Single sign-on control method and device, equipment and storage medium
By querying the shared login token in a multi-data center architecture and forcing logout when the dynamic token is different, the single sign-on control problem in a multi-data center architecture is solved, user security verification and separate login control are achieved, and data resource utilization and system continuity are improved.
Patent Information
- Application Number
- CN202511059046.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-10-10
AI Technical Summary
In a multi-data center architecture, existing technologies lack an effective single sign-on control mechanism, resulting in the inability to synchronize user authentication information, affecting business continuity and user experience.
By responding to the target user's page request, querying the shared login token based on the user identification number, and forcing the user to log out when the dynamic login token is different from the shared login token, single sign-on control is achieved.
It improves data resource utilization, ensures users can perform secure verification and individual login control in a multi-data center architecture, and enhances the system's business continuity and user experience.
Smart Images

Figure CN120768653A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data centers, and in particular to a single sign-on control method and device. Background Art
[0002] With the development of digitalization, enterprises have increasingly higher requirements for business continuity. The risk of failure in a single data center is high. Once a hardware failure or natural disaster occurs, business interruption will inevitably occur, seriously affecting user experience and business operations. In order to improve the level of system business continuity and scalability, the development from a single data center to multiple data centers has become an inevitable trend. In a single data center, the single sign-on control of web applications can be directly and independently controlled by the data center. In a multi-data center, each data center is independently deployed, and web applications can log in to each data center separately. Each data center independently handles business traffic. There is no effective synchronization mechanism for authentication information, and the single sign-on mechanism is facing failure problems. Summary of the Invention
[0003] The present invention provides a single sign-on control method and device to solve the technical problem of single sign-on control for users in a multi-data center architecture in the prior art.
[0004] According to one aspect of the present invention, a single sign-on control method is provided, comprising:
[0005] In response to a page request of an Internet application of a data center triggered by a target user, querying a shared login token corresponding to the target user based on the user identification number of the target user;
[0006] In the case where the target user has the shared login token, if the target user's dynamic login token is different from the shared login token, the Internet application controls the target user to log out forcibly
[0007] According to another aspect of the present invention, a single sign-on control device is provided, comprising:
[0008] A detection module, configured to respond to a page request of an Internet application of a data center triggered by a target user, and query a shared login token corresponding to the target user based on a user identification number of the target user;
[0009] The control module is configured to control the target user to forcibly log out if the target user has the shared login token and the dynamic login token of the target user is different from the shared login token.
[0010] According to another aspect of the present invention, there is provided an electronic device, comprising: at least one processor; and
[0011] a memory communicatively connected to the at least one processor; wherein,
[0012] The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the single sign-on control method according to any embodiment of the present invention.
[0013] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the single sign-on control method according to any embodiment of the present invention when executed.
[0014] The technical solution of the embodiment of the present invention is to respond to the target user's page request for the Internet application of the data center, and query the shared login token corresponding to the target user based on the user identification number of the target user. When the user requests a page from the data center, the shared login tokens of the user in multiple data centers can be queried, and the utilization rate of data resources can be improved through data sharing; when the target user has the shared login token, if the dynamic login token of the target user is different from the shared login token, the Internet application controls the target user to forcibly log out. The technical problem of single-point login control for users under a multi-data center architecture in the prior art is solved. When a user logs in to each data center, a security check can be performed in any data center to achieve individual login control for the user.
[0015] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description.
[0016] Other features of the present invention will become readily understood from the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0018] Figure 1 A flow chart of a single sign-on control method is provided for an embodiment of the present invention;
[0019] Figure 2 A flowchart of another single sign-on control method provided by an embodiment of the present invention;
[0020] Figure 3 A flow chart of another single sign-on control method provided by an embodiment of the present application is shown in FIG. 6.
[0021] Figure 4 A flow chart of another single sign-on control method provided by an embodiment of the present application is shown in FIG. 6.
[0022] Figure 5 A structural schematic diagram of a single sign-on control device provided by an embodiment of the present application is shown in FIG. 7.
[0023] Figure 6 A structural schematic diagram of an electronic device 10 that can be used to implement an embodiment of the present application is shown in FIG. 8. DETAILED DESCRIPTION
[0024] In order to make the personnel in the technical field better understand the present application scheme, the technical scheme in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by the personnel in the technical field without creative labor should belong to the protection scope of the present application.
[0025] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0026] Figure 1 A flow chart of a single sign-on control method provided by an embodiment of the present application is shown in FIG. 1. The present embodiment can be applicable to the case where each data center performs single sign-on control on the logged-in user under a plurality of data center architectures. The method can be performed by a single sign-on control device, which can be realized in the form of hardware and / or software, and can be configured in an electronic device. As shown in FIG. 1, the method comprises: Figure 1
[0027] S110, in response to a target user triggering a page request of an Internet application of a data center, querying a shared login token corresponding to the target user based on a user identification number of the target user.
[0028] The target user can be a requestor of logging into an Internet application deployed in the data center.
[0029] Optionally, the Internet application of the present application is deployed in multiple data centers, and the Internet applications of the data centers are data-interconnected, and the target user logging into the Internet application can log into any data center.
[0030] The page request can be used by the user to request a page resource from the data center through the Internet application.
[0031] Optionally, when the target user uses the Internet application, the target user sends a page request to the data center, and the data center receives the page request and responds to the target user triggering the page request of the Internet application of the data center.
[0032] The user identification number can be identification information of the target user identified by multiple data centers.
[0033] Optionally, the target user has a unique mark in the multiple data centers of the present application, and the data center generates a user identification number for the target user based on the unique mark.
[0034] The shared login token can be a dynamic login token generated by other data centers for the target user.
[0035] The dynamic login token can be a dynamic token recording the login state of the user.
[0036] Optionally, when the target user logs into any data center, the data center generates a dynamic login token for the target user, and shares the dynamic login token as a shared login token to other data centers.
[0037] Optionally, any data center stores the shared login token in a local shared storage after obtaining the shared login token.
[0038] Optionally, any one of the data centers stores the user identification number as a key and the shared login token as a value in the local shared storage in the form of key-value when storing the shared login token.
[0039] Specifically, the target logs into the Internet application of any one of the data centers, the target user sends a page request to the data center through the Internet application, the data center responds to the page request of the Internet application, the data center obtains the user identification number of the target user, queries the local shared storage based on the user identification number of the target user, and queries the shared login token corresponding to the target user.
[0040] S120, in the case where the target user has the shared login token, if the dynamic login token of the target user is different from the shared login token, the Internet application controls the target user to forcibly log out.
[0041] Optionally, in the present application, the local shared storage is queried based on the user identification number of the target user, and if the user identification number and the shared login token are found in the local shared storage, it is indicated that the target user logs into any one of the data centers based on the Internet application, and then the shared login token is obtained.
[0042] Optionally, if the user identification number and the shared login token are not found in the local shared storage of the data center, it is indicated that the target user logs in for the first time, the dynamic login token is required as the shared login token, the shared login token is stored in the local shared storage in the form of key-value, and the shared login token is shared to other data centers.
[0043] Optionally, the shared login token is queried in the data center, and the shared login token and the dynamic login token generated by the data center are compared, if the shared login token and the dynamic login token are the same, it is considered that the target user logs in for the first time in the current data center, and the target user does not log in to two or more different data centers at the same time, and the page request of the target user is responded.
[0044] Specifically, in the case where the target user has the shared login token, if the dynamic login token of the target user is different from the shared login token, it is indicated that the target user logs in to two or more different data centers at the same time, and then the Internet application controls the target user to forcibly log out, so as to realize the single sign-on control of the target user.
[0045] Optionally, when the Internet application controls the target user to forcibly log out, the page request sent by the target user to the data center based on the Internet application is intercepted, and an error page is returned.
[0046] The technical scheme of the embodiment of the present application can query the shared login token of a user in multiple data centers through data sharing to improve the utilization rate of data resources when the user requests a page from the data center, and can control the forced logout of the user if the dynamic login token of the user is not the same as the shared login token when the shared login token exists for the user. The technical scheme can solve the technical problem of single sign-on control of a user in a multi-data-center architecture in the prior art. The security check can be performed in any data center when the user logs in each data center, and the single login control of the user can be realized.
[0047] Figure 2 The flowchart of another single sign-on control method provided by the embodiment of the present application, and the relationship between the embodiment and the above embodiment is that the specific method of sharing the shared login token by the data center is specifically introduced. As shown in Figure 2 The method comprises the following steps.
[0048] S210, in response to a login request of a target user to an internet application of a data center, a dynamic login token is generated for the target user.
[0049] The login request can be request information of the target user logging in the internet application.
[0050] Specifically, the target user makes a login request to the internet application, the internet application processes the login logic of the target user, and a login success interface is responded to the target user, and the data center generates a dynamic login token for the target user.
[0051] Optionally, in another optional embodiment of the present application, in the case that the target user logs in the internet application of the data center, the target user generates session identification information corresponding to the internet application; the dynamic login token is generated based on the session identification information, the data center identification of the data center and the system timestamp.
[0052] The session identification information can be used to maintain the login state of the target user, track the behavior of the target user and save the temporary data of the target user. The session identification information can be a session ID (Session ID).
[0053] Optionally, when the target user logs in the internet application of the data center, the data center generates a session ID for the target user based on the unique mark of the target user.
[0054] The data center identifier may be unique information for identifying a data center; and a unique data center may be determined based on the data center identifier.
[0055] The system timestamp may be time recording information generated based on the system clock of the data center. It should be noted that when generating a dynamic login token, the data center generates a system timestamp for the dynamic login token based on the system clock as the time recording information of the dynamic login token.
[0056] Optionally, the data center generates a dynamic login token based on a data center flag, a session ID, and a system timestamp corresponding to the data center, and generates a user identification number based on a unique flag.
[0057] Specifically, when the target user logs into the Internet application of the data center, session identification information corresponding to the Internet application is generated for the target user; a dynamic login token is generated based on the session identification information, the data center identification of the data center and the system timestamp.
[0058] S220: Use the dynamic login token as a shared login token, and generate shared token information based on the user identification number of the target user and the shared login token.
[0059] The shared token information may be a user identification number and a shared login token in the form of a key-value pair.
[0060] Specifically, when the target user logs into the Internet application of the data center, the data center uses the dynamic login token as a shared login token and generates shared token information based on the user identification number of the target user and the shared login token.
[0061] S230: Share the shared token information with each data center.
[0062] Specifically, the data center shares the shared token information with each data center.
[0063] Optionally, in another optional embodiment of the present invention, sharing the shared token information to each data center includes:
[0064] Placing the shared token information in any token queue preset in the data center;
[0065] If the token distribution service of the data center detects that the shared token information exists in the one token queue, the token distribution service based on the data center shares the shared token information with each of the data centers.
[0066] The token queue can be a message dispatch queue pre-set for a data center, and the foreman queue can be used to share shared token information with each data center.
[0067] The token distribution service may be a shared service interface pre-set in a data center. It should be noted that a token distribution service exists in each data center, and can share shared token information based on a token queue.
[0068] Optionally, in a data center, each token queue corresponds to a thread, and when data is shared, each token queue is distributed by at least one thread to increase data distribution speed.
[0069] Specifically, the shared token information is added to any token queue and placed in the token queue. The token distribution service of the data center is used to detect whether there is shared data in the token queue. If the token distribution service of the data center detects that a token queue has shared token information, the token distribution service based on the data center will share the shared token information with each data center.
[0070] Optionally, in another optional embodiment of the present invention, the data center-based token distribution service shares the shared token information to at least one of the data centers, including:
[0071] The token distribution service based on the data center requests the global routing service to share the interface address list through the data center identifier of the data center;
[0072] The token distribution service of the data center shares the shared token information to each of the data centers based on the shared interface address list.
[0073] The shared interface address list may be a list of the interface addresses of the token distribution service of each data center. It should be noted that the shared interface address list records the data center name, data center identifier, and interface address of the token distribution service of each data center. For example, Table 1 is a shared interface address list provided by the present invention, as shown in Table 1:
[0074] Table 1 Shared interface address list
[0075] Data center name Data center logo API address Data center 1 dc-1 http: / / ip-1:port / path / api Data center 2 dc-2 http: / / ip-2:port / path / api .......... .......... .......... Data center n dc-n http: / / ip-n:port / path / api
[0076] The global routing service can be the core service component responsible for coordinating all data centers. It should be noted that the global routing service dynamically maintains a list of shared interface addresses, which can be provided to each data center for query and call.
[0077] Optionally, in the present invention, the addition or removal of a data center requires synchronous maintenance of a global routing service.
[0078] Specifically, the token distribution service based on the data center is connected to the global routing service, and the data center identifier based on the data center requests a shared interface address list from the global routing service. Based on the shared interface address list issued by the global routing service, the token distribution service of the data center sends shared token information to each data center based on the interface address of each data center in the shared interface address list.
[0079] Optionally, when any data center receives the shared token information, it stores the shared token information in a key-value format, correspondingly including the user identification number and the shared login token, in a local shared storage.
[0080] S240: In response to a page request of an Internet application of a data center triggered by a target user, query a shared login token corresponding to the target user based on the user identification number of the target user.
[0081] S250: When the target user has the shared login token, if the target user's dynamic login token is different from the shared login token, the Internet application controls the target user to forcibly log out.
[0082] The technical solution of the embodiment of the present invention is to respond to the target user's page request for the Internet application of the data center, and query the shared login token corresponding to the target user based on the user identification number of the target user. When the user requests a page from the data center, the shared login tokens of the user in multiple data centers can be queried, and the utilization rate of data resources can be improved through data sharing; when the target user has the shared login token, if the dynamic login token of the target user is different from the shared login token, the Internet application controls the target user to forcibly log out. The technical problem of single-point login control for users under a multi-data center architecture in the prior art is solved. When a user logs in to each data center, a security check can be performed in any data center to achieve individual login control for the user.
[0083] Figure 3 This is a flow chart of another single sign-on control method provided by an embodiment of the present invention. The relationship between this embodiment and the above embodiment is that it specifically introduces a specific method for single sign-on control of a target user exiting an Internet application. Figure 3 As shown, the method includes:
[0084] S310: In response to a page request of an Internet application of a data center triggered by a target user, a shared login token corresponding to the target user is searched based on the user identification number of the target user.
[0085] S320: When the target user has the shared login token, if the target user's dynamic login token is the same as the shared login token, respond to the target user's page request.
[0086] S330: In response to a logout request from a target user to an Internet application of a data center, identifying a shared login token corresponding to the target user.
[0087] The logout request may be a request message for the target user to actively log out of the Internet application.
[0088] Optionally, after the target application uses the Internet application, a logout request is triggered based on a logout control or logout operation steps provided by the Internet application, and a logout request is sent to the Internet application in the data center.
[0089] Specifically, after the target user sends a logout request to the Internet application of the data center, the Internet application of the data center responds to the logout request of the target user and obtains the shared login token of the target user in the data center.
[0090] S340: Generate token expiration information of the shared login token based on the token distribution service of the data center, and delete the shared login token.
[0091] The token expiration information can be used to destroy the valid state of the shared login token. The token expiration information includes the shared token information.
[0092] Optionally, after the target user logs out of the Internet application, the target user does not use the Internet application of any data center, and there is no need to perform single sign-on control on the user. The data center needs to destroy the shared login token, generate token expiration information, and notify other data centers of the token expiration information.
[0093] Optionally, the shared token information stored in the shared local storage is deleted in the data center.
[0094] Specifically, the token distribution service based on the data center generates token expiration information of the shared login token and deletes the shared login token.
[0095] S350: Sharing the token expiration information with each data center based on the token distribution service of the data center.
[0096] Optionally, token expiration information of the target user is generated in the data center, and the data center places the token expiration information in any token queue. When the token distribution service of the data center detects that there is token expiration information in the token queue, the token expiration information is shared with each data center.
[0097] Optionally, the token invalidation information is received by the token distribution service in each data center, the token invalidation information is parsed, shared token information is identified, and the shared token information stored in the shared local storage is deleted.
[0098] The technical solution of the embodiment of the application can query the shared login token of a target user in multiple data centers when the user requests a page from a data center, improve the utilization rate of data resources through data sharing, and control the forced logout of the target user if the dynamic login token of the target user is different from the shared login token when the target user has the shared login token.
[0099] Figure 4 The flowchart of another single sign-on control method provided by the embodiment of the application, the relationship between the embodiment and the above-mentioned embodiment is that the specific method of continuously controlling the single sign-on of a target application logged in by a data center is specifically introduced. Figure 4 As shown in the figure, the method comprises the following steps.
[0100] S410, in response to a page request of an internet application triggered by a target user in a data center, a shared login token corresponding to the target user is queried based on a user identification number of the target user.
[0101] S420, if the dynamic login token of the target user is the same as the shared login token when the target user has the shared login token, the page request of the target user is responded to.
[0102] S430, the token validity time of the shared login token is detected, and if the token validity time of the shared login token is greater than a preset dynamic validity period, a dynamic login token is updated for the target user to obtain an updated dynamic login token.
[0103] It should be noted that the token validity time of the shared login token is calculated based on the system timestamp when the shared login token is generated and the current system time of the data center.
[0104] The preset dynamic validity period can be a pre-set time value used to automatically determine the validity period of the shared login token. It should be noted that the data center sets the same preset dynamic validity period for each shared login token. The preset dynamic validity period can periodically refresh the shared login token of the target user, thereby reducing the risk to the data center and the target user's data and improving the overall security of the system.
[0105] Optionally, when the token validity period of the shared login token is greater than the preset dynamic validity period, the data center needs to update the shared login token for the target user, and generate a new dynamic login token through the session identification information, the data center identification of the data center and the system timestamp to achieve the update of the dynamic login token.
[0106] Optionally, after the dynamic login token is updated in a data center, the updated dynamic login token needs to be shared with other data centers.
[0107] S440: Use the updated dynamic login token as a shared login token, and generate shared token information based on the user identification number of the target user and the shared login token.
[0108] Optionally, the updated dynamic login token is used as a new shared login token, and new shared token information is generated based on the user identification number of the target user and the shared login token. The new shared token information is stored in the local shared storage of the data center, replacing the old shared token information in the local shared storage.
[0109] Specifically, the updated dynamic login token is used as a shared login token, and shared token information is generated based on the user identification number of the target user and the shared login token.
[0110] S450: Share the shared token information with each data center.
[0111] Specifically, the shared token information is added to any token queue of the data center and placed in the token queue. The token distribution service of the data center is used to detect whether there is shared data in the token queue. If the token distribution service of the data center detects that a token queue has shared token information, the token distribution service based on the data center will share the shared token information to each data center.
[0112] The technical scheme of the embodiment of the present application is that, in response to a page request of an Internet application of a data center triggered by a target user, a shared login token corresponding to the target user is queried based on a user identification number of the target user, when the user requests a page from the data center, the shared login token of the user in multiple data centers can be queried, and the utilization rate of data resources can be improved through data sharing; if the dynamic login token of the target user is not the same as the shared login token in the case that the target user has the shared login token, the target user is forced to log out by the Internet application. The technical problem of single sign-on control of a user under a multi-data center architecture in the prior art is solved. When the user logs in each data center, security check can be performed in any data center, and single login control of the user is realized.
[0113] Figure 5 A structural schematic diagram of a single sign-on control device provided by the embodiment of the present application is shown in FIG. 1. Figure 5 As shown in the figure, the device comprises a detection module 510 and a control module 520; wherein,
[0114] The detection module 510 is configured to, in response to a page request of an Internet application of a data center triggered by a target user, query a shared login token corresponding to the target user based on a user identification number of the target user.
[0115] The control module 520 is configured to, if the dynamic login token of the target user is not the same as the shared login token in the case that the target user has the shared login token, force the target user to log out by the Internet application.
[0116] The technical scheme of the embodiment of the present application is that, in response to a page request of an Internet application of a data center triggered by a target user, a shared login token corresponding to the target user is queried based on a user identification number of the target user, when the user requests a page from the data center, the shared login token of the user in multiple data centers can be queried, and the utilization rate of data resources can be improved through data sharing; if the dynamic login token of the target user is not the same as the shared login token in the case that the target user has the shared login token, the target user is forced to log out by the Internet application. The technical problem of single sign-on control of a user under a multi-data center architecture in the prior art is solved. When the user logs in each data center, security check can be performed in any data center, and single login control of the user is realized.
[0117] Optionally, the device further comprises a login module, a token processing module and a sharing module; wherein,
[0118] The login module is used to respond to a target user's login request to the Internet application of the data center and generate a dynamic login token for the target user;
[0119] The token processing module is configured to use the dynamic login token as a shared login token and generate shared token information based on the user identification number of the target user and the shared login token;
[0120] The sharing module is used to share the shared token information with each data center.
[0121] Optionally, the sharing module is specifically used to:
[0122] Placing the shared token information in any token queue preset in the data center;
[0123] If the token distribution service of the data center detects that the shared token information exists in the one token queue, the token distribution service based on the data center shares the shared token information with each of the data centers.
[0124] Optionally, the sharing module is further configured to:
[0125] The token distribution service based on the data center requests the global routing service to share the interface address list through the data center identifier of the data center;
[0126] The token distribution service of the data center shares the shared token information to each of the data centers based on the shared interface address list.
[0127] Optionally, the device further includes a logout module and a token invalidation module; wherein,
[0128] The logout module is configured to respond to a logout request from a target user to an Internet application of a data center and identify a shared login token corresponding to the target user;
[0129] The token invalidation module is used to generate token invalidation information of the shared login token based on the token distribution service of the data center, and delete the shared login token;
[0130] The sharing module is further specifically configured to share the token expiration information with each data center based on the token distribution service of the data center.
[0131] Optionally, the device further includes a dynamic detection module and a token update module; wherein,
[0132] The dynamic detection module is configured to detect a token validity time of the shared login token, and if the token validity time of the shared login token is greater than a preset dynamic validity period, update a dynamic login token for the target user to obtain an updated dynamic login token.
[0133] The token updating module is configured to generate shared token information based on the user identification number of the target user and the shared login token, with the updated dynamic login token taking the dynamic login token as the shared login token.
[0134] The sharing module is specifically configured to share the shared token information to each data center.
[0135] Optionally, the apparatus further comprises a token generation module.
[0136] The token generation module is configured to generate session identification information corresponding to an internet application of the data center for the target user in the case that the target user logs in the internet application of the data center, and generate a dynamic login token based on the session identification information, a data center identification of the data center, and a system timestamp.
[0137] The single sign-on control apparatus provided by the embodiments of the present application can perform the single sign-on control method provided by any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of performing the method.
[0138] Figure 6 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their modes of operation, are meant to be examples only, and are not intended to limit the inventiveness in any way.
[0139] As Figure 6As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0140] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0141] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the single sign-on control method.
[0142] In some embodiments, the single sign-on control method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the single sign-on control method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the single sign-on control method in any other suitable manner (e.g., via firmware).
[0143] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0144] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, cause modes / operations specified in the flow charts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine, or entirely on a remote machine or server.
[0145] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0146] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0147] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or grid browser through which a user can interact with embodiments of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by digital data communication (e.g., a communication grid) in any form or medium. Examples of communication grids include: a local area network (LAN), a wide area network (WAN), a blockchain grid, and the Internet.
[0148] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication grid. This client-server relationship arises through computer programs running on the respective computers, establishing a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within a cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0149] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0150] This embodiment provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the steps of the single sign-on control method provided in any embodiment of the present invention are implemented. The method includes:
[0151] In response to a page request of an Internet application of a data center triggered by a target user, a shared login token corresponding to the target user is queried based on a user identification number of the target user;
[0152] If the dynamic login token of the target user is different from the shared login token, the target user is forced to log out by the Internet application.
[0153] The computer storage medium of the embodiments of the present application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination thereof. More specific examples (non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or apparatus.
[0154] The computer readable signal medium can include a data signal propagating in a baseband or as part of a carrier wave propagating through a transmission medium, in which the computer readable program code is embodied. Such a propagating data signal can take many forms, including but not limited to electro-magnetic, optical, or any suitable combination thereof. The computer readable signal medium can also be any computer readable medium that is not a computer readable storage medium and that can transmit, propagate or transport program for use by or in connection with an instruction execution system, apparatus or device.
[0155] The program code contained on the computer readable medium can be transmitted in any suitable medium, including but not limited to wireless, wire line, optical cable, RF, etc., or any suitable combination thereof.
[0156] The computer program code for performing the operations of the present invention can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of grid, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0157] Those skilled in the art will appreciate that the modules or steps of the present invention described above can be implemented using a general-purpose computing device. They can be centralized on a single computing device or distributed across a grid of multiple computing devices. Alternatively, they can be implemented using program code executable by a computer device, which can then be stored in a storage device and executed by the computing device. Alternatively, they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0158] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0159] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A single sign-on control method, characterized in that: include: In response to a page request of an Internet application of a data center triggered by a target user, querying a shared login token corresponding to the target user based on the user identification number of the target user; In a case where the target user has the shared login token, if the dynamic login token of the target user is different from the shared login token, the Internet application controls the target user to forcibly log out.
2. The method according to claim 1, characterized in that Before responding to the page request of the first Internet application triggered by the target user and searching for the shared login token corresponding to the target user based on the user identification number of the target user, the method further includes: Responding to a target user's login request to an Internet application of the data center, generating a dynamic login token for the target user; Using the dynamic login token as a shared login token, generating shared token information based on the user identification number of the target user and the shared login token; The shared token information is shared with each data center.
3. The method according to claim 2, characterized in that Sharing the shared token information to each data center includes: Placing the shared token information in any token queue preset in the data center; If the token distribution service of the data center detects that the shared token information exists in the one token queue, the token distribution service based on the data center shares the shared token information with each of the data centers.
4. The method according to claim 3, characterized in that The data center-based token distribution service shares the shared token information with at least one of the data centers, including: The token distribution service based on the data center requests the global routing service to share the interface address list through the data center identifier of the data center; The token distribution service of the data center shares the shared token information to each of the data centers based on the shared interface address list.
5. The method according to claim 3, characterized in that After sharing the shared token information to each data center, the method further includes: In response to a logout request from a target user to an Internet application of a data center, identifying a shared login token corresponding to the target user; Generate token expiration information of the shared login token based on the token distribution service of the data center, and delete the shared login token; The data center-based token distribution service shares the token expiration information with each data center.
6. The method according to claim 3, characterized in that After sharing the shared token information with each data center, the method further includes: Detecting the token validity period of the shared login token, and if the token validity period of the shared login token is greater than a preset dynamic validity period, updating the dynamic login token for the target user to obtain an updated dynamic login token; Using the updated dynamic login token as a shared login token, and generating shared token information based on the user identification number of the target user and the shared login token; The shared token information is shared with each data center.
7. The method according to claim 1, characterized in that Also includes: When the target user logs into the Internet application of the data center, generating session identification information corresponding to the Internet application for the target user; A dynamic login token is generated based on the session identification information, a data center identifier of the data center, and a system timestamp.
8. A single sign-on control device, characterized in that: include: A detection module, configured to respond to a page request of an Internet application of a data center triggered by a target user, and query a shared login token corresponding to the target user based on a user identification number of the target user; The control module is configured to control the target user to forcibly log out if the target user has the shared login token and the dynamic login token of the target user is different from the shared login token.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the single sign-on control method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the single sign-on control method according to any one of claims 1 to 7 when executed.