Identity authentication method and device

By using the application identifier and LDAP protocol in the IAM system, two authentications and determining permission information are solved, and the IAM system cannot control user access rights is improved, and the security of the application system is improved.

CN120234791APending Publication Date: 2025-07-01NETSUNION CLEARING CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311865649.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

When using the IAM system for identity authentication, the user's access rights cannot be effectively controlled, resulting in security risks.

Method used

By introducing application identifiers in the IAM system, combining LDAP protocol for identity authentication, first authenticate the user name, obtain path information, then authenticate the user password, and determine the permission information based on the application identifier to confirm whether the user has access rights.

Benefits of technology

It realizes control over user access rights, improves the access security of the application system, and avoids the risk that users can still access business data without access rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234791A_ABST
    Figure CN120234791A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication method and device, and the method comprises the steps that an IAM system receives a first authentication request sent by an application system, and the first authentication request comprises an application identifier of the application system and a user name of a first user; under the condition that the user name authentication is passed, path information is returned, and the path information comprises an application identifier; receiving a second authentication request sent by the application system, wherein the second authentication request comprises path information and a user password of the first user; determining permission information of the application system according to the application identifier under the condition that the user password authentication is passed; and when it is determined that the first user has the access permission to the application system according to the permission information, returning authentication passing information. Therefore, the IAM system can authenticate the access authority of the user on the basis of authenticating the user name and the password of the user, so that the control on the user authority can be realized, and the access safety of the application system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and particularly to an identity authentication method and device. Background Art

[0002] Generally, there are multiple services within an enterprise or company, and each service can correspond to an application system (also referred to as a business system). Users (such as enterprise employees or company employees) can access different business data by accessing different application systems. To improve the access security of business data, when a user accesses a business system, the user can also be authenticated, and the user is allowed to access the application system only when the authentication is passed.

[0003] In the related art, different application systems can support different authentication protocols. To facilitate the management of identity authentication for multiple application systems, multiple application systems can be connected to an Identity and Access Management (IAM) system, and the IAM system can perform identity authentication uniformly based on the Lightweight Directory Access Protocol (LDAP) protocol. Specifically, when a user wants to access a certain application system, the application system can send the username and password entered by the user to the IAM system. After the IAM system authenticates the username and password of the user and passes the authentication, it can return an authentication passed message. At this time, the application system can allow the user to access the business data in the application system. However, in actual applications, to improve security, the business data in the application system has access permissions, and the user is allowed to access only when the user has access permissions, otherwise the user is not allowed to access. However, the above-mentioned identity authentication solution based on the IAM system cannot control the access permissions of users, resulting in security risks. Summary of the Invention

[0004] Embodiments of this application provide an identity authentication method and device, which are used to solve the problem that when the IAM system authenticates users accessing an application system, the access permissions of users cannot be controlled, resulting in security risks.

[0005] To solve the above technical problems, the embodiments of this application are implemented as follows:

[0006] In a first aspect, an identity authentication method is proposed, which is applied to an IAM system. The IAM system performs identity authentication based on the LDAP protocol. The method includes:

[0007] Receiving a first authentication request sent by an application system, where the first authentication request includes an application identifier of the application system and a username of a first user;

[0008] When the authentication of the user name is passed, return path information, and the application identifier is included in the path information;

[0009] Receive a second authentication request sent by the application system, where the second authentication request includes the path information and the user password of the first user;

[0010] When the authentication of the user password is passed, determine the permission information of the application system according to the application identifier;

[0011] When it is determined according to the permission information that the first user has access rights to the application system, return authentication passed information.

[0012] In a second aspect, an identity authentication method is proposed, which is applied to an application system. The method includes:

[0013] Receive an access request from a first user, where the access request includes the user name and user password of the first user;

[0014] Send a first authentication request to the IAM system. The IAM system performs identity authentication based on the LDAP protocol. The first authentication request includes the application identifier of the application system and the user name;

[0015] Receive the path information returned by the IAM system. The path information is sent by the IAM system when the authentication of the user name is passed, and the application identifier is included in the path information;

[0016] Send a second authentication request to the IAM system, where the second authentication request includes the path information and the user password;

[0017] When receiving the authentication passed information returned by the IAM system, allow the first user to access the application system. The authentication passed information is sent by the IAM system after the authentication of the user password is passed, when determining the permission information of the application system according to the application identifier and determining that the first user has access rights to the application system according to the permission information.

[0018] In a third aspect, an identity authentication device is proposed, which is applied to an IAM system. The IAM system performs identity authentication based on the LDAP protocol. The device includes:

[0019] A first receiving module, which receives a first authentication request sent by an application system. The first authentication request includes the application identifier of the application system and the user name of the first user;

[0020] The first sending module returns path information including the application identifier when the authentication of the user name is passed.

[0021] The second receiving module receives a second authentication request sent by the application system, where the second authentication request includes the path information and the user password of the first user.

[0022] The determination module determines the permission information of the application system according to the application identifier when the authentication of the user password is passed.

[0023] The second sending module returns authentication passed information when it is determined according to the permission information that the first user has access permission to the application system.

[0024] In a fourth aspect, an identity authentication device is proposed, which is applied to an application system. The device includes:

[0025] The first receiving module receives an access request of a first user, where the access request includes the user name and user password of the first user.

[0026] The first sending module sends a first authentication request to the IAM system for identity authentication based on the LDAP protocol. The first authentication request includes the application identifier of the application system and the user name.

[0027] The second receiving module receives the path information returned by the IAM system, which is sent by the IAM system when the authentication of the user name is passed. The path information includes the application identifier.

[0028] The second sending module sends a second authentication request to the IAM system, where the second authentication request includes the path information and the user password.

[0029] The processing module allows the first user to access the application system when receiving the authentication passed information returned by the IAM system. The authentication passed information is sent by the IAM system after the authentication of the user password is passed, when determining the permission information of the application system according to the application identifier and determining that the first user has access permission to the application system according to the permission information.

[0030] In a fifth aspect, an electronic device is proposed, which includes:

[0031] A processor;

[0032] A memory for storing executable instructions of the processor;

[0033] Wherein, the processor is configured to execute the instructions to implement the method described in the first aspect or the second aspect above.

[0034] In a sixth aspect, a computer-readable storage medium is provided. When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method described in the first aspect or the second aspect above.

[0035] The above at least one technical solution adopted in the embodiments of the present application can achieve the following beneficial effects:

[0036] In the embodiments of the present application, the permission control of the application system can be implemented by the IAM system. That is, when the IAM system authenticates a user, on the basis of authenticating the user name and password of the user, it will also authenticate the access permission of the user, and only when the user has the access permission will it confirm that the authentication of the user's identity is passed. Thus, the permission control of the user can be realized, and the access security of the application system can be improved. In addition, since in the process of authenticating the user's identity, when the application system sends an authentication request for the user name to the IAM system, it can carry the application identifier in the authentication request, and the IAM system can carry the application identifier in the path information when returning the path information. Therefore, when the application system sends an authentication request for the user password to the IAM system, it can carry the application identifier in the request, so that it is convenient for the IAM system to confirm which application system the authentication request comes from according to the application identifier, and then determine the permission information of the application system and authenticate the access permission of the user according to the permission information, realizing the control of the user's access permission. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.

[0038] Figure 1 is a schematic diagram of identity authentication based on the IAM system in the prior art;

[0039] Figure 2 is a schematic system architecture diagram provided by an embodiment of the present application;

[0040] Figure 3 is a schematic flowchart of an identity authentication method according to an embodiment of the present application;

[0041] Figure 4 is a schematic flowchart of an identity authentication method according to an embodiment of the present application;

[0042] Figure 5 It is a schematic flowchart of the interaction between an IAM system and an application system according to an embodiment of the present application;

[0043] Figure 6 It is a schematic diagram of the access permissions of a user to different application systems according to an embodiment of the present application;

[0044] Figure 7 It is a schematic structural diagram of an electronic device according to an embodiment of the present application;

[0045] Figure 8 It is a schematic structural diagram of an identity authentication device according to an embodiment of the present application;

[0046] Figure 9 It is a schematic structural diagram of an identity authentication device according to an embodiment of the present application;

[0047] Figure 10 It is a schematic structural diagram of an identity authentication system according to an embodiment of the present application. Detailed implementation manners

[0048] In the related art, after multiple application systems are connected to the IAM system, when the IAM system authenticates the users accessing the application systems based on the LDAP protocol, taking a certain application system as an example, the authentication process can be as Figure 1 shown. Figure 1 In, when a user accesses the application system, an access request can be sent to the application system, and the access request includes a username and a password. After receiving the access request, the application system can send the username and password in the access request to the IAM system, and the IAM system can authenticate the username and password of the user based on the LDAP protocol. If the authentication is passed, the IAM system can return an authentication passed message to the application system, and at this time the application system can allow the user to access the application system. If the authentication fails, the IAM system can return an authentication failed message to the application system, and at this time the application system will reject the user's access.

[0049] In actual applications, the business data in the application system usually has access permissions, and users are allowed to access only when they have access permissions, otherwise they will not be allowed to access. However, Figure 1 the authentication process shown only authenticates the username and password of the user, and does not control the access permissions of the user. In this way, there will be a problem that the user can still access the business data without access permissions, resulting in security risks in the application system.

[0050] In order to implement user privilege control, in the prior art, an application system capable of user privilege control is usually connected to an IAM system. In this way, when authenticating a user, the IAM system can authenticate the username and password, and after successful authentication, the application system can control the user's access privileges. However, in actual applications, many application systems cannot implement privilege control, which results in these application systems being unable to be connected to the IAM system, and thus unable to uniformly manage the identity authentication of multiple application systems through the IAM system.

[0051] To solve the above technical problems, the embodiments of the present application provide an identity authentication method and device, which can implement the privilege control of the application system by the IAM system. That is, when the IAM system authenticates a user, on the basis of authenticating the username and password of the user, it will also authenticate the user's access privileges, and only when the user has access privileges will it confirm that the user's identity authentication is passed. Thus, it is possible to implement user privilege control and improve the access security of the application system. In addition, since during the process of authenticating a user, when the application system sends an authentication request for the username to the IAM system, it can carry the application identifier in the authentication request, and the IAM system can carry the application identifier in the path information when returning the path information. Therefore, when the application system sends an authentication request for the user password to the IAM system, it can carry the application identifier in the request, which can facilitate the IAM system to confirm which application system the authentication request comes from according to the application identifier, and then determine the privilege information of the application system and authenticate the user's access privileges according to the privilege information to implement the control of the user's access privileges.

[0052] To enable those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present application.

[0053] It should be noted that the technical solutions provided by the embodiments of the present application can be applied to the scenario where the IAM system uniformly manages the identity authentication of multiple application systems. These multiple application systems can be the multiple application systems corresponding to multiple services involved in an enterprise or a company. For any one of the application systems, when a user wants to access the application system, the IAM system can authenticate the user through the technical solutions provided by the embodiments of the present application.

[0054] The following is combined with Figure 2Describe a possible application scenario of the technical solution provided by the embodiments of the present application.

[0055] Figure 2 It is a schematic diagram of a system architecture provided by the embodiments of the present application. Figure 2 In the shown system framework, it includes an IAM system 21 and multiple application systems 22, 23, ……, 2N. The multiple application systems 22, 23, ……, 2N are all connected to the IAM system 21, and the IAM system 21 uniformly manages the identity authentication of the multiple application systems 22, 23, ……, 2N. Among them, the multiple application systems 22, 23, ……, 2N all support the LDAP protocol, and the IAM system 21 can authenticate the users requesting to access the application systems based on the LDAP protocol.

[0056] In Figure 2 when the IAM system 21 performs identity authentication, taking the authentication of the user accessing the application system 22 as an example, when a user wants to access the application system 22, the user can send an access request to the application system 22, and the access request includes the username and password. After receiving the access request, the application system 22 can send the username and password in the access request to the IAM system 21. The IAM system 21 can first authenticate the username and password based on the LDAP protocol. If the authentication is passed, the IAM system 21 can continue to authenticate the user's access permission, that is, determine whether the user has the access permission to the application system 22. If the user has the access permission to the application system 22, the IAM system 21 can return an authentication passed message to the application system 22, otherwise, it can return an authentication failed message to the application system 22. Thus, on the basis of realizing the authentication of the username and password on the IAM system side, the control of the user's access permission can be further realized, thereby improving the security.

[0057] The following will detail the technical solutions provided by the embodiments of the present application in conjunction with the accompanying drawings.

[0058] Figure 3 It is a schematic flowchart of an identity authentication method according to an embodiment of the present application. Figure 3 The shown identity authentication method can be applied to Figure 2 the shown IAM system 21, and this IAM system performs identity authentication based on the LDAP protocol. Figure 3 The shown identity authentication method includes the following steps.

[0059] S302: Receive a first authentication request sent by an application system. The first authentication request includes the application identifier of the application system and the username of the first user.

[0060] When a first user wants to access an application system, the first user can send an access request to the application system. The access request may include the username and user password of the first user. After receiving the access request from the first user, the application system may request the IAM system to authenticate the first user. In the embodiments of the present application, when the IAM system performs authentication, it is specifically based on the LDAP protocol for authentication. In the related art, the standard authentication process of the LDAP protocol includes two authentication processes, one is the authentication process for the username and the other is the authentication process for the user password. Thus, when the application system requests the IAM system to authenticate the first user, the application system can send a first authentication request (i.e., the username authentication request) to the IAM system. The first authentication request includes the username of the first user, and the first authentication request is used to request the IAM system to authenticate the username of the first user. At this time, the IAM system can receive the first authentication request sent by the application system.

[0061] In the embodiments of the present application, when the application system sends the first authentication request to the IAM system, it can also carry the application identifier of the application system in the first authentication request. The application identifier of the application system is unique and can have a one-to-one correspondence with the application system. After the application system carries the application identifier in the first authentication request and sends it to the IAM system, the IAM system can determine which application system the first authentication request comes from based on the application identifier in the first authentication request. Among them, the application identifier can be pre-assigned by the IAM system to the application system, or, alternatively, it can be determined by the application system itself, as long as different application systems can be distinguished.

[0062] After receiving the first authentication request sent by the application system, the IAM system can authenticate the username carried in the first authentication request. When authenticating the username, it can specifically query in the IAM system whether the username exists. The IAM system can pre-store multiple usernames, and the multiple usernames can be registered and legal usernames. If the username of the first user is queried in the IAM system, it can indicate that the username exists. At this time, it can be determined that the authentication of the username is passed. If the username of the first user is not queried in the IAM system, it can indicate that the username does not exist. At this time, it can be determined that the authentication of the username is not passed, that is, the authentication of the username fails.

[0063] When the user name authentication is passed, the IAM system can execute S304. When the user name authentication fails, that is, when the user name authentication fails, the IAM system can return an authentication failure message to the application system. At this time, the IAM system does not need to execute S304 to S310, that is, it does not need to execute the subsequent password authentication and permission authentication steps. For the application system, after receiving the authentication failure message returned by the IAM system, it can reject the access of the first user.

[0064] S304: When the user name authentication is passed, return path information, and the path information includes an application identifier.

[0065] When the user name authentication is passed, based on the standard verification process of the LDAP protocol, the IAM system can return path information to the application system, so that the subsequent application system can send a password authentication request to the IAM system based on the path information to authenticate the user password. In the prior art, when the IAM system returns path information to the application system, it specifically returns the complete Distinguished Name (DN) path of the user to the application system. However, there is no application identifier of the application system in the DN path. In this way, when the subsequent application system sends a password authentication request to the IAM system based on the DN path, since there is no application identifier in the DN path, the IAM system will not be able to determine which application system the password authentication request comes from, and thus will not be able to determine the corresponding permission information and control the user's permissions. In the embodiments of the present application, in order to facilitate the IAM system to implement user permission control, when the IAM system returns path information to the application system, in addition to returning the complete DN path of the user to the application system, it can also return the application identifier to the application system. In this way, when the application system sends a password authentication request to the IAM system subsequently, it can carry the path information with the application identifier and the user password in the password authentication request and send it to the IAM system. The IAM system can determine which application system the password authentication request comes from according to the application identifier in the path information, and then can obtain the permission information of the application system and implement user permission control according to the permission information.

[0066] Optionally, in some embodiments, when the IAM system passes the user name authentication and returns path information to the application system, it may include:

[0067] When the user name authentication is passed, obtain the complete DN path of the first user;

[0068] Insert the application identifier into the DN path to obtain path information;

[0069] Return the path information.

[0070] The complete DN path of the first user is the Ldap directory path, which can be used to identify the complete path of the object in the active directory. Specifically, it can be determined based on existing methods and will not be elaborated here. The application identifier can be the application identifier included in the first authentication request sent by the application system to the IAM system in S302 above. When inserting the application identifier into the DN path, the application identifier can be spliced into the DN path separated by the # sign. Of course, the application identifier can also be inserted into the DN path in other ways, and the specific insertion method is not specifically limited here. After inserting the application identifier into the DN path, a DN path containing the application identifier can be obtained, and this DN path is the path information. At this time, the IAM system can return the path information to the application system.

[0071] S306: Receive the second authentication request sent by the application system. The second authentication request includes the path information and the user password of the first user.

[0072] After the IAM system authenticates the user name and returns the path information to the application system, the application system can receive the path information returned by the IAM system. When the application system receives the path information, it can confirm that the IAM system has authenticated the user name successfully. At this time, the application system can continue to execute the subsequent authentication steps, that is, request the IAM system to authenticate the user password. When the application system requests the IAM system to authenticate the user password, it can send a second authentication request to the IAM system. The second authentication request is a password authentication request, which includes the path information returned by the IAM system and the user password entered by the first user when requesting access to the application system. The second authentication request is used to request the IAM system to authenticate the user password. After the application system sends the second authentication request to the IAM system, the IAM system can receive the second authentication request from the application system.

[0073] After the IAM system receives the second authentication request sent by the application system, it can authenticate the user password of the first user. When performing password authentication, based on the standard authentication process of the LDAP protocol, password authentication needs to be performed according to the complete DN path of the first user and the user password. However, in the embodiment of the present application, the path information received by the IAM system includes both the complete DN path of the user and the application identifier. Therefore, when the IAM system performs password authentication, it needs to extract the complete DN path of the user from the path information, and then perform password authentication according to the extracted DN path and the user password. Among them, the specific implementation method of the IAM system for password authentication according to the DN path and the user password can refer to the specific implementation in the related technology and will not be elaborated here.

[0074] After the IAM system authenticates the user password, if the authentication is successful, S308 can be executed. If the authentication fails, that is, the authentication fails, the IAM system can return an authentication failure message to the application system. At this time, the IAM system does not need to execute S308 to S310, that is, it does not need to execute the subsequent permission authentication steps. For the application system, after receiving the authentication failure message returned by the IAM system, it can reject the access of the first user.

[0075] S308: When the user password authentication is successful, determine the permission information of the application system according to the application identifier.

[0076] When the IAM system authenticates the user password successfully, it can further authenticate the access permission of the first user to implement the permission control of the first user. When authenticating the access permission of the first user, the IAM system can extract the application identifier in the second authentication request received in S306 and determine the permission information of the application system according to the application identifier. Specifically, multiple different application identifiers and the permission information corresponding to each application identifier can be pre-stored in the IAM system. In this way, when determining the permission information of the application system according to the application identifier, the permission information corresponding to the application identifier can be queried in the pre-stored permission information, and the queried permission information is the permission information of the application system. After determining the permission information of the application system, the access permission of the first user can be authenticated according to the permission information.

[0077] Optionally, in some embodiments, the permission information of the application system may include role information. Here, for the convenience of distinguishing from the role information of the first user, the role information included in the permission information may be represented as the first role information. The first role information includes one or more roles, and the one or more roles have access permissions to the application system. When authenticating the first user according to the first role information, the following steps may be included:

[0078] Obtain the second role information of the first user;

[0079] Determine whether the second role information matches the first role information;

[0080] If they match, determine that the first user has access permissions to the application system;

[0081] If they do not match, determine that the first user does not have access permissions to the application system.

[0082] The second role information can be pre-stored in the IAM system. When authenticating the permissions of the first user, the IAM system can query the second role information based on the username of the first user, and thus obtain the second role information. Of course, the second role information can also be obtained through other means, which is not specifically limited here. After obtaining the second role information, it can be matched with the first role information that has access permissions to the application system to determine whether the first role information includes the second role information. If it includes, it is determined that the second role information matches the first role information; if it does not include, it can be determined that the second role information does not match the first role information. In the case of a match, it can be determined that the first user has access permissions to the application system; in the case of a mismatch, it can be determined that the first user does not have access permissions to the application system.

[0083] When the IAM system determines that the first user has access permissions to the application system, it can execute S310. When the IAM system determines that the first user does not have access permissions to the application system, it can return an authentication failure message to the application system. For the application system, after receiving the authentication failure message returned by the IAM system, it can reject the access of the first user.

[0084] S310: When it is determined that the first user has access permissions to the application system based on the permission information, return an authentication passed message.

[0085] When it is determined that the first user has access permissions to the application system, the IAM system can return an authentication passed message to the application system. For the application system, after receiving the authentication passed message returned by the IAM system, it can allow the first user to access the application system.

[0086] In this way, since the permission control of the application system can be implemented by the IAM system, that is, when the IAM system authenticates the user's identity, on the basis of authenticating the user's username and password, it will also authenticate the user's access permissions and confirm that the user's identity authentication is passed only when the user has access permissions. Thus, the permission control of the user can be realized, and the access security of the application system can be improved. In addition, since during the process of authenticating the user's identity, when the application system sends an authentication request for the username to the IAM system, it can carry the application identifier in the authentication request, and the IAM system can carry the application identifier in the path information when returning the path information. Therefore, when the application system sends an authentication request for the user's password to the IAM system, it can carry the application identifier in the request, which can facilitate the IAM system to confirm which application system the authentication request comes from according to the application identifier, and then determine the permission information of the application system and authenticate the user's access permissions according to the permission information to realize the control of the user's access permissions.

[0087] Figure 4 It is a schematic flowchart of an identity authentication method according to an embodiment of the present application. Figure 4 The identity authentication method shown can be applied to Figure 2 any of the application systems shown. Figure 4 The identity authentication method shown includes the following steps.

[0088] S402: Receive an access request from the first user, where the access request includes the username and user password of the first user.

[0089] When the first user wants to access the application system, the first user can send an access request to the application system, and at this time, the application system can receive the access request from the first user. Among them, the access request can include the username and user password of the first user.

[0090] S404: Send a first authentication request to the IAM system. The IAM system performs identity authentication based on the LDAP protocol. The first authentication request includes the application identifier of the application system and the username.

[0091] After receiving the access request from the user, the application system can request the IAM system to perform identity authentication on the first user. As Figure 3 recorded in the embodiment shown, when the IAM system performs identity authentication, it performs identity authentication based on the LDAP protocol. The standard authentication process of the LDAP protocol includes two authentication processes, one is the authentication process for the username, and the other is the authentication process for the user password. Therefore, when the application system requests the IAM system to perform identity authentication on the first user, it can first send a first authentication request to the IAM system. The first authentication request includes the username of the first user, and the first authentication request is used to request the IAM system to authenticate the username of the first user.

[0092] In the embodiment of the present application, when the application system sends the first authentication request to the IAM system, it can also carry the application identifier of the application system in the first authentication request, so that the IAM system can determine which application system the first authentication request comes from based on the application identifier in the first authentication request. The application identifier can be pre-assigned to the application system by the IAM system, or, alternatively, it can be determined by the application system itself, as long as different application systems can be distinguished.

[0093] After receiving the first authentication request, the IAM system can authenticate the username of the first user. The specific implementation method can refer to Figure 3The corresponding content in the illustrated embodiments will not be repeated here. After the IAM system authenticates the username of the first user, if the authentication is successful, the IAM system can return path information to the application system. At this time, the application system can execute S406. If the authentication fails, that is, the authentication fails, the IAM system can return authentication failure information to the application system. After receiving the authentication failure information, the application system can reject the access of the first user. At this time, the application system does not need to execute the subsequent S406 to S410.

[0094] S406: Receive the path information returned by the IAM system. The path information is sent by the IAM system when the username authentication is successful. The path information includes an application identifier.

[0095] The application identifier included in the path information can be the application identifier sent by the application system to the IAM system in S404. In addition to the application identifier, the path information can also include the complete DN path of the first user. The specific implementation method for the IAM system to determine and return the path information can be referred to Figure 3 the corresponding content in the illustrated embodiments, which will not be repeated here.

[0096] S408: Send a second authentication request to the IAM system. The second authentication request includes the path information and the user password.

[0097] After receiving the path information, the application system can confirm that the IAM system has successfully authenticated the username of the first user. At this time, the application system can continue to request the IAM system to authenticate the user password of the first user. When the application system requests the IAM system to authenticate the user password, it can send a second authentication request to the IAM system. The second authentication request is a password authentication request. The second authentication request can include the path information returned by the IAM system and the user password of the first user. The second authentication request is used to request the IAM system to authenticate the user password of the first user.

[0098] After receiving the second authentication request sent by the application system, the IAM system can authenticate the user password of the first user. The specific implementation method can be referred to Figure 3The corresponding content in the illustrated embodiment will not be repeated here. After the IAM system authenticates the user password of the first user, if the authentication is successful, the IAM system can continue to authenticate the user's access permission. If the authentication fails, that is, the authentication fails, the IAM system can return an authentication failure message to the application system. After receiving the authentication failure message, the application system can reject the access of the first user. At this time, the application system does not need to execute the subsequent S410. Among them, when the IAM system authenticates the access permission of the first user, it can first determine the permission information of the application system according to the application identifier carried in the second authentication request, and then authenticate the access permission of the first user according to the permission information. The specific implementation method can be referred to Figure 3 The corresponding content in the illustrated embodiment will not be repeated here. After the IAM system authenticates the access permission of the first user, if it is determined that the first user has the access permission to the application system, it can return an authentication success message to the application system. At this time, the application system can execute S410. If it is determined that the first user does not have the access permission to the application system, it can return an authentication failure message to the application system. After receiving the authentication failure message, the application system can reject the access of the first user.

[0099] S410: In the case of receiving the authentication success message returned by the IAM system, allow the first user to access the application system. The authentication success message is sent by the IAM system after the user password authentication is successful and after determining the permission information of the application system according to the application identifier and determining that the first user has the access permission to the application system.

[0100] In the case of receiving the authentication success message sent by the IAM system, the application system can confirm that the user name and user password of the first user are correct, and the first user has the access permission to the application system. At this time, the application system can allow the first user to access the application system.

[0101] In this way, since the permission control of the application system can be implemented by the IAM system, that is, when the IAM system authenticates a user, in addition to authenticating the user name and password of the user, it will also authenticate the user's access permission, and confirm that the user's identity authentication is passed only when the user has the access permission. Thus, the permission control of the user can be realized, and the access security of the application system can be improved. In addition, since during the process of authenticating the user, when the application system sends an authentication request for the user name to the IAM system, it can carry the application identifier in the authentication request, and the IAM system can carry the application identifier in the path information when returning the path information. Therefore, when the application system sends an authentication request for the user password to the IAM system, it can carry the application identifier in the request, which can facilitate the IAM system to confirm which application system the authentication request comes from according to the application identifier, and then determine the permission information of the application system and authenticate the user's access permission according to the permission information, so as to realize the control of the user's access permission.

[0102] To facilitate the understanding of the technical solution provided by the embodiments of the present application, reference may be made to Figure 5 . Figure 5 It is a schematic flowchart of the interaction between the IAM system and the application system in an embodiment of the present application. Figure 5 In it, the application system can be represented as an LDAP client, and the IAM system can be represented as an LDAP server. The IAM system authenticates the users accessing the application system based on the LDAP protocol. Figure 5 The embodiment shown may specifically include the following steps.

[0103] S1: The application system receives an access request from a first user.

[0104] When the first user wants to access the application system, it can send an access request to the application system, and the application system can receive the access request from the first user. Among them, the access request may include the user name and user password of the first user.

[0105] S2: The application system sends a first authentication request to the IAM system, and the first authentication request includes the application identifier of the application system and the user name.

[0106] For example, the first authentication request may include uid=appA, ou=users, ou=system.

[0107] S3: The IAM system authenticates the user name.

[0108] When the IAM system authenticates the user name, it can query in the system whether the user name exists. For example, the IAM system can use the query condition (&objectClass=Person)(uid=zhangsan)) to query the user name. If the user name is queried, it can be determined that the authentication of the user name is passed. If the user name is not queried, it can be determined that the authentication of the user name fails.

[0109] When the authentication of the user name is passed, the IAM system can execute S4. When the authentication of the user name fails, the IAM system can execute S10.

[0110] S4: The IAM system returns path information to the application system, and the path information includes the application identifier.

[0111] When the IAM system returns the path information, it can first determine the complete DN path of the first user, then insert the application identifier into the DN path to obtain the path information, and finally return the path information to the application system. For example, if the complete DN path of the first user is uid=zhangsan,ou=users,dc=demo,dc=com, the path information can be uid=zhangsan#appA,ou=users,dc=demo,dc=com, which is obtained by splicing the application identifier appA separated by # into the DN path.

[0112] S5: The application system sends a second authentication request to the IAM system, and the second authentication request includes the path information and the user password.

[0113] S6: The IAM system authenticates the user password.

[0114] When the IAM system authenticates the user password, it can extract the complete DN path of the first user from the path information, and then perform password authentication based on the DN path and the user password. After the IAM system authenticates the user password, if the authentication is passed, it can execute S7. If the authentication fails, that is, the authentication fails, it can execute S10.

[0115] S7: The IAM system determines the permission information of the application system according to the application identifier, and authenticates the access permission of the first user according to the permission information.

[0116] The permission information of the application system may include role information with access permissions to the application system. When authenticating the access permissions of the first user, it can be determined whether the role information of the first user matches the role information included in the permission information. If they match, it can be stated that the first user has access permissions to the application system, and the access permission authentication for the first user passes. At this time, S8 can be executed. If they do not match, it can be stated that the first user does not have access permissions to the application system, and the access permission authentication for the first user fails. At this time, S10 can be executed.

[0117] S8: The IAM system returns an authentication passed message to the application system.

[0118] S9: The application system allows the first user to access the application system.

[0119] S10: The IAM system returns an authentication failed message to the application system.

[0120] S11: The application system rejects the access of the first user.

[0121] For the specific implementation manners of the above S1 to S11, reference can be made to Figure 3 and Figure 4 the specific implementation of the corresponding steps in the illustrated embodiments, which will not be elaborated here.

[0122] Based on Figure 5 the illustrated embodiments, assuming the access permissions of the users are as Figure 6 shown, Figure 6 which shows the roles owned by users Zhang San and Li Si respectively and the system access permissions of each role. Then, when Zhang San and Li Si request to access the security audit system, in the case where the user names and passwords of Zhang San and Li Si are both authenticated successfully, since Zhang San has system access permissions and Li Si does not have system access permissions, Zhang San can be allowed to access, and Li Si is not allowed to access.

[0123] The technical solution provided by the embodiments of the present application can sink the permission management to the IAM system. On the one hand, it protects the access to systems without permission management capabilities, and on the other hand, it can also add an additional layer of access permission control to systems with access permissions, realizing the fallback of access control. In addition, when the IAM system performs identity authentication based on the LDAP protocol, it can also obtain the application identifier of the application system during the two-stage authentication process, thereby realizing the control of user permissions.

[0124] The above describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0125] Figure 7 is a schematic structural diagram of an electronic device according to an embodiment of the present application. Please refer to Figure 7 , at the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. Among them, the memory may include a memory, such as a high-speed random access memory (Random-Access Memory, RAM), and may also include a non-volatile memory, such as at least one disk memory, etc. Of course, the electronic device may also include other hardware required for other services.

[0126] The processor, network interface, and memory can be interconnected through an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 only uses a bidirectional arrow in

[0127] The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operation instructions. The memory may include a memory and a non-volatile memory, and provide instructions and data to the processor.

[0128] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming an identity authentication device at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:

[0129] Receive a first authentication request sent by the application system, where the first authentication request includes the application identifier of the application system and the username of the first user;

[0130] When the authentication of the user name is passed, return path information, and the application identifier is included in the path information;

[0131] Receive a second authentication request sent by the application system, where the second authentication request includes the path information and the user password of the first user;

[0132] When the authentication of the user password is passed, determine the permission information of the application system according to the application identifier;

[0133] When it is determined according to the permission information that the first user has the access permission to the application system, return the authentication passed information.

[0134] Or, used to perform the following operations:

[0135] Receive an access request from the first user, where the access request includes the user name and user password of the first user;

[0136] Send a first authentication request to the IAM system, and the IAM system performs identity authentication based on the LDAP protocol. The first authentication request includes the application identifier of the application system and the user name;

[0137] Receive the path information returned by the IAM system. The path information is sent by the IAM system when the authentication of the user name is passed, and the application identifier is included in the path information;

[0138] Send a second authentication request to the IAM system, and the second authentication request includes the path information and the user password;

[0139] When receiving the authentication passed information returned by the IAM system, allow the first user to access the application system. The authentication passed information is sent by the IAM system after the authentication of the user password is passed, when determining the permission information of the application system according to the application identifier and determining that the first user has the access permission to the application system according to the permission information.

[0140] The above as in this application Figure 7The method executed by the identity authentication device disclosed in the illustrated embodiment can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0141] The electronic device can also execute Figure 3 or Figure 4 the method, and implement the functions of the identity authentication device in Figure 3 or Figure 4 the illustrated embodiment. The embodiments of the present application will not be elaborated herein.

[0142] Of course, in addition to the software implementation method, the electronic device of the present application does not exclude other implementation methods, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and may also be hardware or a logic device.

[0143] The embodiments of the present application also propose a computer-readable storage medium. The computer-readable storage medium stores one or more programs. The one or more programs include instructions. When the instructions are executed by a portable electronic device including a plurality of application programs, the portable electronic device can be enabled to execute Figure 3 or Figure 4 the method of the illustrated embodiment, and specifically used to perform the following operations:

[0144] Receive a first authentication request sent by an application system, where the first authentication request includes an application identifier of the application system and a username of a first user;

[0145] When the username authentication is passed, return path information, where the path information includes the application identifier;

[0146] Receive a second authentication request sent by the application system, where the second authentication request includes the path information and a user password of the first user;

[0147] When the user password authentication is passed, determine the permission information of the application system according to the application identifier;

[0148] When it is determined according to the permission information that the first user has access permission to the application system, return authentication passed information.

[0149] Alternatively, be used to perform the following operations:

[0150] Receive an access request from a first user, where the access request includes a username and a user password of the first user;

[0151] Send a first authentication request to an IAM system, where the IAM system performs identity authentication based on the LDAP protocol, and the first authentication request includes an application identifier of the application system and the username;

[0152] Receive the path information returned by the IAM system, where the path information is sent by the IAM system when the username authentication is passed, and the path information includes the application identifier;

[0153] Send a second authentication request to the IAM system, where the second authentication request includes the path information and the user password;

[0154] When receiving the authentication passed information returned by the IAM system, allow the first user to access the application system, where the authentication passed information is sent by the IAM system after the user password authentication is passed, when determining the permission information of the application system according to the application identifier and determining that the first user has access permission to the application system according to the permission information.

[0155] Figure 8 It is a schematic structural diagram of an identity authentication device 80 according to an embodiment of the present application. Please refer to Figure 8, in a software implementation, the identity authentication device 80 may include: a first receiving module 81, a first sending module 82, a second receiving module 83, a determining module 84, and a second sending module 85, where:

[0156] The first receiving module 81 receives a first authentication request sent by the application system, and the first authentication request includes the application identifier of the application system and the user name of the first user;

[0157] The first sending module 82 returns path information when the user name authentication is passed, and the path information includes the application identifier;

[0158] The second receiving module 83 receives a second authentication request sent by the application system, and the second authentication request includes the path information and the user password of the first user;

[0159] The determining module 84 determines the permission information of the application system according to the application identifier when the user password authentication is passed;

[0160] The second sending module 85 returns authentication passed information when it is determined according to the permission information that the first user has access permission to the application system.

[0161] Optionally, in some embodiments, the first sending module 82, when the user name authentication is passed, returns path information, including:

[0162] When the user name authentication is passed, obtain the complete distinguished name (DN) path of the first user;

[0163] Insert the application identifier into the DN path to obtain the path information;

[0164] Return the path information.

[0165] Optionally, in some embodiments, after the second receiving module 83 receives the second authentication request sent by the application system, it further includes:

[0166] Extract the DN path from the path information;

[0167] Authenticate the password of the first user according to the DN path and the user password.

[0168] Optionally, in some embodiments, the permission information includes first role information with access permission to the application system; after the determining module 84 determines the permission information of the application system according to the application identifier, it further includes:

[0169] Obtain the second role information of the first user;

[0170] Determine whether the second role information matches the first role information;

[0171] If they match, determine that the first user has access rights to the application system;

[0172] If they do not match, determine that the first user does not have access rights to the application system.

[0173] Optionally, in some embodiments, the second sending module 85 further includes any one of the following:

[0174] If the user name authentication fails, return an authentication failure message;

[0175] If the user password authentication fails, return an authentication failure message;

[0176] If it is determined that the first user does not have access rights to the application system according to the permission information, return an authentication failure message.

[0177] The identity authentication device 80 provided by the embodiments of the present application can also execute Figure 3 the method, and implement the functions of the identity authentication device in Figure 3 the embodiments shown, which will not be elaborated herein in the embodiments of the present application.

[0178] Figure 9 is a schematic structural diagram of an identity authentication device 90 according to an embodiment of the present application. Please refer to Figure 9 , in a software implementation manner, the identity authentication device 90 may include: a first receiving module 91, a first sending module 92, a second receiving module 93, a second sending module 94, and a processing module 95, where:

[0179] The first receiving module 91 receives an access request of a first user, and the access request includes the user name and user password of the first user;

[0180] The first sending module 92 sends a first authentication request to the IAM system, and the IAM system performs identity authentication based on the LDAP protocol. The first authentication request includes the application identifier of the application system and the user name;

[0181] The second receiving module 93 receives the path information returned by the IAM system. The path information is sent by the IAM system when the user name authentication is passed, and the path information includes the application identifier;

[0182] A second sending module 94 sends a second authentication request to the IAM system, where the second authentication request includes the path information and the user password;

[0183] A processing module 95 allows the first user to access the application system when receiving the authentication passed information returned by the IAM system. The authentication passed information is sent by the IAM system after passing the authentication of the user password, and when determining the permission information of the application system according to the application identifier and determining that the first user has the access permission to the application system according to the permission information.

[0184] Optionally, in some embodiments, the processing module 95 rejects the first user from accessing the application system when receiving the authentication failed information returned by the IAM system;

[0185] Wherein, the authentication failed information is sent by the IAM system in any of the following situations:

[0186] The authentication of the user name fails;

[0187] The authentication of the user password fails;

[0188] It is determined according to the permission information that the first user does not have the access permission to the application system.

[0189] The identity authentication device 90 provided by the embodiments of the present application can also execute Figure 4 the method, and implement the functions of the identity authentication device in Figure 4 the embodiments shown. The embodiments of the present application will not be elaborated here.

[0190] The embodiments of the present application also provide an identity authentication system. Please refer to Figure 10 . Figure 10 It is a schematic structural diagram of an identity authentication system 100 according to an embodiment of the present application. Please refer to Figure 10 , Figure 10 The identity authentication system 100 shown includes an application system 101 and an IAM system 102, wherein:

[0191] The application system 101 receives an access request from a first user, where the access request includes the user name and user password of the first user; and sends a first authentication request to the IAM system 102. The IAM system 102 performs identity authentication based on the LDAP protocol, and the first authentication request includes the application identifier of the application system and the user name;

[0192] The IAM system 102 receives a first authentication request sent by the application system 101; when the user name authentication is passed, it returns path information to the application system 101, and the application identifier is included in the path information.

[0193] The application system 101 receives the path information returned by the IAM system 102; it sends a second authentication request to the IAM system 102, and the second authentication request includes the path information and the user password.

[0194] The IAM system 102 receives the second authentication request sent by the application system 101; when the user password authentication is passed, it determines the permission information of the application system 101 according to the application identifier; when it is determined that the first user has access permission to the application system 101 according to the permission information, it returns authentication passed information to the application system 101.

[0195] The application system 101, when receiving the authentication passed information returned by the IAM system 102, allows the first user to access the application system.

[0196] In the embodiments of the present application, the application system 101 can implement the functions implemented by the application system in the above Figures 1 to 5 shown embodiments, and the IAM system 102 can implement the functions implemented by the IAM system in the above Figures 1 to 5 shown embodiments. The specific implementation manner can refer to the specific implementation of the corresponding steps in the above Figures 1 to 5 shown embodiments, and will not be described in detail here.

[0197] In summary, the above are only the preferred embodiments of the present application, and are not used to limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0198] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0199] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0200] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0201] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the description of the method embodiment.

Claims

1. An identity authentication method, characterized in that, Applied to the Identity and Access Management (IAM) system, the IAM system performs identity authentication based on the Lightweight Directory Access Protocol (LDAP). The method includes: Receiving a first authentication request sent by an application system, where the first authentication request includes the application identifier of the application system and the username of a first user; Returning path information when the username authentication is successful, where the path information includes the application identifier; Receiving a second authentication request sent by the application system, where the second authentication request includes the path information and the user password of the first user; Determining the permission information of the application system according to the application identifier when the user password authentication is successful; Returning authentication success information when it is determined according to the permission information that the first user has access rights to the application system.

2. The method according to claim 1, wherein When the username authentication is successful, returning path information includes: Obtaining the complete Distinguished Name (DN) path of the first user when the username authentication is successful; Inserting the application identifier into the DN path to obtain the path information; Returning the path information.

3. The method according to claim 2, characterized in that, After receiving the second authentication request sent by the application system, the method further includes: Extracting the DN path from the path information; Performing password authentication on the first user according to the DN path and the user password.

4. The method according to claim 1, wherein The permission information includes first role information with access rights to the application system; After determining the permission information of the application system according to the application identifier, the method further includes: Obtaining the second role information of the first user; Determining whether the second role information matches the first role information; Determining that the first user has access rights to the application system when they match; Determining that the first user does not have access rights to the application system when they do not match.

5. The method according to claim 1, characterized in that, The method further includes any one of the following: Returning authentication failure information when the username authentication fails; Returning authentication failure information when the user password authentication fails; Returning authentication failure information when it is determined according to the permission information that the first user does not have access rights to the application system.

6. An identity authentication method, characterized in that, Applied to an application system, the method includes: Receiving an access request from a first user, where the access request includes the username and user password of the first user; Sending a first authentication request to the IAM system, the IAM system performs identity authentication based on the LDAP protocol, and the first authentication request includes the application identifier of the application system and the username; Receiving the path information returned by the IAM system, the path information is sent by the IAM system when the username authentication is successful, and the path information includes the application identifier; Sending a second authentication request to the IAM system, the second authentication request includes the path information and the user password; In the case of receiving the authentication passed information returned by the IAM system, the first user is allowed to access the application system, and the authentication passed information is sent by the IAM system after passing the user password authentication and determining that the first user has the access right to the application system according to the permission information determined based on the application identifier.

7. The method according to claim 6, characterized in that, The method further includes: In the case of receiving the authentication failed information returned by the IAM system, the first user is refused to access the application system; Wherein, the authentication failed information is sent by the IAM system in any of the following cases: The user name authentication fails; The user password authentication fails; According to the permission information, it is determined that the first user does not have the access right to the application system.

8. An identity authentication device, characterized in that, Applied to the IAM system, the IAM system performs identity authentication based on the LDAP protocol, and the device includes: A first receiving module, which receives a first authentication request sent by the application system, and the first authentication request includes the application identifier of the application system and the user name of the first user; A first sending module, which returns path information in the case of passing the user name authentication, and the path information includes the application identifier; A second receiving module, which receives a second authentication request sent by the application system, and the second authentication request includes the path information and the user password of the first user; A determining module, which determines the permission information of the application system according to the application identifier in the case of passing the user password authentication; A second sending module, which returns the authentication passed information in the case of determining that the first user has the access right to the application system according to the permission information.

9. An identity authentication device, characterized in that, Applied to the application system, the device includes: A first receiving module, which receives an access request from the first user, and the access request includes the user name and user password of the first user; A first sending module, which sends a first authentication request to the IAM system, and the IAM system performs identity authentication based on the LDAP protocol, and the first authentication request includes the application identifier of the application system and the user name; A second receiving module, which receives the path information returned by the IAM system, and the path information is sent by the IAM system in the case of passing the user name authentication, and the path information includes the application identifier; A second sending module, which sends a second authentication request to the IAM system, and the second authentication request includes the path information and the user password; A processing module, which allows the first user to access the application system in the case of receiving the authentication passed information returned by the IAM system, and the authentication passed information is sent by the IAM system after passing the user password authentication and determining that the first user has the access right to the application system according to the permission information determined based on the application identifier.

10. An electronic device, characterized in that, Includes: A processor; A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the instructions to implement the method according to any one of claims 1 to 7.

11. A computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method according to any one of claims 1 to 7.