Key distribution method, device, equipment, medium and product
By establishing user information associations between applications and using one-time keys, the cumbersome key management problem in cross-application single sign-on is solved, and the key distribution efficiency is improved.
Patent Information
- Application Number
- CN202511567100.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies require the management and maintenance of multiple keys for cross-application single sign-on, resulting in inefficient key distribution and failure to distribute keys in a timely manner.
The first application initiates an authorization request to the first business platform, establishes a user information association with the second application, and applies for a one-time key to fill the business key used to execute the second application, thus avoiding frequent single sign authentication.
It improves the efficiency of key distribution, reduces key management and maintenance during cross-application single sign-on authentication, and achieves more efficient key distribution.
Smart Images

Figure CN121508807A_ABST
Abstract
Description
Technical Field
[0001] This disclosure belongs to the field of information security technology, specifically relating to a key distribution method, apparatus, device, medium, and product. Background Technology
[0002] When a user logs into software, the server typically needs to verify the user's identity. Once verification is successful, the server generates a key and returns it to the client. The client must then include this key in every subsequent request so the server can confirm the user's identity. This key usually includes a signature to ensure the security of user authentication.
[0003] Typically, users can only access a single application. However, when performing cross-application single sign-on (SSO), a temporary key needs to be obtained from the certification authority, and this temporary key is then used to authenticate other applications. This key distribution method requires managing and maintaining a large number of keys for cross-application SSO, making timely key distribution difficult. Therefore, it reduces the efficiency of key distribution. Summary of the Invention
[0004] This disclosure addresses some of the shortcomings mentioned in the background art by providing a key distribution method, apparatus, device, medium, and product that can improve the efficiency of key distribution.
[0005] In a first aspect, embodiments of this disclosure provide a key distribution method applied to a first application, the method comprising: Send a key authorization request for the second application's single sign-on authentication to the first business platform; When an authorization pass is received from the first service platform, the first key of the first application is obtained based on the SIM card. The first key is used to associate user information between the first service platform and the second service platform. Send the first key to the second application.
[0006] Optionally, the method further includes: Send an authentication request to the first business platform; Receive access signaling from the first service platform, wherein the access signaling is at least used to indicate that authentication has been successful; The access signaling is sent to the SIM card, and the access signaling is used to request the SIM card to be loaded with the first key.
[0007] In a second aspect, embodiments of this disclosure provide a key distribution method applied to a second application, the method comprising: Receive a first key from a first application, the first key being used to associate user information between a first business platform and a second business platform; Based on the first key, a single sign-on authentication request is initiated to the second business platform; the second business platform is used to obtain user information from the first business platform and perform authentication based on the first key; When the single sign-on authentication is successful, an access signaling message for the second application is sent to the SIM card. The access signaling message is used to request the SIM card to install the second key of the second application.
[0008] Optionally, the method further includes: Based on the SIM card, obtain the second key of the second application; Based on the second key, a service request is sent to the second service platform; Receive business data from the second business platform.
[0009] In a third aspect, embodiments of this disclosure provide a key distribution method applied to a SIM card, the method comprising: Receive key filling requests from any application; The application obtains and stores a Level 3 key, which is used to obtain user information from the corresponding business platform when the application requests services from the business platform.
[0010] Optionally, the method further includes: Receive service requests from any of the applications; Provide the application with the corresponding level 3 key.
[0011] Optionally, obtaining and storing the application's three-level key includes: Based on the access signaling carried in the key filling request, a key acquisition request is sent to the key service platform; wherein, the key service platform is used to manage the three-level keys of each business platform based on the access signaling; Receive the third-level key fed back from the key service platform; Store the three-level key.
[0012] Optionally, the method further includes: When the inactivity period of any of the applications meets the preset duration, the third-level key of the application is deleted.
[0013] Optionally, the method further includes: When the number of Level 3 keys for any application stored in the SIM card is less than a preset threshold, the Level 3 keys for the application are obtained and stored based on a key filling request.
[0014] In a fourth aspect, embodiments of this disclosure provide a key distribution apparatus for use in a first application, comprising: The first sending module is used to send a key authorization request for the second application single sign authentication to the first business platform; The first acquisition module is used to acquire the first key of the first application based on the SIM card when it receives authorization information from the first service platform. The first key is used to associate user information between the first service platform and the second service platform. The second sending module is used to send the first key to the second application.
[0015] In a fifth aspect, embodiments of this disclosure provide a key distribution apparatus for use in a second application, comprising: The second receiving module is used to receive a first key from the first application, the first key being used to associate user information between the first business platform and the second business platform. The request module is used to initiate a single sign-on authentication request to the second business platform based on the first key; the second business platform is used to obtain user information from the first business platform and perform authentication based on the first key. The fifth sending module is used to send an access signaling message for the second application to the SIM card when the single sign-on authentication is successful. The access signaling message is used to request the SIM card to install the second key of the second application.
[0016] In a sixth aspect, embodiments of this disclosure provide a key distribution apparatus for use with a SIM card, comprising: The fourth receiving module is used to receive key filling requests from any application. The third acquisition module is used to acquire and store the application's level 3 key, which is used to acquire user information of the business platform when the application requests services from the corresponding business platform.
[0017] In a seventh aspect, embodiments of this disclosure provide an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described key distribution method.
[0018] In an eighth aspect, embodiments of this disclosure provide a computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the above-described key distribution method.
[0019] In a ninth aspect, embodiments of this disclosure provide a computer program product including computer-readable code, or a non-volatile computer-readable storage medium carrying computer-readable code, wherein when the computer-readable code is run in a processor of an electronic device, the processor in the electronic device executes the above-described key distribution method.
[0020] In this disclosure, a first application sends a key authorization request for single sign-on authentication of a second application to a first service platform. Upon receiving authorization approval information from the first service platform, the first application obtains a first key based on the SIM card. This first key is used to associate user information between the first and second service platforms. The first key is then sent to the second application. By establishing a user information association between the first and second applications, the second application can apply for and receive a key for executing its services based on the one-time first key. This allows the second application to use its own dynamic key when executing services, eliminating the need for single sign-on authentication with the first application each time. This avoids the problem of managing and maintaining numerous keys and delaying key distribution during cross-application single sign-on authentication. Therefore, the efficiency of key distribution can be improved.
[0021] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description
[0022] Figure 1 This is a flowchart of user authentication in existing technologies.
[0023] Figure 2 This is a flowchart of a key distribution method provided in this disclosure.
[0024] Figure 3 A flowchart of the key authorization process provided in this disclosure.
[0025] Figure 4 This is a flowchart of the authentication process for the second APP single sign-on provided in this disclosure.
[0026] Figure 5 Another flowchart of a key distribution method provided in this disclosure.
[0027] Figure 6 A flowchart for obtaining and storing the application's three-level key for this disclosure.
[0028] Figure 7 This is a schematic diagram of the key filling structure provided in this disclosure.
[0029] Figure 8 This is yet another flowchart of a key distribution method provided in this disclosure.
[0030] Figure 9 A flowchart for the business data request provided in this disclosure.
[0031] Figure 10 Another flowchart of a key distribution method provided in this disclosure.
[0032] Figure 11 This is yet another flowchart of a key distribution method provided in this disclosure.
[0033] Figure 12 This is a schematic diagram of a key distribution device provided in this disclosure.
[0034] Figure 13 This is another schematic diagram of a key distribution device provided in this disclosure.
[0035] Figure 14 This is another structural schematic diagram of a key distribution device provided in this disclosure.
[0036] Figure 15 This is a hardware block diagram of an electronic device provided in this disclosure.
[0037] Figure 16 This is a schematic diagram of a computer program product provided in this disclosure. Detailed Implementation
[0038] To enable those skilled in the art to better understand the technical solution of this application, the application scenario of this application will be described first below.
[0039] When a user logs into software, the server typically needs to verify the user's identity. Once verification is successful, the server generates a key and returns it to the client. The client must then include this key in every subsequent request so the server can confirm the user's identity. This key usually includes a signature to ensure the security of user authentication. Figure 1 A flowchart of user authentication in existing technology, such as Figure 1As shown in the diagram, existing user identity systems typically involve a user authentication process. Users can initiate authentication requests to an authentication center through applications, using methods such as account password authentication, SMS authentication, SIM authentication, or one-click login. After authentication, the user is granted a token key to use the application, which can then access services through this authenticated, fixed key. As illustrated, in existing technologies, the authentication center and the service platform can be considered as two separate devices.
[0040] Currently, users typically only have single-system access. When performing cross-system single sign-on, a temporary key needs to be obtained from the certification authority, and this temporary key is then used to authenticate other applications. This key distribution method requires managing and maintaining a large number of keys for cross-system single sign-on, making timely key distribution difficult. Therefore, it reduces the efficiency of key distribution.
[0041] To address the aforementioned technical problems, this disclosure provides an inventive concept: a first application initiates an authorization request to a first business platform to achieve single sign-on for a second application. After authorization is granted, that is, after establishing a user information association between the first and second applications, the second application can apply for and receive a key for executing its business operations based on a one-time first key. This allows the second application to use its own dynamic key when executing business operations, eliminating the need for single sign-on with the first application on each interaction. This avoids the problem of managing and maintaining numerous keys and delaying key distribution during cross-application single sign-on. Therefore, it improves the efficiency of key distribution.
[0042] The present disclosure will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the present disclosure and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the present disclosure are shown in the drawings, not the entire structure.
[0043] Figure 2 This is a flowchart of a key distribution method provided in this disclosure. Figure 2 As shown, this method can be applied to a first application and a second application in a user identity authentication system. The architecture of the system includes at least one of the following: a first application, a second application, a first business platform, a second business platform, and a SIM card.
[0044] In this embodiment, the first application, or first APP, is the currently used APP. It interacts with the first business platform to obtain relevant business data and fulfill the business requirements of the first APP. The second application, or second APP, is used in scenarios where, at least when using the first APP, the user needs to switch to the second APP to fulfill their business requirements. For example, when using a shopping APP, the user needs to switch to a payment APP to make a purchase. The second APP interacts with the second business platform to obtain related business data to fulfill its business requirements. The first APP and the second APP can belong to the same cloud phone system.
[0045] Currently, SIM cards have entered the Super SIM era, using card applications as the management medium and gradually adding capabilities such as security chips, digital certificates, and national cryptographic algorithms. The currently released 3.0+ SIM cards possess stronger computing power and remote upgrade capabilities, achieving the hardware capability to securely store quantum keys. Based on the different uses of the keys, quantum key storage is divided into three levels. The first-level key is used to protect the security of the SIM card itself; the second-level key is used for network transmission; and the third-level key is used for business applications. In this disclosure, the SIM card can store the acquired third-level key, allowing the APP to directly retrieve the corresponding one-time third-level key from the SIM card when performing business operations.
[0046] Based on the above architecture, the key distribution method disclosed herein is as follows: S201: The first application sends a key authorization request for the second application's single sign authentication to the first business platform.
[0047] Specifically, the first app sends a key authorization request to the first business platform to execute the key authorization process. This key authorization request carries the second app's AK (Access Key Id) to inform the first business platform that the first app needs to perform single sign-on authentication with the second app. The second app's AK is a pre-assigned AK by the key service platform.
[0048] S202: When an authorization pass information is received from the first service platform, the first application obtains the first key of the first application based on the SIM card.
[0049] Specifically, upon receiving authorization approval, the first app redirects to the second app's service page or SDK (Software Development Kit) and enters the second app's single sign-on authentication process. The first app retrieves its pre-installed first key from the SIM card. This first key is understood to be a level-three key from the key service platform's key pool, bound to the first app and then installed on the SIM card. This first key is used to associate user information between the first and second service platforms.
[0050] S203: The first application sends the first key to the second application.
[0051] S204: The second application receives the first key from the first application.
[0052] S205: The second application initiates a single sign-on authentication request to the second business platform based on the first key.
[0053] Specifically, the second app sends an authentication request to the second business platform based on the first key. The second app needs to obtain an access token from the second business platform that allows single sign-on. At this time, the second business platform is used to obtain user information from the first business platform and authenticate based on the first key.
[0054] S206: When single sign-on authentication is successful, the second application sends access signaling to the SIM card.
[0055] Specifically, after the second app successfully logs in, it can send an access signaling message to the SIM card to request the installation of a second key for the second application. This process involves installing a Level 3 key to enable the second app's services. The requested second key is the Level 3 key from the key pool of the key service platform, which contains the second app's AK and user information.
[0056] In this disclosure, a first application sends a key authorization request for single sign-on authentication of a second application to a first service platform. Upon receiving authorization approval information from the first service platform, the first application obtains a first key based on the SIM card. This first key is used to associate user information between the first and second service platforms. The first key is then sent to the second application. By establishing a user information association between the first and second applications, the second application can apply for and receive a key for executing its services based on the one-time first key. This allows the second application to use its own dynamic key when executing services, eliminating the need for single sign-on authentication with the first application each time. This avoids the problem of managing and maintaining numerous keys and delaying key distribution during cross-system single sign-on authentication. Therefore, the efficiency of key distribution can be improved.
[0057] Furthermore, Figure 3 A flowchart of the key authorization process provided in this disclosure, such as Figure 3 As shown, the specific key authorization process is as follows: S2011: The first application, carrying the AK of the second APP, sends a key authorization request to the first business platform.
[0058] S2012: The first business platform sends a key authorization request carrying the AK of the second APP and the user information of the first business platform to the key service platform.
[0059] S2013: The key service platform marks some of the level 3 keys in the key pool.
[0060] Specifically, a portion of the Level 3 keys in the key pool are bound to the AK and user information of the second APP to achieve key marking, and this portion of the Level 3 keys is used as the second key for subsequent SIM card filling.
[0061] S2014: After the key service platform marks the success, the key service platform sends the authorization approval information back to the first business platform.
[0062] S2015: The first business platform sends authorization approval information to the first APP.
[0063] Specifically, at this point, the key authorization process is considered complete.
[0064] Furthermore, Figure 4 The flowchart of the authentication process for the second APP single sign-on provided in this disclosure is as follows: Figure 4 As shown, the specific authentication process is as follows: S2051: The second application initiates an authentication request to the second business platform based on the first key.
[0065] S2052: The second business platform obtains user information of the first business platform from the key service platform based on the first key.
[0066] Specifically, the second business platform, based on the first key and the assigned AK of the second APP, parses the user information of the first business platform in the key service platform. The key service platform verifies the binding relationship between the AK of the second APP and the user information. After successful authentication, the user information is returned to the second business platform.
[0067] S2053: The second business platform sends an access token to the second APP.
[0068] Specifically, after obtaining user information from the first business platform, the second business platform sends an access token that allows single sign-on to the second app, so that the second app can call the login interface based on the access token to realize the single sign-on service.
[0069] Figure 5 Another flowchart of a key distribution method provided in this disclosure is shown. Figure 5 As shown, this method can be applied to SIM cards in a user authentication system. The architecture of this system includes at least one of the following: an application, a service platform, a SIM card, and a key service platform.
[0070] In this embodiment, the application (APP) interacts with the business platform to obtain relevant business data and fulfill its business requirements. The key service platform parses user information and binds it to keys in the key pool, facilitating the SIM card's acquisition and loading of a Level 3 key. The SIM card can store the acquired Level 3 key, allowing the APP to directly retrieve the corresponding one-time Level 3 key when performing business operations. SIM card access to the APP is managed by Access Control (AC), which verifies authentication information such as packet name and signature to ensure secure management of the SIM card key's safe operation.
[0071] Based on the relationship between the above devices, the key distribution method disclosed herein is applied to a SIM card, and the specific process is as follows: S501: The SIM card receives a key loading request from any application.
[0072] Specifically, in this embodiment, the business platform and the authentication center are considered as a single integrated device. The application interacts with the corresponding business platform; for example, the cloud phone client application performs routine account and password authentication, short verification, SIM authentication, one-click login, or other single sign-on authentication with the cloud phone business platform. Upon successful authentication, the business platform returns a one-time access token carrying the user's identity. Based on the access token, the application sends a key loading request to the SIM card.
[0073] S502: The SIM card acquires and stores the application's three-level key.
[0074] Specifically, the level 3 key is used to obtain user information from the business platform when the application requests services from the corresponding business platform.
[0075] In one possible implementation, Figure 6 This is a flowchart illustrating the process of obtaining and storing the application's three-level key, as disclosed in this disclosure. Figure 6 As shown, the method includes: S5021: The SIM card sends a key acquisition request to the key service platform based on the access signaling carried in the key filling request.
[0076] Specifically, the SIM card sends a key acquisition request to the key service platform based on the access signaling carried in the key filling request, such as a secondary key and an access token. The key service platform manages the tertiary keys of various service platforms based on the access signaling. In other words, the SIM card securely delivers the access token to the key service platform via the secondary key. The key service platform parses and authenticates the access token with the service platform to obtain user information. After successful authentication, the key service platform marks and binds a portion of the tertiary keys in its key pool with the user information of that service platform. After completing the marking and binding of the tertiary keys, the key service platform sends a portion of the tertiary keys to the SIM card.
[0077] Figure 7 This is a schematic diagram of the key filling structure provided in this disclosure. In this embodiment, key filling between the SIM card and the key service platform can be achieved using dedicated filling equipment. The filling equipment can directly fill a batch of secondary keys for network transmission. Figure 7 As shown, the dashed line represents the initial filling at the factory, while the solid line represents the online filling achieved through the protection of the second-level key when the remaining third-level key in the SIM card is insufficient.
[0078] S5022: The SIM card receives the Level 3 key fed back from the key service platform.
[0079] S5023: SIM card stores three-level keys.
[0080] In this disclosure, a batch of secondary keys for network transmission are pre-loaded into the SIM card. Then, after user authentication, a batch of user-related tertiary keys is obtained in real-time under the protection of the secondary keys. Each subsequent service transmission can use a tertiary key to achieve dynamic authentication. This replaces the fixed tertiary key used for each authentication in related technologies with a one-time tertiary key used per service, improving convenience and security, and making the service more secure. It avoids the risks of eavesdropping and misuse inherent in traditional fixed tertiary key authentication, especially in cases of password leakage, social engineering attacks, or phishing, ensuring that the token used for each authentication is valid only once, greatly reducing the possibility of eavesdropping and misuse. Therefore, it improves the efficiency and security of key distribution.
[0081] Figure 8 This is yet another flowchart of a key distribution method provided in this disclosure. Figure 8 As shown, the method includes: S801: The SIM card receives service requests from any application.
[0082] Specifically, the application sends a service request to the SIM card to obtain a dynamic Level 3 key. In other words, after the Level 3 key is marked, every user-related request from the application obtains a dynamic, one-time Level 3 key through the SIM card.
[0083] S802: The SIM card provides the corresponding three-level key to the application.
[0084] Specifically, after receiving a service request, the SIM card randomly provides the application with a corresponding three-level key.
[0085] Figure 9 A flowchart illustrating the business data request provided in this disclosure. (For example...) Figure 9 As shown, this method is applied to a second application, including: S901: Based on the SIM card, obtain the second key for the second application.
[0086] At the beginning, the second app sends a service request to the SIM card to obtain the dynamic third-level key of the second app, namely the second key.
[0087] S902: Send a service request to the second service platform based on the second key.
[0088] Specifically, based on secondary key encryption protection, the business request carrying the secondary key is sent to the secondary business platform. The secondary business platform authenticates with the key service platform to obtain the user information corresponding to the secondary key, and retrieves the business data based on the returned user information. After retrieving the business data corresponding to the business request, it returns it to the secondary application.
[0089] S903: Receives business data from the second business platform.
[0090] Specifically, the target business is achieved based on the received business data.
[0091] In one possible implementation, applied to a SIM card, the method further includes: When the inactivity period of any application reaches the preset time, delete the application's level 3 key.
[0092] Specifically, the Level 3 key is bound to user information. When the application logs out, this binding is cleared. Subsequent business processes attempting to retrieve data using the Level 3 key will be flagged as not logged in and redirected to a specific login page. Logout can be initiated by the user or automatically due to the application not being used for a preset period.
[0093] Furthermore, when the application is a secondary application, logging out of the primary application will revoke the authorization of the secondary application.
[0094] In related technologies, the lack of further restrictions on the transmission protection, usage period, and access rights of Level 3 keys creates a security risk as unauthorized users can freely access the system due to key leakage. This disclosure addresses this issue by reducing SIM card capacity pressure by clearing the number of bound Level 3 keys to a threshold level when the user has not used the card for a period of time. When the user uses the card again, the key count will fall below the threshold, allowing for online refilling and tagging.
[0095] In one possible implementation, applied to a SIM card, the method further includes: When the number of Level 3 keys for any application stored in the SIM card is less than a preset threshold, the Level 3 keys for the application are obtained and stored based on the key filling request.
[0096] Specifically, the SIM card application has programming and management capabilities. A preset threshold T is set for key storage in the SIM card. When the number of remaining level 3 keys is less than T, a key loading request is made through network and key service platform encryption and level 2 key protection, and the obtained level 3 key is stored in the SIM card. The Super SIM can also be replaced with other hardware with high-security storage capabilities, such as a TF card (Trans-flash Card, Micro SD card).
[0097] In one possible implementation, applied to a first application, the method further includes: Send an authentication request to the first service platform; receive access signaling from the first service platform; send access signaling to the SIM card.
[0098] Specifically, the access signaling is used to request the SIM card to install the first key, whereby the access signaling is at least used to indicate that authentication has been successful. The specific method for installing the third-level key in the application was mentioned earlier. Here, the first application can be considered any of the applications mentioned above; that is, the installation of the first key in the first application is consistent with the third-level key installation method described earlier, and will not be repeated here.
[0099] Figure 10 Another flowchart of a key distribution method provided in this disclosure is shown. Figure 10 As shown, this embodiment takes the use of a cloud phone as an example, and the specific method is as follows: The key distribution method consists of two parts. The dashed line represents the process of binding the Level 3 key with the user of the service in the cloud phone system; the solid line represents the process of the cloud phone system using the one-time Level 3 key to interact each time the service is triggered.
[0100] In this embodiment, the authentication center and the business platform are treated as two independent devices that interact with each other. Figure 10 As shown: S1001: The cloud mobile client needs to initiate login authentication with the authentication center to obtain an authentication Access Token.
[0101] Specifically, the cloud phone client needs to perform regular login authentication with the authentication center and obtain an Access Token. This can be achieved using account password, short verification, SIM authentication, one-click login, or other authentication methods.
[0102] S1002: The cloud mobile client marks the three-level key with an Access Token.
[0103] Specifically, the cloud phone client can send the Access Token to the SIM card, and then the SIM card can apply for a Level 3 key token from the key service platform based on the Access Token protected by the Level 2 key.
[0104] S1003: The key service platform initiates Access Token authentication with the certification center and marks the token after successful authentication.
[0105] Specifically, the key service platform needs to authenticate the received Access Token with the certification center to determine whether it is genuine and valid. After successful authentication, the certification center can return the user information to the key service platform. Subsequently, the key service platform can bind and mark the Level 3 key in the key pool with the user information and send the marked Level 3 key to the SIM card.
[0106] S1004: The cloud phone client obtains the level 3 key from the SIM card.
[0107] Specifically, each time the cloud phone client executes a business transaction, it needs to obtain a one-time three-level key from the SIM card to ensure the security of business interactions.
[0108] S1005: The cloud mobile client obtains business data from the cloud mobile service platform based on the three-level key.
[0109] Specifically, after obtaining the Level 3 key, it can be sent to the cloud phone service platform to request the corresponding service data.
[0110] S1006: The cloud phone service platform initiates key verification to the key service platform.
[0111] Specifically, the cloud phone service platform verifies with the key service platform whether the obtained level 3 key is related to the user information. If the verification is successful, the verification result is returned to the cloud phone service platform. At the same time, the cloud phone service platform can return relevant business information to the cloud phone client to achieve the target business.
[0112] Figure 11 This is yet another flowchart of a key distribution method provided in this disclosure. Figure 11 As shown, this embodiment takes the use of multi-client single sign-on on a cloud phone as an example. The specific method is as follows: The key distribution method is divided into two parts. The dashed line represents the key authorization process for the three-level key, while the solid line represents the process by which the second cloud phone client and the second cloud phone service platform acquire business data based on the three-level key.
[0113] S1101: The key service platform distributes AKs to the first cloud phone service platform and the second cloud phone service platform respectively.
[0114] Specifically, this embodiment involves a cross-system single sign-on process for the first cloud phone client and the second cloud phone client. Therefore, it involves two business platforms. For business platforms that may have business needs, the key service platform needs to allocate their respective AKs.
[0115] S1102: The first cloud phone service platform authorizes a third-level key for the second cloud phone service platform.
[0116] Specifically, the first cloud phone client, carrying the AK (Key Access Detector) of the second cloud phone client, sends a key authorization request to the first cloud phone service platform. The first cloud phone service platform then sends a key authorization request carrying the AK of the second cloud phone client and its user information to the key service platform. The key service platform then marks the third-level key and returns a successful marking message to the first cloud phone client.
[0117] S1103: The cloud phone's second client obtains a level 3 key from the SIM card.
[0118] S1104: The second client of the cloud phone obtains business data from the second service platform of the cloud phone based on the third-level key.
[0119] S1105: The cloud phone's second business platform initiates a key verification to the key service platform.
[0120] Specifically, the above S1103~S1105 are the same as those mentioned earlier, where the cloud mobile client obtains the corresponding business data from the cloud mobile service platform based on the three-level key, and will not be described in detail here.
[0121] This allows for cross-system business operations without requiring additional single sign-on; authorization is all that's needed. Furthermore, the bound associations can be reclaimed after the user logs out, improving key management efficiency.
[0122] Figure 12 This is a schematic diagram of a key distribution device provided in this disclosure. Figure 12 As shown, the device 1200 is applied to a first application and includes: a first sending module 1212, a first acquisition module 1220, and a second sending module 1230.
[0123] The first sending module 1212 is used to send a key authorization request for the second application single sign authentication to the first service platform; The first acquisition module 1220 is used to acquire the first key of the first application based on the SIM card when it receives authorization information from the first service platform. The first key is used to associate user information between the first service platform and the second service platform. The second sending module 1230 is used to send the first key to the second application.
[0124] Optionally, the device further includes: The third sending module is used to send an authentication request to the first service platform; The first receiving module is configured to receive access signaling from the first service platform, wherein the access signaling is at least used to indicate that authentication has been successful; The fourth sending module is used to send the access signaling to the SIM card, the access signaling being used to request the SIM card to be loaded with the first key.
[0125] Figure 13 This is another schematic diagram of a key distribution device provided in this disclosure. Figure 13 As shown, the device 1300 is applied to a second application and includes: a second receiving module 1310, a request module 1320, and a fifth sending module 1330.
[0126] The second receiving module 1310 is used to receive a first key from the first application, the first key being used to associate user information between the first business platform and the second business platform. The request module 1320 is used to initiate a single sign-on authentication request to the second business platform based on the first key; the second business platform is used to obtain user information of the first business platform and authenticate based on the first key. The fifth sending module 1330 is used to send an access signaling message for the second application to the SIM card when the single sign-on authentication is successful. The access signaling message is used to request the SIM card to install the second key of the second application.
[0127] Optionally, the device further includes: The second acquisition module is used to acquire the second key of the second application based on the SIM card; The sixth sending module is used to send a service request to the second service platform based on the second key; The third receiving module is used to receive business data from the second business platform.
[0128] Figure 14 This is another schematic diagram of a key distribution device provided in this disclosure. Figure 14 As shown, the device 1400 is applied to a SIM card and includes: a fourth receiving module 1410 and a third acquiring module 1420.
[0129] The fourth receiving module 1410 is used to receive a key filling request from any application. The third acquisition module 1420 is used to acquire and store the application's level 3 key, which is used to acquire user information of the business platform when the application requests services from the corresponding business platform.
[0130] Optionally, the device further includes: The fifth receiving module is used to receive service requests from any of the applications. The seventh sending module is used to provide the corresponding level 3 key to the application.
[0131] Optionally, the third acquisition module is used for: Based on the access signaling carried in the key filling request, a key acquisition request is sent to the key service platform; wherein, the key service platform is used to manage the three-level keys of each business platform based on the access signaling; Receive the third-level key fed back from the key service platform; Store the three-level key.
[0132] Optionally, the device further includes: The deletion module is used to delete the third-level key of any application when the unused time of any of the applications meets a preset time.
[0133] Optionally, the device further includes: The fourth acquisition module is used to acquire and store the third-level key of any application stored in the SIM card when the number of third-level keys of any application stored in the SIM card is less than a preset threshold, based on a key filling request.
[0134] This application also provides an electronic device for performing the above-described key distribution method. Please refer to... Figure 15 It illustrates a schematic diagram of an electronic device provided by some embodiments of this application. For example... Figure 15 As shown, the electronic device 15 includes: a processor 1500, a memory 1501, a bus 1502, and a communication interface 1503. The processor 1500, the communication interface 1503, and the memory 1501 are connected via the bus 1502. The memory 1501 stores a computer program that can run on the processor 1500. When the processor 1500 runs the computer program, it executes the key distribution method provided in any of the foregoing embodiments of this application.
[0135] The memory 1501 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this device network element and at least one other network element is achieved through at least one communication interface 1503 (which may be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.
[0136] Bus 1502 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Memory 1501 is used to store programs. After receiving an execution instruction, processor 1500 executes the program. The key distribution method disclosed in any of the foregoing embodiments of this application can be applied to processor 1500, or implemented by processor 1500.
[0137] The processor 1500 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 1500 or by instructions in software form. The processor 1500 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 1501. Processor 1500 reads the information in memory 1501 and, in conjunction with its hardware, completes the steps of the above method.
[0138] The electronic device provided in this application embodiment and the key distribution method provided in this application embodiment are based on the same inventive concept and have the same beneficial effects as the methods they adopt, operate or implement.
[0139] This application also provides a computer-readable storage medium corresponding to the key distribution method provided in the foregoing embodiments. The computer-readable storage medium shown can be an optical disc, on which a computer program is stored. When the computer program is run by a processor, it executes the key distribution method provided in any of the foregoing embodiments.
[0140] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.
[0141] The computer-readable storage medium provided in the above embodiments of this application and the key distribution method provided in the embodiments of this application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.
[0142] This application also provides a computer program product 1600, such as... Figure 16 As shown. This computer program product carries a computer program 1601. The instructions included in the program code can be used to execute the steps of the key distribution method described in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.
[0143] The aforementioned computer program product can be implemented through hardware, software, or a combination thereof. In one optional embodiment, the computer program product is specifically embodied in a computer storage medium; in another optional embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.
[0144] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.
[0145] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0146] Additionally, as used herein, the "or" used in a list of items beginning with "at least one" indicates a separate list, such that a list of, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not imply that the described example is preferred or better than other examples.
[0147] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.
[0148] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.
[0149] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.
[0150] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.
Claims
1. A key distribution method, characterized in that, Applied to a first application, the method includes: Send a key authorization request for the second application's single sign-on authentication to the first business platform; When an authorization pass is received from the first service platform, the first key of the first application is obtained based on the SIM card. The first key is used to associate user information between the first service platform and the second service platform. Send the first key to the second application.
2. The method according to claim 1, characterized in that, The method further includes: Send an authentication request to the first business platform; Receive access signaling from the first service platform, wherein the access signaling is at least used to indicate that authentication has been successful; The access signaling is sent to the SIM card, and the access signaling is used to request the SIM card to be loaded with the first key.
3. A key distribution method, characterized in that, Applied to a second application, the method includes: Receive a first key from a first application, the first key being used to associate user information between a first business platform and a second business platform; Based on the first key, a single sign-on authentication request is initiated to the second business platform; the second business platform is used to obtain user information from the first business platform and perform authentication based on the first key; When the single sign-on authentication is successful, an access signaling message for the second application is sent to the SIM card. The access signaling message is used to request the SIM card to install the second key of the second application.
4. The method according to claim 3, characterized in that, The method further includes: Based on the SIM card, obtain the second key of the second application; Based on the second key, a service request is sent to the second service platform; Receive business data from the second business platform.
5. A key distribution method, characterized in that, Applied to a SIM card, the method includes: Receive key filling requests from any application; The application obtains and stores a Level 3 key, which is used to obtain user information from the corresponding business platform when the application requests services from the business platform.
6. The method according to claim 5, characterized in that, The method further includes: Receive service requests from any of the applications; Provide the application with the corresponding level 3 key.
7. The method according to claim 5, characterized in that, The acquisition and storage of the application's three-level key includes: Based on the access signaling carried in the key filling request, a key acquisition request is sent to the key service platform; wherein, the key service platform is used to manage the three-level keys of each business platform based on the access signaling; Receive the third-level key fed back from the key service platform; Store the three-level key.
8. The method according to claim 5, characterized in that, The method further includes: When the inactivity period of any of the applications meets the preset duration, the third-level key of the application is deleted.
9. The method according to claim 5, characterized in that, The method further includes: When the number of Level 3 keys for any application stored in the SIM card is less than a preset threshold, the Level 3 keys for the application are obtained and stored based on a key filling request.
10. A key distribution device, characterized in that, Applied to the first application, including: The first sending module is used to send a key authorization request for the second application single sign authentication to the first business platform; The first acquisition module is used to acquire the first key of the first application based on the SIM card when it receives authorization information from the first service platform. The first key is used to associate user information between the first service platform and the second service platform. The second sending module is used to send the first key to the second application.
11. A key distribution device, characterized in that, Applied to a second application, including: The second receiving module is used to receive a first key from the first application, the first key being used to associate user information between the first business platform and the second business platform. The request module is used to initiate a single sign-on authentication request to the second business platform based on the first key; the second business platform is used to obtain user information from the first business platform and perform authentication based on the first key. The fifth sending module is used to send an access signaling message for the second application to the SIM card when the single sign-on authentication is successful. The access signaling message is used to request the SIM card to install the second key of the second application.
12. A key distribution device, characterized in that, Applied to SIM cards, including: The fourth receiving module is used to receive key filling requests from any application. The third acquisition module is used to acquire and store the application's level 3 key, which is used to acquire user information of the business platform when the application requests services from the corresponding business platform.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The processor runs the computer program to implement the method as described in any one of claims 1-2 and / or 3-4 and / or 5-9.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that, The program is executed by a processor to implement the method as described in any one of claims 1-2 and / or 3-4 and / or 5-9.
15. A computer program product, characterized in that, Includes computer-readable code, or a non-volatile computer-readable storage medium carrying computer-readable code, wherein when the computer-readable code is executed in a processor of an electronic device, the processor in the electronic device performs the method as described in any one of claims 1-2 and / or 3-4 and / or 5-9.