Unified authentication single-point permission control method, device and equipment
By dynamically managing permissions through a unified authentication center, information such as user usernames, IP addresses, and tokens can be obtained, solving the problem of developers arbitrarily expanding their operational scope and improving both security and flexibility.
Patent Information
- Application Number
- CN202511108760.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-11
AI Technical Summary
Application developers or maintenance personnel may exploit access control vulnerabilities to arbitrarily expand the scope of operations, posing a security risk.
The unified authentication center controls access to sensitive operations, obtains the user's username, IP address, global token, and operation type, verifies the user's validity, and determines the corresponding permission identifier and authorization period based on the timestamp, username, IP address, and operation type to dynamically manage permissions.
It effectively reduces the security risk of developers or operations personnel within the application expanding the scope of operations without authorization, and achieves flexible access control and security auditing.
Smart Images

Figure CN120934825A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computer science and technology, and in particular to a unified authentication single point of access control method, apparatus and device. Background Technology
[0002] With the widespread adoption of internet applications, single sign-on (SSO) technology has become an important solution to the problem of users repeatedly logging in to multiple application systems.
[0003] Single sign-on (SSO) allows users to access multiple trusted applications or systems with a single login. Specifically, SSO requires only one login request from a user to log in to multiple applications. Applications can grant different permissions to different types of users.
[0004] However, developers or maintenance personnel within the application may exploit access control vulnerabilities to arbitrarily expand the scope of operations, posing a security risk. Summary of the Invention
[0005] This invention provides a unified authentication single-point access control method, apparatus, and device to address the security risks posed by the possibility that developers or maintenance personnel within applications may exploit access management vulnerabilities to arbitrarily expand their operational scope. The unified authentication center controls access to sensitive operational behaviors, thereby reducing security risks.
[0006] In a first aspect, the present invention provides a unified authentication single sign-on control method, applied to a unified authentication center, the method comprising: In response to a permission management request sent by the first application, a first timestamp is obtained, and the user's username, user IP address, global token, and user operation type are extracted from the permission management request; wherein, the permission management request is generated by the first application based on the sensitive operation request entered by the user after logging into the first application; If the user is verified as a valid user based on the Token and the user IP address, then a corresponding first permission identifier and a first authorization period are determined based on at least one of the first timestamp, the username, the user IP address and the user operation type. The determined first permission identifier and the first authorized time period are returned to the first application so that the first application can grant the user access to the resource corresponding to the first permission identifier during the first authorized time period.
[0007] Optionally, verifying the user as a valid user based on the token and the user's IP address includes: If the validity of the token is verified and the verification is successful, then it is determined whether the user's IP address is in the list of authorized IP addresses that have been created. If the user's IP address is in the authorized IP list, then the user is determined to be a valid user; After determining whether the user's IP address is within the created list of authorized IP addresses, the method further includes: If the user's IP address is not in the authorized IP list, the user is determined to be an invalid user, and the permission management request of the first application is rejected.
[0008] Optionally, determining the corresponding first permission identifier and first authorization period based on at least one of the first timestamp, the username, the user IP address, and the user operation type includes: Obtain a pre-created permission information table; the permission information table includes corresponding time type, network type, role type, permission identifier, and authorization duration; wherein, the time type is working hours or rest hours, and the network type is corporate intranet or corporate extranet; Based on at least one of the time type corresponding to the first timestamp, the role type corresponding to the username, the network type corresponding to the user IP address, and the user operation type, look up the corresponding first permission identifier and authorization duration in the permission information table; Obtain the second timestamp, add the second timestamp to the found authorized duration to obtain the target timestamp, and determine the period from the second timestamp to the target timestamp as the first authorized period.
[0009] Optionally, when the time type corresponding to the first timestamp is a working period, the network type corresponding to the user IP address is an enterprise intranet, the user operation type is modifying employee information, and the role type corresponding to the username is an employee information administrator, the first permission identifier is used to authorize the user to modify employee information.
[0010] Optionally, when the time type corresponding to the first timestamp is a rest period, or the network type corresponding to the user's IP address is the enterprise external network, the first permission identifier is used to prohibit the user from modifying employee information and to authorize the user to query employee information. When the user operation type is to view history, the first permission identifier is used to authorize the user to query and download history.
[0011] Optionally, obtaining the first timestamp in response to the permission management request sent by the first application includes: Receive a first login authentication request sent by the first application; wherein the first login authentication request is generated by the first application when it receives the login request input by the user, and the first login authentication request includes the Token; Parse the first login authentication request to obtain the Token in the first login authentication request; If the validity of the token is verified and the verification is successful, authentication information is returned to the first application so that the first application can confirm that the user has successfully logged in; Receive a permission management request sent by the first application, wherein the permission management request is generated by the first application based on the sensitive operation request entered by the user after successful login; In response to the permission management request sent by the first application, obtain the first timestamp.
[0012] Optionally, before receiving the login authentication request sent by the first application, the method further includes: Receive a second login authentication request sent by a second application; wherein the second login authentication request is generated by the second application when it receives a login request input by the user, and the second login authentication request includes the user's identity information; If the user's identity information is verified as valid, the token is generated based on the user's identity information, and the authentication pass information carrying the token is returned to the second application, so that the second application confirms that the user has successfully logged in and returns the token to the user.
[0013] Optionally, after returning the authentication pass information carrying the Token to the second application so that the second application confirms the user's successful login and returns the Token to the user, the method further includes: In response to the permission management request of the second application, a second permission identifier and a second authorization period are determined, and the second permission identifier and the second authorization period are returned to the second application so that the second application can grant the user access to the resource corresponding to the second permission identifier during the second authorization period; The permission management request of the second application is generated by the second application based on the sensitive operation request entered by the user after logging into the second application.
[0014] Secondly, the present invention provides a unified authentication single sign-on control device, applied to a unified authentication center, the device comprising: The acquisition unit is used to acquire a first timestamp in response to a permission management request sent by the first application; wherein the permission management request is generated by the first application based on a sensitive operation request entered by the user after logging into the first application; The extraction unit is used to extract the user's username, user IP address, global token, and user operation type from the permission management request; The determining unit is configured to verify that the user is a valid user based on the Token and the user IP address, and then determine the corresponding first permission identifier and first authorization period based on at least one of the first timestamp, the username, the user IP address and the user operation type; The return unit is used to return the determined first permission identifier and the first authorized time period to the first application, so that the first application can grant the user access to the resource corresponding to the first permission identifier during the first authorized time period.
[0015] Thirdly, the present invention provides a computer device, including: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the unified authentication single point of access control method of the first aspect or any corresponding embodiment described above.
[0016] The unified authentication single-point access control method, apparatus, and device provided by this invention allow a unified authentication center to verify the validity of a user by using the token and user IP address carried in the sensitive operation request when the user initiates a sensitive operation request in an application. Once the user is confirmed to be a valid user, the center then manages the access rights for the sensitive operation request. The application itself cannot authorize the sensitive operation requested by the user, thus avoiding access control vulnerabilities in the application and preventing the application from self-authorizing. This prevents developers or maintenance personnel within the application from arbitrarily expanding the scope of operations, effectively reducing security risks. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in this invention or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 A flowchart of a unified authentication single sign-on control method provided in an embodiment of the present invention; Figure 2A flowchart of another unified authentication single sign-on control method provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a unified authentication single sign-on control device provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0020] The following is combined Figures 1-2 This invention describes a unified authentication single sign-on control method.
[0021] like Figure 1 As shown, this embodiment proposes a first unified authentication single sign-on control method, which can be applied to a unified authentication center. The method may include the following steps: S101. In response to the permission management request sent by the first application, obtain the first timestamp. The permission management request is generated by the first application based on the sensitive operation request entered by the user after logging into the first application.
[0022] The Unified Authentication Center (UEC) is the authentication center in a single sign-on (SSO) system, responsible for verifying user application login requests. It's important to note that a SSO system can include a UEC and multiple mutually trusted applications. A user enters their username and password on the login page of one of these applications to submit a login request. This application then sends a corresponding login authentication request to the UEC. The UEC verifies the login authentication request, and upon successful verification, returns a global token to the application, confirming the user's successful login. The user can then use this token to directly access other applications without needing to log in to them.
[0023] Specifically, the first application is an application within a single sign-on system.
[0024] Sensitive operation requests can be pre-specified operation requests that pose security risks and require authorization from the unified authentication center, such as information modification, account cancellation, and fund transfer.
[0025] Specifically, after logging into the first application, the user can submit a sensitive operation request to the first application. At this time, the first application responds to the sensitive operation request by generating a corresponding permission management request and sending it to the unified authentication center.
[0026] The permission management request includes the user's username, IP address, global token, and user operation type.
[0027] Specifically, user action type is used to identify sensitive operation requests from user input to the first application.
[0028] Wherein, the first timestamp is the current timestamp. In this embodiment, the current timestamp can be determined and used as the first timestamp in response to the permission management request of the first application.
[0029] S102. Extract the user's username, user IP address, global token, and user operation type from the permission management request.
[0030] Specifically, the unified authentication center can parse the permission management request of the first application and extract the user's username, user IP address, token, and user operation type from the permission management request.
[0031] S103. If the user is verified as a valid user based on the Token and the user's IP address, then the corresponding first permission identifier and first authorization period shall be determined based on at least one of the first timestamp, username, user IP address and user operation type.
[0032] Specifically, the unified authentication center can verify a user's token and IP address to confirm the user's validity. Once a user is determined to be valid, the center then determines the corresponding first permission identifier and first authorization period based on at least one of the following: first timestamp, username, user IP address, and user operation type.
[0033] Optionally, step S103 may include: If the token is verified to be valid and the verification is successful, then determine whether the user's IP address is in the list of authorized IP addresses that have been created. If the user's IP address is in the authorized IP list, then the user is considered a valid user.
[0034] After determining whether the user's IP address is within the created list of authorized IPs, the method also includes: If the user's IP address is not in the authorized IP list, the user is determined to be an invalid user, and the first application's permission management request is rejected.
[0035] Specifically, in this embodiment, the validity of the token can be verified first. If the token is invalid, the user can be directly identified as an invalid user, and the permission management request of the first application can be rejected. If the token is valid, the user's IP address can be verified next.
[0036] Specifically, this embodiment can pre-create a list to store user identity information such as usernames and account information of different users, thereby managing the identity information of different users. This embodiment can also determine authorized IP addresses and store them in a list. When verifying a user's IP address, if the user's IP address exists in the authorized IP list, the user's IP address can be determined to be a valid IP address, thereby determining that the user is a valid user.
[0037] Specifically, if the user's IP address does not exist in the authorized IP list, the user can be directly identified as an invalid user, and the first application's permission management request can be rejected.
[0038] The first permission identifier is used to identify a certain operation permission, and the first authorization period refers to a certain period of time during which the user is authorized to perform sensitive operations.
[0039] Specifically, in this embodiment, the first permission identifier and the first authorization period can be determined based on the first timestamp, username, user IP address and / or user operation type.
[0040] Optionally, step S103 includes: Retrieve the pre-created permission information table; the permission information table includes the corresponding time type, network type, role type, permission identifier, and authorization duration; among which, the time type is working hours or rest hours, and the network type is corporate intranet or corporate extranet; Based on at least one of the following: the time type corresponding to the first timestamp, the role type corresponding to the username, the network type corresponding to the user IP address, and the user operation type, look up the corresponding first permission identifier and authorization duration in the permission information table; Obtain the second timestamp, add the second timestamp to the found authorized duration to obtain the target timestamp, and determine the period from the second timestamp to the target timestamp as the first authorized period.
[0041] The second timestamp is the current timestamp. In this embodiment, the current timestamp can be determined when determining the authorization duration and used as the second timestamp.
[0042] It is understandable that the second timestamp is after the first timestamp.
[0043] Optionally, when the time type corresponding to the first timestamp is a working period, the network type corresponding to the user's IP address is an enterprise intranet, the user operation type is modifying employee information, and the role type corresponding to the username is employee information administrator, the first permission identifier is used to authorize the user to modify employee information.
[0044] Optionally, when the time type corresponding to the first timestamp is a rest period, or the network type corresponding to the user's IP address is the enterprise external network, the first permission identifier is used to prohibit the user from modifying employee information and to authorize the user to query employee information. When the user's action type is to view history, the first permission identifier is used to authorize the user to query and download history.
[0045] To better illustrate the process of determining the first permission identifier and the authorization duration, this embodiment presents Example 1 below.
[0046] Example 1: This embodiment combines adjustments based on time, network, and operational behavior.
[0047] Basic permissions: The basic permission of user "Zhao Liu" (role: HR specialist) in the application (human resources system) is "to query employee social security information".
[0048] The rules are set as follows: the time is "weekday 9:00-17:00" + network is "company intranet" + operation is "onboarding process, processing employee onboarding". This operation is considered a sensitive operation. The first application will send an access control request to the unified authentication center. The unified authentication center will temporarily grant the "modify employee social security contribution base" permission for 2 hours. If the time is a "non-working day" or the network is an "external network", regardless of the username and user IP address, if the sensitive operation request is "modify the employee's social security contribution base", the unified authentication center will prohibit modification and only retain query permissions; If the action is "viewing history" (a non-sensitive operation), the Unified Authentication Center will authorize "downloading social security payment details" regardless of the username, user IP address, time, or network.
[0049] S104. Return the determined first permission identifier and first authorization period to the first application, so that the first application can grant the user access to the resource corresponding to the first permission identifier during the first authorization period.
[0050] Specifically, in this embodiment, after determining the first permission identifier and the first authorization period, the first permission identifier and the first authorization period are sent to the first application. The first application will then grant the user access to the resources corresponding to the first permission identifier during the first authorization period.
[0051] It should be noted that in related technologies, the application itself directly controls user operation permissions, resulting in a deep binding of permissions with business logic and creating the risk of "self-authorization". For example, in order to facilitate its own functions, the application may excessively request permissions, and the developers or maintenance personnel inside the application may take advantage of permission management vulnerabilities to arbitrarily expand the scope of operation.
[0052] The unified authentication single-point access control method proposed in this embodiment allows the unified authentication center to verify the user's validity based on the token and user IP address carried in the sensitive operation request when a user initiates a sensitive operation request in the application. Once the user is determined to be a valid user, the center then manages the access rights for the sensitive operation request initiated by the user. The application itself cannot authorize the sensitive operation requested by the user, thus avoiding application access control vulnerabilities and preventing the application from self-authorizing. This prevents developers or maintenance personnel within the application from arbitrarily expanding the scope of operations, effectively reducing security risks.
[0053] based on Figure 1 This embodiment proposes a second unified authentication single sign-on control method, in which step S101 includes: Receive a first login authentication request sent by a first application; wherein the first login authentication request is generated by the first application when it receives a login request input by the user, and the first login authentication request includes a Token; Parse the first login authentication request to obtain the Token from the first login authentication request; If the token is verified to be valid and the verification is successful, an authentication pass message is returned to the first application so that the first application can confirm that the user has successfully logged in; Receive permission management request sent by the first application. The permission management request is generated by the first application based on the sensitive operation request entered by the user after successful login. In response to the permission management request sent by the first application, obtain the first timestamp.
[0054] Optionally, before receiving the login authentication request sent by the first application, the method may further include: Receive a second login authentication request sent by a second application; wherein the second login authentication request is generated by the second application when it receives a login request input by the user, and the second login authentication request includes the user's identity information; If the user's identity information is verified as valid, a token is generated based on the user's identity information, and the authentication pass information carrying the token is returned to the second application so that the second application can confirm that the user has successfully logged in and return the token to the user.
[0055] like Figure 2As shown, application A is the second application, and application B is the first application. Users can access application A by submitting a login request. Application A redirects the login request to the unified login page of the unified authentication center, carrying the callback URL of application A in the redirect request. Users can enter their username and password on the unified login page. The unified authentication center authenticates the username and password entered by the user. If authentication is successful, a token is generated and returned to the user. The user sends data carrying the token back to application A. Application A verifies the validity of the token with the unified authentication center. The unified authentication center returns the user information, i.e., the validity of the token, to application A, confirming that the user has successfully logged in and allowing the user to access resources.
[0056] After a user successfully logs in to application A, they can directly access application B without having to enter their account password again. When the user enters a sensitive operation request in application B, application B will send an access control request to the unified authentication center, carrying a token, user IP address, username, and user operation type. The center will check the validity of the token and user IP address, use security mechanisms (encryption, multi-factor authentication) to verify the validity of the user's identity, and record the entire verification and management process to generate a security audit log.
[0057] Users can initiate access requests to application A and application B on their user terminals, receive and process response information from the applications and the unified authentication center, and cooperate in completing multi-factor authentication operations, such as receiving and entering mobile phone verification codes.
[0058] Applications A and B are responsible for redirecting users to the unified authentication center for authentication upon access; receiving and verifying user information, token validity verification results, and permission information from the unified authentication center; and determining whether to allow users to access resources based on the results returned by the unified authentication center, and granting resources according to the corresponding permissions. In addition, when a user accesses the service, Application B sends information including the token, IP address, callback address, and dynamic permission management request to the SSO unified authentication center.
[0059] The unified authentication center receives redirection requests and related information from application A and application B, authenticates users, generates and manages global tokens, performs multi-dimensional security verification, including token validity checks, IP address verification, data encryption, and triggering of multi-factor authentication processes, adjusts permissions in real time according to the application's dynamic permission management strategy, records the entire verification and management process, generates security audit logs, and returns the corresponding verification results, user information, and permission information to application A and application B.
[0060] It should be noted that while single sign-on (SSO) systems in related technologies enable users to access multiple applications with a single login, they suffer from several shortcomings in terms of security and management flexibility. For example, relying solely on token authentication lacks effective identification of the login environment, making them vulnerable to token theft attacks; permission management is mostly statically configured, unable to adjust user permissions in real time according to application scenarios; security protection measures are limited, lacking mechanisms such as encryption of data transmission and multi-factor authentication, making them susceptible to complex network attacks; furthermore, the lack of a comprehensive security audit mechanism hinders effective tracking and analysis of user login behavior, impeding the tracing and prevention of security incidents. Therefore, a SSO solution with more comprehensive security protection and flexible management capabilities is urgently needed.
[0061] Specifically, a unified authentication center can embed basic encryption mechanisms during the token generation stage (laying the groundwork for subsequent security verification), and the user information returned by the unified authentication center already includes preliminary permission identifiers (providing a foundation for dynamic permission management). In contrast, the tokens in related technologies may use simple encoding (unencrypted), and the returned user information may only contain identity identifiers (without pre-identification of permissions).
[0062] Specifically, in this embodiment, when a user accesses application B, application B sends a token, the user's IP address, the callback URL of application B, and a dynamic permission management request to the unified authentication center; at the same time, the unified authentication center triggers encryption processing (such as token signature encryption and data transmission encryption) and multi-factor authentication process (such as SMS verification code and biometric identification).
[0063] In related technologies, application B only sends a token and callback address to the authentication center, and the verification logic is simple (only token validity); and it does not force the triggering of encryption processing (or only transmits encryption in a simple way), and multi-factor authentication is usually an optional configuration (not dynamically triggered based on the scenario).
[0064] The difference between this embodiment and related technologies lies in that this embodiment adds user IP address transmission and dynamic permission management requests, and embeds encryption and multi-factor authentication as mandatory processes into the interaction, forming the starting point for multi-dimensional security verification. Related technologies lack such complex information interaction and mandatory security mechanisms.
[0065] Specifically, in related technologies, the authentication center only verifies the validity of the token and does not involve IP verification; permission management is statically configured (e.g., user permissions are set during system initialization and do not change with subsequent scenarios / time); security logs only record login success / failure, without detailed verification process records. In contrast, the unified authentication center in this embodiment verifies token validity, checks the matching of IP address with historical records / authorization scope, adjusts the user's permissions in application B in real time according to dynamic permission policies based on factors such as the user's current operation scenario (e.g., accessing sensitive modules) and time (e.g., non-working hours), records the complete verification process, and generates security audit logs.
[0066] Specifically, in related technologies, the authentication center only returns a logged-in status to application B, and application B's resource access permissions are determined by its own static configuration, independent of the authentication center. However, the unified authentication center in this embodiment can return a logged-in status and real-time adjusted permission information to application B, allowing application B to access corresponding resources based on the permission information. In this embodiment, application B's resource access permissions are dynamically generated and issued in real-time by the unified authentication center, enabling permissions to change dynamically with the scenario. Related technologies, where permissions are decoupled from the authentication center, cannot adapt to dynamic security requirements.
[0067] It is understood that this embodiment can realize a unified authentication mechanism that integrates multi-dimensional security verification and real-time dynamic permission linkage, specifically in the following ways: Integration of multi-dimensional security verification: It integrates scattered security measures such as token verification, IP address verification, encryption processing, multi-factor authentication, and security audit logs into a coherent interactive process, forming a full-link security closed loop of "pre-encryption → in-process multi-factor verification → post-log traceability", which solves the problem of fragmentation of related technical security mechanisms.
[0068] Scenario-based adaptation of dynamic permission management: A strategy is proposed to adjust permissions based on real-time factors such as user operation scenarios (e.g., access to the finance module and the general query module) and time (e.g., weekdays 8:00-18:00 and the early morning hours). For example: If a user accesses application B's sensitive data module from an unauthorized IP address (such as a public network), the Unified Authentication Center will automatically and temporarily restrict their permissions (allowing them to view basic information but prohibiting downloads). If a user accesses application B at 2:00 AM (outside of working hours), the Unified Authentication Center will trigger additional multi-factor authentication (such as facial recognition) and temporarily reduce the user's data modification privileges.
[0069] This dynamic adjustment mechanism breaks through the limitations of existing static permissions, enabling real-time matching of permissions with risk scenarios.
[0070] Deep collaboration between the unified authentication center and application permissions: Unified management and real-time distribution of permission information, which strongly binds the resource access control of the application (such as application B) to the authentication results of the unified authentication center. This avoids the security vulnerabilities caused by the disconnect between the application's own permissions and the unified authentication center's authentication in related technologies. For example, a user may be disabled in the unified authentication center, but the application may still retain their permissions.
[0071] Optionally, in other unified authentication single sign-on control methods proposed in this embodiment, after returning the authentication pass information carrying the token to the second application so that the second application confirms the user's successful login and returns the token to the user, the method may further include: In response to the permission management request of the second application, a second permission identifier and a second authorization period are determined, and the second permission identifier and the second authorization period are returned to the second application so that the second application can grant the user access to the resources corresponding to the second permission identifier during the second authorization period; The permission management request of the second application is generated by the second application based on the sensitive operation request entered by the user after logging into the second application.
[0072] Understandably, a unified authentication center can dynamically manage user access permissions for each application in a single sign-on system, thereby enabling unified dynamic control over user access permissions across multiple applications.
[0073] The unified authentication single sign-on method proposed in this embodiment can address the shortcomings of single sign-on systems in terms of security and management by introducing multiple security verification mechanisms and dynamic permission management strategies. It ensures the security and reliability of user login and application access, while also achieving flexible permission control and security auditing.
[0074] like Figure 3 As shown, this embodiment proposes a unified authentication single sign-on control device, which may include: The acquisition unit 301 is used to acquire a first timestamp in response to a permission management request sent by the first application; wherein the permission management request is generated by the first application based on the sensitive operation request entered by the user after logging into the first application; Extraction unit 302 is used to extract the user's username, user IP address, global token, and user operation type from the permission management request; The determining unit 303 is used to verify that the user is a valid user based on the Token and the user IP address, and then determine the corresponding first permission identifier and first authorization period based on at least one of the first timestamp, username, user IP address and user operation type. The return unit 304 is used to return the determined first permission identifier and first authorized time period to the first application, so that the first application can grant the user access to the resource corresponding to the first permission identifier during the first authorized time period.
[0075] It should be noted that the processing procedures of the acquisition unit 301, extraction unit 302, determination unit 303, and return unit 304, and their beneficial effects, can be referred to respectively. Figure 1 Steps S101 to S104 in the process will not be described again.
[0076] Optionally, the determining unit 303 is also used for: If the token is verified to be valid and the verification is successful, then determine whether the user's IP address is in the list of authorized IP addresses that have been created. If the user's IP address is in the authorized IP list, the user is determined to be a valid user. Based on at least one of the first timestamp, username, user IP address and user operation type, the corresponding first permission identifier and first authorization period are determined. If the user's IP address is not in the authorized IP list, the user is determined to be an invalid user, and the first application's permission management request is rejected.
[0077] Optionally, the determining unit 303 is also used for: Retrieve the pre-created permission information table; the permission information table includes the corresponding time type, network type, role type, permission identifier, and authorization duration; among which, the time type is working hours or rest hours, and the network type is corporate intranet or corporate extranet; Based on at least one of the following: the time type corresponding to the first timestamp, the role type corresponding to the username, the network type corresponding to the user IP address, and the user operation type, look up the corresponding first permission identifier and authorization duration in the permission information table; Obtain the second timestamp, add the second timestamp to the found authorized duration to obtain the target timestamp, and determine the period from the second timestamp to the target timestamp as the first authorized period.
[0078] Optionally, when the time type corresponding to the first timestamp is a working period, the network type corresponding to the user's IP address is an enterprise intranet, the user operation type is modifying employee information, and the role type corresponding to the username is employee information administrator, the first permission identifier is used to authorize the user to modify employee information.
[0079] Optionally, when the time type corresponding to the first timestamp is a rest period, or the network type corresponding to the user's IP address is the enterprise external network, the first permission identifier is used to prohibit the user from modifying employee information and to authorize the user to query employee information. When the user's action type is to view history, the first permission identifier is used to authorize the user to query and download history.
[0080] Optionally, the acquisition unit 301 is also used for: Receive a first login authentication request sent by a first application; wherein the first login authentication request is generated by the first application when it receives a login request input by the user, and the first login authentication request includes a Token; Parse the first login authentication request to obtain the Token from the first login authentication request; If the token is verified to be valid and the verification is successful, an authentication pass message is returned to the first application so that the first application can confirm that the user has successfully logged in; Receive permission management request sent by the first application. The permission management request is generated by the first application based on the sensitive operation request entered by the user after successful login. In response to the permission management request sent by the first application, obtain the first timestamp.
[0081] Optionally, the above-mentioned device further includes: The receiving unit is configured to receive a second login authentication request sent by a second application before receiving a login authentication request sent by a first application; wherein the second login authentication request is generated by the second application when it receives a login request input by the user, and the second login authentication request includes the user's identity information; The generation unit is used to verify that the user's identity information is valid, and then generates a token based on the user's identity information; The information return unit is used to return authentication information carrying the token to the second application, so that the second application can confirm that the user has successfully logged in and return the token to the user.
[0082] Optionally, the above-mentioned device further includes: The response unit is used to respond to the permission management request of the second application after returning the authentication information carrying the token to the second application so that the second application confirms that the user has successfully logged in and returns the token to the user, determine the second permission identifier and the second authorization period, and return the second permission identifier and the second authorization period to the second application so that the second application can grant the user access to the resources corresponding to the second permission identifier during the second authorization period. The permission management request of the second application is generated by the second application based on the sensitive operation request entered by the user after logging into the second application.
[0083] The unified authentication single-point access control device proposed in this embodiment allows the unified authentication center to verify the user's validity based on the token and user IP address carried in the sensitive operation request when a user initiates a sensitive operation request in the application. Once the user is determined to be a valid user, the unified authentication center then manages the access rights for the sensitive operation request initiated by the user. The application itself cannot authorize the sensitive operation requested by the user, thus avoiding access control vulnerabilities in the application and preventing the application from self-authorizing. This prevents developers or maintenance personnel within the application from arbitrarily expanding the scope of operations, effectively reducing security risks.
[0084] In this embodiment, the unified authentication single-point access control device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0085] This invention also provides a computer device having the above-described features. Figure 3 The unified authentication single sign-on control device shown is shown.
[0086] Please see Figure 4 The present invention provides a schematic diagram of the structure of a computer device according to an optional embodiment. The computer device includes one or more processors 10, a memory 20, and interfaces for connecting the various components, including high-speed interfaces and low-speed interfaces. The various components are interconnected via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, multiple processors and / or multiple buses can be used with multiple memories, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 4 Take a processor 10 as an example.
[0087] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.
[0088] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.
[0089] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function. The data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, which can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0090] Memory 20 may include volatile memory, such as random access memory. Memory may also include non-volatile memory, such as flash memory, hard disk, or solid-state drive. Memory 20 may also include combinations of the above types of memory.
[0091] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.
[0092] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0093] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A unified authentication single sign-on control method, characterized in that, Applied to a unified authentication center, the method includes: In response to a permission management request sent by the first application, a first timestamp is obtained, and the user's username, user IP address, global token, and user operation type are extracted from the permission management request; wherein, the permission management request is generated by the first application based on the sensitive operation request entered by the user after logging into the first application; If the user is verified as a valid user based on the Token and the user IP address, then a corresponding first permission identifier and a first authorization period are determined based on at least one of the first timestamp, the username, the user IP address and the user operation type. The determined first permission identifier and the first authorized time period are returned to the first application so that the first application can grant the user access to the resource corresponding to the first permission identifier during the first authorized time period.
2. The method according to claim 1, characterized in that, The step of verifying the user as a valid user based on the token and the user's IP address includes: If the validity of the token is verified and the verification is successful, then it is determined whether the user's IP address is in the list of authorized IP addresses that have been created. If the user's IP address is in the authorized IP list, then the user is determined to be a valid user; After determining whether the user's IP address is within the created list of authorized IP addresses, the method further includes: If the user's IP address is not in the authorized IP list, the user is determined to be an invalid user, and the permission management request of the first application is rejected.
3. The method according to claim 1, characterized in that, The step of determining the corresponding first permission identifier and first authorization period based on at least one of the first timestamp, the username, the user IP address, and the user operation type includes: Obtain a pre-created permission information table; the permission information table includes corresponding time type, network type, role type, permission identifier, and authorization duration; wherein, the time type is working hours or rest hours, and the network type is corporate intranet or corporate extranet; Based on at least one of the time type corresponding to the first timestamp, the role type corresponding to the username, the network type corresponding to the user IP address, and the user operation type, look up the corresponding first permission identifier and authorization duration in the permission information table; Obtain the second timestamp, add the second timestamp to the found authorized duration to obtain the target timestamp, and determine the period from the second timestamp to the target timestamp as the first authorized period.
4. The method according to claim 3, characterized in that, When the time type corresponding to the first timestamp is a working period, the network type corresponding to the user IP address is an enterprise intranet, the user operation type is modifying employee information, and the role type corresponding to the username is employee information administrator, the first permission identifier is used to authorize the user to modify employee information.
5. The method according to claim 3, characterized in that, When the time type corresponding to the first timestamp is a rest period, or the network type corresponding to the user's IP address is the enterprise external network, the first permission identifier is used to prohibit the user from modifying employee information and to authorize the user to query employee information. When the user operation type is to view history, the first permission identifier is used to authorize the user to query and download history.
6. The method according to claim 1, characterized in that, The step of obtaining the first timestamp in response to the permission management request sent by the first application includes: Receive a first login authentication request sent by the first application; wherein the first login authentication request is generated by the first application when it receives the login request input by the user, and the first login authentication request includes the Token; Parse the first login authentication request to obtain the Token in the first login authentication request; If the validity of the token is verified and the verification is successful, authentication information is returned to the first application so that the first application can confirm that the user has successfully logged in; Receive a permission management request sent by the first application, wherein the permission management request is generated by the first application based on the sensitive operation request entered by the user after successful login; In response to the permission management request sent by the first application, obtain the first timestamp.
7. The method according to claim 1, characterized in that, Before receiving the login authentication request sent by the first application, the method further includes: Receive a second login authentication request sent by a second application; wherein the second login authentication request is generated by the second application when it receives a login request input by the user, and the second login authentication request includes the user's identity information; If the user's identity information is verified as valid, the token is generated based on the user's identity information, and the authentication pass information carrying the token is returned to the second application, so that the second application confirms that the user has successfully logged in and returns the token to the user.
8. The method according to claim 7, characterized in that, After returning authentication information carrying the token to the second application so that the second application confirms the user's successful login and returns the token to the user, the method further includes: In response to the permission management request of the second application, a second permission identifier and a second authorization period are determined, and the second permission identifier and the second authorization period are returned to the second application so that the second application can grant the user access to the resource corresponding to the second permission identifier during the second authorization period; The permission management request of the second application is generated by the second application based on the sensitive operation request entered by the user after logging into the second application.
9. A unified authentication single sign-on control device, characterized in that, Applied to a unified authentication center, the device includes: The acquisition unit is used to acquire a first timestamp in response to a permission management request sent by the first application; wherein the permission management request is generated by the first application based on a sensitive operation request entered by the user after logging into the first application; The extraction unit is used to extract the user's username, user IP address, global token, and user operation type from the permission management request; The determining unit is configured to verify that the user is a valid user based on the Token and the user IP address, and then determine the corresponding first permission identifier and first authorization period based on at least one of the first timestamp, the username, the user IP address and the user operation type; The return unit is used to return the determined first permission identifier and the first authorized time period to the first application, so that the first application can grant the user access to the resource corresponding to the first permission identifier during the first authorized time period.
10. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the unified authentication single sign-on control method according to any one of claims 1 to 8.