Unified identity authentication method, device, equipment and system

By generating a unified identity authentication method with hierarchical credentials, the problem of high cross-platform authentication management costs is solved, efficient login of single-factor and two-factor applications is achieved, and user experience and security are improved.

CN120729645APending Publication Date: 2025-09-30CHINA NAT OFFSHORE OIL CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511220499.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

The cost of cross-platform management is high, and the authentication systems of Windows and domestic terminals are independent of each other. Users need to remember the login credentials of different terminals, which reduces the user experience and efficiency.

Method used

Provides a unified identity authentication method that generates first-level and second-level credentials for single-factor and two-factor authentication applications respectively, achieving hierarchical single sign-on and reducing repeated authentication processes.

Benefits of technology

It reduces management costs, improves user experience and efficiency, balances security and convenience, and reduces the risk of credential leakage or abuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729645A_ABST
    Figure CN120729645A_ABST
Patent Text Reader

Abstract

The invention relates to a unified identity authentication method, device, equipment and system. The method comprises the following steps: in response to a received access request sent by a user side, obtaining user information and access application information according to the access request; verifying according to the user information, generating a first-level voucher when detecting that the current user has no voucher information and verification is passed, and returning the first-level voucher to the user side, the first-level voucher being used for first-level single sign-on of the user side; judging whether the current application is two-factor authentication or not according to the application information, if the current application is two-factor authentication, initiating an enhanced authentication request to the user side, executing enhanced authentication according to enhanced authentication information returned by the user side, generating a second-level certificate after the enhanced authentication is passed, and returning the second-level certificate to the user side, the second-level certificate is used for second-level single sign-on of the user side. By adopting the method, the management cost can be reduced, and the user experience and the use efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of identity authentication technology, and in particular to a unified identity authentication method, apparatus, device and system. Background Art

[0002] With the development of technologies in the field of enterprise-level terminal and application security access, an application environment has emerged in which domestic terminals and traditional Windows terminals coexist. The diversification of terminal types, differentiation of architectures, and increased complexity of application systems have required enterprises to ensure secure access to information systems through a combination of terminal login authentication and application access control.

[0003] The current terminal and application authentication methods have significant problems: cross-platform management costs are high, the authentication systems for Windows and domestic terminals are independent of each other, enterprises need to maintain multiple management platforms, and users need to remember login credentials for different terminals, which reduces user experience and efficiency. Summary of the Invention

[0004] Based on this, it is necessary to provide a unified identity authentication method, device, equipment and system that can reduce management costs, improve user experience and usage efficiency in response to the above technical problems.

[0005] In a first aspect, the present application provides a unified identity authentication method, which is applied to the service side, and the method includes:

[0006] In response to receiving an access request sent by the user side, obtaining user information and access application information according to the access request;

[0007] Performing verification based on the user information, generating a first-level credential if it is detected that the current user has no credential information and the verification passes, and returning the first-level credential to the user side, where the first-level credential is used for the first-level single sign-on on the user side;

[0008] Determine whether the current application is two-factor authentication based on the application information. If the current application is two-factor authentication, initiate an enhanced authentication request to the user side, and perform enhanced authentication based on the enhanced authentication information returned by the user side. After the enhanced authentication is passed, generate a second-level credential and return the second-level credential to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0009] In some embodiments of the method, the method further comprises:

[0010] Verify the user information and, if it is detected that the current user credential information is a first-level credential and the current application is single-factor authentication, jump directly to the corresponding current application;

[0011] Verification is performed based on the user information, and when it is detected that the current user credential information is a second-level credential, the application is directly redirected to the corresponding current application.

[0012] In some embodiments of the method, the method further comprises:

[0013] Receive the encrypted identity authentication information sent by the user side, verify the encrypted identity authentication information, and return the identity authentication result to the user side.

[0014] According to a second aspect of an embodiment of the present disclosure, a unified identity authentication method is provided, which is applied to a user side. The method includes:

[0015] Send an access request to the service side;

[0016] When the service side detects that the current user has no credential information and the verification is passed, receiving the first-level credential generated and returned by the service side, where the first-level credential is used for the first-level single sign-on on the user side;

[0017] Receive the enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and if the enhanced authentication on the service side is passed, receive the second-level credential generated and returned by the service side, the second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0018] In some embodiments of the method, the method further comprises:

[0019] Obtain the identity authentication information input by the user, encrypt it according to the identity authentication information, obtain and send the encrypted identity authentication information to the service side;

[0020] Receive the identity authentication result returned by the service side, and complete the login through the local account bound to the user side if the identity authentication result is passed.

[0021] According to a third aspect of an embodiment of the present disclosure, a unified identity authentication device is provided, which is applied to a service side. The device includes:

[0022] A first communication module is configured to, in response to receiving an access request sent by a user side, obtain user information and access application information according to the access request;

[0023] a first verification module configured to perform verification based on the user information, and if it is detected that the current user has no credential information and the verification passes, generate a first-level credential, and return the first-level credential to the user side, where the first-level credential is used for the first-level single sign-on on the user side;

[0024] The second verification module is used to determine whether the current application is two-factor authentication based on the application information. If the current application is two-factor authentication, it initiates an enhanced authentication request to the user side and performs enhanced authentication based on the enhanced authentication information returned by the user side. After the enhanced authentication is passed, a second-level credential is generated and returned to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0025] According to a fourth aspect of an embodiment of the present disclosure, there is provided a unified identity authentication device, which is applied to a user side, and the device includes: a second communication module, which is used to send an access request to a service side;

[0026] A single sign-on module, configured to receive the first-level credentials generated and returned by the service side when the service side detects that the current user has no credential information and the verification passes, wherein the first-level credentials are used for the first-level single sign-on on the user side;

[0027] The single sign-on module is also used to receive an enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and when the enhanced authentication on the service side is passed, receive the second-level credentials generated and returned by the service side. The second-level credentials are used for the second-level single sign-on on the user side, and the level of the second-level credentials is greater than the level of the first-level credentials.

[0028] According to a fifth aspect of an embodiment of the present disclosure, a unified identity authentication device is provided for use on a service side. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the following steps:

[0029] In response to receiving an access request sent by the user side, obtaining user information and access application information according to the access request;

[0030] Performing verification based on the user information, generating a first-level credential if it is detected that the current user has no credential information and the verification passes, and returning the first-level credential to the user side, where the first-level credential is used for the first-level single sign-on on the user side;

[0031] Determine whether the current application is two-factor authentication based on the application information. If the current application is two-factor authentication, initiate an enhanced authentication request to the user side, and perform enhanced authentication based on the enhanced authentication information returned by the user side. After the enhanced authentication is passed, generate a second-level credential and return the second-level credential to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0032] According to a sixth aspect of an embodiment of the present disclosure, a unified identity authentication device is provided, which is applied to a user side. The computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0033] Send an access request to the service side;

[0034] When the service side detects that the current user has no credential information and the verification is passed, receiving the first-level credential generated and returned by the service side, where the first-level credential is used for the first-level single sign-on on the user side;

[0035] Receive the enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and if the enhanced authentication on the service side is passed, receive the second-level credential generated and returned by the service side, the second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0036] According to a seventh aspect of an embodiment of the present disclosure, a unified identity authentication system is provided, the system comprising at least one of the above-mentioned unified identity authentication devices.

[0037] The unified identity authentication solution provided in the embodiment of the present application can perform differentiated processing for single-factor and two-factor authentication applications. For single-factor authentication applications, after the user passes the initial authentication of the terminal, there is no need to repeatedly enter the credentials, and single sign-on can be completed through the first-level credentials. For two-factor authentication applications, after the user enhances the authentication, the second-level single sign-on can be achieved through the second-level credentials. This can avoid repeating the corresponding authentication process, reduce the complexity of the operation, and improve the user experience and efficiency. At the same time, hierarchical single sign-on can balance security and convenience. The second-level credentials are only generated after the enhanced authentication is passed, reducing the risk of credential leakage or abuse.

[0038] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the description are used to explain the principles of the present disclosure, and do not constitute an improper limitation of the present disclosure.

[0040] Figure 1 The figure is a flow chart showing a unified identity authentication method applied to a service side according to an exemplary embodiment;

[0041] Figure 2 The figure is a flow chart of a unified identity authentication method applied to a user side according to an exemplary embodiment;

[0042] Figure 3 The following is a schematic diagram of a specific process of a unified identity authentication method according to an exemplary embodiment;

[0043] Figure 4 is a flow chart of a unified identity authentication method according to another exemplary embodiment;

[0044] Figure 5 is a structural block diagram of a unified identity authentication device applied to a service side according to another exemplary embodiment;

[0045] Figure 6 is a structural block diagram of a unified identity authentication device applied to a user side according to another exemplary embodiment;

[0046] Figure 7 FIG1 is a diagram showing the internal structure of a unified identity authentication device applied to a service side according to an exemplary embodiment;

[0047] Figure 8 The figure is a diagram showing the internal structure of a unified identity authentication device applied to a user side according to an exemplary embodiment. DETAILED DESCRIPTION

[0048] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0049] It should be noted that the terms "first," "second," and the like in the specification and claims of the present disclosure and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than that illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present disclosure. The terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, product, or apparatus comprising a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, product, or apparatus. Without further limitation, the presence of additional identical or equivalent elements in the process, method, product, or apparatus comprising the elements is not precluded. For example, the use of terms such as "first," "second," and the like are used to designate names and do not imply any specific order.

[0050] In some embodiments provided by the present disclosure, the execution of the unified identity authentication method can be controlled by a unified controller or by multiple controllers. These controllers can include controllers of local terminals or controllers of remote servers. In some embodiments, the local terminal controller and the server controller can jointly assist in completing the unified identity authentication. The local terminals described in the present disclosure can include, but are not limited to, various robotic devices, vehicle-mounted devices, personal computers, laptops, smartphones, tablets, wearable devices, medical devices, VR (Virtual Reality) virtual devices, etc. The server can also be a server, server cluster, distributed subsystem, cloud processing platform, server containing blockchain nodes, and combinations thereof. The controller described in the present disclosure may include various control units capable of implementing logic processing functions, including but not limited to CPU (Central Processing Unit), PLC (Programmable Logic Controller), ECU (Electronic Control Unit), MCU (Microcontroller Unit), FPGA (Field Programmable Gate Array) and CPLD (Complex Programmable Logic Device), as well as controllers composed of one or more logic function units, chips, etc.

[0051] In some embodiments of the present disclosure, a unified identity authentication method applied to the service side is provided, such as Figure 1 As shown, the following steps are included:

[0052] S20 . In response to receiving the access request sent by the user side, obtain user information and access application information according to the access request.

[0053] In some embodiments of the present disclosure, the user side generally refers to the terminal that initiates an access request. The user side may include a client. The client may include the local terminal described above. The user side is the interactive object of the service side and can receive user input instructions. The service side may include at least one of a server, an application system, and a unified authentication system. The server, application system, and unified authentication system may each be a separate device or system. The server, application system, and unified authentication system may also be integrated into a single device or system. An access request generally refers to a request initiated by the user side to the service side through a browser or application to access specific resources or use specific functions. User information generally refers to relevant data used to identify the user's identity, including but not limited to the username, terminal binding information, historical authentication records, and other information. User information is provided by the user side client during the access process and can be used by the service side to verify the legitimacy of the user's identity. Access application information generally refers to data related to the target application contained in the access request, including the application identifier and the authentication level required by the application. The service side can use this information to identify the specific application accessed by the user and determine its corresponding authentication requirements.

[0054] S22. Verify based on the user information. If it is detected that the current user has no credential information and the verification passes, generate a first-level credential and return the first-level credential to the user side. The first-level credential is used for the first-level single sign-on on the user side.

[0055] In some embodiments of the present disclosure, the first-level credential generally refers to the basic security level credential generated when the user passes the identity verification for the first time and has no historical credential information. The first-level credential can be bound to the user identity and terminal information, and the first-level credential can be stored on the user-side client or on the service side. The first-level single sign-on generally refers to the single sign-on mode implemented when the user side uses the first-level credential to access the application system. In some examples, it can be applied to an application system with single-factor authentication. In this case, the user does not need to repeatedly enter the account password, and can complete the identity authentication and login of the application system only through the first-level credential provided by the client. This mode relies on the trust relationship of the initial authentication of the terminal, does not require additional security verification, and aims to improve the access efficiency of low-security level applications.

[0056] S24. Determine whether the current application is two-factor authentication based on the application information. If the current application is two-factor authentication, initiate an enhanced authentication request to the user side, and perform enhanced authentication based on the enhanced authentication information returned by the user side. After the enhanced authentication passes, generate a second-level credential and return the second-level credential to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0057] In some embodiments of the present disclosure, enhanced authentication information generally refers to supplementary information provided by a user after completing initial authentication to enhance the security of identity verification for a two-factor authentication-level application. Enhanced authentication generally refers to a secondary identity verification process initiated by the service side for a two-factor authentication application. After the user has passed initial terminal authentication and obtained first-level credentials, the service side sends an enhanced authentication request to the user side. By verifying the enhanced authentication information submitted by the user, the service side confirms the legitimacy of the user's identity to meet the access requirements of high-security applications. In some embodiments, enhanced authentication can include dynamic verification codes, such as SMS verification codes and token generator verification codes; it can also include biometric verification, such as fingerprint verification and facial recognition; it can also include hardware key information, etc. Second-level credentials generally refer to high-security credentials generated by the service side after the user completes enhanced authentication and passes verification. They have a higher security level than first-level credentials and can be used to support single sign-on for two-factor authentication-level applications or single-factor authentication-level applications. Second-level single sign-on generally refers to the single sign-on mode implemented when a user accesses an application system using second-level credentials. Second-level single sign-on (SSO) is suitable for high-security applications that require two-factor authentication. After a user completes enhanced authentication and obtains second-level credentials for the first time, subsequent accesses to similar applications from the same terminal do not require repeated enhanced authentication. Identity verification and login are completed using only the second-level credentials provided by the client. This model relies on the high level of trust established by enhanced authentication, improving access efficiency for high-security applications while ensuring security.

[0058] In some embodiments of the present disclosure, differentiated processing can be performed for single-factor and two-factor authentication applications. For single-factor authentication applications, after the user passes the initial authentication at the terminal, there is no need to repeatedly enter the credentials, and single sign-on can be completed through the first-level credentials. For two-factor authentication applications, after the user has enhanced the authentication, the second-level single sign-on can be achieved through the second-level credentials. This can avoid repeatedly executing the corresponding authentication process, reduce the complexity of the operation, and improve the user experience and efficiency. At the same time, hierarchical single sign-on can balance security and convenience. The second-level credentials are only generated after the enhanced authentication is passed, reducing the risk of credential leakage or abuse.

[0059] In some embodiments of the present disclosure, the method further comprises:

[0060] Verify the user information and, if it is detected that the current user credential information is a first-level credential and the current application is single-factor authentication, jump directly to the corresponding current application;

[0061] Verification is performed based on the user information, and when it is detected that the current user credential information is a second-level credential, the application is directly redirected to the corresponding current application.

[0062] In some embodiments, upon receiving an access request from a user, the service first verifies the user's credential level based on the user information in the request and confirms that the target application is a single-factor authentication system based on the access application information. If the service detects that the user's credential information is a first-level credential and the application is a single-factor authentication application, the security level of the first-level credential matches the requirements of the single-factor authentication application. For similar single-factor authentication applications, the user does not need to perform additional authentication procedures, and the service is directly redirected to the target application through the unified authentication system, completing the first-level single sign-on.

[0063] In other embodiments, if the current user credential information is detected as a second-level credential, regardless of whether the target application is a single-factor or two-factor authentication system, the authentication process is directly redirected to the target application through the unified authentication system. Because the security level of the second-level credential has been verified through enhanced authentication, its trust level covers both single-factor and two-factor authentication requirements, eliminating the need for repeated verification.

[0064] In some embodiments of the present disclosure, when a user holding a first-level credential accesses a single-factor application, the user can be directly redirected to the corresponding application, thereby achieving the user's first-level single sign-on while also performing hierarchical processing; for users holding a second-level credential, compatible jumps to all application types can be achieved, solving the problem of repeated authentication when the user switches between applications of different security levels, reducing redundant authentication, and improving access efficiency.

[0065] In some embodiments of the present disclosure, the method further comprises:

[0066] Receive the encrypted identity authentication information sent by the user side, verify the encrypted identity authentication information, and return the identity authentication result to the user side.

[0067] In some embodiments of the present disclosure, the service side receives encrypted identity authentication information sent by the user-side client through a secure communication channel. The encrypted identity authentication information is generated by the client using a preset encryption algorithm after the user enters the original authentication information, ensuring that the information is not leaked or tampered with during transmission. The service side decrypts the received encrypted information, restores the original identity authentication information, and then verifies it. The service side feeds back the verification result (the verification result includes pass or fail) to the user-side client in encrypted form. If the verification is successful, the result may include the temporary authorization information required for terminal login; if it fails, the reason for the failure may be attached to facilitate the user-side troubleshooting.

[0068] In some embodiments of the present disclosure, encryption processing avoids the risk of the user's original authentication information being eavesdropped or tampered with during transmission. The verification result is the prerequisite for the subsequent generation of first-level credentials and second-level credentials. Only users who pass the identity authentication can obtain terminal login permissions and trust credentials for application access; at the same time, it ensures the consistency of identity authentication interaction between the user side and the service side, avoiding authentication anomalies caused by problems such as transmission format confusion and decryption failure.

[0069] In some embodiments of the present disclosure, differentiated processing can be performed for single-factor and two-factor authentication applications. For single-factor authentication applications, after the user passes the initial authentication at the terminal, there is no need to repeatedly enter the credentials, and single sign-on can be completed through the first-level credentials. For two-factor authentication applications, after the user has enhanced the authentication, the second-level single sign-on can be achieved through the second-level credentials. This can avoid repeatedly executing the corresponding authentication process, reduce the complexity of the operation, and improve the user experience and efficiency. At the same time, hierarchical single sign-on can balance security and convenience. The second-level credentials are only generated after the enhanced authentication is passed, reducing the risk of credential leakage or abuse.

[0070] In some embodiments of the present disclosure, corresponding to the above embodiments, a unified identity authentication method applied to the user side is also provided, such as Figure 2 As shown, the following steps are included:

[0071] S40: Send an access request to the service side;

[0072] S42. When the service side detects that the current user has no credential information and the verification passes, receiving the first-level credential generated and returned by the service side, where the first-level credential is used for the first-level single sign-on on the user side;

[0073] S44. Receive the enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and if the enhanced authentication on the service side is passed, receive the second-level credential generated and returned by the service side, the second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

[0074] In some embodiments of the present disclosure, the user side generally refers to the terminal that initiates the access request. The user side may include a client. The client may include the above-mentioned local terminal. The user side is the interactive object of the service side, and the user side can receive instructions input by the user. The service side may include at least one of a server, an application system, and a unified authentication system. Among them, the server, the application system, and the unified authentication system may be an independent device or system respectively. The server, the application system, and the unified authentication system may also be integrated on a single device or system. An access request generally refers to a request initiated by the user side to the service side through a browser or application to access specific resources or use specific functions.

[0075] In some embodiments of the present disclosure, the first-level credential generally refers to the basic security level credential generated when the user passes the identity verification for the first time and has no historical credential information. The first-level credential can be bound to the user identity and terminal information, and the first-level credential can be stored on the user-side client or on the service side. The first-level single sign-on generally refers to the single sign-on mode implemented when the user side uses the first-level credential to access the application system. In some examples, it can be applied to an application system with single-factor authentication. In this case, the user does not need to repeatedly enter the account password, and can complete the identity authentication and login of the application system only through the first-level credential provided by the client. This mode relies on the trust relationship of the initial authentication of the terminal, does not require additional security verification, and aims to improve the access efficiency of low-security level applications.

[0076] In some embodiments of the present disclosure, enhanced authentication information generally refers to supplementary information provided by a user after completing initial authentication to enhance the security of identity verification for a two-factor authentication-level application. Enhanced authentication generally refers to a secondary identity verification process initiated by the service side for a two-factor authentication application. After the user has passed initial terminal authentication and obtained first-level credentials, the service side sends an enhanced authentication request to the user side. By verifying the enhanced authentication information submitted by the user, the service side confirms the legitimacy of the user's identity to meet the access requirements of high-security applications. In some embodiments, enhanced authentication can include dynamic verification codes, such as SMS verification codes and token generator verification codes; it can also include biometric verification, such as fingerprint verification and facial recognition; it can also include hardware key information, etc. Second-level credentials generally refer to high-security credentials generated by the service side after the user completes enhanced authentication and passes verification. They have a higher security level than first-level credentials and can be used to support single sign-on for two-factor authentication-level applications or single-factor authentication-level applications. Second-level single sign-on generally refers to the single sign-on mode implemented when a user accesses an application system using second-level credentials. Second-level single sign-on (SSO) is suitable for high-security applications that require two-factor authentication. After a user completes enhanced authentication and obtains second-level credentials for the first time, subsequent accesses to similar applications from the same terminal do not require repeated enhanced authentication. Identity verification and login are completed using only the second-level credentials provided by the client. This model relies on the high level of trust established by enhanced authentication, improving access efficiency for high-security applications while ensuring security.

[0077] In some embodiments of the present disclosure, for single-factor authentication applications, after the user passes the initial authentication at the terminal, there is no need to repeatedly enter the credentials, and single sign-on can be completed through the first-level credentials. For two-factor authentication applications, after the user has enhanced the authentication, the second-level single sign-on can be achieved through the second-level credentials. This can avoid repeatedly executing the corresponding authentication process, reduce the complexity of the operation, and improve the user experience and efficiency. At the same time, hierarchical single sign-on can balance security and convenience. The second-level credentials are only generated after the enhanced authentication is passed, reducing the risk of credential leakage or abuse.

[0078] In some embodiments of the present disclosure, the method further comprises:

[0079] Obtain the identity authentication information input by the user, encrypt it according to the identity authentication information, obtain and send the encrypted identity authentication information to the service side;

[0080] Receive the identity authentication result returned by the service side, and complete the login through the local account bound to the user side if the identity authentication result is passed.

[0081] In some embodiments of the present disclosure, the user can input identity authentication information through the client. The client can have a built-in encryption module, and after obtaining the information, it uses a preset encryption algorithm to encrypt the original information to generate encrypted identity authentication information. The encryption process is completed locally to prevent the original information from being exposed in the terminal memory for a long time. The client sends the encrypted identity authentication information to the service side through a secure communication link and waits for verification feedback from the service side. After receiving the encrypted identity authentication result returned by the service side, the client decrypts the result and analyzes whether the authentication is successful. If the identity authentication result is successful, the login is completed through the local account bound to the user side.

[0082] In some embodiments of the present disclosure, encryption processing avoids the risk of the user's original authentication information being eavesdropped or tampered with during transmission. The verification result is the prerequisite for the subsequent generation of first-level credentials and second-level credentials. Only users who pass the identity authentication can obtain terminal login permissions and trust credentials for application access; at the same time, it ensures the consistency of identity authentication interaction between the user side and the service side, avoiding authentication anomalies caused by problems such as transmission format confusion and decryption failure.

[0083] In some embodiments of the present disclosure, for single-factor authentication applications, after the user passes the initial authentication at the terminal, there is no need to repeatedly enter the credentials, and single sign-on can be completed through the first-level credentials. For two-factor authentication applications, after the user has enhanced the authentication, the second-level single sign-on can be achieved through the second-level credentials. This can avoid repeatedly executing the corresponding authentication process, reduce the complexity of the operation, and improve the user experience and efficiency. At the same time, hierarchical single sign-on can balance security and convenience. The second-level credentials are only generated after the enhanced authentication is passed, reducing the risk of credential leakage or abuse.

[0084] The following example illustrates that the user side includes a client, and the service side includes a server, an application system, and a unified authentication system. The server, application system, and unified authentication system can be installed in the same terminal device or independently installed in different terminal devices.

[0085] In some embodiments of the present disclosure, Figure 3 As shown, the user enters their username and password. The client receives the username and password as authentication information and encrypts it. The client and server simultaneously encrypt the authentication information. The server verifies the encrypted authentication information and returns the authentication result (pass or fail). The client receives the authentication result from the server and, if it passes, completes the login process using the bound local account. The user has now completed the local login on the client.

[0086] In some implementations, when a user opens a browser to access an application, the application system receives the user's access request and then redirects the user to a unified authentication system for unified authentication. The unified authentication system obtains the user information logged in by the current terminal and also determines whether the application system uses two-factor authentication. If it detects that the current user has no credential information and the verification passes, a first-level credential is generated and returned to the client. The first-level credential is used for the client's first-level single sign-on.

[0087] In some implementations, if the unified authentication system detects that the application system uses two-factor authentication, it initiates an enhanced authentication request, prompting the user to perform enhanced authentication, at which point the user can submit enhanced authentication information. After the enhanced authentication is successful, the unified authentication system can generate a second-level credential and return it to the client. The client can then implement second-level single sign-on based on the second-level credential.

[0088] In some embodiments, as Figure 4 As shown, when the user closes the browser and accesses the application again, the application system receives the access request and jumps to the unified authentication system for unified authentication. The unified authentication system obtains the user information of the current terminal login, and verifies it according to the user information. When it detects that the current user credential information is a first-level credential and the current application is single-factor authentication, since the security level of the first-level credential matches the requirements of the single-factor authentication application, for similar applications of single-factor authentication, there is no need for the user side to perform additional authentication processes, and it directly jumps to the target application through the unified authentication system to complete the first-level single sign-on. When it is detected that the current user credential information is a second-level credential, regardless of whether the target application is a single-factor authentication system or a two-factor authentication system, it directly jumps to the target application through the unified authentication system. Since the security level of the second-level credential has passed the enhanced authentication verification, its trust level covers the requirements of single-factor and two-factor authentication, and there is no need for repeated verification.

[0089] It is understood that the various embodiments of the above method in this specification are described in a progressive manner. The same / similar parts between the various embodiments can be referred to in detail. Each embodiment focuses on the differences from other embodiments. For related parts, refer to the description of other method embodiments.

[0090] It should be understood that although the steps in the flowcharts involved in the drawings are shown sequentially as indicated by the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least some of the steps in the drawings may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times. The order of execution of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with other steps or at least a portion of steps or stages of other steps.

[0091] Based on the description of the embodiment of the unified identity authentication method described above, the present disclosure also provides a unified identity authentication device for use on the service side to implement the unified identity authentication method involved above. The device may include a system (including a distributed system), software (application), module, component, controller, server, terminal, etc. that uses the method described in the embodiments of this specification and is combined with the necessary implementation hardware. Based on the same innovative concept, the device in one or more embodiments provided by the embodiments of this disclosure is as described in the following embodiments. Since the implementation scheme of the device to solve the problem is similar to the method, the implementation of the specific device in the embodiments of this specification can refer to the implementation of the aforementioned method, and the repeated parts will not be repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements the predetermined function. Although the device described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and conceivable.

[0092] The device may be the aforementioned terminal, or a server, or a module, component, device, control unit, etc. integrated into the terminal. Figure 5The unified authentication device 200 applied to the service side may include: a first communication module 220, a first verification module 240, and a second verification module 260. The first communication module 220 is configured to, in response to receiving an access request sent by a user side, obtain user information and access application information according to the access request; the first verification module 240 is configured to perform verification based on the user information, and if it is detected that the current user has no credential information and the verification passes, generate a first-level credential and return the first-level credential to the user side. The first-level credential is used for the first-level single sign-on on the user side; the second verification module 260 is configured to determine whether the current application uses two-factor authentication based on the application information, and if so, initiate an enhanced authentication request to the user side, perform enhanced authentication based on the enhanced authentication information returned by the user side, generate a second-level credential after the enhanced authentication passes, and return the second-level credential to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than that of the first-level credential.

[0093] In some embodiments of the device, the unified authentication device 200 applied to the service side also includes a third verification module, which is used to verify according to the user information, and directly jump to the corresponding current application when it is detected that the current user credential information is a first-level credential and the current application is a single-factor authentication; it is also used to verify according to the user information, and directly jump to the corresponding current application when it is detected that the current user credential information is a second-level credential.

[0094] In some embodiments of the device, the first communication module 220 is further configured to receive encrypted identity authentication information sent by the user side, verify the encrypted identity authentication information, and return the identity authentication result to the user side.

[0095] Based on the description of the embodiment of the unified identity authentication method described above, the present disclosure also provides a unified identity authentication device applied to the user side to implement the unified identity authentication method involved above. Figure 6The unified authentication device 400 applied to the user side may include: a second communication module 420 and a single sign-on module 440. The second communication module 420 is used to send an access request to the service side; the single sign-on module 440 is used to receive the first-level credentials generated and returned by the service side when the service side detects that the current user has no credential information and the verification is passed. The first-level credentials are used for the first-level single sign-on on the user side; the single sign-on module 440 is also used to receive an enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and receive the second-level credentials generated and returned by the service side when the enhanced authentication on the service side is passed. The second-level credentials are used for the second-level single sign-on on the user side, and the level of the second-level credentials is greater than that of the first-level credentials.

[0096] In some embodiments of the device, the second communication module 420 is also used to obtain identity authentication information input by the user, encrypt it according to the identity authentication information, obtain and send the encrypted identity authentication information to the service side; and receive the identity authentication result returned by the service side. If the identity authentication result is passed, the login is completed through the local account bound to the user side.

[0097] Each module in the unified identity authentication device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0098] In one embodiment, a unified identity authentication device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a unified identity authentication device method is implemented.

[0099] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 8As shown. The computer device includes a processor, memory, a communication interface, a display screen, and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal via wired or wireless communication. The wireless communication can be achieved via Wi-Fi, a mobile cellular network, NFC (near-field communication), or other technologies. When executed by the processor, the computer program implements a unified identity authentication device method. The display screen of the computer device can be a liquid crystal display or an electronic ink display. The input device of the computer device can be a touch layer covering the display screen, or keys, a trackball, or a touchpad provided on the computer device housing, or an external keyboard, touchpad, or mouse.

[0100] Those skilled in the art will understand that Figure 7 or Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0101] According to the aforementioned description of the related method and device embodiments, the present disclosure further provides a unified identity authentication system, including at least one of the aforementioned unified authentication device applied to the service side and the unified authentication device applied to the user side.

[0102] The various embodiments in this specification are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other. Each embodiment focuses on the differences between the other embodiments. In particular, the hardware + program embodiments are generally similar to the method embodiments, so their description is relatively simple. For relevant portions, refer to the description of the method embodiments.

[0103] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0104] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0105] It should be noted that the aforementioned apparatus, computer device, storage medium, and computer program product, etc., may also include other implementation methods based on the description of the method embodiments. For specific implementations, reference may be made to the description of the relevant method embodiments. Furthermore, new embodiments formed by combining features of various method, apparatus, device, and server embodiments remain within the scope of this disclosure and are not detailed here.

[0106] For the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing one or more of the present specifications, the functions of each module can be implemented in the same or multiple software and / or hardware, or the module that implements the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. On the other hand, the coupling, communication connection, etc. between the devices or units shown or described can be realized in the form of direct and / or indirect coupling / connection, and can be realized through some standard or customized interfaces, protocols, etc., in electrical, mechanical or other forms.

[0107] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow from the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.

[0108] It will be understood that the present disclosure is not limited to the exact construction that has been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof.

Claims

1. A unified identity authentication method, characterized in that: Applied to the service side, the method includes: In response to receiving an access request sent by the user side, obtaining user information and access application information according to the access request; Performing verification based on the user information, generating a first-level credential if it is detected that the current user has no credential information and the verification passes, and returning the first-level credential to the user side, where the first-level credential is used for the first-level single sign-on on the user side; Determine whether the current application is two-factor authentication based on the application information. If the current application is two-factor authentication, initiate an enhanced authentication request to the user side, and perform enhanced authentication based on the enhanced authentication information returned by the user side. After the enhanced authentication is passed, generate a second-level credential and return the second-level credential to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

2. The method according to claim 1, characterized in that The method further comprises: Verify the user information and, if it is detected that the current user credential information is a first-level credential and the current application is single-factor authentication, jump directly to the corresponding current application; Verification is performed based on the user information, and when it is detected that the current user credential information is a second-level credential, the application is directly redirected to the corresponding current application.

3. The method according to claim 1, characterized in that The method further comprises: Receive the encrypted identity authentication information sent by the user side, verify the encrypted identity authentication information, and return the identity authentication result to the user side.

4. A unified identity authentication method, characterized in that: Applied to the user side, the method includes: Send an access request to the service side; When the service side detects that the current user has no credential information and the verification is passed, receiving the first-level credential generated and returned by the service side, where the first-level credential is used for the first-level single sign-on on the user side; Receive the enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and if the enhanced authentication on the service side is passed, receive the second-level credential generated and returned by the service side, the second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

5. The method according to claim 4, characterized in that The method further comprises: Obtain the identity authentication information input by the user, encrypt it according to the identity authentication information, obtain and send the encrypted identity authentication information to the service side; Receive the identity authentication result returned by the service side, and complete the login through the local account bound to the user side if the identity authentication result is passed.

6. A unified identity authentication device, characterized in that: Applied to the service side, the device includes: A first communication module is configured to, in response to receiving an access request sent by a user side, obtain user information and access application information according to the access request; a first verification module configured to perform verification based on the user information, and if it is detected that the current user has no credential information and the verification passes, generate a first-level credential, and return the first-level credential to the user side, where the first-level credential is used for the first-level single sign-on on the user side; The second verification module is used to determine whether the current application is two-factor authentication based on the application information. If the current application is two-factor authentication, it initiates an enhanced authentication request to the user side and performs enhanced authentication based on the enhanced authentication information returned by the user side. After the enhanced authentication is passed, a second-level credential is generated and returned to the user side. The second-level credential is used for the second-level single sign-on on the user side, and the level of the second-level credential is greater than the level of the first-level credential.

7. A unified identity authentication device, characterized in that: Applied to the user side, the device includes: A second communication module is used to send an access request to the service side; A single sign-on module, configured to receive the first-level credentials generated and returned by the service side when the service side detects that the current user has no credential information and the verification passes, wherein the first-level credentials are used for the first-level single sign-on on the user side; The single sign-on module is also used to receive an enhanced authentication request sent by the service side, send enhanced authentication information to the service side according to the enhanced authentication request, and if the enhanced authentication on the service side is passed, receive the second-level credentials generated and returned by the service side. The second-level credentials are used for the second-level single sign-on on the user side, and the level of the second-level credentials is greater than the level of the first-level credentials.

8. A unified identity authentication device, characterized in that: The device is applied to a service side, comprising a memory and a processor, wherein the memory stores a computer program, and is characterized in that the processor implements the steps of the method according to any one of claims 1 to 3 when executing the computer program.

9. A unified identity authentication device, characterized in that: Applied to the user side, comprising a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of the method described in claim 4 or 5 are implemented.

10. A unified identity authentication system, characterized in that: The system includes at least one of the unified identity authentication devices according to claim 8 and claim 9.

Citation Information

Patent Citations

  • Single sign-on method and system as well as single sign-on client-side

    CN103634111A

  • A single sign-on method and a sign-on system for multi-factor identity authentication

    CN109388937A

  • Single sign-on method and device, computing equipment and computer readable storage medium

    CN112182544A

  • Login authentication method, zero-trust controller and electronic equipment

    CN116962088A

  • Identity management system for automatic user authentication

    SG112575A1