Webpage application access method and device based on single sign-on mechanism and electronic equipment
By intercepting data through a client-side proxy and performing secondary authentication at the SSO authentication center, the problem of the secondary authentication mechanism being ineffective in single sign-on is solved, information security is improved, and the integrity of user authentication and protection of the enterprise network are ensured.
Patent Information
- Application Number
- CN202410757670.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2025-12-12
AI Technical Summary
In existing single sign-on (SSO) technologies, the two-factor authentication mechanism is practically useless in actual applications, resulting in poor information security and an inability to effectively address security risks when devices are lost or stolen.
The client-side proxy intercepts the target client's access requests and determines whether the target web application has enabled a two-factor authentication mechanism at the SSO authentication center. If enabled, it performs two-factor authentication and sends the login result to the application server based on the authentication result to ensure the integrity of user authentication.
It implements an effective two-factor authentication process in SSO technology, improves information security, prevents unauthorized access, and enhances the protection of enterprise networks.
Smart Images

Figure CN121125131A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network communication, in particular to a webpage application access method and device based on a single sign-on mechanism, an electronic device, a computer storage medium and a computer program product. BACKGROUND
[0002] With the continuous development of technology, single sign-on (SSO) technology has become an important part of enterprise information security architecture. SSO technology allows users to access multiple web applications or services using a set of credentials. However, the popularity of SSO technology means that once a user's device is lost or stolen, an attacker can use these credentials to access web applications or services within the enterprise at will, even gaining extensive access to the enterprise network, posing a security risk.
[0003] In related technologies, in order to deal with the risks existing in SSO technology, additional security measures are taken, namely, multi-factor authentication (MFA), also known as secondary authentication. However, in actual application, web applications or services usually maintain login sessions themselves, making the secondary authentication mechanism meaningless and not solving the security risks existing in SSO technology, resulting in poor information security. SUMMARY
[0004] The embodiments of the present application provide a webpage application access method and device based on a single sign-on mechanism, an electronic device, a computer readable storage medium and a computer program product, which can improve information security.
[0005] A webpage application access method based on a single sign-on mechanism, applied to a first server, the method comprising:
[0006] Obtaining an access request initiated by a target client for a target webpage application, wherein the access request is intercepted by a client proxy and forwarded to the first server;
[0007] In response to the access request, determining whether the target webpage application has enabled a secondary authentication mechanism;
[0008] If it is determined that the secondary authentication mechanism is enabled, then when a target user has passed single sign-on authentication, the target user is subjected to secondary authentication;
[0009] Based on the secondary authentication result, sending a login result corresponding to the target user to a second server, so that the target client accesses the target webpage application based on the login result, wherein the second server is an application server running the target webpage application.
[0010] Correspondingly, the application also provides a web application access device based on a single sign-on mechanism, applied to a first server, comprising:
[0011] a request obtaining unit configured to obtain an access request initiated by a target client to a target web application, wherein the access request is intercepted by a client agent and forwarded to the first server;
[0012] a mechanism determining unit configured to determine whether a secondary authentication mechanism is enabled for the target web application in response to the access request;
[0013] an authentication unit configured to perform secondary authentication on a target user when the target user has passed single sign-on authentication if it is determined that the secondary authentication mechanism is enabled;
[0014] a sending unit configured to send a login result corresponding to the target user to a second server based on a secondary authentication result, so that the target client accesses the target web application based on the login result, wherein the second server is an application server running the target web application.
[0015] Optionally, in some embodiments, the device further comprises:
[0016] a detection unit configured to detect whether the identity of the target user has passed single sign-on authentication before performing secondary authentication on the identity of the target user after it is determined that the secondary authentication mechanism is enabled;
[0017] the authentication unit is configured to directly perform secondary authentication on the identity of the target user if it is detected that the identity of the target user has passed single sign-on authentication;
[0018] the authentication unit is further configured to perform single sign-on authentication on the identity of the target user if it is detected that the identity of the target user has not passed single sign-on authentication, and perform secondary authentication on the identity of the target user after the identity of the target user passes single sign-on authentication
[0019] Optionally, in some embodiments, the sending unit is configured to:
[0020] if the secondary authentication result is passed, determine that the target user logs in successfully and generate a corresponding unified authentication identifier, send the unified authentication identifier and a login result that the target user logs in successfully to the second server;
[0021] if the secondary authentication result is not passed, determine that the target user logs in fails, and send a login result that the target user logs in fails to the second server.
[0022] Optionally, in some embodiments, the apparatus further comprises:
[0023] a device code obtaining unit, configured to, after determining that the secondary authentication result is passed, obtain a device code of a device where the target client is located before sending the uniform authentication identifier and the login result that the target user logs in successfully to the second server;
[0024] a network address obtaining unit, configured to obtain a network IP address corresponding to the target client;
[0025] a first time length determining unit, configured to determine an effective time length of the secondary authentication result according to the network IP address and the device code.
[0026] Optionally, in some embodiments, the apparatus further comprises:
[0027] a level determining unit, configured to, after determining that the secondary authentication result is passed, determine an application level of the target web application before sending the uniform authentication identifier and the login result that the target user logs in successfully to the second server;
[0028] a second time length determining unit, configured to determine an effective time length of the secondary authentication result according to the application level.
[0029] Optionally, in some embodiments, the apparatus further comprises:
[0030] a first number obtaining unit, configured to, after determining that the secondary authentication result is not passed, obtain a first number of times that the secondary authentication result is not passed before determining that the target user fails to log in;
[0031] an information obtaining unit, configured to, for each time that the secondary authentication result is not passed, obtain an information type of identity authentication information verified when the target user is subjected to secondary authentication;
[0032] a second number obtaining unit, configured to obtain a second number of times of the information type;
[0033] a judging unit, configured to judge whether the first number and the second number satisfy a preset condition;
[0034] the authentication unit is configured to, if it is judged that the preset condition is satisfied, re-subject the target account to secondary authentication;
[0035] the sending unit is further configured to, if it is judged that the preset condition is not satisfied, determine that the target user fails to log in.
[0036] Optionally, in some embodiments, when the target user is subjected to secondary authentication, the authentication unit is specifically configured to:
[0037] obtaining a secondary authentication state of the target user currently;
[0038] if the secondary authentication state is not authenticated or authentication invalid, performing secondary authentication on the target user;
[0039] if the secondary authentication state is authentication valid, forwarding the access request to the second server, so that the target client accesses the target web application based on the access request
[0040] Optionally, in some embodiments, the apparatus further comprises:
[0041] a level determination unit, configured to, after determining that the secondary authentication state is authentication valid, before forwarding the access request to the second server, determine an application level of the target web application;
[0042] a third time length obtaining unit, configured to obtain a preset valid time length of secondary authentication corresponding to the application level;
[0043] a fourth time length obtaining unit, configured to obtain a current valid time length corresponding to the secondary authentication state;
[0044] an updating unit, configured to, when the current valid time length is greater than the preset valid time length, update the current valid time length based on the preset valid time length.
[0045] Optionally, in some embodiments, the access request is intercepted by the client proxy and forwarded to a target gateway, and is forwarded to the first server through the target gateway; the apparatus further comprises:
[0046] a forwarding unit, configured to, if it is determined that the secondary authentication mechanism is not enabled, forward the obtained access request to the second server through the target gateway, so that the target client accesses the target web application based on the access request.
[0047] In addition, an electronic device is further provided in the embodiments of the present application, comprising a processor and a memory, the memory stores a computer program, and the processor is used to run the computer program in the memory to realize the steps in the web application access method based on the single sign-on mechanism provided in the embodiments of the present application.
[0048] In addition, a computer readable storage medium is further provided in the embodiments of the present application, the computer readable storage medium stores a plurality of instructions, the instructions are suitable for being loaded by a processor to execute the steps in the web application access method based on the single sign-on mechanism provided in the embodiments of the present application.
[0049] Further, the embodiment of the present application further provides a computer program product comprising a computer program or instructions, which, when executed by a processor, implement the steps in the web application access method based on a single sign-on mechanism provided by the embodiment of the present application.
[0050] The embodiment of the present application intercepts the access request initiated by the target client by the client agent and forwards the access request to the first server, and then the first server responds to the access request and determines whether the target web application enables a secondary authentication mechanism; if the secondary authentication mechanism is enabled, the target user is subjected to secondary authentication when the target user has passed the single sign-on authentication; the login result corresponding to the target user is sent to the second server based on the secondary authentication result, so that the target client accesses the target web application based on the login result. The present scheme can intercept the access request initiated by the target client and forward the access request to the first server to initiate the secondary authentication process, rather than redirecting to the first server, so that the secondary authentication can be initiated as expected regardless of how the web application interfaces with the first server, and the security risks existing in the single sign-on technology are solved, and the information security is improved. BRIEF DESCRIPTION OF DRAWINGS
[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0052] Figure 1 is a scenario diagram of the web application access method based on a single sign-on mechanism provided by the embodiment of the present application;
[0053] Figure 2 is a flow diagram of the web application access method based on a single sign-on mechanism provided by the embodiment of the present application;
[0054] Figure 3 is a diagram of the management interface of the SSO authentication center provided by the embodiment of the present application;
[0055] Figure 4 is an interaction flow diagram of the application access system based on a single sign-on mechanism provided by the embodiment of the present application;
[0056] Figure 5 is a diagram of the user login interface provided by the embodiment of the present application;
[0057] Figure 6 is another diagram of the user login interface provided by the embodiment of the present application;
[0058] Figure 7is a structural schematic diagram of a web application access device based on a single sign-on mechanism provided by an embodiment of the present application.
[0059] Figure 8 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0060] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person skilled in the art without creative work fall within the scope of protection of the present application.
[0061] In actual applications, a secondary authentication mechanism requires a user to provide at least two different verification methods in a login process to increase the difficulty of an attacker to illegally access an account. However, in the related art, a secondary authentication scheme requires that, after a web application or a service initiates an SSO authentication process, an SSO authentication center can determine whether secondary authentication is needed. In actual applications, many web applications / services usually have the ability to maintain a login session by themselves to manage the login status of a user independently of the SSO authentication center in order to improve efficiency. When an application needs to initiate secondary authentication, the SSO authentication center can not be able to respond and execute the secondary authentication process in time due to the lack of interaction with the SSO authentication center, resulting in that the secondary authentication is a mere formality and affecting information security.
[0062] Based on this, the embodiments of the present application provide a web application access method and device based on a single sign-on mechanism, an electronic device, a computer readable storage medium, and a computer program product, which can improve information security. The web application access device based on a single sign-on mechanism can be integrated in an electronic device, which can be a server or a terminal or the like.
[0063] The server can be a stand-alone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud service, cloud database, cloud computing, cloud function, cloud storage, network service, cloud communication, middleware service, domain name service, security service, network acceleration service, and big data and artificial intelligence platform. The terminal can be a mobile phone, a computer, a smart voice interaction device, a smart home appliance, a vehicle-mounted terminal, an aircraft, and the like, but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication, which is not limited in the present application.
[0064] For example, referring to Figure 1Taking a web application access device based on a single sign-on (SSO) mechanism integrated into a first server as an example, the first server receives access requests for a target web application initiated by the target client. These requests are intercepted by the client proxy and forwarded to the first server. Then, in response to the access request, the first server determines whether the target web application has enabled a two-factor authentication mechanism. If it is determined that two-factor authentication is enabled, and the target user has already passed SSO authentication, two-factor authentication is performed on the target user. Finally, based on the two-factor authentication result, the second server sends the login result corresponding to the target user to a second server, enabling the target client to access the target web application based on the login result. The second server is the application server running the target web application. This solution intercepts access requests initiated by the target client and forwards them to the first server to initiate the two-factor authentication process, rather than redirecting them to the first server. This ensures that regardless of how the web application connects to the first server, two-factor authentication can be initiated as expected, resolving the security vulnerabilities inherent in SSO technology and improving information security.
[0065] It is understood that in the specific implementation of this application, related data such as attribute data, attribute sets and attribute subsets are involved. When the following embodiments of this application are applied to specific products or technologies, permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0066] The following sections provide detailed descriptions of each example. It should be noted that the order in which the embodiments are described is not intended to limit the preferred order of the embodiments.
[0067] This embodiment will describe the corner information of the web application access device based on the single sign-on mechanism. The web application access device based on the single sign-on mechanism can be integrated into an electronic device, which can be a server or a terminal, etc. The terminal can be a mobile phone, computer, smart voice interaction device, smart home appliance, vehicle terminal, aircraft, etc., but is not limited to these.
[0068] This application provides a web application access method based on a single sign-on mechanism, applied to a first server. The method includes: obtaining an access request for a target web application initiated by a target client, wherein the access request is intercepted by a client proxy and forwarded to the first server; responding to the access request and determining whether the target web application has enabled a two-factor authentication mechanism; if it is determined that the two-factor authentication mechanism is enabled, then performing two-factor authentication on the target user if the target user has already passed single sign-on authentication; and sending a login result corresponding to the target user to a second server based on the two-factor authentication result, so that the target client can access the target web application based on the login result, wherein the second server is an application server running the target web application.
[0069] like Figure 2 As shown, the specific process of this web application access method based on the single sign-on mechanism is as follows:
[0070] 101. Obtain access requests for the target web application initiated by the target client, wherein the access requests are intercepted by the client proxy and forwarded to the first server.
[0071] In this embodiment, the target client is a client application with web browsing capabilities installed on an electronic device, such as a web browser or a desktop application with an embedded browser; the target web application is one of the web applications or services that has been pre-connected to the SSO authentication center and can be configured in the SSO authentication center's management interface or configuration file. Specifically, the target client can input the network address of the target web application to initiate an access request for the target web application.
[0072] A client proxy is middleware located between a target client and a first server, used to handle requests initiated by the target client and communicate with the first server. Client proxies can exist as software, installed and run on electronic devices. These proxy software programs can be implemented in various ways, such as browser plugins, system proxy settings, or standalone applications. In this embodiment, the client proxy is configured to intercept web page access requests (i.e., requests to access relevant web applications) initiated by the target client. In specific implementations, a client proxy can be integrated into a client already installed on the electronic device to intercept these access requests, such as a desktop client responsible for software management on the electronic device.
[0073] In this embodiment, the first server is the server where the SSO authentication center is located, and it is mainly responsible for verifying the user's identity. In specific implementation, the client proxy can intercept access requests initiated by the client and forward the intercepted access requests directly or indirectly to the first server, so that the access requests bypass the target web application and directly reach the SSO authentication center.
[0074] 102. Respond to the access request and determine whether the target web application has enabled a two-factor authentication mechanism.
[0075] In this embodiment, the existing SSO infrastructure is used to implement secondary authentication without requiring significant modifications to web applications or services already connected to SSO. Specifically, secondary authentication can be configured for the relevant web applications in the SSO authentication center's management interface or configuration file. For example, when configuring the relevant web applications to connect to the SSO authentication center, the secondary authentication mechanism can be directly configured; alternatively, it can be configured later during subsequent use.
[0076] In one implementation, two-factor authentication can be unified to ensure that all web applications or services with two-factor authentication enabled receive the same level of protection, simplifying management and maintenance complexity. In another implementation, to balance user experience and security, different security policies can be set for web applications or services with varying levels of sensitivity, enabling two-factor authentication as needed. For web applications or services handling sensitive data or critical business processes, two-factor authentication can be enabled; while for other less sensitive web applications or services, it is not necessary to enable two-factor authentication, thus simplifying the user access process.
[0077] Specifically, after receiving an access request, the first server will respond to the access request, parse the target network address carried in the access request, determine the target web application to be accessed based on the target network address, and then check the configuration of the target web application based on the stored configuration data. Based on the configuration check results, it will determine whether the target web application has enabled a two-factor authentication mechanism.
[0078] 103. If it is determined that a two-factor authentication mechanism is enabled, then when the target user has already passed single sign-on authentication, a two-factor authentication will be performed on the target user.
[0079] Specifically, if it is determined that the target web application has enabled a two-factor authentication mechanism, then if the target user is already logged in (i.e., the target user has already completed the initial login through the SSO authentication center), the SSO authentication is skipped and the target user's identity is verified through two-factor authentication. If no user's login status is detected (i.e., no user has completed the initial login through SSO authentication), then the initial login must be completed before the target user's identity is verified through two-factor authentication. That is, in some implementations, to avoid duplicate authentication, after determining that a two-factor authentication mechanism is enabled, the following process may also be included before performing two-factor authentication on the target user:
[0080] Check whether the target user's identity has been authenticated via single sign-on.
[0081] If so, then directly perform secondary authentication of the target user's identity;
[0082] If not, then perform single sign-on authentication on the target user's identity, and after the target user's identity is successfully authenticated by single sign-on, perform secondary authentication on the target user's identity.
[0083] Specifically, if it is detected that the target user has already completed their initial login through SSO authentication, a secondary authentication process is initiated directly, returning a secondary authentication page to the target client. The target client obtains the secondary verification information (such as facial features, SMS verification code, MOA verification code, etc.) entered by the user through the secondary authentication page and sends it to the SSO authentication center. The SSO authentication center performs secondary verification of the user account's identity based on the received secondary verification information. If the verification is successful, the target user is logged into the system and a basic authentication identifier is generated. Then, the successful login result and the basic authentication identifier are sent to the second server. After verifying the target client's user identity based on the basic authentication identifier, the second server sends the relevant content of the target web application to the target client, enabling the target client to access the target web application. If the verification fails, the login failure result must also be returned to the second server, and a login failure message must be returned to the target client. In practice, the user can re-enter the secondary verification information on the secondary authentication page, and the SSO authentication center will re-authenticate the user's identity.
[0084] If no login status is detected for the target user, an SSO authentication process is initiated, returning an SSO login page to the target client. The target client obtains the user's entered username and authentication information (such as password and verification code) through the SSO login page and sends it to the SSO authentication center. The SSO authentication center performs an initial SSO verification of the user's identity based on the received authentication information. If the initial verification passes, the target user is logged into the system and a basic authentication identifier is generated. Then, a secondary authentication process is initiated, returning a secondary authentication page to the target client. The user's identity is further verified by obtaining the secondary verification information entered by the user. If the secondary verification passes, a valid authentication identifier is generated, and the target user is allowed to log in to the target web application, enabling the target client to access the target web application. If the secondary verification fails, the second server and the target client are notified, and the user can re-enter the secondary verification information on the secondary authentication page for the SSO authentication center to re-authenticate the user's identity.
[0085] Based on the above description, in one embodiment, a basic authentication identifier can be generated for the user after the target user has completed their initial login via SSO authentication. When the target user attempts to access a web application that requires secondary authentication, the system checks the target user's secondary authentication status and generates a valid authentication identifier upon successful secondary authentication. This ensures that for web applications requiring higher security levels, access is only granted after the user has passed secondary authentication.
[0086] In this embodiment, both the basic authentication identifier and the valid authentication identifier are tokens or identifiers used to identify user identity and authorization information, such as authentication tickets, session tickets, and access tokens, which can be used to verify user identity and user authorization. The basic authentication identifier and the valid authentication identifier differ in several aspects, including content, validity period, purpose, and issuance mechanism, as detailed below:
[0087] (11) Content level: Basic authentication identifiers only contain the most basic user identity information, such as username or user ID, while valid authentication identifiers contain more security attributes or authorization information, such as the timeline of secondary authentication or access permissions of specific applications.
[0088] (12) Validity period: Basic authentication marks have a shorter validity period, while valid authentication marks have a longer validity period to ensure that users do not need to repeat secondary authentication within a certain period of time.
[0089] (13) Usage level: Basic authentication tokens only allow users to access some resources or applications that do not require additional security verification, while valid authentication tokens allow users to access resources or applications that require a higher level of security, such as sensitive data or transaction functions.
[0090] (14) Issuance mechanism level: Basic certification mark is issued after passing the first SSO certification, while valid certification mark needs to be issued through secondary certification.
[0091] In general, the basic authentication identifier and the valid authentication identifier after secondary authentication may differ in terms of content, validity period and purpose, in order to meet different requirements of system security and user access needs.
[0092] In one embodiment, to avoid duplicate authentication, the secondary authentication of the target user may include the following process:
[0093] Get the current target user's secondary authentication status;
[0094] If the secondary authentication status is unauthenticated or invalid, then perform secondary authentication on the target user;
[0095] If the secondary authentication status is valid, the access request is forwarded to the second server so that the target client can access the target web application based on the access request.
[0096] Specifically, during secondary authentication of a target user, if the system detects that the target user has already undergone secondary authentication during this login session and the secondary authentication is still valid (i.e., the secondary authentication status is valid), then secondary authentication is not required at this time, and the client can directly access the target web application using the target user's identity. Therefore, it is only necessary to forward the access request to the second server, and the target client can access the target web application based on the access request. If the system detects that the target user has not undergone secondary authentication during this login session, secondary authentication failed, or secondary authentication passed but has expired, then a secondary authentication process needs to be initiated to re-authenticate the target user's identity.
[0097] In this embodiment, Single Sign-On (SSO) authentication means that a user can access multiple related web applications or services after logging in only once, without needing to log in again for each web application or service. The validity period of SSO authentication refers to the time a user can access other web applications or services after their initial login without needing to re-enter their credentials. Typically, the validity period of SSO authentication is longer than the validity period of a session (i.e., the session created for the user by the SSO authentication center after successful login), because it determines the time a user can access protected resources without re-login.
[0098] After a user completes their first SSO login, the system establishes a session for them and uses this session to record their login status and actions. By maintaining this session, the system can effectively manage user authentication status and provide a seamless single sign-on experience. This session can contain the following information:
[0099] (21) User identity information: including the user's unique identifier (such as username, email address, etc.) and other related identity information;
[0100] (22) Authentication status: Records whether the user has passed identity authentication and possible secondary authentication. It can be a Boolean value (authenticated or unauthenticated) or a more complex status to indicate the user's authentication level or status.
[0101] (23) Session identifier: A unique identifier generated when a user logs in to identify the user's session and used to verify the user's identity and status when the user accesses the application;
[0102] (24) Session creation time: Records the session creation time, which is used to determine the session's validity period and expiration time;
[0103] (25) Session Expiration Time: This determines the validity period of the session, i.e., the time during which the session remains active. Once the session expires, the user may need to log in again or re-authenticate.
[0104] (26) Access control information: including user access permissions and authorization information for various resources, to assist the system in managing user access permissions to applications and services.
[0105] The session expiration time is typically determined based on several factors, including security policies (configuring session expiration times according to industry security requirements and policies), risk assessments (e.g., assessing risk based on user behavior and activity levels to adjust session expiration times), user type and permission levels (e.g., administrators may have longer session expiration times, while regular users may have shorter expiration times), application requirements, and user activity status (e.g., extending session expiration times for continuously active users and shortening them for inactive users). By comprehensively considering these factors, the system can dynamically adjust session expiration times to balance security, user experience, and system resource utilization.
[0106] Two-factor authentication (2SA) validity period refers to the time a user can continue to access protected resources after their initial login, provided they are required to re-authenticate their identity. In practice, 2SA requires re-authentication within a short period, typically shorter than the validity period of single sign-on authentication and sessions. The system can determine the validity period for each authentication type based on security policies and business needs, and configure the web application accordingly.
[0107] In practice, the SSO authentication center can use a session management mechanism to determine a user's authentication status and whether the secondary authentication is still valid. Specifically, the system establishes a session for each user and starts the session after the user successfully logs in. The session typically contains information about the user's identity and authentication status, as well as the session's creation and expiration times. Additionally, the system records the time the user performs secondary authentication and determines the authentication validity period based on the system's configured secondary authentication validity duration. Once the user successfully completes secondary authentication, the system updates the session's authentication status and records the secondary authentication time and validity period.
[0108] In practical applications, after successfully accessing and authenticating a sensitive application that has enabled two-factor authentication, the system will allow subsequent access to other sensitive applications that also enable two-factor authentication without requiring re-authentication, provided the user's session is still valid and the two-factor authentication is within its validity period. However, if the user's session has expired or the two-factor authentication has exceeded its system-configured validity period, the system will require the user to re-authenticate to ensure security and the effectiveness of authentication.
[0109] In some implementations, to further ensure the information security of all web applications, the following process may be included after the secondary authentication status is determined to be valid and before forwarding the access request to the second server:
[0110] Determine the application level of the target webpage;
[0111] Obtain the preset validity period of the secondary authentication corresponding to the application level;
[0112] Get the current validity period corresponding to the second authentication status;
[0113] When the current valid duration is longer than the preset valid duration, the current valid duration is updated based on the preset valid duration.
[0114] Application levels can be categorized into multiple levels, such as high, medium, and low, or level one, level two, and level three, etc. Application levels can be determined based on business importance, application type, target user group, etc., and can be configured and categorized according to actual needs. In practice, application levels for web applications can be pre-configured, and when the application level needs to be determined, the application level of the target web application can be obtained based on the configuration data; alternatively, the application level of the target web application can be determined in real time based on a pre-set application level determination logic. Then, the preset validity period of the secondary authentication corresponding to the application level of the target web application is obtained, and the current validity period corresponding to the secondary authentication status (i.e., the remaining validity period corresponding to the valid secondary authentication status) is obtained, and the two are compared. If the current valid duration is longer than the preset valid duration, it means that the target web application's secondary authentication validity period is shorter, the application is more sensitive, and secondary authentication is required more frequently under the same conditions. Therefore, the system's secondary authentication validity period is updated to the preset valid duration. If the current valid duration is less than or equal to the preset valid duration, it means that the target web application's secondary authentication validity period is longer, and the frequency of secondary authentication required is relatively lower under the same conditions. Therefore, there is no need to update the system's current secondary authentication validity period.
[0115] 104. Based on the two-factor authentication result, send the login result corresponding to the target user to the second server so that the target client can access the target web application based on the login result. The second server is the application server running the target web application.
[0116] Specifically, after performing secondary authentication on the target user and obtaining the authentication result (i.e., authentication passed or failed), a corresponding login result is sent to the second server based on the obtained secondary authentication result, enabling the target client to access the target web application based on the login result. The second server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, network acceleration services, and big data and artificial intelligence platforms.
[0117] In practical implementation, to unify two-factor authentication, a unified authentication identifier can be generated immediately after the target user's initial SSO authentication. When the target user attempts to access other web applications requiring two-factor authentication, the system verifies the target user's identity again and requires two-factor authentication. Only after successful two-factor authentication is the generated unified authentication identifier issued to the web application. At this point, the generation of the unified authentication identifier is unrelated to the status of the two-factor authentication, but rather to the user's initial SSO authentication status. That is, in one implementation, when sending the login result corresponding to the target user to the second server based on the two-factor authentication result, if the two-factor authentication result is successful, the target user is determined to have successfully logged in, and the corresponding unified authentication identifier is generated. The unified authentication identifier and the successful login result are then sent to the second server. If the two-factor authentication result is unsuccessful, the target user is determined to have failed to log in, and the failed login result is sent to the second server.
[0118] The unified authentication identifier is a token or identifier used to identify user identity and authorization information, such as authentication tickets, session tickets, access tokens, etc., which can all be used to verify user identity and user authorization.
[0119] In practical applications, to facilitate access to web applications or services within the SSO system for internal members and reduce the frequency of user authentication, a longer validity period can be configured for secondary authentication of internal member users in a relatively secure environment. That is, in one implementation, after confirming the secondary authentication result is successful and before sending the unified authentication identifier and the login result of the target user to the second server, the following process may also be included:
[0120] Obtain the device code of the target client's device;
[0121] Obtain the network IP address corresponding to the target client;
[0122] The validity period of the secondary authentication result is determined based on the network IP address and device code.
[0123] Specifically, the system obtains the device code (such as MAC address, IMEI number, etc.) of the user's current device and the network IP address it is using. The device code and network IP address can, to some extent, indicate whether the user is attempting to log in to a target web application using a secure device within a specified area. The validity period of the two-factor authentication result is then determined based on the results. For example, if an employee is using a company-assigned computer in the company's office area and attempting to access an application already connected to the SSO authentication center, the validity period of the two-factor authentication result can be set to a larger value, such as 24 hours or 48 hours. Conversely, if a user is not in the designated office area and is using a personal computer to access an application already connected to the SSO authentication center, the validity period of the two-factor authentication result can be set to a more conventional value, such as 6 hours or 12 hours.
[0124] Additionally, the validity period of the secondary authentication result can be determined based on the level of the application being accessed, to ensure its information security. That is, in one embodiment, after determining that the secondary authentication result is successful, but before sending the unified authentication identifier and the login result indicating successful login of the target user to the second server, the following process may also be included:
[0125] Determine the application level of the target webpage;
[0126] The validity period of the secondary authentication result is determined based on the application level.
[0127] Specifically, application levels can be pre-configured based on the application's importance and sensitivity, and the configured data can be saved. When it's necessary to determine the application level of a target web application, its application level can be directly obtained, and the validity period of the two-factor authentication result can be set to match that application level. It should be noted that all web applications with the same application level have the same configured validity period for the two-factor authentication result.
[0128] In practical applications, to address situations where secondary authentication fails due to user error, users are allowed to repeatedly enter verification information for secondary authentication. However, endless input of verification information by users may pose security risks; therefore, certain restrictions on the operation information are necessary. Specifically, in one embodiment, after determining that the secondary authentication result has failed but before determining that the target user's login has failed, the following process may also be included:
[0129] The first number of secondary authentication failures is obtained.
[0130] For each instance where the secondary authentication fails, obtain the information type of the identity authentication information verified when performing secondary authentication on the target user;
[0131] The second quantity of information types to be acquired;
[0132] Determine whether the first quantity and the second quantity meet the preset conditions;
[0133] If so, then the target account will undergo secondary authentication again;
[0134] If not, then the target user's login was determined to have failed.
[0135] Specifically, conditions are imposed on the number of authentication failures and the type of identity verification information (reflecting different authentication methods, such as numeric information for dynamic verification codes, image information for facial recognition, and string information for MAC address verification). If the number of authentication failures (the first count) is too high, and multiple authentication methods have been tried (the second count), it indicates the user may be insecure. In this case, login is deemed failed, and the user is banned from logging in for a certain period. If the number of authentication failures and the number of verified identity verification information types meet preset conditions, the target account can be re-authenticated. These preset conditions limit the values of the first and second counts, and can be set according to actual needs.
[0136] As can be seen from the above, the web application access method based on the single sign-on mechanism provided in this application intercepts and forwards the access request initiated by the target client to the first server through a client proxy. Then, the first server responds to the access request and determines whether the target web application has enabled a two-factor authentication mechanism. If the two-factor authentication mechanism is enabled, then if the target user has already passed single sign-on authentication, the target user is subjected to two-factor authentication. Based on the two-factor authentication result, the login result corresponding to the target user is sent to the second server, so that the target client can access the target web application based on the login result. In this solution, the access request initiated by the target client can be intercepted and forwarded to the first server to initiate the two-factor authentication process, instead of being redirected to the first server. This ensures that regardless of how the web application is connected to the first server, two-factor authentication can be initiated as expected, solving the security risks existing in single sign-on technology and improving information security.
[0137] In practical implementation, to avoid overloading the client proxy with too much business logic, a gateway can be introduced to handle more processing. That is, in one embodiment, the aforementioned access requests to the target web application can be intercepted by the client proxy and forwarded to the target gateway, and then forwarded to the first server through the target gateway.
[0138] In practical applications, to simplify the deployment process and reduce the additional development and integration costs of web applications, when secondary authentication is not required, the SSO login request will follow the original method of how the application connects to the SSO authentication center. Since the existing method directly connects to the SSO authentication center rather than through a gateway proxy, in one implementation, if it is determined that the target web application has not enabled a secondary authentication mechanism, the obtained access request can be forwarded through the target gateway to a second server (i.e., the application server hosting and running the target web application), allowing the target client to access the target web application based on this access request.
[0139] Specifically, after receiving the access request, the second server checks whether the current user is logged into the target web application. If not, the second server requests the user to log in from the SSO authentication center to trigger the SSO authentication process. The SSO authentication center returns an SSO login page to the target client based on the second server's login request. The target client obtains the user's entered username and authentication information (such as password and verification code) through the SSO login page and sends it to the SSO authentication center. The SSO authentication center verifies the user's identity based on the received authentication information. If the verification is successful, the user is allowed to log in to the target web application, a unified authentication identifier is generated, and the successful login result and unified authentication identifier are sent to the second server. After verifying the target client's user identity based on the unified authentication identifier, the second server sends the relevant content of the target web application to the target client, enabling the target client to access the target web application. If the verification fails, the login failure result is returned to the second server, and a login failure message is returned to the target client. In practice, the user can re-enter their username and authentication information on the SSO login page, and the SSO authentication center will re-authenticate the user's identity.
[0140] Based on the method described in the above embodiments, the following will provide further detailed examples. In another embodiment of this application, an application access system based on a single sign-on mechanism is provided. This application access system includes: a browser, a client proxy, a gateway, an SSO authentication center, and a web application. The browser and client proxy are installed and run on the same electronic device. Specifically, as follows:
[0141] A browser is used to provide an interactive interface for users, access web applications through the browser, and receive redirection requests and responses from web applications and SSO authentication centers;
[0142] A client-side proxy is used to intercept web application access requests initiated by the browser, act as a proxy for the browser to interact with the SSO authentication center, and receive and process redirection requests and responses in the authentication process.
[0143] A gateway is used to redirect user requests to an SSO authentication center, ensuring that all user traffic is authenticated.
[0144] SSO (Site Authentication Center) is a centralized service for authentication and authorization. It is responsible for managing user identity information, issuing tokens, enforcing authentication policies, and controlling user access to protected resources.
[0145] Web applications used to authenticate users and control access to protected resources, interact with SSO certification authorities, receive and verify authentication information, and associate user identities with application sessions.
[0146] In this embodiment, it is necessary to pre-connect the relevant web applications or services to the SSO authentication center and configure the connection mode for each web application or service. Specifically, the access mode of the web applications or services can be configured through the management interface provided by the platform where the SSO authentication center is located. First, the application must enable SSO authentication. Based on enabling SSO authentication, a method for connecting to the SSO authentication center is selected. After determining the SSO connection method, secondary authentication can be enabled. For example, refer to... Figure 3 The management page provided by the SSO authentication center allows you to configure employee login methods, employee information retrieval methods, employee information encryption methods, and whether to enable unified login two-factor authentication. Specifically, the employee login method should be selected as unified login (SSO authentication is enabled here); the employee information retrieval method can be selected via request headers or via API; the employee information encryption method can be selected as secure mode, compatibility mode (this mode cannot use quick login and SSO), or plaintext mode (this mode cannot use quick login and SSO); unified login two-factor authentication can be enabled or disabled via a toggle button. Enabling two-factor authentication is effective immediately and requires no additional integration.
[0147] In one implementation, the technical implementation of a web application connecting to an SSO authentication center is as follows:
[0148] (31) Configure SSO Authentication Center
[0149] Configure relevant information about the web application in the SSO authentication center's management interface or configuration file, including the application identifier (client ID), key (client secret), redirect URL, etc. This information will be used to verify and authorize the application during the authentication process.
[0150] (32) Integrate the SSO authentication center client library
[0151] Web applications need to integrate client libraries or SDKs provided by SSO (Site Authentication and Solicitation) authorities to communicate with them. These client libraries typically provide simplified interfaces for handling user authentication requests, generating and verifying tokens, and other operations.
[0152] In this embodiment, if a user accesses a web application with two-factor authentication enabled and is not currently logged in, they need to log in for the first time before performing two-factor authentication. If the user has already completed the first login, for web applications with two-factor authentication enabled, access is only allowed after two-factor authentication; for web applications without two-factor authentication enabled, access is direct. For details, refer to... Figure 4 , Figure 4 This is a schematic diagram of the interaction flow of an application access system based on a single sign-on mechanism, provided in an embodiment of this application. The following will be based on... Figure 4 The application access system based on the single sign-on mechanism provided in this application embodiment is described in detail below:
[0153] First, the user enters the URL of the web application in the browser's address bar to trigger an application access request. Then, the local client proxy detects the access request initiated by the browser, intercepts it, and forwards the intercepted access request to the gateway. Next, the gateway forwards the received access request to the SSO authentication center. After receiving the access request, the SSO authentication center determines whether secondary authentication is required to access the web application.
[0154] If the SSO authentication center determines that secondary authentication is required, it will further determine whether the current user has already logged into their SSO authentication center account for the first time. If not, the SSO authentication center will return the SSO login page to the browser. The browser will then display the SSO login page to the user, who will enter their login information (such as username and password) and send it to the SSO authentication center for identity verification. The SSO authentication center will verify the user's identity based on the received login information and obtain the login result. If the user logs in successfully, the SSO authentication center will return the secondary authentication page to the browser. The browser will then display the secondary authentication page to the user, who will enter secondary verification information (SMS verification code, MOA verification code, etc.) and send it to the SSO authentication center for identity verification. The SSO authentication center will perform secondary authentication based on the received secondary verification information and obtain the secondary authentication result. If the two-factor authentication succeeds, the SSO authentication center sends a login result to the web application, notifying the web application that the current user has successfully logged in and providing the user's relevant information, so that the web application trusts the SSO authentication center and directly allows the user to access the application. If the two-factor authentication fails, the SSO authentication center will also send a login result to the web application, notifying the web application that the current user's login has failed, so that the web application denies the user's access.
[0155] If the SSO authentication center determines that secondary authentication is not required, it forwards the access request to the gateway. Upon receiving the request, the gateway forwards it to the web application. The web application responds to the access request, requesting login from the SSO authentication center to initiate the SSO authentication process. The SSO authentication center responds to the web application's request, returning an SSO login page to the browser. The browser displays the SSO login page to the user, who enters their login information (such as username and password) and sends it to the SSO authentication center for identity verification. The SSO authentication center verifies the user's identity based on the received login information and obtains the login result. If the user logs in successfully, the SSO authentication center sends the login result to the web application, notifying it of the successful login and providing relevant user information to gain the web application's trust in the SSO authentication center and allow the user to access the application. If the user fails to log in, the SSO authentication center also sends the login result to the web application, notifying it of the failed login and preventing the web application from accessing the user.
[0156] It should be noted that, in order to prevent the second authentication request from being missed, this embodiment must set up a client proxy to intercept the application access request initiated by the browser and forward it to the SSO authentication center by the gateway.
[0157] In addition, since the user's first login is required before initiating secondary authentication, if the user has not logged in for the first time, the first login should be completed before secondary authentication is initiated; if the user has already logged in for the first time, the first login page can be skipped and secondary authentication can be initiated directly.
[0158] refer to Figure 5 When performing an initial SSO login, if an existing user account is detected (i.e., the user is logged in to other related applications), the user can directly click the "Quick Login" button to obtain account information for the initial SSO login. The user will then be redirected to the secondary authentication page, where they can choose one of the provided methods (such as SMS verification) to perform secondary authentication of their identity.
[0159] refer to Figure 6 When performing an SSO login for the first time, if no user login account is detected, a login page with account and password will be displayed so that users can log in to SSO for the first time using their account and password, or by scanning an identification code (such as a QR code).
[0160] The application access system based on a single sign-on (SSO) mechanism provided in this application addresses the lack of secondary authentication in SSO systems, effectively preventing unauthorized access and potential security threats. Simultaneously, through intelligent interaction between the client proxy and the gateway, it ensures that secondary authentication requests are not missed, further enhancing system security. Furthermore, while retaining the SSO experience, this solution allows for selective activation of secondary authentication for certain applications based on actual needs and the sensitivity of different applications. It also allows users to perform secondary authentication only in applications requiring it after their initial login, avoiding the tedious process of repeated authentication every time they access a new application, thus achieving a balance between user experience and system security.
[0161] Furthermore, since the two-factor authentication mechanism is implemented based on the existing SSO infrastructure, it requires no major modifications to applications already integrated with SSO, simplifying system management and maintenance. Simultaneously, the two-factor authentication mechanism in this solution can be directly applied to other third-party applications already integrated with SSO, demonstrating strong scalability without additional development or integration work, simplifying the deployment process and reducing development and management costs. Moreover, this solution can run stably on different devices and operating systems, providing users with consistent security protection.
[0162] To better implement the above methods, this application also provides a web application access device based on a single sign-on mechanism. This web application access device based on a single sign-on mechanism can be integrated into an electronic device, which can specifically be a first server, that is, the server where the SSO authentication center is located.
[0163] For example, such asFigure 7 As shown, the web application access device based on the single sign-on mechanism may include: a request acquisition unit 301, a mechanism determination unit 302, an authentication unit 303, and a sending unit 304, as follows:
[0164] The request acquisition unit 301 is used to acquire the access request for the target web application initiated by the target client, wherein the access request is intercepted by the client proxy and forwarded to the first server;
[0165] Mechanism determination unit 302 is used to respond to the access request and determine whether the target web page application has enabled a two-factor authentication mechanism;
[0166] The authentication unit 303 is used to perform secondary authentication on the target user if it is determined that the two-factor authentication mechanism is enabled, when the target user has already been authenticated by single sign-on.
[0167] The sending unit 304 is used to send the login result corresponding to the target user to the second server based on the secondary authentication result, so that the target client can access the target web application based on the login result, wherein the second server is the application server running the target web application.
[0168] Optionally, in some embodiments, the device further includes:
[0169] The detection unit is used to detect whether the target user's identity has been authenticated by single sign-on before performing secondary identity authentication on the target user after determining that the two-factor authentication mechanism has been enabled.
[0170] The authentication unit 303 is used to directly perform secondary authentication of the target user's identity if it is detected that the target user's identity has been authenticated by single sign-on.
[0171] The authentication unit 303 is further configured to perform single sign-on authentication on the target user if it detects that the target user's identity has not passed single sign-on authentication, and to perform secondary authentication on the target user's identity after the target user's identity has passed single sign-on authentication.
[0172] Optionally, in some embodiments, the transmitting unit 304 is used for:
[0173] If the secondary authentication result is successful, it is determined that the target user has successfully logged in and a corresponding unified authentication identifier is generated. The unified authentication identifier and the login result of the target user successfully logging in are sent to the second server.
[0174] If the secondary authentication result is unsuccessful, it is determined that the target user has failed to log in, and the login result indicating that the target user has failed to log in is sent to the second server.
[0175] Optionally, in some embodiments, the device further includes:
[0176] The device code acquisition unit is used to acquire the device code of the device where the target client is located before sending the unified authentication identifier and the login result of the target user to the second server after determining that the secondary authentication result is passed;
[0177] The URL acquisition unit is used to obtain the network IP address corresponding to the target client.
[0178] The first duration determination unit is used to determine the validity duration of the secondary authentication result based on the network IP address and the device code.
[0179] Optionally, in some embodiments, the device further includes:
[0180] The level determination unit is used to determine the application level of the target web application after determining that the secondary authentication result is passed and before sending the unified authentication identifier and the login result of the target user's successful login to the second server.
[0181] The second duration determination unit is used to determine the validity duration of the secondary authentication result based on the application level.
[0182] Optionally, in some embodiments, the device further includes:
[0183] The first quantity acquisition unit is used to acquire the first quantity of the second authentication result that failed after determining that the second authentication result is unsuccessful and before determining that the target user's login has failed.
[0184] The information acquisition unit is used to acquire the information type of the identity authentication information verified when performing secondary authentication on the target user, for each case where the secondary authentication result is unsuccessful.
[0185] The second quantity acquisition unit is used to acquire the second quantity of this information type;
[0186] The judgment unit is used to determine whether the first quantity and the second quantity meet the preset conditions;
[0187] The authentication unit 303 is used to perform secondary authentication on the target account if it is determined that the preset conditions are met.
[0188] The sending unit 304 is also used to determine that the target user's login has failed if the preset conditions are not met.
[0189] Optionally, in some embodiments, when performing secondary authentication on the target user, the authentication unit 303 is specifically used for:
[0190] Get the current secondary authentication status of the target user;
[0191] If the secondary authentication status is unauthenticated or invalid, then secondary authentication will be performed on the target user.
[0192] If the secondary authentication status is valid, the access request is forwarded to the second server, enabling the target client to access the target web application based on the access request.
[0193] Optionally, in some embodiments, the device further includes:
[0194] The level determination unit is used to determine the application level of the target web page application after determining that the secondary authentication status is valid and before forwarding the access request to the second server.
[0195] The third duration acquisition unit is used to acquire the preset valid duration of the secondary authentication corresponding to the application level;
[0196] The fourth duration acquisition unit is used to acquire the current valid duration corresponding to the secondary authentication status;
[0197] The update unit is used to update the current valid duration based on the preset valid duration when the current valid duration is longer than the preset valid duration.
[0198] Optionally, in some embodiments, the access request is intercepted by the client proxy and forwarded to the target gateway, and then forwarded to the first server through the target gateway; the apparatus further includes:
[0199] The forwarding unit is used to forward the obtained access request to the second server through the target gateway if it is determined that the two-factor authentication mechanism is not enabled, so that the target client can access the target web application based on the access request.
[0200] As can be seen from the above, the web application access device based on the single sign-on mechanism provided in this application intercepts and forwards access requests initiated by the target client to the first server through a client proxy. The first server then responds to the access request and determines whether the target web application has enabled a two-factor authentication mechanism. If the two-factor authentication mechanism is enabled, then if the target user has already passed single sign-on authentication, two-factor authentication is performed on the target user. Based on the two-factor authentication result, the login result corresponding to the target user is sent to the second server, enabling the target client to access the target web application based on the login result. This solution intercepts access requests initiated by the target client and forwards them to the first server to initiate the two-factor authentication process, rather than redirecting to the first server. This ensures that regardless of how the web application connects to the first server, two-factor authentication can be initiated as expected, solving the security vulnerabilities existing in single sign-on technology and improving information security.
[0201] This application also provides an electronic device, such as... Figure 8 As shown, it illustrates a structural schematic diagram of the electronic device involved in the embodiments of this application, specifically:
[0202] The electronic device may include components such as a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, and an input unit 404. Those skilled in the art will understand that... Figure 8 The electronic device structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements. Wherein:
[0203] The processor 401 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines, and performs various functions and processes data by running or executing software programs and / or modules stored in the memory 402, and by calling data stored in the memory 402. Optionally, the processor 401 may include one or more processing cores; preferably, the processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and computer programs, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 401.
[0204] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and accesses web applications based on a single sign-on mechanism by running the software programs and modules stored in the memory 402. The memory 402 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, computer programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 402 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 402 may also include a memory controller to provide the processor 401 with access to the memory 402.
[0205] The electronic device also includes a power supply 403 that supplies power to the various components. Preferably, the power supply 403 can be logically connected to the processor 401 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 403 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0206] The electronic device may also include an input unit 404, which can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.
[0207] Although not shown, the electronic device may also include a display unit, etc., which will not be described in detail here. It should be noted that the electronic device in this embodiment can specifically be the first server, that is, the server where the SSO certification center is located. Specifically, in this embodiment, the processor 401 in the electronic device loads the executable files corresponding to the processes of one or more computer programs into the memory 402 according to the following instructions, and the processor 401 runs the computer programs stored in the memory 402 to achieve various functions, as follows:
[0208] Obtain access requests for the target web application initiated by the target client, wherein the access requests are intercepted by the client proxy and forwarded to the electronic device;
[0209] In response to the access request, determine whether the target web application has enabled a two-factor authentication mechanism;
[0210] If it is determined that a two-factor authentication mechanism is enabled, then when the target user has already passed single sign-on authentication, a two-factor authentication will be performed on the target user.
[0211] Based on the two-factor authentication result, the login result corresponding to the target user is sent to the second server so that the target client can access the target web application based on the login result. The second server is the application server running the target web application.
[0212] In one embodiment, after determining that the two-factor authentication mechanism is enabled, before performing two-factor authentication on the target user, the processor 401 is further configured to: detect whether the target user's identity has been authenticated by single sign-on; if so, directly perform two-factor authentication on the target user's identity; if not, perform single sign-on authentication on the target user's identity, and perform two-factor authentication on the target user's identity after the target user's identity has been authenticated by single sign-on.
[0213] In one embodiment, when sending the login result corresponding to the target user to the second server based on the secondary authentication result, the processor 401 is specifically configured to: if the secondary authentication result is successful, determine that the target user has successfully logged in and generate a corresponding unified authentication identifier, and send the unified authentication identifier and the login result of the target user successfully logging in to the second server; if the secondary authentication result is unsuccessful, determine that the target user has failed to log in, and send the login result of the target user failing to log in to the second server.
[0214] In one embodiment, after determining that the secondary authentication result is successful, before sending the unified authentication identifier and the login result of the target user successfully logging in to the second server, the processor 401 is further configured to: obtain the device code of the device where the target client is located; obtain the network IP address corresponding to the target client; and determine the validity period of the secondary authentication result based on the network IP address and the device code.
[0215] In one embodiment, after determining that the secondary authentication result is successful, before sending the unified authentication identifier and the login result of the target user successfully logging in to the second server, the processor 401 is further configured to: determine the application level of the target web application; and determine the validity period of the secondary authentication result based on the application level.
[0216] In one embodiment, after determining that the secondary authentication result is unsuccessful and before determining that the target user's login has failed, the processor 401 is specifically configured to: obtain a first number of times the secondary authentication result is unsuccessful; for each instance of unsuccessful secondary authentication, obtain the information type of the identity authentication information verified when performing secondary authentication on the target user; obtain a second number of the information type; determine whether the first number and the second number meet a preset condition; if yes, then perform secondary authentication on the target account again; if no, then determine that the target user's login has failed.
[0217] In one embodiment, when performing secondary authentication on the target user, the processor 401 is specifically configured to: obtain the current secondary authentication status of the target user; if the secondary authentication status is unauthenticated or invalid, perform secondary authentication on the target user; if the secondary authentication status is valid, forward the access request to the second server so that the target client can access the target web application based on the access request.
[0218] In one embodiment, after determining that the secondary authentication status is valid, and before forwarding the access request to the second server, the processor 401 is specifically configured to: determine the application level of the target web application; obtain the preset validity period of the secondary authentication corresponding to the application level; obtain the current validity period corresponding to the secondary authentication status; and update the current validity period based on the preset validity period when the current validity period is longer than the preset validity period.
[0219] In one embodiment, the access request is intercepted by the client proxy and forwarded to the target gateway, and then forwarded to the electronic device through the target gateway; the processor 401 is specifically configured to: if the two-factor authentication mechanism is not enabled, forward the obtained access request to the second server through the target gateway, so that the target client can access the target web application based on the access request.
[0220] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0221] As described above, in this embodiment, the electronic device obtains the access request intercepted and forwarded by the client proxy, and determines whether the target web application has enabled a two-factor authentication mechanism. If the two-factor authentication mechanism is enabled, then when the target user has already passed single sign-on authentication, the target user is subjected to two-factor authentication. Based on the two-factor authentication result, the login result corresponding to the target user is sent to the second server, so that the target client can access the target web application based on the login result. This solution can intercept the access request initiated by the target client and forward it to the first server to initiate the two-factor authentication process, rather than redirecting it to the first server. This ensures that regardless of how the web application is connected to the first server, two-factor authentication can be initiated as expected, solving the security risks existing in single sign-on technology and improving information security.
[0222] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0223] Therefore, embodiments of this application provide a computer-readable storage medium storing a plurality of instructions that can be loaded by a processor to execute steps in any of the web application access methods based on a single sign-on mechanism provided in embodiments of this application. For example, the instructions can execute the following steps:
[0224] The system retrieves access requests for a target web application initiated by the target client, wherein the access request is intercepted by the client proxy and forwarded to the first server; responds to the access request and determines whether the target web application has enabled a two-factor authentication mechanism; if it is determined that the two-factor authentication mechanism is enabled, then performs two-factor authentication on the target user if the target user has already passed single sign-on authentication; based on the two-factor authentication result, it sends the login result corresponding to the target user to a second server, so that the target client can access the target web application based on the login result, wherein the second server is the application server running the target web application.
[0225] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0226] The computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0227] Since the instructions stored in the computer-readable storage medium can execute the steps in any of the web application access methods based on the single sign-on mechanism provided in the embodiments of this application, the beneficial effects that any of the web application access methods based on the single sign-on mechanism provided in the embodiments of this application can achieve can be realized, as detailed in the preceding embodiments, and will not be repeated here.
[0228] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various alternative implementations of web application access based on a single sign-on mechanism described above.
[0229] The foregoing has provided a detailed description of a web application access method, apparatus, electronic device, computer-readable storage medium, and computer program product based on a single sign-on mechanism, as provided in the embodiments of this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A web application access method based on a single sign-on mechanism, applied to a first server, characterized in that, include: Obtain access requests for a target web application initiated by the target client, wherein the access requests are intercepted by the client proxy and forwarded to the first server; In response to the access request, determine whether the target web application has enabled a two-factor authentication mechanism; If it is determined that a two-factor authentication mechanism is enabled, then when the target user has already passed single sign-on authentication, a two-factor authentication will be performed on the target user. Based on the two-factor authentication result, the login result corresponding to the target user is sent to the second server so that the target client can access the target web application based on the login result. The second server is the application server running the target web application.
2. The web application access method based on single sign-on mechanism according to claim 1, characterized in that, After confirming that the two-factor authentication mechanism is enabled, but before performing two-factor authentication on the target user, the process also includes: Check whether the target user's identity has been authenticated via single sign-on. If so, then directly perform secondary authentication of the target user's identity; If not, then single sign-on authentication is performed on the target user's identity, and after the target user's identity is successfully authenticated by single sign-on, secondary authentication is performed on the target user's identity.
3. The web application access method based on single sign-on mechanism according to claim 1, characterized in that, The step of sending the login result corresponding to the target user to the second server based on the secondary authentication result includes: If the secondary authentication result is successful, then the target user is determined to have successfully logged in and a corresponding unified authentication identifier is generated. The unified authentication identifier and the login result of the target user successfully logging in are sent to the second server. If the secondary authentication result is unsuccessful, it is determined that the target user's login has failed, and the login result indicating the target user's login failure is sent to the second server.
4. The web application access method based on single sign-on mechanism according to claim 3, characterized in that, After confirming that the secondary authentication result is successful, and before sending the unified authentication identifier and the login result of the target user's successful login to the second server, the method further includes: Obtain the device code of the device where the target client is located; Obtain the network IP address corresponding to the target client; The validity period of the secondary authentication result is determined based on the network IP address and the device code.
5. The web application access method based on single sign-on mechanism according to claim 3, characterized in that, After confirming that the secondary authentication result is successful, and before sending the unified authentication identifier and the login result of the target user's successful login to the second server, the method further includes: Determine the application level of the target webpage application; The validity period of the secondary authentication result is determined based on the application level.
6. The web application access method based on single sign-on mechanism according to claim 3, characterized in that, After determining that the secondary authentication result is unsuccessful but before determining that the target user's login has failed, the process also includes: The number of failed secondary authentication results is obtained. For each instance where the secondary authentication fails, the information type of the identity authentication information verified when performing secondary authentication on the target user is obtained; Obtain a second quantity of the information type; Determine whether the first quantity and the second quantity meet the preset conditions; If so, then the target account will be re-authenticated. If not, then the target user's login is determined to have failed.
7. The web application access method based on single sign-on mechanism according to claim 1, characterized in that, The secondary authentication of the target user includes: Obtain the current secondary authentication status of the target user; If the secondary authentication status is unauthenticated or invalid, then secondary authentication is performed on the target user; If the secondary authentication status is valid, the access request is forwarded to the second server so that the target client can access the target web application based on the access request.
8. The web application access method based on single sign-on mechanism according to claim 7, characterized in that, After determining that the secondary authentication status is valid, but before forwarding the access request to the second server, the process further includes: Determine the application level of the target webpage application; Obtain the preset validity period of the secondary authentication corresponding to the application level; Obtain the current validity period corresponding to the secondary authentication status; When the current valid duration is greater than the preset valid duration, the current valid duration is updated based on the preset valid duration.
9. The web application access method based on a single sign-on mechanism according to any one of claims 1-8, characterized in that, The access request is intercepted and forwarded by the client proxy to the target gateway, and then forwarded to the first server through the target gateway; the method further includes: If the two-factor authentication mechanism is not enabled, the obtained access request will be forwarded to the second server through the target gateway, so that the target client can access the target web application based on the access request.
10. A web application access device based on a single sign-on mechanism, applied to a first server, characterized in that, include: The request acquisition unit is used to acquire access requests for a target web application initiated by a target client, wherein the access requests are intercepted by a client proxy and forwarded to the first server; The mechanism determination unit is used to respond to the access request and determine whether the target web page application has enabled a two-factor authentication mechanism; An authentication unit is used to perform secondary authentication on the target user if it is determined that a two-factor authentication mechanism is enabled, when the target user has already been authenticated through single sign-on. The sending unit is used to send the login result corresponding to the target user to the second server based on the secondary authentication result, so that the target client can access the target web application based on the login result, wherein the second server is an application server running the target web application.
11. The web application access device based on a single sign-on mechanism according to claim 10, characterized in that, Also includes: The detection unit is used to detect whether the target user's identity has been authenticated by single sign-on before performing secondary identity authentication on the target user after determining that the secondary authentication mechanism has been enabled. The authentication unit is configured to directly perform secondary authentication of the target user's identity if it is detected that the target user's identity has already been authenticated through single sign-on. The authentication unit is further configured to perform single sign-on authentication on the target user's identity if it is detected that the target user's identity has not passed single sign-on authentication, and to perform secondary authentication on the target user's identity after the target user's identity has passed single sign-on authentication.
12. The web application access device based on a single sign-on mechanism according to claim 10, characterized in that, The sending unit is used for: If the secondary authentication result is successful, then the target user is determined to have successfully logged in and a corresponding unified authentication identifier is generated. The unified authentication identifier and the login result of the target user successfully logging in are sent to the second server. If the secondary authentication result is unsuccessful, it is determined that the target user's login has failed, and the login result indicating the target user's login failure is sent to the second server.
13. An electronic device, characterized in that, It includes a processor and a memory, the memory storing a computer program, and the processor running the computer program in the memory to perform the steps in the web application access method based on a single sign-on mechanism as described in any one of claims 1-9.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions adapted for loading by a processor to execute the steps of the web application access method based on a single sign-on mechanism as described in any one of claims 1-9.
15. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the steps in the web application access method based on the single sign-on mechanism as described in any one of claims 1-9.