Client authentication system, method and apparatus, electronic device, and medium

By setting up a proxy server and a local authentication server on the user side, and using the remote authentication history results of the local authentication server to generate authentication results, the authentication failure problem caused by network interruption of the remote authentication server is solved, and the service continuity of the user side is achieved.

WO2025111876A1PCT designated stage expired Publication Date: 2025-06-05SIEMENS AG +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/135164
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-29
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

The existing remote authentication system cannot perform authentication normally when the network is interrupted or delayed between the user and the remote authentication server, resulting in the user being unable to access the application server, affecting business continuity.

Method used

Set up a proxy server and a local authentication server on the user side. The proxy server receives authentication requests from the user side and forwards them to the remote authentication server. If the remote authentication result cannot be obtained, it will forward to the local authentication server. Use the remote authentication history results saved by the local authentication server to generate the local authentication result and return the result to the user side.

Benefits of technology

Even if there is a network interruption or delay between the user and the remote authentication server, authentication results can still be generated through the local authentication server to ensure that the user can access the application server normally and ensure business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023135164_05062025_PF_FP_ABST
    Figure CN2023135164_05062025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present invention are a client authentication system, method and apparatus, an electronic device, and a medium. The system comprises a proxy server and a local authentication server. The proxy server is used for receiving an authentication request from a client, the authentication request comprising login information; sending the authentication request to a remote authentication server; and sending the authentication request to the local authentication server when no remote authentication result can be obtained from the remote authentication server. The local authentication server is used for implementing associated storage of the login information and a historical remote authentication result provided by the remote authentication server; and determining a local authentication result on the basis of the historical remote authentication result, and sending the local authentication result to the proxy server. The proxy server is used for returning the local authentication result to the client. When the network connection to the remote authentication server is interrupted, on the basis of the collaborative cooperation between the proxy server and the local authentication server, an authentication service is provided for the client, ensuring the service continuity.
Need to check novelty before this filing date? Find Prior Art

Description

User-side authentication system, method, device, electronic device, and medium Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a user-side authentication system, method, device, electronic equipment, and medium. Background Art

[0002] Remote authentication technology verifies the user's identity over a remote connection to determine whether access rights are granted. Currently, application servers integrated with remote authentication servers require the client to directly access the remote authentication server to perform authentication. For example, the login process involves redirecting to a login page provided by the remote authentication server.

[0003] However, a network interruption with the remote authentication server may cause the client to be unable to connect to the remote authentication server normally, resulting in the client being unable to access the application server normally.

[0004] Summary of the Invention

[0005] The embodiments of the present invention provide a user-side authentication system, method, device, electronic device, and medium.

[0006] A user-side authentication system includes a proxy server and a local authentication server:

[0007] The proxy server is configured to receive an authentication request from a user terminal, the authentication request including login information; send the authentication request to a remote authentication server; and when a remote authentication result cannot be obtained from the remote authentication server, send the authentication request to the local authentication server;

[0008] The local authentication server is configured to associate and store the login information with a remote authentication history result provided by the remote authentication server; determine a local authentication result based on the remote authentication history result, and send the local authentication result to the proxy server;

[0009] The proxy server is used to return the local authentication result to the user terminal.

[0010] Therefore, when the remote authentication result cannot be obtained from the remote authentication server, the proxy server, acting as a forwarding agent, can send an authentication request to the local authentication server. The local authentication server generates a local authentication result based on its stored remote authentication history. The proxy server returns the local authentication result to the client, thus completing authentication for the client. Therefore, even if the network between the client and the remote authentication server is interrupted or delayed, the client can still obtain the authentication result and access the application server, ensuring business continuity.

[0011] In one embodiment, the inability to obtain the remote authentication result from the remote authentication server includes: the inability to obtain the remote authentication result from the remote authentication server within a predetermined time; the proxy server is used to return the remote authentication result to the user terminal when the remote authentication result is obtained from the remote authentication server within the predetermined time.

[0012] Therefore, if the remote authentication result cannot be obtained from the remote authentication server within the predetermined time, it can be determined that the network between the user terminal and the remote authentication server is disconnected or delayed. Furthermore, if the remote authentication result can be obtained from the remote authentication server within the predetermined time, the proxy server returns the remote authentication result to the user terminal, thereby maintaining compatibility with existing authentication architectures.

[0013] In one embodiment, the proxy server is used to send the remote authentication result and the login information to the local authentication server; and the local authentication server is used to update the remote authentication history result based on the remote authentication result.

[0014] Therefore, the proxy server sends the remote authentication result and login information to the local authentication server. The local authentication server can use the remote authentication result to update the remote authentication history result corresponding to the login information, ensuring the timeliness and accuracy of the authentication result.

[0015] In one embodiment, the local authentication server is used to parse the authentication scope field from the remote authentication history result; when the access command included in the authentication request belongs to the scope field, a local authentication result indicating that the authentication is passed is generated; when the access command included in the authentication request does not belong to the scope field, a local authentication result indicating that the authentication is not passed is generated.

[0016] It can be seen that based on the analysis and processing of the remote authentication history results by the local authentication server, the local authentication results are accurately generated, ensuring the accuracy of the authentication.

[0017] A user-side authentication method, comprising:

[0018] receiving an authentication request from a user terminal, wherein the authentication request includes login information;

[0019] Sending the authentication request to a remote authentication server;

[0020] When the remote authentication result cannot be obtained from the remote authentication server, sending the authentication request to the local authentication server, wherein the local authentication server has associated and saved the login information with the remote authentication history result provided by the remote authentication server;

[0021] receiving a local authentication result from the local authentication server, wherein the local authentication result is determined based on the remote authentication history result;

[0022] The local authentication result is returned to the user terminal.

[0023] Therefore, when the remote authentication result cannot be obtained from the remote authentication server, the proxy server, acting as a forwarding agent, can send an authentication request to the local authentication server. The local authentication server generates a local authentication result based on its stored remote authentication history. The proxy server returns the local authentication result to the client, thus achieving authentication for the client. Therefore, even if the network between the client and the remote authentication server is interrupted or delayed, the client can still obtain the authentication result and access the application server, ensuring business continuity.

[0024] In one embodiment, the failure to obtain the remote authentication result from the remote authentication server includes: the failure to obtain the remote authentication result from the remote authentication server within a predetermined time; the method includes:

[0025] When a remote authentication result is obtained from the remote authentication server within the predetermined time, the remote authentication result is returned to the user terminal.

[0026] Therefore, if the remote authentication result cannot be obtained from the remote authentication server within the predetermined time, it can be determined that the network between the user terminal and the remote authentication server is disconnected or delayed. Furthermore, if the remote authentication result can be obtained from the remote authentication server within the predetermined time, the proxy server returns the remote authentication result to the user terminal, thereby maintaining compatibility with existing authentication architectures.

[0027] In one embodiment, it includes:

[0028] The remote authentication result and the login information are sent to the local authentication server, so that the local authentication server updates the remote authentication history result based on the remote authentication result.

[0029] Therefore, the proxy server sends the remote authentication result and login information to the local authentication server. The local authentication server can use the remote authentication result to update the remote authentication history result corresponding to the login information, thereby ensuring the timeliness and accuracy of the authentication.

[0030] A user-side authentication device, comprising:

[0031] A first receiving module is configured to receive an authentication request from a user terminal, wherein the authentication request includes login information;

[0032] A first sending module, configured to send the authentication request to a remote authentication server;

[0033] a second sending module, configured to send the authentication request to a local authentication server when a remote authentication result cannot be obtained from the remote authentication server, wherein the local authentication server has associated and saved the login information with a remote authentication history result provided by the remote authentication server;

[0034] A second receiving module is configured to receive a local authentication result from the local authentication server, wherein the local authentication result is determined based on the remote authentication history result;

[0035] The return module is used to return the local authentication result to the user terminal.

[0036] Therefore, when the remote authentication result cannot be obtained from the remote authentication server, the proxy server, acting as a forwarding agent, can send an authentication request to the local authentication server. The local authentication server generates a local authentication result based on its stored remote authentication history. The proxy server returns the local authentication result to the client, thus achieving authentication for the client. Therefore, even if the network between the client and the remote authentication server is interrupted or delayed, the client can still obtain the authentication result and access the application server, ensuring business continuity.

[0037] In one embodiment, the failure to obtain the remote authentication result from the remote authentication server includes: failure to obtain the remote authentication result from the remote authentication server within a predetermined time;

[0038] The returning module is configured to return the remote authentication result to the user terminal when the remote authentication result is obtained from the remote authentication server within the predetermined time.

[0039] Therefore, if the remote authentication result cannot be obtained from the remote authentication server within the predetermined time, it can be determined that the network between the user terminal and the remote authentication server is disconnected or delayed. Furthermore, if the remote authentication result can be obtained from the remote authentication server within the predetermined time, the proxy server returns the remote authentication result to the user terminal, thereby maintaining compatibility with existing authentication architectures.

[0040] In one embodiment, the second sending module is configured to send the remote authentication result and the login information to the local authentication server, so that the local authentication server updates the remote authentication history result based on the remote authentication result.

[0041] Therefore, the proxy server sends the remote authentication result and login information to the local authentication server. The local authentication server can use the remote authentication result to update the remote authentication history result corresponding to the login information, thereby ensuring the timeliness of the authentication.

[0042] An electronic device, comprising:

[0043] processor;

[0044] a memory for storing executable instructions of the processor;

[0045] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the user terminal authentication method as described in any one of the above items.

[0046] A computer-readable storage medium stores computer instructions, wherein the computer instructions, when executed by a processor, implement the user terminal authentication method as described in any one of the above items.

[0047] A computer program product comprises a computer program, wherein when the computer program is executed by a processor, the computer program implements the user terminal authentication method as described in any one of the above items. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, so that those skilled in the art will understand the above and other features and advantages of the present invention more clearly. In the accompanying drawings:

[0049] FIG1 is an exemplary structural diagram of a remote authentication system at a user end in the prior art.

[0050] FIG. 2 is an exemplary schematic diagram of a remote authentication process in the prior art.

[0051] FIG3 is an exemplary structural diagram of an authentication system at a user terminal according to an embodiment of the present invention.

[0052] FIG4 is an exemplary schematic diagram of an authentication method for a user terminal according to an embodiment of the present invention.

[0053] FIG5 is a schematic diagram of an authentication process at a user end when a remote authentication server is available according to an embodiment of the present invention.

[0054] FIG6 is a schematic diagram of an authentication process at a user end when a remote authentication server is unavailable according to an embodiment of the present invention.

[0055] FIG7 is an exemplary structural diagram of an authentication device at a user terminal according to an embodiment of the present invention.

[0056] FIG8 is an exemplary structural diagram of an electronic device according to an embodiment of the present invention.

[0057] The accompanying drawings are numerals as follows: DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention is further described in detail with reference to the following examples.

[0059] For the sake of brevity and intuitiveness in description, the solution of the present invention is explained below by describing several representative implementations. A large number of details in the implementations are only used to help understand the solution of the present invention. However, it is obvious that the technical solution of the present invention may not be limited to these details when implemented. In order to avoid unnecessarily obscuring the solution of the present invention, some implementations are not described in detail, but only a framework is given. Hereinafter, "including" means "including but not limited to", and "according to..." means "at least according to..., but not limited to only according to...". Due to the language habits of Chinese, when the number of a component is not specifically specified below, it means that the component can be one or more, or can be understood as at least one.

[0060] FIG1 exemplarily shows an exemplary structural diagram of a remote authentication system for a user terminal in the prior art.

[0061] First, the client 10 authenticates with the remote authentication server 11 using a login / token request process 13. This process includes a login phase and a token request phase. In the login phase, the client 10 provides a username and password to remotely log in to the remote authentication server 11. In the token request phase, executed after logging in to the remote authentication server 11, the client 10 sends a token request containing an access command, and the remote authentication server 11 returns a corresponding token to the client 10.

[0062] Then, the user terminal 10 carries the token in an access request 14 containing an access command to request access to the application server 12. The application server 12 can verify the token in the remote authentication server 11. When the verification is successful, the application server 12 allows the user terminal 10 to perform access based on the access command.

[0063] FIG2 is an exemplary schematic diagram of a remote authentication process in the prior art. In FIG2 , the process includes:

[0064] Step 16: Determine whether the client 10 is in an unauthenticated state.

[0065] Step 17: The client 10 sends an access request including an access command to the application server 12. For example, the access command may include obtaining an email address, obtaining a user ID, or obtaining user profile information, etc.

[0066] Step 18 : The application server 12 rejects the access request and prompts the client 10 to redirect to the remote authentication server 11 .

[0067] Step 19: The client 10 sends an authentication request to the remote authentication server 11 . The authentication request may include login information and the type of access command.

[0068] Step 20: The remote authentication server 11 determines whether to allow access by the user terminal 10 based on the login information, and performs authentication on the authentication request if allowed, and returns the authentication result for this type of access command to the user terminal 10, for example, the authentication result may include a token indicating that access is allowed.

[0069] Step 21: Determine whether the client 10 is in an authenticated state.

[0070] Step 22: The client 10 sends an access request including a token and an access command to the application server 12 .

[0071] Step 23: The application server 12 returns a response message to the user terminal 10 indicating that access is allowed.

[0072] As can be seen, in the prior art, authentication of the user terminal is completely dependent on the remote authentication server. If the network between the user terminal and the remote authentication server is interrupted or delayed, the user terminal may not be able to connect to the remote authentication server in time, and the user terminal cannot be authenticated, resulting in the user terminal being unable to access the application server.

[0073] The above disclosure details the description of the existing technologies that can be improved, the reasons for the improvements, and the thought and analysis process. In fact, the recognition of the above-mentioned technologies that can be improved is not common knowledge in the field, but rather a novel discovery made by the applicant during research. In addition, the tracing of the reasons for the improvements and the thought and analysis process for overcoming the technical deficiencies are also the results of the applicant's gradual analysis during actual research and are not common knowledge in the field.

[0074] In an embodiment of the present invention, a local authentication server is set as a backup of the remote authentication server so that when the user terminal cannot normally access the remote authentication server, the authentication is switched to the local authentication server. In addition, a proxy server is set between the user terminal and the local authentication server and the remote authentication server. The proxy server forwards messages (for example, login request / response and token request / response) between the user terminal and the authentication server (including the local authentication server and the remote authentication server). The proxy server can also synchronize login information and remote authentication results from the remote authentication server to the local authentication server. The proxy server can also perform switching between the remote authentication server and the local authentication server based on the connection status of the remote authentication server. In addition, the application server is configured using a proxy server instead of a remote authentication server.

[0075] Figure 3 is an exemplary structural diagram of a user-side authentication system according to an embodiment of the present invention. In Figure 3, the authentication system of user terminal 40 includes a proxy server 42 and a local authentication server 43. User terminal 40, application server 41, proxy server 42, and local authentication server 43 are all located on local terminal 90. Remote authentication server 44 is located remotely from local terminal 90.

[0076] Proxy server 42 is configured to receive an authentication request from client 40, the authentication request including login information (e.g., username and password). Proxy server 42 is also configured to send the authentication request to remote authentication server 44. If remote authentication server 44 is accessible, remote authentication server 44 directly authenticates the authentication request.

[0077] When remote server 44 is inaccessible, proxy server 42 cannot obtain the remote authentication result from remote authentication server 44. In this case, proxy server 42 sends an authentication request to local authentication server 43. Local authentication server 43 associates and stores the login information with the remote authentication history results provided by remote authentication server 44, determines the local authentication result based on the remote authentication history results, and sends the local authentication result to proxy server 42. Proxy server 42 then returns the local authentication result to client 40.

[0078] As can be seen, when the remote authentication result cannot be obtained from the remote authentication server, the proxy server, acting as a forwarding agent, can send an authentication request to the local authentication server. The local authentication server then generates a local authentication result using its own stored historical remote authentication results generated by the remote authentication server for the login information. The proxy server then returns the local authentication result to the client, thus completing authentication for the client. Therefore, even if the network between the client and the remote authentication server is interrupted or delayed, the client can still obtain the authentication result and access the application server, ensuring service continuity.

[0079] In one embodiment, the failure to obtain the remote authentication result from the remote authentication server 44 includes: the failure to obtain the remote authentication result from the remote authentication server 44 within a predetermined time.

[0080] It can be seen that when the remote authentication result cannot be obtained from the remote authentication server within the predetermined time, it can be determined that the network between the user terminal and the remote authentication server is disconnected or delayed.

[0081] In one embodiment, the proxy server 42 is configured to return the remote authentication result to the user terminal 40 upon receiving it from the remote authentication server 44 within a predetermined time. Specifically, the proxy server 42 performs authentication on the remote authentication server 44 based on a login / token request process. The login / token request process includes a login portion and a token request portion. In the login portion, the proxy server 42 provides a username and password to remotely log in to the remote authentication server 44. In the token request portion, executed after logging in to the remote authentication server 44, the proxy server 42 sends a token request indicating the type of access command, and the remote authentication server 44 returns the corresponding token to the proxy server 42. The proxy server 42 returns the token to the user terminal 40. The user terminal 40 then includes the token in an access request containing an access command to request access to the application server 41. The application server 41 can verify the token on the local authentication server 43 through forwarding by the proxy server 42. If verification is successful, the application server 41 allows the user terminal 40 to perform access based on the access command.

[0082] Therefore, when the remote authentication result can be obtained from the remote authentication server within a predetermined time, the proxy server 42 returns the remote authentication result to the user terminal, thereby being compatible with the existing authentication architecture.

[0083] In one embodiment, the proxy server 42 is used to send the remote authentication result and login information to the local authentication server 43; the local authentication server 43 is used to update the remote authentication history result based on the remote authentication result.

[0084] Therefore, the proxy server sends the remote authentication result and login information to the local authentication server. The local authentication server can use the remote authentication result to update the remote authentication history result corresponding to the login information, ensuring the timeliness and accuracy of the authentication.

[0085] In one embodiment, the local authentication server 43 is used to parse the authentication scope (Scope) field from the remote authentication history result; when the access command included in the authentication request belongs to the scope field, a local authentication result indicating that the authentication is passed is generated; when the access command included in the authentication request does not belong to the scope field, a local authentication result indicating that the authentication is not passed is generated.

[0086] As can be seen, the local authentication server 43 accurately generates local authentication results based on its parsing of historical remote authentication results, ensuring authentication accuracy. Furthermore, the local authentication server does not completely replace the remote authentication server's functionality. Instead, by storing historical authentication results completed by the local authentication server, it implements a similar authentication result cache (e.g., by modifying the authentication scope field or issuer field accordingly). This ensures both the authority of the remote authentication server and service continuity.

[0087] For example: Assume that the local authentication server 43 has associated and saved: login information 1 and the remote authentication history results of login information 1. The remote authentication history results of login information 1 include an authentication scope field, a valid time field, and an issuer field. Among them: the authentication scope field describes the types of access commands that the user end of login information 1 is allowed to access during the historical remote authentication process. For example, it can include: obtaining an email address, obtaining a user ID, or obtaining user profile information, etc. The valid time field describes the validity period of the remote authentication history results. The issuer field describes the entity that provides the remote authentication history results, such as the URL address of the remote authentication server 44.

[0088] Assume that the type of access command contained in the authentication request sent by the proxy server 42 is: Get email address. The local authentication server 43 compares it with the authentication scope field in the remote authentication history result and determines that the type of access command contained in the authentication request (i.e., Get email address) belongs to the authentication scope field. Therefore, the local authentication server 43 generates a local authentication result representing the consent to access. The local authentication result may include an authentication scope field, a valid time and an issuer field. Among them: the authentication scope field in the local authentication result is specifically: Get email address. The valid time field in the local authentication result specifies the valid time of the local authentication result. The issuer field in the local authentication result describes the entity that provides the local authentication history result, such as the URL address of the local authentication server 43. It can be seen that compared with the remote authentication history result, the authentication scope field, valid time field and issuer field in the local authentication result are all modified accordingly, thereby realizing a novel authentication.

[0089] Based on the above description, the present invention also provides a method for authenticating a user terminal. FIG4 is an exemplary schematic diagram of the method for authenticating a user terminal according to the present invention. The method can be executed by the proxy server 42 in FIG3.

[0090] As shown in FIG4 , the method includes:

[0091] Step 101: Receive an authentication request from a user terminal, where the authentication request includes login information.

[0092] Step 102: Send an authentication request to a remote authentication server.

[0093] Step 103: When the remote authentication result cannot be obtained from the remote authentication server, an authentication request is sent to the local authentication server, wherein the local authentication server has associated and saved the login information with the remote authentication history result provided by the remote authentication server.

[0094] Step 104: Receive a local authentication result from the local authentication server, wherein the local authentication result is determined based on the remote authentication history result.

[0095] Step 105: Return the local authentication result to the user terminal.

[0096] In one embodiment, the inability to obtain the remote authentication result from the remote authentication server includes: the inability to obtain the remote authentication result from the remote authentication server within a predetermined time; the method includes: when the remote authentication result is obtained from the remote authentication server within the predetermined time, returning the remote authentication result to the user terminal.

[0097] In one embodiment, the method includes sending the remote authentication result and login information to a local authentication server, so that the local authentication server updates the remote authentication history result based on the remote authentication result.

[0098] 3, FIG5 is a schematic diagram of the authentication process of the user terminal when the remote authentication server is available according to an embodiment of the present invention. In FIG5, the process includes:

[0099] Step 50: Determine whether the client 40 is in an unauthenticated state.

[0100] Step 51: The client 40 sends an access request including an access command to the application server 41. For example, the access command may include obtaining an email address, obtaining a user ID, or obtaining user profile information, etc.

[0101] Step 52 : The application server 41 rejects the access request and prompts the client 40 to redirect to the remote authentication server 44 .

[0102] Step 53: The client 40 sends an authentication request to the proxy server 42. The authentication request may include login information and the type of access command.

[0103] Step 54 : The proxy server 42 sends an authentication request to the remote authentication server 44 .

[0104] Step 55: The remote authentication server 11 determines whether to allow access based on the login information, and performs authentication on the authentication request if access is allowed, and returns the authentication result for this type of access command to the proxy server 42, for example, the authentication result may include a token indicating that access is allowed.

[0105] Step 56 : The proxy server 42 sends the login information and the remote authentication result to the local authentication server 43 .

[0106] Step 57: Local authentication server 43 associates and stores the login information with the remote authentication result. When local authentication server 43 subsequently receives subsequent remote authentication results for the login information, it updates the currently stored remote authentication result based on the subsequent remote authentication results. The updating process may include adding a new access command allowing access to the authentication scope field when a new access command allowing access is received.

[0107] Step 58 : The proxy server 42 sends the remote authentication result returned by the remote authentication server 11 to the client 40 .

[0108] Step 59: Determine whether the client 40 is authenticated.

[0109] Step 60 : The client 40 sends an access request including a token and an access command to the application server 41 .

[0110] Step 61: The application server 41 returns a response message to the user terminal 40 indicating that access is allowed.

[0111] 3 , FIG6 is a schematic diagram of an authentication process at a user end when a remote authentication server is unavailable according to an embodiment of the present invention.

[0112] In Figure 6, the process includes:

[0113] Step 70: Determine whether the client 40 is in an unauthenticated state.

[0114] Step 71: The client 40 sends an access request including an access command to the application server 41. For example, the access command may include obtaining an email address, obtaining a user ID, or obtaining user profile information, etc.

[0115] Step 72 : The application server 41 rejects the access request and prompts the client 40 to redirect to the remote authentication server 44 .

[0116] Step 73: The client 40 sends an authentication request to the proxy server 42. The authentication request may include login information and the type of access command.

[0117] Step 74 : The proxy server 42 sends an authentication request to the remote authentication server 44 .

[0118] Step 75 : When the proxy server 42 cannot receive the remote authentication result from the remote authentication server 44 within a predetermined time, the proxy server 42 sends an authentication request to the local authentication server 43 .

[0119] Step 76: Local authentication server 43 parses the authentication scope field from its stored remote authentication history corresponding to the login information. If the type of access command included in the authentication request falls within this scope field, a local authentication result is generated, indicating that authentication was successful. If the type of access command included in the authentication request does not fall within this scope field, a local authentication result is generated, indicating that authentication failed. This step 76 assumes that authentication was successful, and the generated local authentication result contains a token.

[0120] Step 77 : The proxy server 42 returns the local authentication result to the client 44 .

[0121] Step 78: Determine whether the client 40 is authenticated.

[0122] Step 79 : The client 40 sends an access request including a token and an access command to the application server 41 .

[0123] Step 80: The application server 41 returns a response message to the user terminal 40 indicating that access is allowed.

[0124] FIG7 is an exemplary structural diagram of an authentication device for a user terminal according to an embodiment of the present invention. As shown in FIG7 , the authentication device 700 for a user terminal includes: a first receiving module 701 for receiving an authentication request from a user terminal, the authentication request including login information; a first sending module 702 for sending the authentication request to a remote authentication server; a second sending module 703 for sending the authentication request to a local authentication server when a remote authentication result cannot be obtained from the remote authentication server, wherein the local authentication server has associated and stored the login information with a remote authentication history result provided by the remote authentication server; a second receiving module 704 for receiving a local authentication result from the local authentication server, wherein the local authentication result is determined based on the remote authentication history result; and a returning module 705 for returning the local authentication result to the user terminal.

[0125] In one embodiment, the inability to obtain the remote authentication result from the remote authentication server includes: the inability to obtain the remote authentication result from the remote authentication server within a predetermined time; the return module 705 is used to return the remote authentication result to the user end when the remote authentication result is obtained from the remote authentication server within the predetermined time.

[0126] In one embodiment, the second sending module 703 is configured to send the remote authentication result and login information to the local authentication server, so that the local authentication server updates the remote authentication history result based on the remote authentication result.

[0127] The embodiment of the present invention also proposes an electronic device with a processor-memory architecture. Figure 8 is a structural diagram of an electronic device according to an embodiment of the present invention. As shown in Figure 8, the electronic device 800 includes a processor 801, a memory 802, and a computer program stored on the memory 802 and executable on the processor 801. When the computer program is executed by the processor 801, it implements any of the above user-side authentication methods. Among them, the memory 802 can be specifically implemented as a variety of storage media such as an electrically erasable programmable read-only memory (EEPROM), a flash memory (Flash memory), and a programmable read-only memory (PROM). The processor 801 can be implemented to include one or more central processing units or one or more field programmable gate arrays, wherein the field programmable gate array integrates one or more central processing unit cores. Specifically, the central processing unit or the central processing unit core can be implemented as a CPU, an MCU, or a DSP, and so on.

[0128] It should be noted that not all steps and modules in the above processes and structure diagrams are required, and certain steps or modules can be omitted based on actual needs. The execution order of the steps is not fixed and can be adjusted as needed. The division of the modules is merely for the convenience of describing the functional division adopted. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can be implemented by the same module. These modules can be located in the same device or in different devices.

[0129] The hardware modules in each embodiment can be implemented mechanically or electronically. For example, a hardware module may include a specially designed permanent circuit or logic device (such as a dedicated processor, such as an FPGA or ASIC) for performing a specific operation. The hardware module may also include a programmable logic device or circuit (such as a general-purpose processor or other programmable processor) temporarily configured by software to perform a specific operation. As for whether to implement the hardware module mechanically, or using a dedicated permanent circuit, or using a temporarily configured circuit (such as configured by software), it can be decided based on cost and time considerations.

[0130] The above are only preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. An authentication system for a client, characterized in that, it includes a proxy server (42) and a local authentication server (43): The proxy server (42) is used to receive an authentication request from the client (40), and the authentication request contains login information; send the authentication request to the remote authentication server (44); When the remote authentication result cannot be obtained from the remote authentication server (44), send the authentication request to the local authentication server (43); The local authentication server (43) is used to associate and save the login information with the remote authentication historical result provided by the remote authentication server (44); determine the local authentication result based on the remote authentication historical result, and send the local authentication result to the proxy server (42); The proxy server (42) is used to return the local authentication result to the client (40).

2. The system according to claim 1, characterized in that, The situation that the remote authentication result cannot be obtained from the remote authentication server (44) includes: the remote authentication result cannot be obtained from the remote authentication server (44) within a predetermined time; The proxy server (42) is used to return the remote authentication result to the client (40) when the remote authentication result is obtained from the remote authentication server (44) within the predetermined time.

3. The system according to claim 2, characterized in that, The proxy server (42) is used to send the remote authentication result and the login information to the local authentication server (43); The local authentication server (43) is used to update the remote authentication historical result based on the remote authentication result.

4. The system according to any one of claims 1-3, characterized in that, The local authentication server (43) is used to parse the authentication scope field from the remote authentication historical result; when the access command included in the authentication request belongs to the scope field, generate a local authentication result indicating successful authentication, and when the access command included in the authentication request does not belong to the scope field, generate a local authentication result indicating failed authentication.

5. An authentication method for a client, characterized in that, it includes: Receiving (101) an authentication request from the client, and the authentication request contains login information; Sending (102) the authentication request to the remote authentication server; When the remote authentication result cannot be obtained from the remote authentication server, sending (103) the authentication request to the local authentication server, where the local authentication server has associated and saved the login information with the remote authentication historical result provided by the remote authentication server; Receiving (104) a local authentication result from the local authentication server, where the local authentication result is determined based on the remote authentication historical result; Returning (105) the local authentication result to the client.

6. The method according to claim 5, characterized in that, The inability to obtain a remote authentication result from the remote authentication server includes: being unable to obtain a remote authentication result from the remote authentication server within a predetermined time; The method includes: When a remote authentication result is obtained from the remote authentication server within the predetermined time, returning the remote authentication result to the client.

7. The method according to claim 6, wherein, it includes: Sending the remote authentication result and the login information to the local authentication server, so that the local authentication server updates the remote authentication historical result based on the remote authentication result.

8. An authentication device for a client, wherein, it includes: A first receiving module (701) for receiving an authentication request from a client, the authentication request including login information; A first sending module (702) for sending the authentication request to a remote authentication server; A second sending module (703) for sending the authentication request to a local authentication server when a remote authentication result cannot be obtained from the remote authentication server, where the local authentication server has associated and saved the login information and the remote authentication historical result provided by the remote authentication server; A second receiving module (704) for receiving a local authentication result from the local authentication server, where the local authentication result is determined based on the remote authentication historical result; A return module (705) for returning the local authentication result to the client.

9. The device according to claim 8, wherein, The inability to obtain a remote authentication result from the remote authentication server includes: being unable to obtain a remote authentication result from the remote authentication server within a predetermined time; The return module (705) for returning the remote authentication result to the client when a remote authentication result is obtained from the remote authentication server within the predetermined time.

10. The device according to claim 9, wherein, The second sending module (703) for sending the remote authentication result and the login information to the local authentication server, so that the local authentication server updates the remote authentication historical result based on the remote authentication result.

11. An electronic device, wherein, it includes: A processor (801); A memory (802) for storing executable instructions of the processor (801); The processor (801) for reading the executable instructions from the memory (802) and executing the executable instructions to implement the authentication method for the client according to any one of claims 5-7.

12. A computer-readable storage medium having computer instructions stored thereon, wherein, The computer instructions, when executed by a processor, implement the authentication method for the client according to any one of claims 5-7.

13. A computer program product, wherein, it includes a computer program, and the computer program, when executed by a processor, implements the authentication method for the client according to any one of claims 5-7.

Citation Information

Patent Citations

  • Third party login authentication method and system, proxy server and client

    CN106453414A

  • Authentication method, device and system and medium

    CN110753062A

  • Authentication method, device, equipment and medium

    CN110753063A

  • System and method for user authorization access management at the local administrative domain during the connection of a user to an ip network

    CN1918885A

  • Electronic device including local identity provider server for single sign on and related methods

    US20190364033A1