Third-party authorized login
By introducing third-party authorized login methods and systems, using the engine app to identify the identity of the fast application and pass it into the mobile application app, the problem that the manufacturer's app cannot verify the identity of the fast application is solved, and the security of authorized login is improved.
Patent Information
- Application Number
- PCT/CN2024/128459
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-10-30
- Publication Date
- 2025-05-30
AI Technical Summary
The authorized services provided by the manufacturer's APP are only applicable to common Android applications, not fast applications, which leads to the manufacturer's app being unable to directly verify the identity of the fast applications, which may introduce security risks.
By introducing third-party authorized login methods and systems, the engine app controlled by mobile phone manufacturers is responsible for maintaining and identifying the main identity information of the fast application and passing it into the mobile application app, which then transmits two parts of the information to the manufacturer's server for security detection.
Ensure the legality of fast applications and prevent user authorization credentials from being transferred to illegal third parties, thereby improving the security of the authorization login process.
Smart Images

Figure CN2024128459_30052025_PF_FP_ABST
Abstract
Description
Third-party authorization login Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a third-party authorized login method and system. Background Art
[0002] Quick apps are mini-program-like applications based on the underlying mobile phone system. They are click-and-use by end users and run in the engine app controlled by the mobile phone manufacturer. Currently, a large number of quick apps need to access the third-party authorization service of large mobile applications (hereinafter referred to as manufacturer apps) and authenticate their users' identities through the returned authorization information without the user having to enter an additional account and password. However, the authorization service currently provided by the manufacturer app is only applicable to general Android applications, not quick apps. More specifically, in the current authorization service, it is the mobile phone manufacturer's engine app that interacts with the manufacturer app, not the quick app running in it. Therefore, the manufacturer app cannot directly verify the identity of the quick app, and may introduce security risks.
[0003] Summary of the Invention
[0004] One or more embodiments of this specification provide a third-party authorization login method and system, which can provide a reliable third-party authorization login solution for quick applications and ensure the security of the authorization process.
[0005] According to a first aspect, a third-party authorized login method is provided, which is applicable to an authorization end, wherein the authorization end includes a mobile application APP and an application server; the method includes: in response to an authorization request from an engine APP, the mobile application APP obtains the identity information of a target quick application that has been authenticated and uploaded by the engine APP, and collects the identity information of the engine APP; the mobile application APP initiates an authorization request to the application server, and synchronously sends the identity information of the engine APP and the identity information of the target quick application; in response to the authorization request from the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application, and after the authentication is successful, issues an authorization credential to the target quick application through the engine APP, so that the target quick application can obtain user information by means of the authorization credential and complete login to the target quick application based on the user information.
[0006] As an optional implementation of the method described in the first aspect, the engine APP authenticates the identity information of the target quick app, specifically including: in response to the authorization request of the target quick app, the engine APP collects the identity information of the target quick app; the engine APP compares the identity information of the target quick app with the locally pre-stored quick app identity information for consistency, and if the pre-stored quick app identity information is consistent with the identity information of the target quick app, the identity information of the target quick app is authenticated.
[0007] As an optional implementation of the method described in the first aspect, after the mobile application APP collects the identity information of the engine APP, it also authenticates the identity information of the engine APP. After the authentication is passed, it sends an authorization request, the identity information of the engine APP and the identity information of the target quick application to the application server.
[0008] Specifically, the mobile application APP authenticates the identity information of the engine APP, specifically including: comparing the identity information of the engine APP with the authorization request of the engine APP. If the identity information of the engine APP is associated with the authorization request of the engine APP, the identity information of the engine APP is authenticated.
[0009] As an optional implementation of the method described in the first aspect, the application server authenticates the identity information of the engine APP and the identity information of the target quick application, specifically including: the application server compares the identity information of the engine APP with the locally pre-stored engine identity information for consistency; if the pre-stored engine identity information is consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated; the application server compares the identity information of the target quick application with the locally pre-stored quick application identity information for consistency; if the pre-stored quick application identity information is consistent with the identity information of the target quick application, the identity information of the target quick application is authenticated.
[0010] As an optional implementation of the method described in the first aspect, before the application server sends the authorization credential to the target quick application through the engine APP, it also includes: generating the authorization credential in response to the user's authorization confirmation information for the target quick application through the mobile application APP.
[0011] According to a second aspect, a third-party authorized login method is provided, which is applicable to a quick app side, wherein the quick app side includes a target quick app and a quick app server of the target quick app; the method includes: in response to a user operation, the target quick app sends an authorization request to an engine app, so that the engine app collects and authenticates the identity information of the target quick app, and after the authentication is successful, applies for an authorization credential from an authorization side; in response to the authorization credential returned by the engine app, the target quick app sends the authorization credential to the quick app server; in response to obtaining the authorization credential, the quick app server obtains user information from the authorization side based on the authorization credential, and completes the target quick app login based on the user information.
[0012] As an optional implementation manner of the method described in the second aspect, the authorization end includes a mobile application APP and an application server; the engine APP applies for the authorization credential from the authorization end, specifically including: the engine APP initiates an authorization request to the mobile application APP and synchronizes the identity information of the target quick application; in response to the authorization request of the engine APP, the mobile application APP collects the identity information of the engine APP, and sends the authorization request, the identity information of the target quick application and the identity information of the engine APP to the application server; in response to the authorization request of the mobile application APP, the application server authenticates the identity information of the target quick application and the identity information of the engine APP, and after the authentication is passed, returns the authorization credential to the mobile application APP; the mobile application APP sends the authorization credential to the target quick application through the engine APP.
[0013] According to a third aspect, a third-party authorization login system is provided, including an authorization end and a quick application end; the authorization end is used to execute the third-party authorization login method applicable to the authorization end, and the quick application end is used to execute the third-party authorization login method applicable to the quick application end to implement authorized login of a target quick application.
[0014] According to a fourth aspect, a terminal device is provided, the device having an engine app and a mobile application app provided by an authorization end installed therein, a target quick application deployed in the engine app; the target quick application performing third-party authorized login based on user information obtained by the mobile application app, specifically comprising: in response to a user operation, the target quick application sending an authorization request to the engine app; in response to the authorization request of the target quick application, the engine app collecting and authenticating identity information of the target quick application, and after successful authentication, sending the authorization request and the identity information of the target quick application to the mobile application app; in response to the authorization request of the engine app, the mobile application app collecting the identity information of the engine app and sending the authorization request, the identity information of the engine app, and the identity information of the target quick application to an application server; in response to the authorization request of the mobile application app, the application server authenticates the identity information of the engine app and the identity information of the target quick application, and after successful authentication, issues an authorization credential to the target quick application through the engine app; in response to obtaining the authorization credential, the target quick application obtains user information from the application server based on the authorization credential, and completes login based on the user information.
[0015] As an optional implementation manner of the terminal device described in the fourth aspect, the target quick application obtains user information from the application server based on the authorization credential and completes login based on the user information, specifically including: the target quick application sends the authorization credential to the quick application server; in response to obtaining the authorization credential, the quick application service requests user information from the application server based on the authorization credential, and completes login to the target quick application based on the obtained user information.
[0016] The beneficial effect of the authorized login method described in one or more embodiments of this specification is that during third-party authorized login for quick apps, the engine app controlled by the mobile phone manufacturer is responsible for maintaining and identifying the quick app's principal identity information and transmitting it to the mobile app along with the authorization request. Subsequently, the mobile app also needs to collect the engine app's identity information and transmit both pieces of information (the quick app and the engine app) to the manufacturer's server for security verification. This allows the mobile app to ensure the legitimacy of the quick apps it interacts with, ensuring that the user's authorization credentials are being transmitted to a legitimate third party.
[0017] The systems and terminal devices described in the embodiments of this specification also have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] FIG1 shows a schematic diagram of a third-party authorization login process provided by a mobile application in the prior art.
[0020] FIG2 is a schematic structural diagram illustrating a third-party authorization login system according to some embodiments of the present application.
[0021] FIG3 is a flow chart illustrating a third-party authorization login method implemented by a third-party authorization login system according to some embodiments of the present application.
[0022] FIG4 is a flow chart showing a third-party authorization login method applicable to an authorization terminal according to some embodiments of the present application.
[0023] FIG5 is a flow chart illustrating a third-party authorization login method applicable to a quick app terminal according to some embodiments of the present application.
[0024] FIG6 is a structural diagram showing a terminal device according to some embodiments of the present application. DETAILED DESCRIPTION
[0025] Quick apps are mini-program-like applications based on the underlying mobile phone system. They are click-and-use by end users and run in the engine app controlled by the mobile phone manufacturer. Currently, a large number of quick apps (hereinafter referred to as merchant apps) need to access the third-party authorization service of large mobile applications (hereinafter referred to as manufacturer apps) and authenticate their users' identities through the returned authorization information without the user having to enter an additional account and password. However, the authorization service currently provided by the manufacturer app is only applicable to general Android applications, not quick apps. More specifically, in the current authorization service, it is the mobile phone manufacturer's engine app that interacts with the manufacturer app, not the quick app running in it. Therefore, the manufacturer app cannot directly verify the identity of the quick app, and may introduce security risks.
[0026] Please refer to FIG1 , which shows a schematic diagram of a third-party authorization login process provided by a manufacturer's App in the prior art. The process includes the following steps.
[0027] (101) The merchant app initiates an authorization request to the manufacturer app.
[0028] (102) The manufacturer App collects the identity information of the merchant App and detects whether the identity information of the merchant App is associated with the authorization request in step (101); if so, proceed to step (103), otherwise, terminate the authorization login process.
[0029] (103) The manufacturer App sends an authorization request to the manufacturer server and simultaneously sends the identity information of the merchant App.
[0030] (104) The manufacturer server verifies the identity information of the merchant App received.
[0031] (105) After the manufacturer server verifies the identity information of the merchant App received, it returns a user authorization request to the manufacturer App. The user authorization request is used to ask the user whether he agrees to authorize the merchant App to use the user information in the manufacturer App.
[0032] (106) The user confirms through the manufacturer App's page that the user information in the manufacturer App is authorized for use by the merchant App; the manufacturer App sends the user confirmation authorization information to the manufacturer server.
[0033] (107) After receiving the user's authorization confirmation information, the manufacturer server generates an authorization credential code and then returns the authorization credential code to the manufacturer App.
[0034] (108) The manufacturer App returns the authorization credential code to the merchant App.
[0035] (109) The merchant App sends the authorization credential code to the merchant server and requests the merchant server to verify the authorization credential code.
[0036] (110) The merchant server verifies the authorization credential code with the manufacturer server and requests to obtain user information.
[0037] (111) After the manufacturer server verifies the authorization credential code, it returns the user information to the merchant server.
[0038] (112) The merchant server authenticates the user's identity based on the user information.
[0039] (113) The merchant server returns the user login status to the merchant app, completing the user's login on the merchant app.
[0040] As can be seen from the above process, in steps (102) to (104), the manufacturer App will actively collect the identity information of the merchant App and detect whether it is associated with the authorization request in step 1. Otherwise, the attacker may control a malicious App and use a forged authorization request to defraud the victim's authorization credentials from the manufacturer App to launch subsequent attacks. However, in the scenario of quick applications, the interactive subject of the manufacturer App becomes the engine App of the mobile phone manufacturer, and it is unable to directly interact with the quick application and authenticate its identity. Therefore, security risks may be introduced. For example, a malicious quick application may disguise itself as another legitimate quick application, initiate an authorization request to the manufacturer App, and steal the user's authorization information, and then log in to the user account through the stolen authorization information, resulting in the loss of the user's personal information or funds.
[0041] In view of this, one or more embodiments of this specification propose a third-party authorized login method and system to defend against potential user information theft attacks during the third-party authorized login process for quick applications.
[0042] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments in this specification without creative work should fall within the scope of protection of this specification.
[0043] It should be noted that in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the method may include more or fewer steps than those described in this specification. In addition, a single step described in this specification may be broken down into multiple steps for description in other embodiments, and multiple steps described in this specification may be combined into a single step for description in other embodiments.
[0044] Those skilled in the art will appreciate that the terms used in the embodiments of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The singular forms "a," "an," "the," and "the" used in the embodiments of the present invention and the appended claims are intended to include the plural forms, unless the context clearly indicates otherwise.
[0045] One or more embodiments of the present invention provide a third-party authorized login method. Please refer to Figure 2, which exemplifies a third-party authorized login system that can be used to implement the third-party authorized login method. It should be noted that the third-party authorized login method described in one or more embodiments of the present application can be implemented using the third-party authorized login system shown in Figure 2, but is not limited to the third-party authorized login system.
[0046] As shown in FIG2 , the authorization login system includes a terminal device 20, a merchant server 21, and a manufacturer server 22. The terminal device 20 is connected to the merchant server 21 and the manufacturer server 22 via a communication link 23. The communication link 23 can be a wired network or a wireless network. For example, the terminal device 20 can establish a communication connection with the merchant server 21 and the manufacturer server 22 using a communication method such as WIFI, Bluetooth, or infrared. Alternatively, the terminal device 20 can also establish a communication connection with the merchant server 21 and the manufacturer server 22 via a mobile network, wherein the network standard of the mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, etc.
[0047] The communication link 23 can be implemented through a communication interface set on the terminal device 20, the merchant server 21 and the manufacturer server 22. The communication interface can use a transceiver module such as, but not limited to, a network interface card and a transceiver to achieve communication between the terminal device 20 and the merchant server 21 and the manufacturer server 22.
[0048] The terminal device 20 can be implemented using, for example but not limited to, a smart phone, a notebook, an iPad, etc. The terminal device 20 will be described below using a smart phone as an example.
[0049] The smartphone has an engine app installed on it, which is provided by the mobile phone vendor. Several quick apps are deployed in the engine app. The engine app provides an authorization JSAPI interface to the quick apps. Through this interface, the quick apps can initiate authorization requests to the vendor app, obtain user information about the vendor app, and log in to the quick app's page based on the user information.
[0050] Merchant server 21 is a server for quick applications and can be any device, equipment, platform, or device cluster with computing and processing capabilities. In this embodiment, the implementation of merchant server 21 is not limited. For example, merchant server 21 can be a single server or a server cluster consisting of multiple servers. Merchant server 21 can also be a cloud server, also known as a cloud computing server or cloud host, which is a host product in a cloud computing service system.
[0051] The vendor server 22 is the server for the vendor app. Similarly, the vendor server 22 can be any device, equipment, platform, or device cluster with computing and processing capabilities. In this embodiment, the implementation of the vendor server 22 is not limited. For example, the vendor server 22 can be a single server or a server cluster consisting of multiple servers. The vendor server 22 can also be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system.
[0052] Please refer to Figure 3, which shows a flowchart of the third-party authorization login system described above when implementing the third-party authorization login method described in this embodiment. In this third-party authorization login method, the manufacturer app and manufacturer server 22 constitute the authorization end, and the target quick app and merchant server 21 constitute the quick app end. The terminal device 20, merchant server 21, and manufacturer server 22 execute the following process.
[0053] (301) The quick application calls the authorization jsapi interface provided by the engine app and initiates an authorization request to the engine app.
[0054] (302) The engine app collects the identity information of the quick app and authenticates the identity information of the quick app.
[0055] (303) After the engine app authenticates the identity information of the quick app, it initiates an authorization request to the manufacturer app and simultaneously sends the identity information of the quick app.
[0056] (304) The manufacturer App collects the identity information of the engine App and authenticates the identity information of the engine App. Specifically, it determines whether the identity information of the engine App is associated with the authorization request in step (303); if so, proceed to step (305); otherwise, terminate the third-party authorization login process.
[0057] (305) The manufacturer App initiates an authorization request to the manufacturer server and simultaneously sends the identity information of the engine App and the identity information of the quick app.
[0058] (306) The manufacturer server verifies the identity information of the engine app and the identity information of the quick app.
[0059] (307) After verifying the identity information of the engine app and the identity information of the quick app, the manufacturer server returns a user authorization request for the quick app to the manufacturer app. The request is used to ask the user whether he agrees to authorize the user information in the manufacturer app to be used by the quick app.
[0060] (308) The user confirms through the authorization page provided by the manufacturer App that the user information in the manufacturer App is authorized for use by the merchant App; the manufacturer App sends the user confirmation authorization information to the manufacturer server.
[0061] (309) The manufacturer server generates an authorization credential code based on the user's confirmed authorization information and returns the authorization credential code to the manufacturer App.
[0062] (310) The manufacturer App returns the authorization credential code to the engine App.
[0063] (311) The engine app returns the authorization credential code to the quick app.
[0064] (312) The quick application returns the authorization credential code to the quick application server and requests the quick application server to verify the authorization credential code.
[0065] (313) The quick application server verifies the authorization credential code with the manufacturer server and requests to obtain user information.
[0066] (314) After the manufacturer server verifies the authorization credential code, it returns the user information to the quick application server.
[0067] (315) The quick application server authenticates the user identity based on the user information.
[0068] (316) The quick application server returns the user login status to the quick application, completing the user's login on the quick application server.
[0069] As can be seen from the above process, the engine app controlled by the mobile phone manufacturer is responsible for maintaining and identifying the identity information of the quick app's principal and transmitting it to the manufacturer app along with the authorization request. The manufacturer app then needs to collect the engine app's identity information and transmit both pieces of information (the quick app and the engine app) to the manufacturer's server for security verification. This ensures the legitimacy of the quick apps it interacts with, ensuring that the user's authorization credential code is transmitted to a legitimate third party, thereby ensuring the security of the quick app's authorization login process.
[0070] This method shifts the responsibility for identifying quick apps to the phone manufacturer's engine app. Therefore, modifications to the original protocol primarily occur on the phone manufacturer and platform side. Quick app access remains largely the same as for standard Android apps, reducing modification costs. This third-party authorization login solution is scalable and can be extended and applied to other third-party services within Android quick apps, such as facial recognition and payment deductions.
[0071] Corresponding to the above-mentioned third-party authorized login system, in some embodiments, a third-party authorized login method is provided. Please refer to Figure 4 , which shows a flow chart of the third-party authorized login method. The method is applicable to an authorization terminal, which includes a mobile application APP (i.e., a manufacturer's App) and an application server; the method includes steps S400 to S404.
[0072] S400: In response to the authorization request of the engine APP, the mobile application APP obtains the identity information of the authenticated target quick application uploaded by the engine APP, and collects the identity information of the engine APP.
[0073] The identity information may include, but is not limited to, the package name and signature of the target quick app, and other information that can uniquely identify the target quick app.
[0074] Before uploading the target quick app's identity information, the engine app must authenticate the target quick app's identity information. The engine app deploys several quick apps. When deployed to the engine app, these quick apps synchronize their identity information locally to the engine app for storage. The engine app then synchronizes this quick app's identity information locally to the application server for storage. Therefore, the engine app can authenticate the target quick app's identity information in the following manner: In response to the target quick app's authorization request, the engine app collects the target quick app's identity information. The engine app compares the target quick app's identity information with locally stored quick app identity information. If the pre-stored quick app identity information matches the target quick app's identity information, the target quick app's identity information is authenticated.
[0075] Through the above authentication method, the engine app can confirm that the identity of the target quick app is trustworthy.
[0076] S402: The mobile application APP initiates an authorization request to the application server and simultaneously sends the identity information of the engine APP and the identity information of the target quick application.
[0077] In some implementations, before the mobile application initiates an authorization request to the application server, it is necessary to authenticate the collected identity information of the engine app to confirm that the identity of the engine app is trustworthy. Specifically, the mobile application can authenticate the identity information of the engine app by comparing the identity information of the engine app with the authorization request of the engine app. If the identity information of the engine app is consistent with the authorization request of the engine app, the identity information of the engine app is authenticated.
[0078] The engine APP's authorization request may carry all or part of the engine APP's identity information, or may be mapped to other identifiers using all or part of the engine APP's identity information. Therefore, the mobile application APP may verify whether the engine APP is trustworthy by determining whether the engine APP's authorization request is associated with the engine APP's identity information.
[0079] S404: In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application. After the authentication is successful, the engine APP sends the authorization credentials to the target quick application.
[0080] Among them, since the application server pre-stores the identity information of the engine APP locally, and also stores the identity information of the quick application uploaded by the engine APP and deployed in the engine APP, the application server can use the following method to authenticate the identity information of the engine APP and the identity information of the target quick application: For the identity information of the engine APP, the application server compares the identity information of the engine APP with the locally pre-stored engine identity information for consistency. If the pre-stored engine identity information is consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated.
[0081] For the identity information of the target quick app, the application server compares the identity information of the target quick app with the locally pre-stored quick app identity information. If the pre-stored quick app identity information is consistent with the identity information of the target quick app, the identity information of the target quick app is authenticated.
[0082] Through this method, the application server confirms that the engine app and the target quick app are trustworthy. After authentication, the application server generates an authorization credential code, which the target quick app can use to obtain user information and complete the target quick app login based on the user information.
[0083] Specifically, the authorization credential code is a temporary certificate confirming the user's authorization for the quick app. It is valid for a short period of time. During this period, the target quick app's quick app server can use this temporary certificate to request user information from the application server. The application server verifies the validity of the authorization credential code and, if successful, sends the user information to the quick app server. After authenticating the user based on the user information, the quick app server returns the login status to the target quick app, completing the user's login operation on the target quick app page.
[0084] Corresponding to the above-mentioned third-party authorized login system, in some embodiments, a third-party authorized login method is also provided. Please refer to Figure 5 , which shows a flowchart of the third-party authorized login method. The method is applicable to a quick app end, which includes a target quick app and a quick app server; the method includes steps S500 to S504.
[0085] S500: In response to a user operation, the target quick app sends an authorization request to the engine app, so that the engine app collects and authenticates the identity information of the target quick app, and applies for authorization credentials from the authorization end after the authentication is successful.
[0086] The identity information of the target quick app may include, but is not limited to, the package name and signature of the target quick app, and other information that can uniquely identify the target quick app.
[0087] The Engine App deploys several quick apps. When deployed to the Engine App, these quick apps synchronize their identity information to the Engine App for local storage. The Engine App then synchronizes these quick app identities and its own identity information to the application server for local storage. Therefore, the Engine App can authenticate the target quick app's identity information in the following manner: In response to the target quick app's authorization request, the Engine App collects the target quick app's identity information. The Engine App compares the target quick app's identity information with locally stored quick app identity information. If the pre-stored quick app identity information matches the target quick app's identity information, the target quick app's identity information is authenticated.
[0088] Through the above authentication method, the engine app can confirm that the identity of the target quick app is trustworthy.
[0089] The authorization end includes the mobile app and the application server. After confirming that the target quick app's identity is trustworthy, the engine app initiates an authorization request to the mobile app and simultaneously sends the target quick app's identity information to the mobile app. In response to the engine app's authorization request, the mobile app collects the engine app's identity information and authenticates it to determine whether the engine app's identity is trustworthy. Specifically, the mobile app can authenticate the engine app's identity information by comparing it with the engine app's authorization request. If the engine app's identity information correlates with the engine app's authorization request, the engine app's identity information is authenticated.
[0090] The engine APP's authorization request may carry all or part of the engine APP's identity information, or may be mapped to other identifiers using all or part of the engine APP's identity information. Therefore, the mobile application APP may verify whether the engine APP is trustworthy by determining whether the engine APP's authorization request is associated with the engine APP's identity information.
[0091] After the mobile app confirms the engine app is trustworthy, it initiates an authorization request to the application server and simultaneously sends the engine app's identity information and the target quick app's identity information. In response to the mobile app's authorization request, the application server authenticates the engine app's identity information and the target quick app's identity information. Upon successful authentication, it returns an authorization credential to the mobile app.
[0092] In some embodiments, since the application server locally pre-stores the identity information of the engine APP and also stores the identity information of the quick application uploaded by the engine APP and deployed in the engine APP, the application server can use the following method to authenticate the identity information of the engine APP and the identity information of the target quick application: For the identity information of the engine APP, the application server compares the identity information of the engine APP with the locally pre-stored engine identity information for consistency. If the pre-stored engine identity information is consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated.
[0093] For the identity information of the target quick app, the application server compares the identity information of the target quick app with the locally pre-stored quick app identity information. If the pre-stored quick app identity information is consistent with the identity information of the target quick app, the identity information of the target quick app is authenticated.
[0094] Through this method, the application server confirms that the engine app and the target quick app are trustworthy. After authentication, the application server generates an authorization credential code and sends it to the mobile app. The mobile app sends the authorization credential code to the engine app, which then sends it to the target quick app.
[0095] S502: In response to the authorization credential returned by the engine APP, the target quick app sends the authorization credential to the quick app server.
[0096] Specifically, the authorization credential code is a temporary certificate used by the user to confirm the authorization of the quick app, and has a short validity period.
[0097] S504: In response to obtaining the authorization credential, the quick application server obtains user information from the authorization end based on the authorization credential, and completes target quick application login based on the user information.
[0098] During the validity period of the authorization credential code, the target quick app's quick app server can use this temporary certificate to request user information from the application server. The application server verifies the validity of the authorization credential code and, if successful, sends the user information to the quick app server. After authenticating the user based on the user information, the quick app server returns the login status to the target quick app, completing the user's login on the target quick app page.
[0099] To implement the above-mentioned third-party authorized login method, some embodiments further provide a terminal device. The terminal device is installed with an engine app and a mobile application app provided by the authorization end. The engine app has a target quick app deployed in it. The target quick app performs third-party authorized login based on user information obtained by the mobile application app, specifically including steps S600 to S608.
[0100] S600: In response to the user operation, the target quick app sends an authorization request to the engine APP.
[0101] S602: In response to the authorization request of the target quick app, the engine APP collects and authenticates the identity information of the target quick app, and after the authentication is successful, sends the authorization request and the identity information of the target quick app to the mobile application APP.
[0102] S604: In response to the authorization request from the engine APP, the mobile application APP collects the identity information of the engine APP and sends the authorization request, the identity information of the engine APP, and the identity information of the target quick application to the application server.
[0103] S606: In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application. After the authentication is successful, the engine APP sends the authorization credential to the target quick application.
[0104] S608: In response to obtaining the authorization credentials, the target quick app obtains user information from the application server based on the authorization credentials and completes the login based on the user information.
[0105] Please refer to Figure 6, which shows a schematic diagram of the structure of the above-mentioned terminal device. The terminal device includes a bus 701, a processor 702, a memory 703, and a communication interface 704. The memory 703 stores a computer program. When the computer program runs on the processor 702, the processor 702 executes the specific steps of the target quick application in the terminal device to perform third-party authorization login based on the user information obtained by the mobile application APP. It should be understood that this application does not limit the number of processors and memories in the terminal device.
[0106] Bus 701 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Bus 701 may be divided into an address bus, a data bus, a control bus, and the like. For ease of illustration, FIG6 shows only one line, but this does not imply a single bus or a single type of bus. Bus 701 may include a path for transmitting information between various components of a terminal device (e.g., processor 702, memory 703, and communication interface 704).
[0107] The processor 702 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0108] The memory 703 may include a volatile memory, such as a random access memory (RAM). The memory 703 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0109] The communication interface 704 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the terminal device and other devices or a communication network, such as communication between the terminal device and an application server and a fast application server.
[0110] Those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, can be centralized on a single computing device, or can be distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computing device, and thus, can be stored in a storage device and executed by the computing device. In some cases, the steps shown or described herein can be performed in a different order than that described herein, or can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0111] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0112] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0113] It should be noted that the above examples are merely specific embodiments of the present invention. Obviously, the present invention is not limited to the above examples, and many similar variations are possible. All variations directly derived from or associating with the present invention by those skilled in the art are intended to fall within the scope of protection of the present invention.
Claims
1. A third-party authorized login method, applicable to an authorization terminal, wherein the authorization terminal includes a mobile application APP and an application server; the method includes: In response to the authorization request of the engine APP, the mobile application APP obtains the identity information of the authenticated target quick application uploaded by the engine APP, and collects the identity information of the engine APP; The mobile application APP initiates an authorization request to the application server, and simultaneously sends the identity information of the engine APP and the identity information of the target quick application; In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application. After the authentication is passed, the engine APP sends the authorization credentials to the target quick application, so that the target quick application can obtain user information with the authorization credentials and complete the target quick application login based on the user information.
2. According to the method of claim 1, the engine APP authenticates the identity information of the target quick application, specifically comprising: In response to the authorization request of the target quick application, the engine APP collects the identity information of the target quick application; The engine APP compares the identity information of the target quick application with the locally pre-stored quick application identity information for consistency. If the pre-stored quick application identity information is consistent with the identity information of the target quick application, the identity information of the target quick application is authenticated.
3. According to the method as claimed in claim 1, after the mobile application APP collects the identity information of the engine APP, it also authenticates the identity information of the engine APP. After the authentication is passed, an authorization request, the identity information of the engine APP and the identity information of the target quick application are sent to the application server.
4. The method according to claim 3, wherein the mobile application APP authenticates the identity information of the engine APP, specifically comprising: The identity information of the engine APP is compared with the authorization request of the engine APP. If the identity information of the engine APP is associated with the authorization request of the engine APP, the identity information of the engine APP is authenticated.
5. The method according to claim 1, wherein the application server authenticates the identity information of the engine APP and the identity information of the target quick application, specifically comprising: The application server compares the identity information of the engine APP with the locally pre-stored engine identity information for consistency. If the pre-stored engine identity information is consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated. The application server compares the identity information of the target quick application with the quick application identity information pre-stored locally. A consistency comparison is performed, and if the pre-stored quick application identity information is consistent with the identity information of the target quick application, the identity information of the target quick application is authenticated.
6. The method according to claim 1, before the application server sends the authorization credential to the target quick application through the engine APP, further comprising: The authorization credential is generated in response to the user's authorization confirmation information for the target quick application through the mobile application APP.
7. A third-party authorization login method, applicable to a quick application end, wherein the quick application end includes a target quick application and a quick application server of the target quick application; the method comprises: In response to the user operation, the target quick application sends an authorization request to the engine APP, so that the engine APP collects and authenticates the identity information of the target quick application, and after the authentication is passed, applies for authorization credentials from the authorization end; In response to the authorization credential returned by the engine APP, the target quick application sends the authorization credential to the quick application server; In response to obtaining the authorization credential, the quick application server obtains user information from the authorization end based on the authorization credential, and completes the target quick application login based on the user information.
8. The method according to claim 7, wherein the authorization end includes a mobile application APP and an application server; the engine APP applies to the authorization end for the authorization credential, specifically including: The engine APP initiates an authorization request to the mobile application APP and synchronizes the identity information of the target quick application; In response to the authorization request of the engine APP, the mobile application APP collects the identity information of the engine APP, and sends the authorization request, the identity information of the target quick application and the identity information of the engine APP to the application server; In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the target quick application and the identity information of the engine APP, and returns the authorization credential to the mobile application APP after the authentication is successful; The mobile application APP sends the authorization credential to the target quick application through the engine APP.
9. A third-party authorization login system, including an authorization end and a quick application end; The authorization end is used to execute the method according to any one of claims 1 to 6, and the quick application end is used to execute the method according to any one of claims 7 to 8 to achieve authorized login of the target quick application.
10. A terminal device, wherein the device is installed with an engine APP and a mobile application APP provided by an authorization end, and a target quick application is deployed in the engine APP; The target quick application performs third-party authorization login based on the user information obtained by the mobile application APP, specifically including: In response to the user operation, the target quick app sends an authorization request to the engine APP; In response to the authorization request of the target quick application, the engine APP collects and authenticates the identity information of the target quick application, and after the authentication is passed, sends the authorization request and the identity information of the target quick application to the mobile application APP; In response to the authorization request of the engine APP, the mobile application APP collects the identity information of the engine APP, and sends the authorization request, the identity information of the engine APP and the identity information of the target quick application to the application server; In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application, and after the authentication is passed, sends the authorization credential to the target quick application through the engine APP; In response to obtaining the authorization credential, the target quick application obtains user information from the application server based on the authorization credential, and completes login based on the user information.
11. The device according to claim 10, wherein the target quick application obtains user information from the application server based on the authorization credential and completes the login based on the user information, specifically comprising: The target quick application sends the authorization credential to the quick application server; In response to obtaining the authorization credential, the quick application service requests user information from the application server based on the authorization credential, and completes the target quick application login based on the obtained user information.
Citation Information
Patent Citations
A fast application display method and a terminal device
CN109885302A
Data processing method and device and storage medium
CN110008668A
Third-party authorized login method and system
CN117499137A
Account binding method, device, and system
US20230122238A1
Account association method, device, system, server, and storage medium
WO2020228013A1