the verification is successful, session information for establishing a session required for the user to access the application system is generated, and the unified authorization code based on the Oauth authorization framework in the session information is passed to the front-end system, so that the front-end system can display its own page, receive the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a session with the target application system of the user;

[0128] An eighth module is used to receive a request for calling the service interface sent by the front-end system when the front-end system has a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request or does not have the target application system session of the user;

[0129] The ninth module is used to obtain user information according to the unified authorization code contained in the operation request, and transmit the user information to the front-end system, so that the front-end system performs the following processing based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

[0130] As an embodiment of the present application, the front-end system of the portal system can be implemented as follows: Figure 5 The illustrated embodiments and other related method embodiments in this application.

[0131] The process of each module realizing its own function in the unified identity authentication system provided in the embodiment of the present application can be specifically referred to in the above Figure 5 The description of the illustrated embodiment and other related method embodiments will not be repeated here.

[0132] It should be noted that the information interaction, execution process and other contents between the above modules are based on the same concept as the method embodiment of the present application, and their specific functions and technical effects can be found in the method embodiment section, which will not be repeated here. In addition, the above modules can be applied to a computing device including a memory and a processor.

[0133] Figure 7 The following is a technical architecture diagram of a portal system in an actual application. Figure 7The business system 1, business system 2 and business system 3 shown in refer to the different application systems described in the above embodiments. Among them, there are two ways to integrate different application systems with the portal system: one is to integrate the name of the application system or, click on an application system, and a new tab will pop up to display the application system. The style of the application system can be different from that of the portal system; the other is to integrate all the menus of the application system into the portal system in an iframe manner, excluding the permission menu. The security framework of the portal system that includes a unified identity authentication system can adopt Spring Security's powerful and flexible security framework, support user password, OIDC, SAML2 and other authentication methods, support role-based access control (RBAC), the authorization framework adopts Oauth2.0 open standard protocol and subpackages it, adopts iamCode for system integration, and the cross-domain identity authentication scheme adopts jwt, supporting cross-language, concise, self-contained, extensible, cross-domain and other features.

[0134] Figure 8 The structure block diagram of the computer device according to the embodiment of the present application is schematically shown. Figure 8 As shown. The computer device includes a processor A01, a network interface A02, a display screen A04, an input device A05 and a memory (not shown in the figure) connected through a system bus. Among them, the processor A01 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes an internal memory A03 and a non-volatile storage medium A06. The non-volatile storage medium A06 stores an operating system B01 and a computer program B02. The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A06. The network interface A02 of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor A01, a unified authentication method based on the Oauth authorization framework is implemented. The display screen A04 of the computer device can be a liquid crystal display or an electronic ink display, and the input device A05 of the computer device can be a touch layer covered on the display screen, or a button, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse.

[0135] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0136] In one embodiment, the present application also provides a machine-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the unified authentication method based on the Oauth authorization framework in the above embodiment is implemented.

[0137] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0138] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0139] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A unified authentication method based on the Oauth authorization framework, characterized in that: A front-end system applied to a portal system, the portal system includes a unified identity authentication system, the service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published, and the page of the front-end system integrates link entrances of multiple application systems, the method includes: In response to a portal system access request initiated by a user, determining whether there is a portal system session of the user; If there is no portal system session for the user, jump to the login page of the unified identity authentication system to obtain the user's login information, and call the service interface to enable the unified identity authentication system to verify the login information, generate session information for establishing a session required for the user to access the application system after the verification is passed, and return a unified authorization code based on the Oauth authorization framework in the session information, and then display the page of the front-end system; In response to an operation request containing the unified authorization code triggered by the user through a link entry of the target application system, determining whether there is a target application system session of the user; If there is a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or there is no target application system session of the user, the service interface is called. If user information obtained by the unified identity authentication system based on the unified authorization code contained in the operation request is returned by the service interface, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

2. The unified authentication method based on the Oauth authorization framework according to claim 1 is characterized in that: After the verification is passed, session information for establishing a session required for the user to access the application system is generated, including: According to the user's login information and the user information registered by the user when registering on the login page of the unified identity authentication system, a unified authorization code based on the Oauth authorization framework is generated using a preset password mode; Generate session information for establishing a session required for the user to access the application system, wherein the session information includes the unified authorization code, the access token, and the refresh token.

3. The unified authentication method based on the Oauth authorization framework according to claim 1, characterized in that: Also includes: If there is a target application system session of the user, and the unified authorization code bound to the current session matches the unified authorization code contained in the operation request, then jump to the operation page of the target application system.

4. The unified authentication method based on the Oauth authorization framework according to claim 1, characterized in that: Also includes: If the user information returned by the service interface and obtained by the unified identity authentication system according to the unified authorization code contained in the operation request is not received or the session times out, the process jumps to the login page of the unified identity authentication system.

5. A unified authentication method based on the Oauth authorization framework, characterized in that: A unified identity authentication system applied to a portal system, wherein a service interface provided by the unified identity authentication system is pre-registered with a service gateway of the portal system and published, wherein the portal system includes a front-end system, wherein a page of the front-end system integrates link entrances of multiple application systems, and wherein the method includes: Receiving login information of a user transmitted through an internal login page when the front-end system responds to a portal system access request initiated by a user and does not have a portal system session of the user; Receiving a request for calling the service interface sent by the front-end system; Verify the login information. If the verification is successful, generate session information for establishing a session required for the user to access the application system, and pass the unified authorization code based on the Oauth authorization framework in the session information to the front-end system, so that the front-end system can display its own page, receive the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a session with the target application system of the user; Receiving a request for calling the service interface sent by the front-end system when the front-end system has a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or does not have a target application system session of the user; The user information is obtained according to the unified authorization code contained in the operation request, and the user information is transmitted to the front-end system so that the front-end system performs the following processing based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

6. The unified authentication method based on the Oauth authorization framework according to claim 5, characterized in that: Generate session information for establishing a session required for the user to access the application system, including: According to the user's login information and the user information registered by the user when registering on the login page of the unified identity authentication system, a unified authorization code based on the Oauth authorization framework is generated using a preset password mode; Generate session information for establishing a session required for the user to access the application system, wherein the session information includes the unified authorization code, the access token, and the refresh token.

7. A front-end system of a portal system, characterized in that: The portal system includes a unified identity authentication system. The service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published. The page of the front-end system integrates the link entrances of multiple application systems. The front-end system includes: The first module is used to respond to a portal system access request initiated by a user and determine whether there is a portal system session of the user; The second module is used to jump to the login page of the unified identity authentication system to obtain the user's login information when there is no portal system session of the user, and call the service interface to enable the unified identity authentication system to verify the login information, generate session information for establishing a session required for the user to access the application system after the verification is passed, and return a unified authorization code based on the Oauth authorization framework in the session information, and then display the page of the front-end system; The third module is used to respond to the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a target application system session of the user; The fourth module is used to call the service interface when there is a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request, or there is no target application system session of the user. If user information obtained by the unified identity authentication system according to the unified authorization code contained in the operation request is returned by the service interface, the following processing is performed based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

8. A unified identity authentication system, characterized in that: The service interface provided by the unified identity authentication system is pre-registered with the service gateway of the portal system and published. The portal system includes a front-end system. The page of the front-end system integrates the link entrances of multiple application systems. The unified identity authentication system includes: A fifth module is used to receive the user's login information transmitted by the user through the internal login page when the front-end system responds to the portal system access request initiated by the user and does not have the portal system session of the user; The sixth module receives a request for calling the service interface sent by the front-end system; The seventh module is used to verify the login information. If the verification is successful, session information for establishing a session required for the user to access the application system is generated, and the unified authorization code based on the Oauth authorization framework in the session information is passed to the front-end system, so that the front-end system can display its own page, receive the operation request containing the unified authorization code triggered by the user through the link entrance of the target application system, and determine whether there is a session with the target application system of the user; An eighth module is used to receive a request for calling the service interface sent by the front-end system when the front-end system has a target application system session of the user and the unified authorization code bound to the current session does not match the unified authorization code contained in the operation request or does not have the target application system session of the user; The ninth module is used to obtain user information according to the unified authorization code contained in the operation request, and transmit the user information to the front-end system, so that the front-end system performs the following processing based on the received user information: identity authentication, responding to the user's login request, and creating the user's target application system session.

9. A computer device, characterized in that: include: a memory configured to store instructions; as well as A processor is configured to call the instructions from the memory and implement the unified authentication method based on the Oauth authorization framework according to any one of claims 1 to 6 when executing the instructions.

10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores instructions, which are used to enable a machine to execute a unified authentication method based on an Oauth authorization framework according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Single sign-on method and system based on virtual account authentication

    CN116170234A

  • Third-party open authorization device and method

    CN117997608A