Proxy login method and device, storage medium and computing equipment
By performing data desensitization on the proxy login server side, the problem of sensitive information leakage during proxy login is solved, and effective protection of sensitive information is achieved without changing the data structure, avoiding intrusion of business systems.
Patent Information
- Application Number
- CN202510384861.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-04
AI Technical Summary
During the proxy login process, how to avoid sensitive information being obtained by other users or accounts whose sensitive information is logged in by the proxy, resulting in information leakage and avoid intrusion of the functions of the business system.
Data desensitization is performed on the proxy login server side, instead of data desensitization is performed from the business system side. The authentication module verifies the authority of the proxy login client, uses the configuration module to obtain the sensitive data item configuration of the target account, and uses string replacement, masking algorithm or encryption algorithm to desensitize sensitive information in the display page.
Without changing the data structure of the page to be displayed, the risk of sensitive information leakage is reduced, the intrusion of business systems is avoided, and the effective protection of sensitive information is achieved.
Smart Images

Figure CN120263459A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technology. More specifically, embodiments of the present disclosure relate to a proxy login method, apparatus, storage medium, and computing device. Background Art
[0002] This section aims to provide background or context for the embodiments of the present disclosure. The descriptions herein are not admitted to be prior art merely because they are included in this section.
[0003] Proxy login means that a target account opens permissions to other users or accounts, enabling other users or accounts to log in and operate in the identity of the target account without providing a password. Summary of the Invention
[0004] In a first aspect of the embodiments of the present disclosure, a proxy login method is provided. The method includes:
[0005] Receiving an authorization request for proxy login initiated by a proxy login client; wherein the authorization request includes a unique identifier of the proxy login client and a target account providing authorization;
[0006] Forwarding the authorization request to the target account so that the target account determines whether to grant the proxy login client the permission for proxy login;
[0007] In response to a proxy login request initiated by the proxy login client, verifying whether the proxy login client has the permission for proxy login;
[0008] In response to the proxy login client having the permission for proxy login, performing desensitization processing on sensitive information included in the page to be displayed;
[0009] Transmitting the page to be displayed after desensitization processing to the proxy login client to display the page to be displayed after desensitization processing in the proxy login client.
[0010] Optionally, the proxy login request includes a unique identifier of the proxy login client;
[0011] The verifying whether the proxy login client has the permission for proxy login includes:
[0012] Verifying whether the unique identifier of the proxy login client included in the proxy login request is the unique identifier authorized by the target account;
[0013] If so, determining that the proxy login client has the permission for proxy login.
[0014] Optionally, in response to the proxy login client having the permission for proxy login, desensitizing the sensitive information included in the page to be displayed, including:
[0015] In response to the proxy login client having the permission for proxy login, further receiving a page acquisition request initiated after the proxy login client successfully completes the proxy login;
[0016] In response to the page identifier carried in the page acquisition request, acquiring the page to be displayed corresponding to the page identifier;
[0017] The method further includes:
[0018] Generating a browsing record corresponding to the page acquisition request according to the page acquisition request, the acquired page to be displayed, and the desensitized page to be displayed.
[0019] Optionally, the desensitizing the sensitive information included in the page to be displayed includes:
[0020] Desensitizing the sensitive information included in the page to be displayed by using at least one of string replacement, masking algorithm, encryption algorithm, or manual desensitization.
[0021] Optionally, the sensitive information included in the page to be displayed is configured by the target account;
[0022] The desensitizing the sensitive information included in the page to be displayed includes:
[0023] Obtaining the sensitive data items pre-configured by the target account for the page to be displayed;
[0024] Based on the sensitive data indicated by the sensitive data items, desensitizing the same sensitive data in the page to be displayed.
[0025] Optionally, when the target account grants the proxy login client the permission for proxy login, an expiration date is set for the permission;
[0026] The in response to the proxy login client having the permission for proxy login includes:
[0027] In response to the proxy login client having the permission for proxy login and the permission being within the expiration date, monitoring whether the permission exceeds the expiration date;
[0028] In response to monitoring that the permission exceeds the expiration date, ending the proxy login of the proxy login client.
[0029] In the second aspect of the embodiments of the present disclosure, a proxy login device is provided, and the device includes:
[0030] A receiving unit, which receives an authorization application for proxy login initiated by a proxy login client; wherein, the authorization application includes a unique identifier of the proxy login client and a target account for providing authorization.
[0031] An authorization unit, which forwards the authorization application to the target account so that the target account determines whether to grant the proxy login client the permission for proxy login.
[0032] An authentication unit, which, in response to a proxy login request initiated by the proxy login client, verifies whether the proxy login client has the permission for proxy login.
[0033] A desensitization unit, which, in response to the proxy login client having the permission for proxy login, performs desensitization processing on sensitive information included in the page to be displayed.
[0034] A display unit, which transmits the page to be displayed after desensitization processing to the proxy login client so as to display the page to be displayed after desensitization processing in the proxy login client.
[0035] Optionally, the proxy login request includes a unique identifier of the proxy login client.
[0036] The authentication unit is further configured to verify whether the unique identifier of the proxy login client included in the proxy login request is the unique identifier authorized by the target account; if so, determine that the proxy login client has the permission for proxy login.
[0037] Optionally, the desensitization unit is further configured to, in response to the proxy login client having the permission for proxy login, receive a page acquisition request initiated after the proxy login client successfully completes proxy login; and in response to a page identifier carried in the page acquisition request, acquire a page to be displayed corresponding to the page identifier.
[0038] The device further includes:
[0039] A generation unit, which generates a browsing record corresponding to the page acquisition request according to the page acquisition request, the acquired page to be displayed, and the page to be displayed after desensitization processing.
[0040] Optionally, the desensitization unit is further configured to perform desensitization processing on sensitive information included in the page to be displayed by at least one of string replacement, masking algorithm, encryption algorithm, or manual desensitization.
[0041] Optionally, the sensitive information included in the page to be displayed is configured by the target account.
[0042] The desensitization unit is further configured to obtain sensitive data items pre-configured by the target account for the page to be displayed; and desensitize the same sensitive data in the page to be displayed based on the sensitive data indicated by the sensitive data items.
[0043] Optionally, when the target account grants the proxy login client the permission for proxy login, an expiration period is set for the permission.
[0044] The authentication unit is further configured to monitor whether the permission has exceeded the expiration period when the proxy login client has the permission for proxy login and the permission is within the expiration period; and terminate the proxy login of the proxy login client in response to monitoring that the permission has exceeded the expiration period.
[0045] In a third aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided, including:
[0046] When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the proxy login method as described in any one of the preceding items.
[0047] In a fourth aspect of the embodiments of the present disclosure, a computing device is provided, including:
[0048] A processor;
[0049] A memory for storing executable instructions of the processor;
[0050] Wherein, the processor is configured to execute the executable instructions to implement the proxy login method as described in any one of the preceding items.
[0051] According to the proxy login solution provided by the embodiments of the present disclosure, for proxy login, the sensitive images included in the page to be displayed are desensitized to reduce the risk of sensitive information leakage while keeping the data structure of the page to be displayed unchanged. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] By referring to the accompanying drawings and reading the following detailed description, the above and other objects, features, and advantages of the exemplary embodiments of the present disclosure will become easily understood. In the drawings, several embodiments of the present disclosure are shown in an exemplary and non-limiting manner, wherein:
[0053] Figure 1 Schematically shows the system architecture diagram of the proxy login system provided by the present disclosure;
[0054] Figure 2 Schematically shows the schematic diagram of the proxy login method provided by the present disclosure;
[0055] Figure 3Schematically shows a schematic diagram of data desensitization provided by the present disclosure;
[0056] Figure 4 Schematically shows a timing diagram of multi-party interaction for proxy login provided by the present disclosure;
[0057] Figure 5 Schematically shows a schematic diagram of a medium provided by the present disclosure;
[0058] Figure 6 Schematically shows a schematic diagram of a proxy login device provided by the present disclosure;
[0059] Figure 7 Schematically shows a schematic diagram of a computing device provided by the present disclosure.
[0060] In the drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed Embodiments
[0061] The principles and spirit of the present disclosure will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are given only to enable those skilled in the art to better understand and thus implement the present disclosure, and not to limit the scope of the present disclosure in any way. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to be able to fully convey the scope of the present disclosure to those skilled in the art.
[0062] Those skilled in the art know that the embodiments of the present disclosure can be implemented as a system, a device, an apparatus, a method, or a computer program product. Therefore, the present disclosure can be specifically implemented in the following forms: completely hardware, completely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0063] According to the embodiments of the present disclosure, a proxy login method, a computer-readable storage medium, a device, and a computing device are provided.
[0064] In this article, it should be understood that any number of elements in the drawings is for illustration rather than limitation, and any naming is only for distinction and does not have any limiting meaning.
[0065] The principles and spirit of the present disclosure will be elaborated in detail below with reference to several representative embodiments of the present disclosure.
[0066] The data involved in the present disclosure can be data authorized by users or fully authorized by all parties. The collection, dissemination, use, etc. of the data all comply with the requirements of relevant national laws and regulations. The embodiments / examples of the present disclosure can be combined with each other.
[0067] As described above, proxy login means that the target account opens permissions to other users or accounts, enabling other users or accounts to log in and operate in the identity of the target account without providing a password.
[0068] However, since the other users or accounts of proxy login are not the target account itself after all, how to avoid the sensitive information under the target account being obtained by the other users or accounts of proxy login during the proxy login process, thus causing information leakage, has become an urgent problem to be solved.
[0069] In the related art, a specific data desensitization system is usually developed on the business system to desensitize the sensitive information of the target account under proxy login; however, this method is invasive and may cause irreversible functional intrusion into the original business system.
[0070] In view of this, the present disclosure provides a brand-new proxy login solution, which no longer performs data desensitization from the business system side, but performs data desensitization on the proxy login side, thereby avoiding intrusion into the business system.
[0071] On the other hand, after the proxy login side obtains the page to be displayed provided by the business system, it can desensitize the sensitive information included in the page to be displayed without changing the data structure in the page to be displayed; in this way, not only the risk of sensitive information leakage is avoided, but also since the data structure of the page to be displayed is not changed, the page to be displayed after desensitization will not be deformed.
[0072] Overview of Application Scenarios
[0073] The present disclosure can be applied to any device, system or platform that provides proxy login services. Such as Figure 1 the system architecture diagram of the proxy login system shown.
[0074] Such as Figure 1 shown, the proxy login system may include a proxy login client, a proxy login server, and a business system.
[0075] Among them, the proxy login server may include several functional modules, such as Figure 1 the authentication module, operation audit module, configuration module, storage module, data desensitization module, etc. shown in
[0076] The authentication module can be used to authenticate the proxy login request initiated by the proxy login client to determine whether the proxy login client has the permission for proxy login.
[0077] In addition, the authentication module may also be integrated with an authorization function for proxy login. Specifically, it can forward the authorization request for proxy login initiated by the proxy login client to the target account to obtain whether the target account authorizes the proxy login client to perform proxy login.
[0078] Furthermore, the authentication module can also monitor the validity period of the permission authorized to the proxy login client for proxy login, so as to terminate the proxy login after the permission expires, etc.
[0079] The operation auditing module can be used to generate operation records related to various operations initiated after the proxy login client successfully performs proxy login, and support the target account to view the operation records, etc.
[0080] The configuration module can be used for the target account to configure sensitive information, so that the proxy login server performs desensitization processing on the sensitive information in the page to be displayed based on the configured sensitive data items, etc.
[0081] The storage module can be used to store authorization records for functions such as authentication and permission validity period monitoring by the foregoing authentication module, and can also be used to store operation records generated by the foregoing operation auditing module, etc.
[0082] The data desensitization module can store various algorithms, rules, or models for data desensitization, etc.
[0083] Through the various modules of the above proxy login server, a proxy login service can be provided for the proxy login client. During the proxy login process, the sensitive information included in each page to be displayed provided by the business system can be desensitized, and then the page to be displayed after desensitization is returned to the proxy login client; since the proxy login client receives the page to be displayed that has been desensitized and does not contain sensitive information, the risk of sensitive information leakage can be avoided.
[0084] Exemplary Method
[0085] Next, in combination with Figure 1 the application scenario shown, with reference to Figure 2 the method for proxy login according to an exemplary embodiment of the present disclosure will be described. It should be noted that the above application scenario is only shown for the convenience of understanding the spirit and principle of the present disclosure, and the embodiments of the present disclosure are not limited in this regard. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.
[0086] As Figure 2 shown, the proxy login method may include the following steps:
[0087] Step 210: Receive an authorization application for proxy login initiated by a proxy login client; wherein, the authorization application includes the unique identifier of the proxy login client and the target account that provides authorization.
[0088] Step 220: Forward the authorization application to the target account so that the target account can determine whether to grant the proxy login client the permission for proxy login.
[0089] Step 230: In response to a proxy login request initiated by the proxy login client, verify whether the proxy login client has the permission for proxy login.
[0090] Step 240: In response to the proxy login client having the permission for proxy login, desensitize the sensitive information included in the page to be displayed.
[0091] Step 250: Transmit the page to be displayed after desensitization to the proxy login client so as to display the page to be displayed after desensitization in the proxy login client.
[0092] Exemplarily, this embodiment can be applied to the aforementioned proxy login server.
[0093] A complete data desensitization process for proxy login may include: the proxy login client initiates a proxy login request to the proxy login server, and the authentication module in the proxy login server authenticates the proxy login request to determine whether the proxy login client has the permission for proxy login; if so, the proxy login server can obtain the page to be displayed from the business system in the identity of the target account, determine the sensitive information included in the page to be displayed based on the configuration module, and desensitize the sensitive information based on the data desensitization module to obtain the page to be displayed after desensitization; finally, the page to be displayed after desensitization is returned to the proxy login client so as to display the page to be displayed after desensitization in the proxy login client.
[0094] It should be noted that after authentication is passed, the proxy login server can embed the page to be displayed provided by the business system to be proxied in the framework of the proxy login server, and the user of the proxy login client can use the complete functions of the business system in the identity of the target account through the proxy login server.
[0095] Through the above embodiment, on the one hand, data desensitization is no longer performed on the business system side, but on the proxy login server, thus avoiding intrusion into the business system.
[0096] On the other hand, after obtaining the page to be displayed provided by the business system, the proxy login server can desensitize the sensitive information included in the page to be displayed without changing the data structure in the page to be displayed; in this way, not only the risk of sensitive information leakage is avoided, but also since the data structure of the page to be displayed is not changed, the page to be displayed after desensitization will not be deformed.
[0097] In an exemplary embodiment, the proxy login request may include a unique identifier of the proxy login client;
[0098] Correspondingly, verifying whether the proxy login client has the permission to perform proxy login in step 230 may include:
[0099] Verifying whether the unique identifier of the proxy login client included in the proxy login request is the unique identifier authorized by the target account;
[0100] If so, it is determined that the proxy login client has the permission to perform proxy login;
[0101] On the contrary, if not, it is determined that the proxy login client does not have the permission to perform proxy login.
[0102] In this embodiment, the unique identifier may be a unique information based on the proxy login client, such as a user account, an account ID, etc.; or, a unique information of the machine where the client is located, such as an EMI code (International Mobile Equipment Identity), etc.; or, a unique identifier generated from the unique information used by the user, such as the user's mobile phone number, ID number, etc.
[0103] Since applying for proxy login requires obtaining the authorization of the target account, the proxy login client has already provided unique information during the application, and the target account can also be authorized based on the unique information; thus, during the authentication process, authentication can be performed according to the unique information provided by the proxy login client again.
[0104] It should be noted that after the target account is authorized, an authorization record including unique information can be generated, and this authorization record can be sent to the proxy login server, and the proxy login server stores and maintains this authorization record (such as storing it in Figure 1 the storage module).
[0105] By using the uniqueness of the unique identifier of the proxy login client for authentication in the above embodiment, the situation where an unauthorized proxy login client pretends to be an authorized one can be avoided.
[0106] In an exemplary embodiment, in response to the proxy login client having the proxy login authority, the above step 240 desensitizes the sensitive information contained in the page to be displayed, and may include:
[0107] In response to the proxy login client having the authority for proxy login, further receiving a page acquisition request initiated by the proxy login client after successfully completing the proxy login;
[0108] In response to the page identifier carried in the page acquisition request, acquiring a to-be-displayed page corresponding to the page identifier;
[0109] In addition, the above method may further include:
[0110] A browsing record corresponding to the page acquisition request is generated according to the page acquisition request, the acquired page to be displayed and the desensitized page to be displayed.
[0111] In this embodiment, after the proxy login client passes the authentication, it can browse various pages of the business system or perform related page operations as the target account.
[0112] Exemplarily, the proxy login client initiates a page acquisition request to the proxy login server, and the proxy login server responds to the page identifier carried in the page acquisition request and obtains the page to be displayed corresponding to the page identifier from the business system; then the sensitive information in the page to be displayed is desensitized.
[0113] As before Figure 1 As shown, the operation audit module in the proxy login server can generate an operation record for each operation of the proxy login client, and a browsing record will be generated for each page browsing operation, which can include the current business acquisition request, the page to be displayed before desensitization, and the page to be displayed after desensitization. As mentioned above, the operation audit module supports the target account to view the operation record, and can also support the trusted third party to view the operation record.
[0114] Through the above embodiments, all operation records are recorded to check whether there is any sensitive information leakage, or to trace back and determine whether there is any operation record of information leakage when information leakage occurs, and locate possible operation records and corresponding proxy login clients.
[0115] In an exemplary embodiment, the above step 240 of desensitizing the sensitive information contained in the page to be displayed may include:
[0116] The sensitive information contained in the page to be displayed is desensitized by using at least one of string replacement, mask algorithm, encryption algorithm or manual desensitization.
[0117] In this embodiment, the sensitive information included in the page to be displayed is hidden or replaced by any of the above desensitization methods, so as to minimize the recognizability of the sensitive information on the premise of maintaining the data structure of the page to be displayed, thereby reducing the risk of information leakage during the proxy login process.
[0118] In an exemplary embodiment, the sensitive information included in the page to be displayed can be configured by the target account;
[0119] Correspondingly, the desensitization process of the sensitive information included in the page to be displayed in step 240 above may include:
[0120] Obtain the sensitive data items pre-configured by the target account for the page to be displayed;
[0121] Based on the sensitive data indicated by the sensitive data items, desensitize the same sensitive data in the page to be displayed.
[0122] In this embodiment, the target account can pre-configure which data in the page to be displayed belongs to sensitive information, so as to achieve accurate data desensitization.
[0123] Such as Figure 3 shown, the client of the target account can freely set the security levels of different types of data, and which types need to be desensitized. For example, e-commerce sellers usually need to keep information such as their business income, passenger flow, and average customer price confidential. In order to configure these data as sensitive data items, the proxy login server will save the configured sensitive data items (such as saving to the Figure 1 configuration module shown, or other databases).
[0124] In this way, when the proxy login client successfully logs in as a proxy, the proxy login server can intercept the page to be displayed provided by the business system and desensitize the sensitive information included in the page to be displayed based on the above-configured sensitive data items, so as to ensure that the sensitive information that the target account needs to keep confidential is not leaked.
[0125] In an exemplary embodiment, when the target account grants the proxy login client the permission to log in as a proxy, an expiration date is set for the permission;
[0126] Correspondingly, the response to the proxy login client having the permission to log in as a proxy in step 230 above may include:
[0127] In response to the proxy login client having the permission to log in as a proxy and the permission being within the expiration date, monitor whether the permission exceeds the expiration date;
[0128] In response to monitoring that the permission exceeds the validity period, terminating the proxy login of the proxy login client.
[0129] In this embodiment, when the target account authorizes other users to perform proxy login, the target account can set a validity period for the permission; during the validity period, other users can pass authentication and perform proxy login as the target account, and outside the validity period, other users cannot pass authentication and cannot perform proxy login as the target account.
[0130] In addition, the proxy login server can monitor the permissions that are within the validity period, and when it monitors that the permissions have exceeded the validity period, it actively ends the proxy login of the proxy login client.
[0131] By setting the validity period and the monitoring function of the proxy login server, the target account does not need to manually revoke each permission, and the proxy login permission can be automatically reclaimed, thereby achieving reasonable management and control of the permission life cycle.
[0132] Please refer to the following Figure 4 The timing diagram of multi-party interaction of proxy login is shown, and the multi-party interaction may include a proxy login client, a proxy login server, a target account and a business system.
[0133] 1.1, the proxy login client initiates a proxy login authorization request to the proxy login server.
[0134] The authorization application may include a unique identifier of the proxy login client and a designated target account.
[0135] 1.2, the proxy login server forwards the authorization request.
[0136] The proxy login server forwards the authorization request to the target account based on the target account specified in the authorization request.
[0137] 1.3. The target account agrees to the authorization.
[0138] After receiving the authorization application, the target account may agree to the authorization or not, and the authorization result may be returned to the proxy login server. The proxy login server performs relevant processing according to the authorization result returned by the target account. For example, if the authorization result is to agree to the authorization, the authorization record carried in the authorization result may be stored, and the authorization record may contain the above-mentioned unique identifier; regardless of whether the authorization result agrees to the authorization, the proxy login server may forward the authorization result to the proxy login client to notify the proxy login client whether it is authorized.
[0139] 2.1, the proxy login client initiates a proxy login request to the proxy login server.
[0140] The unique identifier of the proxy login client can be carried in the proxy login request.
[0141] 2.2. The proxy login server authenticates the proxy login request.
[0142] The proxy login server compares the unique identifier in the proxy login request with the stored authorization records to determine whether there is the same unique identifier in the authorization records; if there is, it is determined that the proxy login server initiating the proxy login request has the permission to perform proxy login, and the authentication is successful. On the contrary, if there is no unique identifier in the authorization records that is the same as that in the proxy login request, or the validity period of the permissions associated with the authorization records has expired, it is determined that the proxy login server initiating the proxy login request does not have the permission to perform proxy login, and the authentication fails.
[0143] 2.3. The proxy login server obtains the page to be displayed from the business system.
[0144] After successful authentication, the proxy login client can log in and operate as the target account; in response to the page acquisition request initiated by the proxy login client, the proxy login server obtains the page to be displayed corresponding to the page identifier in the page acquisition request from the business system.
[0145] 3.1. The proxy login server conducts operation auditing.
[0146] The proxy login server can record the operation records of the proxy login client each time.
[0147] 4.1. The proxy login server performs desensitization processing on the page to be displayed.
[0148] Based on the sensitive data indicated by the sensitive data items configured by the target user, the proxy login server desensitizes the same sensitive data in the page to be displayed. Among them, the page to be displayed after desensitization processing can be added to the aforementioned operation records.
[0149] 4.2. The proxy login server returns the page to be displayed after desensitization processing to the proxy login client.
[0150] The proxy login client displays the page to be displayed after desensitization processing.
[0151] 5.1. The proxy login server logs out when the permission validity period expires by listening for it.
[0152] The proxy login server listens to whether the permission granted by the target account to the proxy login client to perform proxy login has exceeded the validity period, and when it monitors that the permission has exceeded the validity period, it ends the proxy login of the proxy client.
[0153] Exemplary Medium
[0154] After introducing the method of the exemplary embodiments of the present disclosure, next, reference is made to Figure 5 the medium of the exemplary embodiments of the present disclosure is described.
[0155] In this exemplary embodiment, the above method can be implemented by a program product. For example, a portable compact disc read-only memory (CD-ROM) can be adopted and includes program code, and can be run on a device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, a readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.
[0156] The program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0157] The computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable signal medium can also be any readable medium other than the readable storage medium, and this readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.
[0158] The program code contained on the readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RE, etc., or any suitable combination of the above.
[0159] Program code for performing the operations of the present disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the C language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0160] In summary, the present disclosure can provide a computer-readable storage medium, and when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device can be enabled to execute the foregoing method embodiments of proxy login.
[0161] Exemplary Device
[0162] After introducing the medium of the exemplary embodiments of the present disclosure, next, reference is made to Figure 6 to describe the device of the exemplary embodiments of the present disclosure.
[0163] Figure 6 A block diagram of a proxy login device according to an embodiment of the present disclosure is schematically shown, corresponding to the foregoing Figure 2 shown method embodiments. The proxy login device may include:
[0164] A receiving unit 610 that receives an authorization application for proxy login initiated by a proxy login client; wherein, the authorization application includes a unique identifier of the proxy login client and a target account for providing authorization;
[0165] An authorization unit 620 that forwards the authorization application to the target account so that the target account determines whether to grant the proxy login client the permission for proxy login;
[0166] An authentication unit 630 that, in response to a proxy login request initiated by the proxy login client, verifies whether the proxy login client has the permission for proxy login;
[0167] A desensitization unit 640 that, in response to the proxy login client having the permission for proxy login, performs desensitization processing on the sensitive information included in the page to be displayed;
[0168] The display unit 650 transmits the to-be-displayed page after the desensitization process to the proxy login client, so as to display the to-be-displayed page after the desensitization process in the proxy login client.
[0169] Optionally, the proxy login request includes the unique identifier of the proxy login client;
[0170] The authentication unit 630 is further configured to verify whether the unique identifier of the proxy login client included in the proxy login request is the unique identifier authorized by the target account; if so, determine that the proxy login client has the permission for proxy login.
[0171] Optionally, the desensitization unit 640 is further configured to, in response to the proxy login client having the permission for proxy login, receive the page acquisition request initiated after the proxy login client successfully completes the proxy login; and in response to the page identifier carried in the page acquisition request, acquire the to-be-displayed page corresponding to the page identifier;
[0172] The apparatus further includes:
[0173] The generation unit 642 generates a browsing record corresponding to the page acquisition request according to the page acquisition request, the acquired to-be-displayed page, and the to-be-displayed page after the desensitization process.
[0174] Optionally, the desensitization unit 640 is further configured to desensitize the sensitive information included in the to-be-displayed page by at least one of string replacement, masking algorithm, encryption algorithm, or manual desensitization.
[0175] Optionally, the sensitive information included in the to-be-displayed page is configured by the target account;
[0176] The desensitization unit 640 is further configured to acquire the sensitive data items pre-configured by the target account for the to-be-displayed page; and based on the sensitive data indicated by the sensitive data items, desensitize the same sensitive data in the to-be-displayed page.
[0177] Optionally, when the target account grants the proxy login client the permission for proxy login, an expiration period is set for the permission;
[0178] The authentication unit 630 is further configured to, when the proxy login client has the permission for proxy login and the permission is within the expiration period, monitor whether the permission exceeds the expiration period; and in response to monitoring that the permission exceeds the expiration period, end the proxy login of the proxy login client.
[0179] Through the above-described embodiments of multi-party interaction, a proxy login scheme for data desensitization can be implemented, which has various functions such as complete proxy login permission application, proxy login permission authentication, data desensitization, operation auditing, sensitive data configuration, and permission recovery.
[0180] Exemplary Computing Device
[0181] After introducing the methods, media, and devices of the exemplary embodiments of the present disclosure, next, reference is made to Figure 7 describe the computing device of the exemplary embodiments of the present disclosure.
[0182] Figure 7 The computing device 1500 shown is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.
[0183] As Figure 7 shown, the computing device 1500 is presented in the form of a general-purpose computing device. The components of the computing device 1500 may include, but are not limited to: at least one processing unit 1501, at least one storage unit 1502, and a bus 1503 connecting different system components (including the processing unit 1501 and the storage unit 1502).
[0184] The bus 1503 includes a data bus, a control bus, and an address bus.
[0185] The storage unit 1502 may include a readable medium in the form of volatile memory, such as a random access memory (RAM) 15021 and / or a cache memory 15022, and may further include a readable medium in the form of non-volatile memory, such as a read-only memory (ROM) 15023.
[0186] The storage unit 1502 may also include a program / utility 15025 having a set (at least one) of program modules 15024. Such program modules 15024 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0187] The computing device 1500 may also communicate with one or more external devices 1504 (such as a keyboard, a pointing device, etc.).
[0188] Such communication may be carried out through an input / output (I / O) interface 1505. And, the computing device 1500 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 1506. As Figure 7As shown, network adapter 1506 communicates with other modules of computing device 1500 via bus 1503. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with computing device 1500, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0189] Via computing device 1500 as Figure 7 shown, the foregoing proxy login method can be implemented. More specifically, storage unit 1502 stores instructions executable by processing unit 1501, and when processing unit 1501 executes the instructions, the foregoing proxy login method is implemented.
[0190] It should be noted that although several units / modules or sub-units / modules of the proxy login device are mentioned in the foregoing detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-described units / modules can be embodied in one unit / module. Conversely, the features and functions of one unit / module described above can be further divided and embodied by multiple units / modules.
[0191] In addition, although the operations of the method of the present disclosure are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the shown operations must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0192] Although the spirit and principles of the present disclosure have been described with reference to several specific embodiments, it should be understood that the present disclosure is not limited to the specific embodiments disclosed, and the division of each aspect does not mean that the features in these aspects cannot be combined for benefit. This division is only for the convenience of description. The present disclosure aims to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
Claims
1. A proxy login method, comprising: Receiving an authorization application for proxy login initiated by a proxy login client; wherein, the authorization application includes a unique identifier of the proxy login client and a target account providing authorization; Forwarding the authorization application to the target account so that the target account determines whether to grant the proxy login client the permission for proxy login; In response to a proxy login request initiated by the proxy login client, verifying whether the proxy login client has the permission for proxy login; In response to the proxy login client having the permission for proxy login, performing desensitization processing on sensitive information included in the page to be displayed; Transmitting the page to be displayed after desensitization processing to the proxy login client to display the page to be displayed after desensitization processing in the proxy login client.
2. The method according to claim 1, wherein the proxy login request includes a unique identifier of the proxy login client; The verifying whether the proxy login client has the permission for proxy login includes: Verifying whether the unique identifier of the proxy login client included in the proxy login request is the unique identifier authorized by the target account; If so, determining that the proxy login client has the permission for proxy login.
3. The method according to claim 1, wherein the performing desensitization processing on sensitive information included in the page to be displayed in response to the proxy login client having the permission for proxy login includes: In response to the proxy login client having the permission for proxy login, further receiving a page acquisition request initiated after the proxy login client successfully completes proxy login; In response to the page identifier carried in the page acquisition request, acquiring the page to be displayed corresponding to the page identifier; The method further includes: Generating a browsing record corresponding to the page acquisition request according to the page acquisition request, the acquired page to be displayed, and the page to be displayed after desensitization processing.
4. The method according to claim 1, wherein the performing desensitization processing on sensitive information included in the page to be displayed includes: Performing desensitization processing on sensitive information included in the page to be displayed by at least one of string replacement, masking algorithm, encryption algorithm, or manual desensitization.
5. The method according to claim 1, wherein the sensitive information included in the page to be displayed is configured by the target account; The performing desensitization processing on sensitive information included in the page to be displayed includes: Acquiring sensitive data items pre-configured by the target account for the page to be displayed; Based on the sensitive data indicated by the sensitive data items, performing desensitization processing on the same sensitive data in the page to be displayed.
6. The method according to claim 1, when the target account grants the proxy login client the permission for proxy login, a validity period is set for the permission; The responding to the proxy login client having the permission for proxy login includes: In response to the proxy login client having the permission for proxy login and the permission being within the validity period, monitoring whether the permission exceeds the validity period; In response to monitoring that the permission exceeds the validity period, end the proxy login of the proxy login client.
7. A proxy login device, the device comprising: A receiving unit, which receives an authorization application for proxy login initiated by a proxy login client; wherein, the authorization application includes the unique identifier of the proxy login client and the target account providing the authorization. An authorization unit, which forwards the authorization application to the target account so that the target account determines whether to grant the proxy login client the permission for proxy login. An authentication unit, which, in response to a proxy login request initiated by a proxy login client, verifies whether the proxy login client has the permission for proxy login. A desensitization unit, which, in response to the proxy login client having the permission for proxy login, performs desensitization processing on the sensitive information included in the page to be displayed. A display unit, which transmits the page to be displayed after desensitization processing to the proxy login client to display the page to be displayed after desensitization processing in the proxy login client.
8. The device according to claim 7, wherein the proxy login request includes the unique identifier of the proxy login client. The authentication unit is further configured to verify whether the unique identifier of the proxy login client included in the proxy login request is the unique identifier authorized by the target account; if so, determine that the proxy login client has the permission for proxy login.
9. A computer-readable storage medium, comprising: When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the proxy login method according to any one of claims 1-6.
10. A computing device, comprising: A processor; A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the executable instructions to implement the proxy login method according to any one of claims 1-6.