Login authentication method and device and storage medium
By introducing gateways and IAM authentication servers into the login authentication system, generating tokens and loading target pages, the problem of client login-free jumping to servers in the existing technology is solved, and information security and user experience are improved.
Patent Information
- Application Number
- CN202410089506.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-22
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, central authentication server (CAS) authentication mainly allows single sign-in between multiple applications and systems, but lacks the exploration of client login without jumping to the server, resulting in insufficient information security.
By introducing gateway, front-end, client and IAM authentication server into the login authentication system, the gateway controls the client to receive login requests, and after verification is passed, the IAM authentication server generates a token, sends instructions to the front-end through the gateway, loads the target page, and realizes that the client can log in without logging and jump to the server.
It realizes the information security of the client, avoids unnecessary jumps, improves information security, and simplifies the user login process.
Smart Images

Figure CN120358041A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a login authentication method, apparatus, and storage medium. Background Art
[0002] With the development of Internet technologies, network applications have penetrated all aspects of people's lives, and information security has become a top priority in Internet technologies. The Central Authentication Service (CAS) is a centralized authentication service, whose main function is to simplify the user login process, enabling users to access all applications and systems that support CAS authentication with only one login.
[0003] Currently, CAS authentication mainly allows single sign-on between multiple applications and systems, lacking exploration of client-free-login jump to the server side. Summary of the Invention
[0004] This application provides a login authentication method, apparatus, and storage medium, which can ensure the information security of the client and enable the client to jump to the server side without logging in.
[0005] To achieve the above object, this application adopts the following technical solutions:
[0006] In a first aspect, this application provides a login authentication method, which is applied to a login authentication system. The login authentication system includes a gateway, a front end, a client, and an IAM authentication server. The method includes: controlling the gateway to receive a login request from the client; when the login request is verified and the user information of the client is stored in the IAM authentication server, controlling the IAM authentication server to send a first indication message to the front end through the gateway. The first indication message is used to instruct the front end to load a target page, where the target page is a page associated with the first indication message, and the target page displays login authentication information.
[0007] In combination with the first aspect, in a possible implementation manner, the first indication information carries a token corresponding to the user information; one token corresponds to one target page; when the verification of the login request passes and the user information of the client is stored in the IAM authentication server, controlling the IAM authentication server to send the first indication information to the front end through the gateway includes: when the verification of the login request passes, controlling the gateway to send second indication information to the IAM authentication server; the second indication information is used to instruct the IAM authentication server to query whether the user information is stored; when the user information is stored in the IAM authentication server, controlling the IAM authentication server to generate the token and send the first indication information to the front end through the gateway.
[0008] In combination with the first aspect, in a possible implementation manner, the login authentication system further includes a CAS authentication server; before controlling the gateway to send the second indication information to the IAM authentication server, it further includes: controlling the gateway to send third indication information to the CAS authentication server; the third indication information is used to instruct the CAS authentication server to perform pre-verification on the login request; when the verification of the login request passes, controlling the CAS authentication server to send the user information to the gateway.
[0009] In combination with the first aspect, in a possible implementation manner, the method further includes: when the verification of the login request fails, controlling the client to send a system internal error message to the front end through the gateway.
[0010] In combination with the first aspect, in a possible implementation manner, the method further includes: when the user information is not stored in the IAM authentication server, controlling the client to send a message indicating that the user information does not exist to the front end through the gateway.
[0011] In a second aspect, the present application provides a login authentication device applied to a login authentication system, the login authentication system including a gateway, a front end, a client, and an IAM authentication server; the device includes: a processing unit and a communication unit; the communication unit is used to control the gateway to receive the login request of the client; when the verification of the login request passes and the user information of the client is stored in the IAM authentication server, the communication unit is further used to control the IAM authentication server to send the first indication information to the front end through the gateway; the first indication information is used to instruct the front end to load a target page, the target page is a page associated with the first indication information, and the target page displays login authentication information.
[0012] In combination with the second aspect, in a possible implementation, the first indication information carries a token corresponding to the user information; one token corresponds to one target page; when the login request is verified successfully, the communication unit is further configured to control the gateway to send second indication information to the IAM authentication server; the second indication information is used to instruct the IAM authentication server to query whether the user information is stored; when the user information is stored in the IAM authentication server, the processing unit is further configured to control the IAM authentication server to generate the token, and send the first indication information to the front end through the gateway.
[0013] In combination with the second aspect, in a possible implementation, the login authentication system further includes a CAS authentication server; the communication unit is further configured to: control the gateway to send third indication information to the CAS authentication server; the third indication information is used to instruct the CAS authentication server to perform pre-check on the login request; when the login request is verified successfully, control the CAS authentication server to send the user information to the gateway.
[0014] In combination with the second aspect, in a possible implementation, the communication unit is further configured to: when the login request is not verified successfully, control the client to send an internal system error message to the front end through the gateway.
[0015] In combination with the second aspect, in a possible implementation, the communication unit is further configured to: when the user information is not stored in the IAM authentication server, control the client to send a message indicating that the user information does not exist to the front end through the gateway.
[0016] In a third aspect, the present application provides a login authentication device, which includes: a processor and a communication interface; the communication interface is coupled to the processor, and the processor is configured to run a computer program or instruction to implement the login authentication method described in the first aspect and any possible implementation of the first aspect.
[0017] In a fourth aspect, the present application provides a computer-readable storage medium, in which instructions are stored, and when the instructions are run on a terminal, the terminal is caused to execute the login authentication method described in the first aspect and any possible implementation of the first aspect.
[0018] In the present application, the name of the above-mentioned login authentication device does not constitute a limitation to the device or functional module itself. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those of the present application, they fall within the scope of the claims of the present application and their equivalent technologies.
[0019] These aspects or other aspects of the present application will be more clearly understood in the following description.
[0020] Based on the above technical solution, in a login authentication method provided by the present application, the login authentication system can control the gateway to receive a login request from the client. If the login request is verified and passed, it indicates that the verification message sent by the client is valid, and subsequent operations can be performed, thereby ensuring the information security of the client. Furthermore, the IAM authentication server can determine whether user information associated with the client is stored. If so, the login authentication system can control the IAM authentication server to send information indicating to load the target page to the front end through the gateway, and control the front end to display the login authentication information, thereby being able to ensure the information security of the client and enabling the client to skip the login and jump to the server. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic structural diagram of a login authentication system provided by the present application;
[0022] Figure 2 It is a schematic structural diagram of a login authentication device provided by the present application;
[0023] Figure 3 It is a flowchart of a login authentication method provided by the present application;
[0024] Figure 4 It is a schematic diagram of front-end display information provided by the present application;
[0025] Figure 5 It is a flowchart of another login authentication method provided by the present application;
[0026] Figure 6 It is a flowchart of another login authentication method provided by the present application;
[0027] Figure 7 It is a flowchart of another login jump method provided by the present application;
[0028] Figure 8 It is a schematic structural diagram of another login authentication device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] Next, the technical solutions in some embodiments of the present disclosure will be clearly and completely described in conjunction with the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. Based on the embodiments provided by the present disclosure, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present disclosure.
[0030] Unless the context requires otherwise, throughout the specification and claims, the term "comprise" and its other forms, such as the third-person singular form "comprises" and the present participle form "comprising", are to be construed in an open, inclusive sense, i.e., "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "example", "specific example", or "some examples", etc., are intended to indicate that a specific feature or characteristic related to the embodiment or example is included in at least one embodiment or example of the present disclosure. The schematic representations of the above terms do not necessarily refer to the same embodiment or example. In addition, the specific features or characteristics may be included in any one or more embodiments or examples in any appropriate manner.
[0031] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present disclosure, unless otherwise stated, the meaning of "a plurality of" is two or more.
[0032] When describing some embodiments, the expressions "coupled" and "connected" and their derivatives may be used. For example, when describing some embodiments, the term "connected" may be used to indicate that two or more components have direct physical contact or electrical contact with each other. Another example is that when describing some embodiments, the term "coupled" may be used to indicate that two or more components have direct physical contact or electrical contact. However, the term "coupled" or "communicatively coupled" may also mean that two or more components do not have direct contact with each other but still cooperate or interact with each other. The embodiments disclosed herein are not necessarily limited to the content herein.
[0033] "At least one of A, B, and C" has the same meaning as "at least one of A, B, or C", and both include the following combinations of A, B, and C: only A, only B, only C, the combination of A and B, the combination of A and C, the combination of B and C, and the combination of A, B, and C.
[0034] "A and / or B" includes the following three combinations: only A, only B, and the combination of A and B.
[0035] As used herein, depending on the context, the term "if" is optionally interpreted to mean "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined that..." or "if [the stated condition or event] is detected" is optionally interpreted to mean "when it is determined that..." or "in response to determining..." or "when [the stated condition or event] is detected" or "in response to detecting [the stated condition or event]".
[0036] The use of "configured to" or "adapted to" in this document means open and inclusive language that does not exclude devices that are configured to or adapted to perform additional tasks or steps.
[0037] In addition, the use of "based on" is open and inclusive because a process, step, calculation, or other action "based on" one or more conditions or values can, in practice, be based on additional conditions or values beyond those stated. Currently, the Internet of Things (IoT) is a network that connects and interacts various physical devices and sensors via the Internet. The core idea of the IoT is to enable various devices to achieve intelligence, automation, and remote control via the Internet. Among them, the development of IoT devices refers to the process of developing, designing, and implementing IoT devices, including work in aspects such as hardware design, communication technology, and software development. The development of IoT devices enables the interconnection and interoperability between devices. Through IoT technology, traditional devices and instruments can be made intelligent and remotely controllable, achieving more efficient, convenient, and intelligent applications.
[0038] Hereinafter, the terms related to the embodiments of the present application are explained to facilitate the understanding of readers.
[0039] Spring Cloud architecture.
[0040] It is one of the microservices architectures currently available on the market, providing rich components such as the Spring Gateway gateway and Spring Boot, etc. Generally, microservices architectures have an independent IAM authentication service that cooperates with the gateway to control the permissions of the entire microservices. The core of this architecture is to intercept all requests entering the system through a set of filter chains, verify whether the requests have resource access permissions, achieve the purpose of secure access control, and quickly implement functions such as authentication, authorization, and attack protection.
[0041] With the development of Internet technology, network applications have penetrated into all aspects of people's lives, and information security has become a top priority in Internet technology. The Central Authentication Service (CAS) is a centralized authentication service, whose main function is to simplify the user login process, enabling users to access all applications and systems that support CAS authentication with only one login. Currently, CAS authentication mainly allows single sign-on between multiple applications and systems, lacking exploration of client-free-login jump to the server side.
[0042] To solve the problems in the prior art, in the login authentication method provided by an embodiment of this application, the login authentication system can control the gateway to receive the login request from the client. If the login request is verified successfully, it indicates that the verification message sent by the client is valid, and subsequent operations can be carried out to ensure the information security of the client. Furthermore, the IAM authentication server can determine whether it stores user information associated with the client. If so, the login authentication system can control the IAM authentication server to send information instructing to load the target page to the front end through the gateway, and control the front end to display the login authentication information, thereby ensuring the information security of the client and enabling the client to jump to the server side without logging in.
[0043] As Figure 1 shown is a schematic structural diagram of a login authentication system 100 provided by an embodiment of this application. The login authentication system 100 includes a client 101, a CAS authentication server 102, a front end 103, and a server 104.
[0044] Among them, the server 104 includes a gateway, an IAM authentication server, and microservices.
[0045] The client 101 can be understood as a customer informatization management platform, which can synchronize multiple user information to the IAM authentication server 105 in advance, and the IAM authentication server 105 stores the multiple user information for subsequent query.
[0046] The CAS authentication server 102, that is, the Central Authentication Server, is used to verify the validity of the client login request, that is, the validity of the ticket.
[0047] The front end 103 is a software front end, such as a third-party application (APP) on a certain terminal device.
[0048] The gateway in the embodiments of the present application may be the Spring Gateway. The Spring Gateway is a gateway framework based on Netflix Zuul under the Spring framework, and its main functions include traffic management, request filtering, response processing, integration with other frameworks, etc.
[0049] The IAM authentication server is for Identity and Access Management (IAM) authentication. It is a technology used to verify user identities and grant them access rights, and has functions such as single sign-on, powerful authentication management, policy-based centralized authorization and auditing, dynamic authorization, and enterprise manageability.
[0050] The microservices architecture includes an overall architecture and a service-oriented architecture (SOA), and usually includes many small, loosely coupled, and separately deployable components or services in a single application. In the embodiments of the present application, it is used to feedback the request results of the front end 103 to the gateway.
[0051] It should be noted that the communication system described in the embodiments of the present application is to more clearly illustrate the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of communication systems and the emergence of other communication systems, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.
[0052] In one example, Figure 2 This is a schematic structural diagram of a login authentication device provided in the embodiments of the present application. The login authentication device 200 includes at least one processor 201, a communication line 202, and at least one communication interface 204, and may further include a memory 203. Among them, the processor 201, the memory 203, and the communication interface 204 can be connected through the communication line 202.
[0053] The processor 201 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, for example: one or more digital signal processors (DSP), or one or more field programmable gate arrays (FPGA).
[0054] The communication line 202 may include a path for transmitting information between the above components.
[0055] A communication interface 204, which is used to communicate with other devices or communication networks, can use any device such as a transceiver, such as Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc.
[0056] The memory 203 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to include or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0057] In a possible design, the memory 203 can exist independently of the processor 201, that is, the memory 203 can be a memory external to the processor 201. At this time, the memory 203 can be connected to the processor 201 through a communication line 202, used to store execution instructions or application program codes, and controlled by the processor 201 to execute, so as to implement the network quality determination method provided in the following embodiments of the present application. In another possible design, the memory 203 can also be integrated with the processor 201, that is, the memory 203 can be an internal memory of the processor 201. For example, the memory 203 is a cache, which can be used to temporarily store some data and instruction information, etc.
[0058] As an implementable manner, the processor 201 can include one or more CPUs, such as Figure 2 CPU0 and CPU1 in Figure 2 As another implementable manner, the login authentication device 200 can include multiple processors, such as
[0059] From the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the network node is divided into different functional modules to complete all or part of the functions described above. The specific working processes of the systems, modules, and network nodes described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0060] As Figure 3 shown, it is a flowchart of a login authentication method provided by an embodiment of the present application. The login authentication method provided by the embodiment of the present application can be applied to a login authentication system as Figure 1 shown. The login authentication method provided by the embodiment of the present application can be implemented through the following steps.
[0061] S301. The control gateway receives a login request from the client.
[0062] In the embodiment of the present application, the client (user information management platform) pre-configures a jump link of the server in response to the user's operation. Furthermore, when the client clicks the jump link again in response to the user's touch operation, the gateway receives the login request from the client.
[0063] Exemplarily, the client clicks the link and accesses the gateway with a ticket issued by CAS.
[0064] S302. When the login request is verified and the user information of the client is stored in the IAM authentication server, control the IAM authentication server to send a first indication message to the front end through the gateway.
[0065] Among them, the first indication message is used to indicate the front end to load a target page, and the target page is a page associated with the first indication message. Further, the first indication message carries a token corresponding to the user information, and one token corresponds to one target page.
[0066] In the embodiment of the present application, the login authentication system controls the gateway to send a third indication message to the CAS authentication server, and when the login request is verified, the login authentication system controls the CAS authentication server to send user information to the gateway.
[0067] Furthermore, the login authentication system controls the gateway to send a second indication message to the IAM authentication server. If the user information is stored in the IAM authentication server, the login authentication system controls the IAM authentication server to generate a token and send a first indication message to the front end through the gateway.
[0068] Among them, the second indication information is used to indicate the IAM authentication server to query whether user information is stored, and the third indication information is used to indicate the CAS authentication server to perform pre-verification on the login request.
[0069] Exemplarily, the gateway receives a login request carrying a ticket sent by the client and calls the CAS authentication server to verify the validity of the ticket, that is, sends the third indication information to the CAS authentication server. When the CAS authentication server verifies that the ticket is valid, it feeds back the user information of the client to the gateway, such as: username.
[0070] Furthermore, the gateway calls the IAM authentication server to generate a token associated with the user information. That is, the gateway sends the second indication information to the IAM authentication server to indicate the IAM authentication server to query whether the user information is stored in its own memory. If so, the IAM authentication server generates a token associated with the user information. The IAM authentication server feeds back the token to the front end through the gateway, and the front end loads the target page after receiving the token.
[0071] It can be understood that the ticket in the embodiment of the present application can be a verification message. The Token can be a token used in the free authentication system of the login authentication system, and the token authentication is uniformly used in the login authentication system.
[0072] Exemplarily, the display screen of the front end can display the words "Login authentication successful" to inform the user that the login is completed.
[0073] It should be understood that the front end can be mobile phones of different brands or models, and the display word methods of mobile phones of different brands or models are designed differently. For example, the words can be displayed through the negative first screen of the mobile phone.
[0074] For another example, the mobile phone can send a prompt message through a notification message. For another example, the mobile phone can respond to the operation of the user inputting to open the notification bar on the touch screen and display Figure 4 the shown notification interface 401. The notification interface 401 includes a notification bar 402 and a logged-in authentication message 403. The logged-in authentication message 403 includes the above prompt message.
[0075] Optionally, the mobile phone or the user can set a display duration for the reminder message in advance. For example, after the display duration, the mobile phone can automatically clear the prompt message.
[0076] Based on Figure 3In the technical solution, in the login authentication method provided in the embodiments of the present application, the login authentication system can control the gateway to receive the login request from the client. If the login request is verified successfully, it indicates that the verification message sent by the client is valid, and subsequent operations can be performed to ensure the information security of the client. Furthermore, the IAM authentication server can determine whether user information associated with the client is stored. If so, the login authentication system can control the IAM authentication server to send information indicating to load the target page to the front end through the gateway, and control the front end to display the login authentication information, thereby being able to ensure the information security of the client and enabling the client to skip the login and jump to the server without logging in.
[0077] The following outlines the process of another login authentication method provided in the embodiments of the present application, specifically as Figure 5 shown.
[0078] S501. The gateway receives the login request from the client.
[0079] S502. Control the gateway to send the third indication information to the CAS authentication server.
[0080] Among them, the third indication information is used to instruct the CAS authentication server to perform pre-check on the login request.
[0081] S503. The CAS authentication server verifies whether the login request is successful.
[0082] S504. If the login request fails to be verified, control the client to send an internal system error message to the front end through the gateway.
[0083] S505. If the login request is verified successfully, control the CAS authentication server to send user information to the gateway.
[0084] S506. Control the gateway to send the second indication information to the IAM authentication server.
[0085] Among them, the second indication information is used to instruct the IAM authentication server to query whether user information is stored.
[0086] S507. Whether user information is stored in the IAM authentication server.
[0087] S508. If user information is not stored in the IAM authentication server, control the client to send a message indicating that the user information does not exist to the front end through the gateway.
[0088] S509. If user information is stored in the IAM authentication server, control the IAM authentication server to generate a token and send the first indication information to the front end through the gateway.
[0089] S510. Control the front end to display the login authentication information.
[0090] The following outlines the process of another login authentication method provided by the embodiments of the present application, specifically as Figure 6 shown.
[0091] S601. The client (customer informatization management platform) sends multiple user information to the IAM authentication server. Correspondingly, the IAM authentication server receives the multiple user information sent by the client.
[0092] In the embodiments of the present application, the user information can be a username, a user ID, a user email, etc., so as to ensure that the user information owned by the client and the server is consistent.
[0093] S602. The IAM authentication server saves the multiple user information provided by the client, that is, stores the multiple user information.
[0094] S603. The client sends a login request to the gateway. Correspondingly, the gateway receives the login request sent by the client.
[0095] Among them, the user configures a jump link in the client (customer informatization management platform). The client can, in response to the user's touch operation, click the jump link and access the gateway with the ticket issued by the CAS authentication server.
[0096] S604. The gateway sends third indication information to the CAS authentication server.
[0097] Among them, the third indication information is used to instruct the CAS authentication server to perform a pre-check on the login request.
[0098] In the embodiments of the present application, the gateway can call the CAS authentication server to verify the validity of the ticket in the login request.
[0099] S605. The CAS authentication server verifies the login request.
[0100] In the embodiments of the present application, the CAS authentication server verifies the validity of the ticket in the login request.
[0101] S606. When the login request is verified to be passed, the CAS authentication server sends user information to the gateway.
[0102] In the embodiments of the present application, when the CAS authentication server verifies that the ticket is valid, it can send the user information associated with the ticket, such as the username, to the gateway.
[0103] S607. The gateway sends second indication information to the IAM authentication server.
[0104] Among them, the second indication information is used to indicate whether the IAM authentication server queries and stores user information.
[0105] In the embodiments of the present application, the gateway may call the IAM authentication server to query whether user information is stored in its own memory.
[0106] S608. The IAM authentication server generates a token.
[0107] In the embodiments of the present application, when the IAM authentication server queries and stores user information, it may generate a token.
[0108] S609. The IAM authentication server sends the token to the gateway. Correspondingly, the gateway receives the token sent by the IAM authentication server.
[0109] S610. The gateway uses redirection to send the token to the front end.
[0110] S611. The front end initializes the page.
[0111] In the embodiments of the present application, the display screen of the front end may display the words "Login authentication successful".
[0112] The above has introduced in detail the process of another login authentication method provided by the embodiments of the present application. After the above login authentication is completed on the client side, it is possible to jump to the microservice without logging in. The following outlines the process of this login jump method, specifically as Figure 7 shown.
[0113] S701. The front end sends a login request. Correspondingly, the gateway receives the login request sent by the front end.
[0114] S702. The gateway calls the IAM authentication server to verify the token.
[0115] In the embodiments of the present application, the login request carries the token, and the IAM authentication server can verify the validity of the token.
[0116] S703. The IAM authentication server sends the verification result to the gateway.
[0117] S704. When the verification result is passed, the gateway sends a login request to the microservice.
[0118] S705. The microservice sends the processing result of the login request to the front end through the gateway.
[0119] In summary, the login authentication method provided by the embodiments of the present application can integrate the client (customer information management platform) into the login authentication system of the embodiments of the present application. The login authentication system integrates the Spring Gateway gateway and the CAS authentication server to achieve front-end seamless jump to microservices.
[0120] The embodiments of the present application can divide the functional modules or functional units of the login authentication device according to the above method examples. For example, each functional module or functional unit can be corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules or functional units. Among them, the division of modules or units in the embodiments of the present application is illustrative, only a logical function division, and there can be other division methods in actual implementation.
[0121] As Figure 8 shown, it is a schematic structural diagram of a login authentication device provided by an embodiment of the present application. The login authentication device is applied to a login authentication system, and the login authentication system includes a gateway, a front end, a client, and an IAM authentication server. The device includes: a processing unit 801 and a communication unit 802. The communication unit 802 is configured to control the gateway to receive a login request from the client. When the login request is verified and the user information of the client is stored in the IAM authentication server, the communication unit 802 is further configured to control the IAM authentication server to send a first indication message to the front end through the gateway. The first indication message is used to instruct the front end to load a target page, and the target page is a page associated with the first indication message. The processing unit 801 is configured to control the front end to display login authentication information.
[0122] In a possible implementation manner, the first indication message carries a token corresponding to the user information; one token corresponds to one target page. When the login request is verified, the communication unit 802 is further configured to control the gateway to send a second indication message to the IAM authentication server. The second indication message is used to instruct the IAM authentication server to query whether user information is stored. When the user information is stored in the IAM authentication server, the processing unit 801 is further configured to control the IAM authentication server to generate a token and send the first indication message to the front end through the gateway.
[0123] In a possible implementation manner, the login authentication system further includes a CAS authentication server. The communication unit 802 is further configured to: control the gateway to send a third indication message to the CAS authentication server. The third indication message is used to instruct the CAS authentication server to perform pre-check on the login request. When the login request is verified, control the CAS authentication server to send user information to the gateway.
[0124] In a possible implementation, when the login request fails to be verified, the client is controlled to send an internal system error message to the front end through the gateway.
[0125] In a possible implementation, when the user information is not stored in the IAM authentication server, the client is controlled to send a message indicating that the user information does not exist to the front end through the gateway.
[0126] When implemented by hardware, the communication unit 802 in the embodiment of the present application may be integrated on a communication interface, and the processing unit 801 may be integrated on a processor. The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A login authentication method, characterized in that, Applied to a login authentication system, the login authentication system includes a gateway, a front end, a client, and an IAM authentication server; The method includes: Controlling the gateway to receive a login request from the client; When the login request is verified and the user information of the client is stored in the IAM authentication server, controlling the IAM authentication server to send first indication information to the front end through the gateway; the first indication information is used to indicate the front end to load a target page, and the target page displays login authentication information.
2. The method according to claim 1, wherein The first indication information carries a token corresponding to the user information; one token corresponds to one target page; When the login request is verified and the user information of the client is stored in the IAM authentication server, controlling the IAM authentication server to send first indication information to the front end through the gateway includes: When the login request is verified, controlling the gateway to send second indication information to the IAM authentication server; the second indication information is used to indicate the IAM authentication server to query whether the user information is stored; When the user information is stored in the IAM authentication server, controlling the IAM authentication server to generate the token and send the first indication information to the front end through the gateway.
3. The method according to claim 2, wherein The login authentication system further includes a CAS authentication server; Before controlling the gateway to send the second indication information to the IAM authentication server, it further includes: Controlling the gateway to send third indication information to the CAS authentication server; the third indication information is used to indicate the CAS authentication server to perform a pre-check on the login request; When the login request is verified, controlling the CAS authentication server to send the user information to the gateway.
4. The method according to any one of claims 1-3, characterized in that, The method further includes: When the login request is not verified, controlling the client to send a system internal error message to the front end through the gateway.
5. The method according to any one of claims 1 to 3, characterized in that, The method further includes: When the user information is not stored in the IAM authentication server, controlling the client to send a message indicating that the user information does not exist to the front end through the gateway.
6. A login authentication device, characterized in that, Applied to a login authentication system, the login authentication system includes a gateway, a front end, a client, and an IAM authentication server; the device includes: a processing unit and a communication unit; The communication unit is used to control the gateway to receive a login request from the client; When the login request is verified and the user information of the client is stored in the IAM authentication server, the communication unit is further used to control the IAM authentication server to send first indication information to the front end through the gateway; the first indication information is used to indicate the front end to load a target page, the target page is a page associated with the first indication information, and the target page displays login authentication information.
7. The apparatus according to claim 6, characterized in that, The first indication information carries a token corresponding to the user information; one token corresponds to one target page; When the login request is verified successfully, the communication unit is further configured to control the gateway to send second indication information to the IAM authentication server; the second indication information is used to instruct the IAM authentication server to query whether the user information is stored. When the user information is stored in the IAM authentication server, the processing unit is further configured to control the IAM authentication server to generate the token and send the first indication information to the front end through the gateway.
8. The device according to claim 7, characterized in that, The login authentication system further includes a CAS authentication server; The communication unit is further configured to: Control the gateway to send third indication information to the CAS authentication server; the third indication information is used to instruct the CAS authentication server to perform pre-check on the login request; When the login request is verified successfully, control the CAS authentication server to send the user information to the gateway.
9. The device according to any one of claims 6 - 8, characterized in that The communication unit is further configured to: When the login request is not verified successfully, control the client to send an internal system error message to the front end through the gateway.
10. The device according to any one of claims 6-8, characterized in that, The communication unit is further configured to: When the user information is not stored in the IAM authentication server, control the client to send a message indicating that the user information does not exist to the front end through the gateway.
11. A login authentication device, characterized in that, Comprising: A processor and a communication interface; the communication interface is coupled to the processor, and the processor is configured to run a computer program or instruction to implement the login authentication method described in any one of claims 1-5.
12. A computer-readable storage medium storing instructions therein, characterized in that, When the computer executes the instruction, the computer executes the login authentication method described in any one of claims 1-5 above.