Authorization authentication method and device, electronic equipment, medium and program product

By jumping between applets and authorizing server communication to generate tokens, the problems of low security and restricted configuration in applets are solved, and more efficient and secure resource access authorization are achieved.

CN120277653APending Publication Date: 2025-07-08BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510459023.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

When accessing user resources in mini programs, the existing technology has problems such as low security, limited authorization server configuration, and excessive domain name resource utilization.

Method used

By jumping between the first applet and the second applet of the terminal device, using the second applet to communicate with the authorization server, generating and passing tokens to realize user authentication and resource access authorization, avoiding direct user authentication in the first applet.

Benefits of technology

It improves the security of authorization and authentication, reduces the configuration burden of authorization servers, optimizes the use of domain name resources, and improves the efficiency of mini programs to access user resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277653A_ABST
    Figure CN120277653A_ABST
Patent Text Reader

Abstract

An authorization authentication method and apparatus, a medium, an electronic device and a program product, relating to the technical field of computers, the authorization authentication method being executed by a terminal device, the method comprising: in response to an authorization application operation triggered by a user for a first applet displayed by the terminal device, skipping from the first applet to a second applet; communicating with an authorization server through a second applet, so as to generate a first token and send the first token to the second applet under the condition that the authorization server confirms that the user passes the authentication; in response to the second applet receiving the first token, jumping back from the second applet to the first applet, and passing the received first token to the first applet, the first applet obtaining authorization to access the resource of the user from the authorization server based on the first token, the user does not need to be authenticated in the first applet in a page access mode, so that the problems of low security, limited configuration of the authorization server and the like caused by authentication of the user in the mode are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular, to an authorization and authentication method, apparatus, electronic device, medium, and program product. Background Art

[0002] A mini-program is a lightweight application that can be used without being downloaded and installed, and usually runs in an application that has been downloaded and installed on a terminal device. Due to many advantages of mini-programs, such as no need for installation and small memory occupancy, etc., they are widely used in various fields.

[0003] During the use of a mini-program, access to user resources may be involved. In order to prevent unauthorized users from stealing and tampering with user resources, user authentication is required. Summary of the Invention

[0004] This Summary of the Invention section is provided to introduce concepts in a brief form, which will be described in detail in the subsequent Detailed Description section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] In a first aspect, the present disclosure provides an authorization and authentication method, which is executed by a terminal device. The method includes: In response to an authorization application operation triggered by a user for a first mini-program displayed on the terminal device, jump from the first mini-program to a second mini-program; Communicate with an authorization server through the second mini-program, where the communication is for the authorization server to generate a first token and send the first token to the second mini-program when confirming that the user has passed authentication; In response to the second mini-program receiving the first token, jump back from the second mini-program to the first mini-program, and pass the received first token to the first mini-program. The first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0006] In a second aspect, the present disclosure provides an authorization and authentication method, which is executed by an authorization server. The method includes: Communicate with a second mini-program displayed on a terminal device; Among them, the second mini-program is displayed on the terminal device after jumping from the first mini-program in response to an authorization application operation triggered by the user for the first mini-program displayed on the terminal device. The communication is used for the authorization server to generate a first token and send the first token to the second mini-program when it confirms that the user has passed the authentication. The terminal device passes the first token to the first mini-program through the second mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0007] In a third aspect, the present disclosure provides an authorization and authentication device, which is applied to a terminal device. The authorization and authentication device includes: A first response module, configured to jump from the first mini-program to a second mini-program in response to an authorization application operation triggered by the user for the first mini-program displayed on the terminal device; A first communication module, configured to communicate with an authorization server through the second mini-program. The communication is used for the authorization server to generate a first token and send the first token to the second mini-program when it confirms that the user has passed the authentication; A second response module, configured to jump back from the second mini-program to the first mini-program in response to the second mini-program receiving the first token, and pass the received first token to the first mini-program. The first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0008] In a fourth aspect, the present disclosure provides an authorization and authentication device, which is applied to an authorization server. The authorization and authentication device includes: A second communication module, configured to communicate with a second mini-program displayed on a terminal device; Among them, the second mini-program is displayed on the terminal device after jumping from the first mini-program in response to an authorization application operation triggered by the user for the first mini-program displayed on the terminal device. The communication is used for the authorization server to generate a first token and send the first token to the second mini-program when it confirms that the user has passed the authentication. The terminal device passes the first token to the first mini-program through the second mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0009] In a fifth aspect, the present disclosure provides a computer-readable medium, on which a computer program is stored. When the computer program is executed by a processing device, it implements the steps of the method described in the first aspect or the steps of the method described in the second aspect.

[0010] In a sixth aspect, the present disclosure provides an electronic device, including: a storage device on which a computer program is stored; a processing device configured to execute the computer program in the storage device to implement the steps of the method according to the first aspect or the steps of the method according to the second aspect.

[0011] In a seventh aspect, the present disclosure provides a computer program product including a computer program, which when executed by a processor implements the steps of the method according to the first aspect or the steps of the method according to the second aspect.

[0012] Through the above technical solution, after the authorization application operation triggered by the first applet displayed on the terminal device, the user jumps from the first applet to the second applet, and the second applet communicates with the authorization server to complete the authentication of the user through the second applet and the authorization server. When the authentication is passed, the authorization server generates a first token and sends the first token to the second applet; on this basis, the second applet passes the first token to the first applet and jumps back to the first applet. The first applet obtains the authorization to access the user's resources from the authorization server based on the passed-back first token. In this authorization authentication process, the second applet different from the first applet completes the authentication of the user, and there is no need to authenticate the user by accessing a page in the first applet, thereby avoiding problems such as low security and limited configuration of the authorization server caused by authenticating the user by accessing a page in the first applet.

[0013] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In combination with the drawings and with reference to the following specific implementation, the above and other features, advantages and aspects of the embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original elements and elements are not necessarily drawn to scale. In the drawings: Figure 1 is a schematic diagram of an authorization authentication system shown according to an embodiment of the present disclosure.

[0015] Figure 2 is a schematic diagram of an authorization authentication method shown according to an embodiment of the present disclosure.

[0016] Figure 3 is a schematic diagram of an authorization authentication method shown according to an embodiment of the present disclosure.

[0017] Figure 4 is a block diagram of an authorization authentication device shown according to an embodiment of the present disclosure.

[0018] Figure 5 It is a schematic structural diagram of an electronic device shown according to an embodiment of the present disclosure. Detailed implementation manners

[0019] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0020] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0021] As used herein, the term "including" and its variations are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0022] It should be noted that the concepts such as "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of the functions executed by these devices, modules or units or their interdependent relationships.

[0023] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly stated in the context, it should be understood as "one or more".

[0024] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0025] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0026] For example, when responding to an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, application program, server, or storage medium that performs the operations of the present disclosure's technical solution based on the prompt message.

[0027] As an optional but non-limiting implementation manner, the way of sending a prompt message to the user in response to receiving the user's active request can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0028] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present disclosure. Other ways that meet relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0029] At the same time, it can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of corresponding laws, regulations, and related regulations.

[0030] A mini-program is a lightweight application program that can be used without downloading and installing, and usually runs in the application programs of terminal devices. Due to many advantages of mini-programs, such as no need to install and small memory occupation, etc., they are widely used in various fields.

[0031] During the use of a mini-program, it may involve access to user resources. In order to prevent unauthorized users from stealing and tampering with user resources, user authentication is required.

[0032] If user authentication is directly performed in the mini-program that accesses user resources, there are the following three disadvantages: First, the authorization server needs to configure permissions in the mini-program to be able to access the page for verifying the user. And this mini-program is equivalent to an external mini-program to the authorization server, so there are security issues. Second, if the number of mini-programs accessing user resources is large, the configuration amount of the authorization server is relatively large. Third, since opening a page in a mini-program requires using a webview component, this component will limit the number of mini-programs associated with the domain name corresponding to the page. If the number of mini-programs accessing user resources is too large, a large number of domain names need to be set, resulting in excessive resource occupation.

[0033] In view of this, in order to solve the above drawbacks, embodiments of the present disclosure provide an authorization authentication method, apparatus, electronic device, medium, and program product.

[0034] The embodiments of the present disclosure will be explained and described below with reference to the accompanying drawings.

[0035] Figure 1 is a schematic diagram of an authorization authentication system shown according to an embodiment of the present disclosure. Refer to Figure 1 This system includes a terminal device, an authorization server, and a resource server.

[0036] The application programs already downloaded and installed on the terminal device can provide an environment for running the first mini-program and the second mini-program. The user can use the terminal device to interact with the authorization server through the network. Specifically, the first mini-program and the second mini-program in the terminal interact with the authorization server through the network. Among them, the terminal device can be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, desktop computers, wearable devices, virtual reality devices, smart homes, and so on.

[0037] The terminal device can display an authorization interface of the first mini-program in the application program. The authorization interface includes a request authorization control. The terminal device can respond to the authorization application operation triggered by the user for the request authorization control in the first mini-program displayed on the terminal device, and realize the jump from the first mini-program to the second mini-program; communicate with the authorization server through the second mini-program to generate a first token and send the first token to the second mini-program when the authorization server confirms that the user passes the authentication. Further, the terminal device can respond to the second mini-program receiving the first token, jump back from the second mini-program to the first mini-program, and pass the received first token to the first mini-program; the first mini-program obtains authorization to access the user's resources from the authorization server based on the first token passed to the first mini-program.

[0038] The authorization server can be a server that provides various services. The authorization server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The present disclosure does not limit this.

[0039] After obtaining authorization to access the user's resources, the terminal device can access the corresponding resources from the resource server. Similar to the authorization server, the resource server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The present disclosure does not limit this.

[0040] Figure 2 It is a schematic diagram of an authorization and authentication method shown according to an embodiment of the present disclosure. This authorization and authentication method is executed by a terminal device. Referring to Figure 2 This authorization and authentication method includes step 210, step 220, and step 230.

[0041] In step 210, the terminal device responds to an authorization application operation triggered by the user for a first applet displayed on the terminal device and jumps from the first applet to a second applet; In step 220, the terminal device communicates with the authorization server through the second applet. The communication is for the authorization server to generate a first token and send the first token to the second applet when it confirms that the user has passed the authentication; In step 230, the terminal device responds to the second applet receiving the first token, jumps back from the second applet to the first applet, and passes the received first token to the first applet. The first applet obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first applet.

[0042] Through the above technical solution, after the user triggers an authorization application operation for the first applet displayed on the terminal device, the user jumps from the first applet to the second applet. The second applet communicates with the authorization server to complete the authentication of the user through the second applet and the authorization server. When the authentication is passed, the authorization server generates a first token and sends the first token to the second applet. On this basis, the first token is passed to the first applet through the second applet, and then jumps back to the first applet. The first applet obtains authorization to access the user's resources from the authorization server based on the passed-back first token. In this authorization and authentication process, the second applet different from the first applet completes the authentication of the user, without authenticating the user by accessing a page in the first applet, thus avoiding problems such as low security and limited configuration of the authorization server caused by authenticating the user by accessing a page in the first applet.

[0043] Among them, the first mini-program can be displayed in the application of the terminal device, and the application can be a social application, a shopping application, or the like.

[0044] Among them, the first mini-program is a mini-program that needs to access the user's resources. The second mini-program is an official mini-program provided by the authorization server for authenticating the user. It can be understood that the second mini-program can also be displayed in the above application.

[0045] Among them, the authorization application operation is an operation for obtaining the first token. The authorization server generates the first token and sends the first token to the second mini-program when it confirms that the user has passed the authentication. As an example, the authorization server can use a hash algorithm to generate the first token.

[0046] In some embodiments, the above authorization and authentication method may include the following steps: The terminal device sends a second acquisition request to the authorization server through the first mini-program. The second acquisition request carries a target token, and the target token includes the first token passed to the first mini-program; The terminal device receives a third token returned by the authorization server through the first mini-program. Among them, the third token is sent by the authorization server when the authorization server authenticates the target token based on the token trusted by the authorization server and the authentication is passed. The first mini-program accesses the user's resources through the third token.

[0047] Among them, the token trusted by the authorization server can be stored locally in the authorization server or in a third-party storage device trusted by the authorization server. It is worth noting that both the token stored locally in the authorization server and the token stored in a third-party storage device trusted by the authorization server can be used as the token trusted by the authorization server for the authorization server to authenticate the target token.

[0048] Among them, the second acquisition request is used to acquire the third token. The target token includes the first token passed from the second mini-program to the first mini-program. On this basis, the authorization server can authenticate the first token in the target token based on the trusted token. If the trusted token includes the first token in the target token, it is determined that the authentication is passed. If the trusted token does not include the first token in the target token, it is determined that the authentication fails.

[0049] From the above Figure 1 It can be seen that the user's resources can be stored in the resource server. In this case, the first mini-program can request resources from the resource server through the third token. After verifying the third token, the resource server can provide corresponding resources for the first mini-program.

[0050] In the above manner, the authorization server authenticates the first applet that needs to access user resources based on the target token sent by the first applet, so as to confirm whether to authorize the first applet to have the permission to access user resources. It can be understood that in this embodiment, a third token can be issued so that the applet with the third token has the permission to access user resources.

[0051] In some embodiments, the step of the above terminal device jumping from the first applet to the second applet in response to an authorization application operation triggered by the user for the first applet displayed on the terminal device can be implemented in the following manner: The terminal device responds to the authorization application operation triggered by the user for the first applet displayed on the terminal device, and generates a second token through the first applet; The terminal device jumps from the first applet to the second applet and passes the second token to the second applet, where the communication is also used to pass the second token to the authorization server through the second applet, and the first applet obtains authorization to access the user's resources from the authorization server based on the first token passed to the first applet and the second token generated by the first applet.

[0052] Among them, the first applet can generate the second token by using a hashing algorithm.

[0053] It can be understood that when the second applet passes the first token to the first applet, it may be intercepted by other applets. Then, other applets obtain the first token and use the first token to request authorization from the authorization server to access the user's resources, thus causing leakage or tampering of user resources.

[0054] Therefore, this embodiment proposes to generate a second token through the first applet and pass the second token to the second applet when the first applet jumps to the second applet. In this way, during the communication process between the second applet and the authorization server, the second applet can pass the second token to the authorization server, providing a data basis for the subsequent first applet to request authorization from the authorization server with the first token and the second token to access the user's resources, and avoiding the situation that the first token is intercepted by other applets and the first token can be used to request authorization from the authorization server to access the user's resources, thereby improving the security of authorization authentication.

[0055] In some embodiments, the steps for the above terminal device to communicate with the authorization server through the second mini-program may include: The terminal device responds to a login operation triggered by the user for the login interface of the second mini-program, and sends an authentication request to the authorization server through the second mini-program. The authentication request carries the login information corresponding to the login operation; The terminal device responds to the authentication passed message returned by the authorization server based on the authentication request, and displays a confirmation authorization control in the second mini-program. The authentication passed message is sent when the authorization server confirms that the user has passed the authentication based on the login information; The terminal device responds to the triggering operation of the user for the confirmation authorization control, and sends a first acquisition request to the authorization server through the second mini-program. The first acquisition request is used to request a first token; The terminal device receives the first token generated and returned by the authorization server through the second mini-program.

[0056] Among them, the login interface of the second mini-program can support the user to select a login method. For example, the login method of account and password, or the login method of SMS. Exemplarily, in the case of selecting the login method of account and password, the user inputs an account and a password based on the login interface, and triggers a login operation based on the input account and input password. It can be understood that, in this embodiment, the login information includes the input account and input password.

[0057] Among them, when the authorization server confirms that the user has passed the authentication based on the login information, it can return an authentication passed message to the second mini-program.

[0058] Among them, the confirmation authorization control can be displayed in a pop-up window on the login interface.

[0059] Among them, the triggering operation for the confirmation authorization control can be a click operation, such as a single click operation.

[0060] In the above manner, whether the user's login information can successfully log in to the second mini-program is used to enable the authorization server to confirm whether the user has passed the authentication; in this case, a secondary operation to support the user's confirmation of authorization is provided to avoid triggering subsequent processes due to the user's misoperation, thereby avoiding the occupation of resources by the terminal device or the authorization server when executing subsequent processes.

[0061] In some embodiments, when the authorization server confirms that the user has not passed the authentication based on the login information, it can send an authentication failure message to the second mini-program. Further, a prompt message indicating authentication failure can be displayed in the second mini-program, so that it is convenient for the user to understand the result of the authentication through the second mini-program.

[0062] In some embodiments, a deauthorization control may further be included. Similar to the authorization confirmation control, the deauthorization control and the authorization confirmation control may be synchronously displayed in a pop-up window on the login interface. The user may trigger an operation on the deauthorization control, thereby ending the execution of the authorization authentication method.

[0063] In some embodiments, both the first token generated by the authorization server and the second token generated by the first applet are temporary tokens. It can be understood that a temporary token is an authorization credential with a validity period, thereby enhancing the security of authorization authentication.

[0064] Figure 3 is a schematic diagram of the authorization authentication method shown according to an embodiment of the present disclosure. In this embodiment, the target token includes the first token generated by the authorization server and the second token generated by the first applet. Refer to Figure 3 , display the first applet in the application of the terminal device. The terminal device responds to the authorization application operation triggered by the user in the first applet displayed on the terminal device, jumps from the first applet to the second applet, and transfers the second token generated by the first applet to the second applet.

[0065] The terminal device responds to the login operation triggered by the user in the login interface of the second applet through the second applet; the terminal device sends an authentication request to the authorization server through the second applet, and the login information is carried in the authentication request.

[0066] The authorization server confirms whether the user passes the authentication based on the login information, and in the case of successful authentication, the authorization server returns authentication passed information to the second applet.

[0067] The terminal device responds to the triggering operation on the authorization confirmation control triggered by the user in the second applet through the second applet. The terminal device sends a first acquisition request to the authorization server through the second applet. The second token is carried in the first acquisition request, and the first acquisition request is used to request the first token.

[0068] The authorization server responds to the first acquisition request, generates the first token, stores the first token and the second token generated by the first applet locally, and returns the first token to the second applet. Among them, the second token generated by the first applet may be carried in the first acquisition request to facilitate the second applet to transfer the second token to the authorization server. In other embodiments, the second token may not be carried in the first acquisition request and may be transferred to the authorization server by other means. This embodiment does not limit this.

[0069] The terminal device jumps back from the second mini-program to the first mini-program and passes the first token to the first mini-program through the second mini-program. The terminal device sends a second acquisition request to the authorization server through the first mini-program, and the target token is carried in the second acquisition request. The target token includes the second token generated by the first mini-program and the first token passed back by the second mini-program.

[0070] The authorization server authenticates the target token based on the token stored locally. When the target token is authenticated successfully, the authorization server issues a third token to the first mini-program, so that the first mini-program obtains the authorization to access the user's resources. That is, the first mini-program can access the user's resources with the third token.

[0071] The embodiments of the present disclosure further provide an authorization and authentication method, which is executed by the authorization server. The method includes: the authorization server communicates with the second mini-program displayed on the terminal device; wherein, the second mini-program is displayed on the terminal device after jumping from the first mini-program in response to the authorization application operation triggered by the user for the first mini-program displayed on the terminal device. The communication is used for the authorization server to generate the first token and send the first token to the second mini-program when it is confirmed that the user passes the authentication. The terminal device passes the first token to the first mini-program through the second mini-program, and the first mini-program obtains the authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0072] In some embodiments, the above communication is further used to pass the second token to the authorization server through the second mini-program, where the second token is generated by the terminal device through the first mini-program in response to the authorization application operation triggered by the user for the first mini-program displayed on the terminal device. The first mini-program obtains the authorization to access the user's resources from the authorization server based on the first token passed to the first mini-program and the second token generated by the first mini-program.

[0073] In some embodiments, the above communication between the authorization server and the second mini-program displayed on the terminal device can be implemented in the following manner: the authorization server receives an authentication request sent by the second mini-program, and the login information is carried in the authentication request. The login information is the information corresponding to the login operation triggered by the user through the terminal device for the login interface of the second mini-program; when the authorization server confirms that the user passes the authentication based on the login information, it sends an authentication passed message to the second mini-program; the authorization server receives a first acquisition request sent by the second mini-program, and the first acquisition request is sent when the user triggers an operation on the confirmation authorization control through the terminal device; in response to the first acquisition request, the authorization server generates the first token and sends the first token to the second mini-program.

[0074] In some embodiments, the above authorization and authentication method further includes: the authorization server receives a second acquisition request sent by the first mini-program, where the target token is carried in the second acquisition request, and the target token includes the first token passed to the first mini-program, or the target token includes the first token passed to the first mini-program and the second token generated by the first mini-program; when the authorization server authenticates the target token based on the trusted token and the authentication is passed, the authorization server sends a third token to the first mini-program, and the first mini-program accesses the user's resources through the third token.

[0075] In some embodiments, both the first token and the second token are temporary tokens.

[0076] Among them, for the implementation process of the authorization and authentication method executed by the authorization server, reference can be made to the implementation process of the authorization and authentication method executed by the above terminal device, and details are not described herein.

[0077] Figure 4 is a block diagram of an authorization and authentication device shown according to an embodiment of the present disclosure. The authorization and authentication device 400 is applied to a terminal device. Referring to Figure 4 , the authorization and authentication device 400 may include: A first response module 401, configured to respond to an authorization application operation triggered by a user for a first mini-program displayed on the terminal device, and jump from the first mini-program to a second mini-program; A first communication module 402, configured to communicate with an authorization server through the second mini-program, where the communication is used for the authorization server to generate a first token and send the first token to the second mini-program when it is confirmed that the user passes the authentication; A second response module 403, configured to respond to the second mini-program receiving the first token, jump back from the second mini-program to the first mini-program, and pass the received first token to the first mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0078] Optionally, the first response module 401 includes: A first response sub-module, configured to respond to an authorization application operation triggered by a user for a first mini-program displayed on the terminal device, and generate a second token through the first mini-program; The first-hop rotor module is used to jump from the first applet to the second applet and transfer the second token to the second applet. Among them, the communication is also used to transfer the second token to the authorization server through the second applet. The first applet obtains authorization to access the user's resources from the authorization server based on the first token transferred to the first applet and the second token generated by the first applet.

[0079] Optionally, the first communication module 402 includes: The second response sub-module is used to send an authentication request to the authorization server through the second applet in response to the login operation triggered by the user for the login interface of the second applet. The authentication request carries the login information corresponding to the login operation. The third response sub-module is used to display a confirmation authorization control in the second applet in response to the authentication passed message returned by the authorization server based on the authentication request. The authentication passed message is sent when the authorization server confirms that the user has passed the authentication based on the login information. The fourth response sub-module is used to send a first acquisition request to the authorization server through the second applet in response to the trigger operation of the user for the confirmation authorization control. The first acquisition request is used to request a first token. The receiving sub-module is used to receive the first token generated and returned by the authorization server through the second applet.

[0080] Optionally, the authorization and authentication device 400 further includes: The first sending module is used to send a second acquisition request to the authorization server through the first applet. The second acquisition request carries the target token. The target token includes the first token transferred to the first applet, or the target token includes the first token transferred to the first applet and the second token generated by the first applet. The first receiving module is used to receive the third token returned by the authorization server through the first applet. Among them, the third token is sent when the authorization server authenticates the target token based on the token trusted by the authorization server and the authentication is passed. The first applet accesses the user's resources through the third token.

[0081] Optionally, both the first token and the second token are temporary tokens.

[0082] Among them, the implementation manners of the various modules in the above authorization and authentication device 400 can refer to the above related embodiments, and this embodiment will not be elaborated here.

[0083] An embodiment of the present disclosure further provides an authorization and authentication device, which is applied to an authorization server. The authorization and authentication device includes: A second communication module, configured to communicate with a second mini-program displayed on a terminal device; Wherein, the second mini-program is displayed on the terminal device after jumping from a first mini-program in response to an authorization application operation triggered by a user for the first mini-program displayed on the terminal device. The communication is used for the authorization server to generate a first token and send the first token to the second mini-program when it is confirmed that the user passes the authentication. The terminal device passes the first token to the first mini-program through the second mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0084] An embodiment of the present disclosure further provides a computer-readable medium, on which a computer program is stored. When the computer program is executed by a processing device, the steps of the above authorization and authentication method are implemented.

[0085] An embodiment of the present disclosure further provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the above feature processing method are implemented.

[0086] An embodiment of the present disclosure further provides an electronic device, including: A storage device, on which a computer program is stored; A processing device, configured to execute the computer program in the storage device to implement the steps of the above authorization and authentication method.

[0087] Next, refer to Figure 5 , which shows a schematic structural diagram of an electronic device (such as a terminal device or an authorization server in Figure 1 ) 500 suitable for implementing the embodiments of the present disclosure. The electronic device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0088] As shown in Figure 5As shown, the electronic device 500 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 501, which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage device 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 are also stored. The processing device 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.

[0089] Generally, the following devices may be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 509. The communication device 509 may allow the electronic device 500 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 5 the electronic device 500 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0090] Specifically, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above functions defined in the method of the embodiment of the present disclosure are executed.

[0091] It should be noted that the computer-readable medium described above in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0092] In some embodiments, the terminal device and the authorization server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0093] The above computer-readable medium can be included in the above electronic device; it can also exist separately without being assembled into the electronic device.

[0094] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: in response to an authorization application operation triggered by the user for a first mini-program displayed on the terminal device, jump from the first mini-program to a second mini-program; communicate with an authorization server through the second mini-program, where the communication is for the authorization server to generate a first token and send the first token to the second mini-program when it confirms that the user has passed authentication; in response to the second mini-program receiving the first token, jump back from the second mini-program to the first mini-program and pass the received first token to the first mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0095] Alternatively, the above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: communicate with a second mini-program displayed on the terminal device; where the second mini-program is displayed on the terminal device after jumping from a first mini-program in response to an authorization application operation triggered by the user for the first mini-program displayed on the terminal device, and the communication is for the authorization server to generate a first token and send the first token to the second mini-program when it confirms that the user has passed authentication, and the terminal device passes the first token to the first mini-program through the second mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

[0096] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The above programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0097] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0098] The modules described in the embodiments of the present disclosure can be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the module itself.

[0099] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0100] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0101] The above description is only a preferred embodiment of the present disclosure and an illustration of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by the mutual replacement of the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.

[0102] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0103] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms for implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

Claims

1. An authorization and authentication method, characterized in that, Executed by a terminal device, the method includes: In response to an authorization application operation triggered by a user for a first mini-program displayed on the terminal device, jump from the first mini-program to a second mini-program; Communicate with an authorization server through the second mini-program, where the communication is for the authorization server to generate a first token and send the first token to the second mini-program when it confirms that the user has passed authentication; In response to the second mini-program receiving the first token, jump back from the second mini-program to the first mini-program and pass the received first token to the first mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first mini-program.

2. The method according to claim 1, characterized in that, The step of, in response to an authorization application operation triggered by a user for a first mini-program displayed on the terminal device, jump from the first mini-program to a second mini-program, includes: In response to an authorization application operation triggered by a user in the first mini-program displayed on the terminal device, generate a second token through the first mini-program; Jump from the first mini-program to the second mini-program and pass the second token to the second mini-program, where the communication is further for passing the second token to the authorization server through the second mini-program, and the first mini-program obtains authorization to access the user's resources from the authorization server based on the first token passed to the first mini-program and the second token generated by the first mini-program.

3. The method according to claim 1 or 2, characterized in that, The step of communicating with an authorization server through the second mini-program includes: In response to a login operation triggered by the user for the login interface of the second mini-program, send an authentication request to the authorization server through the second mini-program, where the authentication request carries the login information corresponding to the login operation; In response to an authentication passed message returned by the authorization server based on the authentication request, display a confirmation authorization control in the second mini-program, where the authentication passed message is sent when the authorization server confirms that the user has passed authentication based on the login information; In response to a trigger operation by the user for the confirmation authorization control, send a first acquisition request to the authorization server through the second mini-program, where the first acquisition request is used to request a first token; Receive the first token generated and returned by the authorization server through the second mini-program.

4. The method according to claim 1 or 2, characterized in that, The method further includes: Send a second acquisition request to the authorization server through the first mini-program, where the second acquisition request carries the target token, and the target token includes the first token passed to the first mini-program, or the target token includes the first token passed to the first mini-program and the second token generated by the first mini-program; Receive a third token returned by the authorization server through the first applet, where the third token is sent by the authorization server when the authorization server authenticates the target token based on a token trusted by the authorization server and the authentication is successful, and the first applet accesses the user's resources through the third token.

5. The method according to claim 2, wherein Both the first token and the second token are temporary tokens.

6. An authorization and authentication method, characterized in that, Executed by the authorization server, the method includes: Communicate with a second applet displayed on the terminal device; Wherein, the second applet is displayed on the terminal device after jumping from the first applet in response to an authorization application operation triggered by the user for the first applet displayed on the terminal device. The communication is used for the authorization server to generate a first token and send the first token to the second applet when it confirms that the user has passed the authentication. The terminal device passes the first token to the first applet through the second applet, and the first applet obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first applet.

7. An authorization and authentication device, characterized in that, Applied to a terminal device, the authorization authentication device includes: A first response module, configured to jump from the first applet to a second applet in response to an authorization application operation triggered by the user for the first applet displayed on the terminal device; A first communication module, configured to communicate with the authorization server through the second applet, where the communication is used for the authorization server to generate a first token and send the first token to the second applet when it confirms that the user has passed the authentication; A second response module, configured to jump back from the second applet to the first applet in response to the second applet receiving the first token, and pass the received first token to the first applet, and the first applet obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first applet.

8. An authorization and authentication device, characterized in that, Applied to the authorization server, the authorization authentication device includes: A second communication module, configured to communicate with a second applet displayed on the terminal device; Wherein, the second applet is displayed on the terminal device after jumping from the first applet in response to an authorization application operation triggered by the user for the first applet displayed on the terminal device. The communication is used for the authorization server to generate a first token and send the first token to the second applet when it confirms that the user has passed the authentication. The terminal device passes the first token to the first applet through the second applet, and the first applet obtains authorization to access the user's resources from the authorization server at least based on the first token passed to the first applet.

9. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by the processing device, the computer program implements the steps of the method according to any one of claims 1-5, or the steps of the method according to claim 6.

10. An electronic device, characterized in that, Including: A storage device on which a computer program is stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-5, or the steps of the method according to claim 6.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-5, or the steps of the method according to claim 6.