Login control method, application client, device, medium, and program product

By decoupling the domain controller and terminal device management logic in the Active Directory domain network architecture, and using the client and server of the target application to modify the system password to the application password and associate the account, the problems of high coupling of the domain controller and multiple password login are solved, thereby simplifying login and improving security.

WO2025251680A1PCT designated stage Publication Date: 2025-12-11BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/077221
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-07
Filing Date
2025-02-13
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

In existing technologies, when using Active Directory (AD) domains for network management, the high degree of coupling between the domain controller and AD domain resources leads to low network security. Users need to enter multiple different passwords to log in, and improper password management results in password complexity and replacement cycles that do not meet requirements, increasing network security risks.

Method used

A new network architecture is provided that decouples the management logic of the domain controller from that of the terminal device. Through the application client and server of the target application, in response to the password change command, a password change interface is displayed, the system password of the terminal device is authenticated and changed to the application password, and the application account and system account are associated to achieve unified login.

Benefits of technology

It simplifies the user login process, reduces the risk of network attacks, improves network security and management efficiency, reduces the risk of password leakage, and achieves unified password management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025077221_11122025_PF_FP_ABST
    Figure CN2025077221_11122025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of computers. Disclosed are a login control method, an application client, a device, a medium, and a program product. The method is applied to an application client, and comprises: in response to a password modification instruction having been received, displaying a first password modification interface, and receiving password modification information by means of the first password modification interface, wherein the password modification information comprises a system password of a terminal device in which an application client is located, and an application account and a first application password, which are registered by a first object in an identity source and are used for logging in to a target application; authenticating the password modification information, and when the authentication is successful, modifying the system password to the first application password; and associating the application account with a system account of the terminal device, and sending to an application serving end the association relationship between the application account and the system account.
Need to check novelty before this filing date? Find Prior Art

Description

Login control method, application client, device, medium and program product

[0001] Cross-reference to related applications

[0002] The present application claims priority to the Chinese patent application No. 202410741994.6, filed on June 7, 2024, and entitled "Login control method, application client, device, medium and program product", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] The present disclosure relates to the technical field of computer, and specifically relates to a login control method, an application client, a device, a medium and a program product. BACKGROUND

[0004] At present, the network of many enterprises and other organizations uses an AD domain (Active Directory Domain) to uniformly manage the devices in the network. For example, the password complexity, password replacement period, and installed application software of the devices can be uniformly managed. SUMMARY

[0005] Therefore, the present disclosure provides a login control method, an application client, an electronic device, a computer readable storage medium and a computer program product, which can simplify login.

[0006] In an aspect, the present disclosure provides a login control method, which is applied to an application client, and the method comprises:

[0007] In response to receiving a password modification instruction, a first password modification interface is displayed, and password modification information is received through the first password modification interface, wherein the password modification information comprises a system password of a terminal device where the application client is located, an application account registered in an identity source for logging into the target application by the first object, and a first application password;

[0008] The password modification information is authenticated, and in the case of passing the authentication, the system password is modified to the first application password;

[0009] The application account is associated with a system account of the terminal device, and the association relationship between the application account and the system account is sent to an application server.

[0010] In an aspect, the present disclosure provides an application client, which comprises:

[0011] The login information obtaining module is configured to, in response to receiving the password modification instruction, display a first password modification interface, and receive password modification information through the first password modification interface, wherein the password modification information comprises a system password of a terminal device where the application client is located, an application account registered in an identity source by the first object for logging into the target application, and a first application password;

[0012] The password modification module is configured to authenticate the password modification information, and modify the system password to the first application password if the authentication is passed.

[0013] The account association module is configured to associate the application account with a system account of the terminal device, and send the association relationship between the application account and the system account to an application server.

[0014] Another aspect of the present disclosure also provides a computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to implement the method described above.

[0015] Another aspect of the present disclosure also provides an electronic device comprising a processor and a memory, wherein the memory is configured to store a computer program, and the computer program is executed by the processor to implement the method described above.

[0016] Another aspect of the present disclosure also provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the method described above. BRIEF DESCRIPTION OF DRAWINGS

[0017] The features and advantages of the present disclosure will be more clearly understood through the following detailed description taken in conjunction with the accompanying drawings, which are shown by way of illustration and not by way of limitation, wherein:

[0018] FIG. 1 shows a network architecture schematic diagram of an AD domain;

[0019] FIG. 2 shows a new network architecture schematic diagram provided by an embodiment of the present disclosure;

[0020] FIG. 3 shows a flow schematic diagram of a login control method provided by an embodiment of the present disclosure;

[0021] FIG. 4 shows a schematic diagram of an application client login interface provided by an embodiment of the present disclosure;

[0022] FIG. 5 shows a schematic diagram of a first password modification interface provided by an embodiment of the present disclosure;

[0023] FIG. 6 shows a module interaction schematic diagram for modifying a system password based on a first application password provided by an embodiment of the present disclosure;

[0024] FIG. 7 shows a schematic diagram of module interaction for modifying a system password from a first application password to a second application password according to an embodiment of the present disclosure;

[0025] FIG. 8 shows a schematic diagram of module interaction for modifying a system password locally at a terminal device according to an embodiment of the present disclosure;

[0026] FIG. 9 shows a schematic diagram of modules of a login control system according to an embodiment of the present disclosure;

[0027] FIG. 10 shows a schematic diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0028] For the purpose of making the objectives, technical solutions and advantages of embodiments of the present disclosure clearer, the technical solutions in embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in embodiments of the present disclosure. Obviously, the described embodiments are some of the embodiments of the present disclosure but not all of the embodiments of the present disclosure. Based on the embodiments in the present disclosure, any other embodiments obtained by a person of ordinary skill in the art without creative effort should be within the scope of the present disclosure.

[0029] Embodiments of the present disclosure will be described in greater detail below with reference to the drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be interpreted as being limited to the embodiments set forth herein. Rather, these embodiments are provided so that the present disclosure can be more thoroughly and completely understood. It should be understood that the drawings and embodiments of the present disclosure are merely for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0030] In the description of embodiments of the present disclosure, the term “comprising” and similar terms are to be understood as open-ended, i.e., “including but not limited to”. The term “based on” is to be understood as “based at least in part on”. The term “one embodiment” or “the embodiment” is to be understood as “at least one embodiment”. The term “some embodiments” is to be understood as “at least some embodiments”. Other explicit or implicit definitions can also be included below.

[0031] In this document, unless explicitly stated otherwise, performing a step “in response to” an event means performing the step at one or more times in response to the event, and can include one or more intervening steps.

[0032] It can be understood that the data involved in the technical solutions (including but not limited to the data itself, obtaining, using, storing or deleting of the data) should comply with the requirements of relevant laws and regulations and relevant provisions.

[0033] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type of information involved in the present disclosure, the use range, the use scenario, etc. should be informed to the relevant user and the authorization of the relevant user should be obtained through appropriate means according to relevant laws and regulations, wherein the relevant user can include any type of right subject, such as an individual, an enterprise, or a group.

[0034] For example, in response to receiving the active request of the user, the prompt information is sent to the relevant user to explicitly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can voluntarily choose whether to provide the information to the software or hardware such as the electronic device, the application program, the server or the storage medium, etc. performing the operation of the technical solutions of the present disclosure according to the prompt information.

[0035] As an optional but non-limiting implementation manner, in response to receiving the active request of the relevant user, the prompt information can be sent to the relevant user in the form of a pop-up window, and the prompt information can be presented in the form of text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to select “agree” or “disagree” to provide information to the electronic device.

[0036] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0037] As described above, when using a device that needs to be managed through an AD domain, the user usually needs to log in to the local device first and then log in to the AD domain, which brings many inconveniences to the user operation.

[0038] Therefore, there is an urgent need for a method that can simplify the login.

[0039] Office security usually involves the security management of network, identity, and terminal. By implementing proprietary network networking, access control, management of terminals in the proprietary network, and information security protection, digital office can be more secure, efficient, and easy to use. The security management at the network level can ensure that the proprietary network such as the office network can operate safely and efficiently, and thus ensure that business data can be transmitted and stored safely. The security management at the identity level can improve the efficiency and security of user identity authentication when accessing the proprietary network. The security management at the terminal level can realize the unified management of terminal devices in the proprietary network, data leakage prevention, and terminal threat protection, thereby ensuring the security of enterprise data.

[0040] In practical applications, the security management of the network, the identity, and the terminal can be implemented in association with multiple technical branches such as networking strategy, network access and control, remote access, unified terminal management, terminal detection and response, enterprise data leakage prevention, and identity authentication management, so that digital office is simpler, more efficient, and easier to implement.

[0041] In the technical solution of some embodiments of the present disclosure, in response to receiving the password modification instruction, the system password of the terminal device is modified to the first application password based on the application account for logging into the target application and the first application password, and the application account and the system account of the terminal device are associated, so that the terminal device and the target application can be logged into based on the same password without inputting multiple different passwords, thereby achieving the purpose of simplifying login.

[0042] With reference to FIG. 1, a network architecture of an AD domain is shown. In FIG. 1, the AD domain includes one or more devices 11, a domain controller 12, and AD domain resources 13. The AD domain resources 13 refer to resources that can be provided to the devices 11, such as printers, databases, file servers, various business systems, and the like. The domain controller 12 can perform unified management on the devices 11 that join the AD domain, such as performing permission management on the AD domain resources 13 that the devices 11 are allowed to use, managing application software installed in the devices 11, and the like.

[0043] Specifically, an AD domain username and an AD domain password can be created for each device 11 in the domain controller 12. On the one hand, based on the AD domain username, the access permission of each device 11 to the AD domain resources 13 can be set. For example, the AD domain username of device A is AA, and the AD domain username of device B is BB. Associating the AD domain username AA with the printer A, the business system A, and the application software A can indicate that device A is allowed to use the printer A and the business system A, and only application software A is allowed to be installed on device A; associating the AD domain username BB with the printer B, the business system B, and the application software B can indicate that device A is allowed to use the printer B and the business system B, and only application software B is allowed to be installed on device B.

[0044] The device 11 can send an authentication request to the domain controller 12 based on the AD domain username and the AD domain password. In the case where the AD domain username and the AD domain password of the device 11 are authenticated by the domain controller 12, the device 11 can join the AD domain and use the AD domain resources 13 within the permission range.

[0045] On the other hand, the domain controller 12 can also manage the AD domain password of the device 11, such as managing the complexity of the AD domain password and the replacement period of the AD domain password.

[0046] The network architecture shown in FIG. 1 has the following problems:

[0047] 1) The domain controller 12 is the authority control center of all AD domain resources 13, and has a high degree of coupling with the AD domain resources 13 and the device 11, so that it is easy to be attacked by a network, and there is a risk of data leakage, and the network security is low.

[0048] 2) For a user using the device 11, because the operating system 111 of the device 11 has a system account and a system password, the user needs to log in to the device 11 based on the system account and the system password of the device 11, and then input the AD domain username and the AD domain password in the AD login interface of the device 11 to add the device 11 to the AD domain. Usually, the system account and the AD domain username are different, and the system password and the AD domain password are different, which brings many inconveniences to the login operation of the user.

[0049] 3) The domain controller 12 usually does not manage the system password of the device 11, resulting in problems such as that the system password of the device 11 does not meet the complexity requirement, the password replacement period does not meet the requirement, and the network security is low.

[0050] Therefore, some embodiments of the present disclosure first provide a new network architecture, which can solve the above problem 1). As shown in FIG. 2, the network architecture of the present disclosure includes a terminal device 21, a management server 22 and a domain controller 23. The terminal device 21 can be a device with a macOS system. The terminal device 21 can be installed with an operating system 213, and the terminal device 21 and the management server 22 can be installed with a target application. The target application can be used to manage the terminal device 21, such as managing the network resources allowed to be accessed by the terminal device 21, managing the network access time length of the terminal device 21, and the like, protecting the terminal device 21, managing the data leakage of the terminal device 21, and the like.

[0051] Specifically, the target application can include an application client 211 and an application server 221. The application client 211 can be a client program of the target application running in the terminal device 21. The application server 221 can be a server program of the target application running in the management server 22. The application client 211 and the application server 221 cooperate with each other to complete the management of the terminal device 21. For example, the correspondence between the account and the network resources allowed to be accessed can be pre-set in the application server 221, such as the correspondence between the account A and the websites a and b, and the correspondence between the account B and the websites a and c. In the terminal device 21, in response to receiving an instruction to start running (such as the shortcut icon of the application client 211 being double-clicked), the application client 211 can start running and display the client interface 212. In response to the client interface 212 being input with an account and a password, the application client 211 can send the account and the password in the client interface 212 to the application server 221 for authentication. If the authentication is passed, the application server 221 can determine the network resources allowed to be accessed by the terminal device 21 according to the pre-set correspondence between the account and the network resources allowed to be accessed. For example, when the account in the client interface 212 is the account A, it indicates that the terminal device 21 is allowed to access the websites a and b; when the account in the client interface 212 is the account B, it indicates that the terminal device 21 is allowed to access the websites a and c.

[0052] Further, the account and the password can be pre-registered in the domain controller 23. In short, the domain controller 23 can be an account management platform of the target application. The account management includes but is not limited to account registration, account complexity management, account replacement period management, etc.

[0053] In some embodiments, the account and the password in the domain controller 23 can be synchronized to the application server 221 to facilitate the application server 221 to authenticate the account and the password sent by the application client 211.

[0054] In another embodiment, the application server 221 can send the account and the password to the domain controller 23 for authentication. After the authentication of the domain controller 23 is passed, the application server 221 manages the terminal device 21, such as managing the network resources accessed by the terminal device 21 based on the correspondence between the account and the network resources allowed to be accessed.

[0055] In the network architecture shown in FIG. 2, the domain controller 23 can only perform basic account management, and the application server 221 can manage the terminal device 21 based on the account. In other words, the account management logic can be placed in the domain controller 23, and the management logic of the terminal device 21 can be placed in the application server 221. The login of the terminal device 21 to the target application in the present disclosure can be equivalent to the joining of the terminal device 21 to the AD domain in the technology shown in FIG. 1. In this way, the management logic of the domain controller 23 and the terminal device 21 is decoupled, and the network security is improved.

[0056] In addition, it should be noted that in the network architecture shown in FIG. 1, multiple AD domains can be included. The logic for uniformly managing the device 11 in each AD domain can not be the same. In the network architecture shown in FIG. 2 of the present disclosure, domain division can not be required, and in the application server 221, management logic can be separately set for different terminal devices 21.

[0057] Based on the network architecture shown in FIG. 2, the present disclosure provides a login control method based on a target application, which can solve problems 2) and 3) in the network architecture shown in FIG. 1. Specifically, the login control method can be applied to the application client 211 in FIG. 2 or the terminal device 21 running the application client 211. The terminal device 21 includes but is not limited to a tablet computer, a notebook computer, a mobile phone, a desktop computer, etc. In combination with FIG. 3, a flowchart of the login control method provided by an embodiment of the present disclosure is shown. In FIG. 3, the login control method includes the following steps:

[0058] Step S31, in response to receiving a password modification instruction, a first password modification interface is displayed, and password modification information is received through the first password modification interface, wherein the password modification information includes a system password of a terminal device 21 where the application client 211 is located, an application account registered in an identity source for logging into a target application by a first object, and a first application password.

[0059] Specifically, the identity source refers to a module that manages the account of the target application, such as the domain controller 23 in FIG. 2. The first object refers to a subject that can register an account in the identity source, such as a user. The application account and the first application password refer to the account and password managed in the identity source for logging into the target application. The system password refers to the login password of the operating system 213 of the terminal device 21 (also referred to as the local password of the terminal device 21). In general, the application account and the first application password can be pre-registered in the identity source. The system password can be set locally by the user using the terminal device 21.

[0060] In this embodiment, the password modification instruction can be issued by the application server 221 to the application client 211 when the user logs in the target application, and is used to instruct to modify the system password of the terminal device 21. Specifically, before displaying the first password modification interface, the application client 211 can display a login interface as shown in FIG. 4 in response to the user performing an operation of logging in the target application in the terminal device 21. For example, the user double-clicks the shortcut icon of the application client 211 in the terminal device 21, indicating that the target application needs to be logged in, and the login interface as shown in FIG. 4 can be displayed.

[0061] In response to receiving the application account and the first application password through the login interface, the application client 211 can send the application account and the first application password to the application server 221. The application server 221 can include a configuration interface, and an operation and maintenance personnel can configure the management policy of the terminal device 21 based on the application account in the configuration interface. The management policy can include whether the system password of the terminal device 21 needs to be modified. After the application server 221 authenticates the received application account and first application password, if it is determined that the password modification operation needs to be performed on the terminal device 21 based on the management policy corresponding to the application account, the application server 221 can issue a password modification instruction to the application client 211.

[0062] Specifically, after the management policy of an application account is configured to modify the system password of the terminal device 21, if the user logs in the target application using the application account in the terminal device 21 for the first time, the application server 221 can issue a password modification instruction to the application client 211 in the terminal device 21, so that the application client 211 displays the first password modification interface as shown in FIG. 5. Conversely, when the management policy of an application account is configured not to modify the system password of the terminal device 21, if the user logs in the target application using the application account in the terminal device 21, the application server 221 can not issue a password modification instruction to the application client 211. In this case, the application client 211 can display a login success interface.

[0063] For example, according to the time point sequence, it is assumed that there are time point A, time point B, time point C and time point D in turn. Before time point B, the management policy corresponding to the application account A is configured not to modify the system password of the terminal device 21, and at time point B, the management policy corresponding to the application account A is configured to modify the system password of the terminal device 21. Then:

[0064] At time point A, when the user logs in the target application using the application account A in the terminal device A, the application server 221 does not need to issue a password modification instruction to the application client 211 in the terminal device A. In this case, the application client 211 can display a login success interface;

[0065] At the time point C, since it is the first time that the user uses the application account A to log in to the target application in the terminal device A after the management policy corresponding to the application account A is configured to require modification of the system password of the terminal device 21, the application server 221 needs to issue a password modification instruction to the application client 211 in the terminal device A, and in this case, the application client 211 displays a first password modification interface;

[0066] At the time point D, although the management policy corresponding to the application account A is configured to require modification of the system password of the terminal device 21, it is not the first time that the user uses the application account A to log in to the target application in the terminal device A, and therefore the application server 221 can not need to issue a password modification instruction to the application client 211 in the terminal device A. In this case, the application client 211 can display a login success interface.

[0067] Step S32, authenticate the password modification information, and modify the system password to the first application password if the authentication is passed.

[0068] Among them, authenticating the password modification information mainly includes authenticating the system password, and authenticating the application account and the first application password. The following will be described respectively.

[0069] 1) Authenticating the system password

[0070] Specifically, the local storage of the terminal device 21 can save the system password preset by the user. The system password obtained in step S31 can be compared with the system password in the local storage. If the two are matched, it means that the authentication of the system password is passed; if the two are not matched, it means that the authentication of the system is not passed.

[0071] Specifically, in this embodiment, in order to protect the security of the password, the system password in the local storage can be saved in the form of a password digest, and therefore, the system password obtained in step S31 can be compared with the system password in the local storage to determine whether they are matched.

[0072] 2) Authenticating the application account and the first application password

[0073] Specifically, the application account and the first application password can be sent to the application server 221 of the target application, so that the application server 221 authenticates the application account and the first application password based on the account password information obtained from the identity source, or the application account and the first application password are sent to the identity source through the application server 221, and the identity source authenticates the application account and the first application password.

[0074] In a case that the system password, the application account and the first application password are authenticated successfully, the system password locally saved by the terminal device 21 can be modified as the first application password.

[0075] In the embodiment, after the system password of the terminal device 21 is modified as the first application password, the first application password can be saved in the terminal device 21 in the form of a password digest. In this way, the security of the password is improved, and the risk of password leakage is reduced.

[0076] It can be understood that since the system password of the terminal device 21 is modified as the first application password when the terminal device 21 is logged in to the target application for the first time, the terminal device 21 can be logged in based on a unified password when the terminal device 21 and the target application are logged in subsequently. In this way, the user can not need to input multiple different passwords, thereby simplifying the login process.

[0077] In step S33, the application account is associated with the system account of the terminal device 21, and the association relationship between the application account and the system account is sent to the application server 221.

[0078] Specifically, the system account is a login account of the operating system 213 of the terminal device 21 (also referred to as a local account of the terminal device 21). The application server 221 can save the association relationship between the application account and the system account. When the user logs in to the target application using the application account on the terminal device 21, the application client 211 can send the application account, the first application password and the system account of the terminal device 21 to the application server 221. After receiving the application account and the system account sent by the application client 211, the application server 221 can find the system account associated with the application account. If the system account associated with the application account is the same as the system account sent by the application client 211, it is determined that the authentication is passed; if the system account associated with the application account is different from the system account sent by the application client 211, it is determined that the authentication fails.

[0079] Based on the above description, after the application account is associated with the terminal device 21, when the user logs in to the target application in the terminal device 21 again, the user can only log in using the application account associated with the system account of the terminal device 21, which is equivalent to that the application account is bound to the terminal device 21. In this way, the following two aspects of beneficial effects can be brought:

[0080] On the one hand, the risk of application account borrowing and password leakage can be greatly reduced, and the network security can be effectively improved. For example, assuming that user A has terminal device A, the application account of user A is application account A, and user A has associated the application account A with the system account of terminal device A. User B has terminal device B. When user A lends application account A to user B for use in terminal device B, user B cannot successfully log in to the target application in terminal device B using application account A because the system account associated with application account A is not the system account of terminal device B. In this way, the purpose of reducing the risk of application account borrowing and password leakage is achieved.

[0081] On the other hand, in the case where the first application password corresponding to the application account associated with the system account is not modified, the user can use a unified password to log in to terminal device 21 and the target application in terminal device 21 at the same time, without the need to input multiple different passwords, thereby achieving the purpose of simplifying login. For example, assuming that the application account and the system account are not associated, and different application accounts are also allowed to log in to the target application in the same terminal device A, because the first application passwords corresponding to the application accounts are different, the first application password may be different from the system password each time the target application is logged in in terminal device A, so that the passwords input for login are different twice, which does not achieve the purpose of simplifying login.

[0082] In summary, in the technical scheme of some embodiments of the present disclosure, in response to receiving a password modification instruction, the system password of the terminal device is modified to the first application password based on the application account and the first application password used to log in to the target application, and the application account is associated with the system account of terminal device 21, and the terminal device 21 and the target application can be logged in based on the same password. In this way, when the terminal device is managed through the target application, multiple different passwords do not need to be input, and the purpose of simplifying login is achieved.

[0083] In addition, in the scheme of the present disclosure, the login is simplified by modifying the system password, so that the functions in the terminal device 21 that need to be verified by the system password can achieve the purpose of simplifying the login, and the adaptability is good. For example, in some technologies, the login of the terminal device is simplified by an authorized plug-in mechanism. In these technologies, although the user can simplify the login when logging into the terminal device and the application for device management, after the terminal device starts the specified function (such as the file safe function), the user still needs to input two different passwords because the specified function needs the user to input the system password and can only run normally after the system password is authenticated. Therefore, the user still needs to input two different passwords, and the simplified login cannot be achieved. However, in the scheme of the present disclosure, because the system password is modified to the application password of the target application, when the function in the terminal device 21 that needs to use the system password for verification is used, the purpose of simplifying the login can also be achieved.

[0084] The scheme of the present disclosure is further described below.

[0085] In some embodiments, in the case where the first application password is modified to the second application password, the method of the present disclosure can further include:

[0086] Obtaining the second application password;

[0087] Modifying the system password from the first application password to the second application password.

[0088] The identity source can manage the password replacement period of each application account. When the first application password of an application account is not replaced for more than a preset time period (such as 3 months), the identity source can send an email or an SMS to the user to remind the user to modify the first application password of the application account; or the user can update the first application password according to actual needs. Specifically, the identity source can include a password reset interface, and the user can enter the password reset interface of the identity source to modify the first application password of the application account to the second application password; or the application client 211 can include a password reset interface, and the user can enter the password reset interface of the application client 211 to modify the first application password of the application account to the second application password. When the first application password is modified through the application client 211, the application client 211 can send a request to modify the first application password to the identity source through the application server 221 in response to the modification of the first application password to the second application password in the password reset interface, to notify the identity source to modify the first application password to the second application password.

[0089] The identity source can send a first password update instruction to the application server 221 in response to the first application password being modified to the second application password, and send the target application account, the first application password (old password) of the target application account, and the second application password (new password) of the target application account to the application server 221. In response to receiving the password update instruction, the application server 221 can modify the first application password of the target application account to the second application password locally, and determine the target terminal device 21 to be updated according to the association relationship between the application account and the system account, and then send a second password update instruction to the application client 211 in the target terminal device 21, and send the received target application account, first application password and second application password of the target application account to the application client 211, so that the application client 211 modifies the locally stored password digest of the first application password to the password digest of the second application password.

[0090] In the above embodiment, the passwords of the application account in the identity source, the application server 221 and the application client 211 can be kept uniform, so that after the first application password is replaced, the user can still log in through the same password.

[0091] Further, in some scenarios (such as network attacks), there may be a case that the first application password of the application account is modified to the second application password by the owner of the non-application account. For example, the application account A belongs to the user A, but in the scenario of network attack, the user B may modify the password of the application account A. In this case, the password digest of the application account A stored in the terminal device 21 will also be modified accordingly, so that the user A cannot log in to the terminal device 21 and the target application based on the first application password. This is very bad for the experience of the user A.

[0092] In view of this, in response to the first application password being modified to the second application password, the application client 211 can save the second application password after obtaining the second application password, but does not immediately modify the password digest of the first application password stored locally to the password digest of the second application password, but can display a second password modification interface and receive the second application password and the system password through the second password modification interface. The second application password and the system password received through the second password modification interface can be manually input by the owner of the application account himself.

[0093] It can be understood that if the password modification operation of the identity source is initiated by the application account owner himself, he must know the second application password and the current system password of the terminal device 21, and therefore, the correct second application password and the current system password can be input in the second password modification interface. In this case, in response to the second application password received through the second password modification interface being the same as the saved second application password, and the system password received through the second password modification interface being the same as the first application password, the system password can be modified from the first application password to the second application password.

[0094] However, if the password modification operation of the identity source is not initiated by the application account owner himself, he must not know the second application password, and therefore, the second application password input in the second password modification interface must be different from the locally temporarily saved second application password. In this case, the user can be prompted through the client interface 212 that the first application password of the application account in the identity source has been modified, so as to facilitate the user to handle in time.

[0095] Further, for password security, when saving the second application password, the password digest of the second application password can be saved. If the password digest of the second application password received through the second password modification interface is the same as the password digest of the saved second application password, it can be considered that the second application password received through the second password modification interface is the same as the saved second application password, and the password digest of the system password received through the second password modification interface is the same as the password digest of the first application password, it can be considered that the system password received through the second password modification interface is the same as the first application password. Further, modifying the system password from the first application password to the second application password can mean modifying the password digest of the system password from the password digest of the first application password to the password digest of the second application password.

[0096] In the above embodiment, after the application client 211 receives the second application password, the system password of the terminal device 21 locally is not immediately modified from the first application password to the second application password, but the user input second application password in the second password modification interface is first verified whether it is the same as the saved second application password, and the system password input in the second password modification interface is verified whether it is the same as the first application password, and in response to the second application password received through the second password modification interface being the same as the saved second application password, and the system password received through the second password modification interface being the same as the first application password, the system password is modified from the first application password to the second application password. In this way, the case that the first application password in the identity source is modified by the non-application account owner can be prevented, and the network security is high.

[0097] In some embodiments, after the system password is modified from the first application password to the second application password, the method of the present disclosure can further include:

[0098] displaying a password update prompt, wherein the password update prompt includes the application account, to prompt that the system password has been modified to the password currently corresponding to the application account.

[0099] For example, after the system password of the terminal device 21 is modified to the second application password of the application account A, the displayed password update prompt can be: please log in using the current password (i.e. the second application password) of the application account A.

[0100] It can be understood that for the owner of the application account A, he knows the current password of the application account A, and therefore can log in the terminal device 21. However, for the non-owner of the application account A, he does not know the current password of the application account A, and therefore cannot log in the terminal device 21. In this way, on the one hand, it can prevent the non-owner of the application account A from logging in the terminal device 21 associated with the application account A, and on the other hand, the modified second application password is not directly displayed in the password update prompt, which can reduce the risk of password leakage. Network security is high.

[0101] Further, in some embodiments, considering that the identity source has a password management function, but the terminal device 21 does not have a password management function, the system password can be managed by the identity source, such as managing the password complexity, password replacement period, etc. of the system password. In order to ensure that the system password is within the management range of the identity source, the modification of the system password can only be triggered by modifying the first application password, i.e. the system password is not allowed to be modified in the terminal device 21. Based on the above description, in the case where the first application password is not modified but the system password is modified, the system password can be modified to the first application password again. In this way, the password management function of the identity source can be used to manage the system password, and the password security is relatively high.

[0102] Specifically, in some embodiments, in step S31, after the password modification information is obtained, the first application password can be saved. Wherein, the first application password can be saved in the form of a password digest. On this basis, the above-mentioned modification of the system password to the first application password again can include:

[0103] displaying a third password modification interface, and receiving the first application password and the system password through the third password modification interface;

[0104] in response to the first application password received through the third password modification interface being the same as the saved first application password, and the system password received through the third password modification interface being the same as the modified system password, the system password is modified to the first application password again.

[0105] Specifically, when the system password is to be modified to the first application password, the user needs to re-input the first application password and the current system password of the operating system 213 through the third password modification interface, and only when the received first application password and system password are the same as the first application password and system password stored locally in the terminal device 21, the system password is modified to the first application password.

[0106] In this way, the user can be informed that the system password has been replaced back to the first application password, preventing the user from continuing to use the modified system password to log in to the terminal device 21.

[0107] Further, in some embodiments, the terminal device 21 includes a password management tool. In some terminal devices 21, the password management tool can also be referred to as a keychain, which is used to store the passwords of one or more applications in the terminal device 21. After the user logs in to the terminal device 21 using the system password, if the user wants to continue to use the applications whose passwords are stored in the password management tool in the terminal device 21, the user needs to log in to these applications through the password in the password management tool to use these applications. In order to realize password unification and simplify login, in the method of the present disclosure, the password of at least part of the applications in the password management tool can also be modified to the first application password when the password modification information in step S31 is authenticated, and the password of at least part of the applications in the password management tool can be modified from the first application password to the second application password in response to the first application password being modified to the second application password.

[0108] In this way, the same password can be used to log in to the terminal device 21, the target application, and other applications in the terminal device 21 except the target application.

[0109] Referring to FIG. 6, a module interaction diagram for modifying the system password based on the first application password according to an embodiment of the present disclosure is provided. FIG. 6 includes the following steps:

[0110] Step S60, the application server issues a password modification instruction to the application client.

[0111] Specifically, as described in step S31, after the management policy corresponding to an application account is configured to modify the system password of the terminal device, if the target application is logged in for the first time in the terminal device using the application account, the application server can issue a password modification instruction to the application client in the terminal device.

[0112] Step S61, the application client displays a first password modification interface through a client interface.

[0113] Wherein, the first password modification interface can be as shown in FIG. 5 for receiving the application account, the first application password and the system password input by the user, as described in step S31.

[0114] Step S62, the application client sends an authentication request to the application server based on the application account and the first application password received from the first password modification interface.

[0115] Step S63, the application server sends an authentication request to the domain controller.

[0116] Specifically, the application server sends the received application account and the first application password to the domain controller, and the domain controller authenticates the application account and the first application password.

[0117] Step S64, the domain controller returns the authentication result to the application server.

[0118] Step S65, the application server sends the authentication result returned by the domain controller to the application client.

[0119] Step S66, in the case that the authentication result returned by the domain controller indicates that the authentication is passed, the application client saves the first application password and continues to authenticate the system password of the operating system.

[0120] Specifically, the password digest of the first application password can be determined and saved in the form of the password digest. In this way, the password leakage can be prevented. The first application password saved here can be used in the scenario shown in FIG. 9.

[0121] Further, as described in step S32, the received system password can be compared with the system password stored locally in the terminal device. If the two are matched, it is considered that the authentication of the system password is passed.

[0122] Step S67, in the case that the authentication of the system password is passed, the application client modifies the system password of the operating system to the first application password.

[0123] Step S68, the application client associates the application account with the system account of the operating system and displays the association relationship through the client interface.

[0124] Step S69, the application client reports the association relationship between the application account and the system account to the application server.

[0125] The principle of associating the application account with the system account can be referred to the related description of FIG. 3, which is not described here.

[0126] With reference to FIG. 7, a module interaction schematic diagram for modifying the system password from the first application password to the second application password is provided according to an embodiment of the present disclosure. FIG. 7 includes the following steps:

[0127] Step S71, in response to the user's password modification operation in the configuration interface, the domain controller modifies the first application password to the second application password.

[0128] Specifically, the configuration interface can be the interface of the domain controller, or the client interface. When the configuration interface is the client interface, in response to the user's password modification operation in the configuration interface, the application client can send the first application password and the second application password filled in by the user in the configuration interface to the domain controller through the application server, so that the domain controller modifies the first application password to the second application password.

[0129] Step S72, the domain controller issues a first password update instruction to the application server.

[0130] Specifically, when issuing the first password update instruction, the domain controller can also send the application account to be modified, the first application password corresponding to the application account, and the second application password to the application server.

[0131] Step S73, the application server issues a second password update instruction to the application client.

[0132] Specifically, the application server can also send the first application password and the second application password to the application server when issuing the second password update instruction.

[0133] Step S74, the application client saves the second application password.

[0134] Specifically, the application client can save the second application password in the form of a password digest.

[0135] Step S75, the application client displays a second password modification interface through the client interface.

[0136] Specifically, the second password modification interface can be used to receive the second application password and the system password input by the user. For the second password modification interface, please refer to the relevant description of the login control method, which will not be repeated here.

[0137] Step S76, the application client authenticates the system password and the second application password received through the second password modification interface.

[0138] Specifically, when authenticating the second application password received through the second password modification interface, the received second application password and the second application password saved in step S74 can be compared by password digest. If they match, it means that the received second application password is authenticated.

[0139] When authenticating the system password received through the second password modification interface, the received system password and the system password locally saved by the terminal device can be compared in a password digest manner. If the two are matched, it indicates that the received system password is authenticated.

[0140] Step S77, the application client modifies the system password from the first application password to the second application password in the case that the system password received through the second password modification interface and the second application password are authenticated.

[0141] Step S78, the application client associates the application account and the system account of the operating system, and displays the association relationship through the client interface.

[0142] Step S79, the application client reports the association relationship between the application account and the system account to the application server.

[0143] With reference to FIG. 8, a module interaction schematic diagram for modifying the system password locally in the terminal device is provided according to an embodiment of the present disclosure. FIG. 8 includes the following steps:

[0144] Step S81, the application client detects that the system password modification exists locally in the terminal device.

[0145] In simple terms, the user modifies the system password locally in the terminal device.

[0146] Step S82, the application client displays a third password modification interface.

[0147] Specifically, the third password modification interface is used to receive the application account, the first application password and the modified system password input by the user. For the third password modification interface, please refer to the related description of the login control method, which will not be described here.

[0148] Step S83, the application client authenticates the system password and the first application password received from the third password modification interface.

[0149] Specifically, authenticating the first application password can be comparing the received first application password and the first application password saved in the above step S66 in a password digest manner. If the two are matched, it is considered that the received first application password is authenticated.

[0150] Authenticating the received system password can refer to the related description of step S76, which will not be described here.

[0151] Step S84, the application client modifies the system password to the first application password again in the case that the system password received through the third password modification interface and the first application password are authenticated.

[0152] In step S85, the application client associates the application account of the target application with the system account of the operating system, and displays the association relationship through the client interface.

[0153] In step S86, the application client reports the association relationship between the application account and the system account to the application server.

[0154] At this point, the related description of the login control method of the present disclosure is completed.

[0155] Corresponding to the login control method, the present disclosure also provides an application client. In combination with FIG. 9, FIG. 9 is a module schematic diagram of an application client provided by an embodiment of the present disclosure. In FIG. 9, the application client includes:

[0156] The login information acquisition module is configured to, in response to receiving a password modification instruction, display a first password modification interface, and receive password modification information through the first password modification interface, wherein the password modification information includes a system password of a terminal device where the application client is located, an application account registered in an identity source by the first object for logging into the target application, and a first application password.

[0157] The password modification module is configured to authenticate the password modification information, and modify the system password to the first application password if the authentication is passed.

[0158] The account association module is configured to associate the application account with the system account of the terminal device, and send the association relationship between the application account and the system account to the application server.

[0159] In some embodiments, in a case where the first application password is modified to a second application password, the password modification module is further configured to:

[0160] obtain the second application password;

[0161] modify the system password from the first application password to the second application password.

[0162] In some embodiments, after obtaining the second application password, the password modification module is further configured to:

[0163] save the second application password;

[0164] modify the system password from the first application password to the second application password, including:

[0165] display a second password modification interface, and receive the second application password and the system password through the second password modification interface;

[0166] In response to the second application password received through the second password modification interface being the same as the saved second application password, and the system password received through the second password modification interface being the same as the first application password, the system password is modified from the first application password to the second application password.

[0167] In some embodiments, after the system password is modified from the first application password to the second application password, the password modification module is further configured to:

[0168] display a password update prompt, wherein the password update prompt includes an application account, for prompting that the system password has been modified to a password currently corresponding to the application account.

[0169] In some embodiments, the terminal device includes a password management tool, and the password management tool is configured to store login passwords of one or more applications in the terminal device.

[0170] In the case that the password modification information is authenticated, the password modification module is further configured to:

[0171] modify the password of at least part of the applications in the password management tool to the first application password.

[0172] In response to the first application password being modified to the second application password, the method further includes:

[0173] modify the password of at least part of the applications in the password management tool from the first application password to the second application password.

[0174] In some embodiments, in the case that the first application password is not modified but the system password is modified, the password modification module is further configured to:

[0175] re-modify the system password to the first application password.

[0176] In some embodiments, after the password modification information is received, the login information acquisition module is further configured to:

[0177] save the first application password.

[0178] The password modification module is further configured to:

[0179] display a third password modification interface, and receive the first application password and the system password through the third password modification interface;

[0180] In response to the first application password received through the third password modification interface being the same as the saved first application password, and the system password received through the third password modification interface being the same as the modified system password, the system password is re-modified to the first application password.

[0181] In some embodiments, the login information acquisition module is specifically configured to:

[0182] determining a password digest of the application password;

[0183] storing the password digest of the application password.

[0184] In some embodiments, the password modification module is specifically configured to:

[0185] sending the application account and the first application password to an application server of the target application, so that the application server authenticates the application account and the first application password based on the account password information obtained from the identity source, or sending the application account and the first application password to the identity source through the application server, so that the identity source authenticates the application account and the first application password.

[0186] In some embodiments, before displaying the first password modification interface, the password modification module is further configured to:

[0187] In response to the first object performing an operation of logging in to the target application in the terminal device, displaying a login interface;

[0188] In response to receiving the application account and the first application password through the login interface, sending the application account and the first application password to the application server, so that the application server determines, based on the management policy corresponding to the application account, that the password modification operation needs to be performed on the terminal device, and then sends a password modification instruction to the application client.

[0189] Referring to FIG. 10, an electronic device provided by an embodiment of the present disclosure is shown. The electronic device includes a processor and a memory. The memory is configured to store a computer program. When the computer program is executed by the processor, the method described above is implemented.

[0190] The processor can be a central processing unit (CPU). The processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or combinations thereof.

[0191] The memory, as a non-transitory computer readable storage medium, can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the method in the embodiments of the present disclosure. The processor executes various functions and data processing of the processor by running the non-transitory software programs, instructions and modules stored in the memory, that is, implements the method in the above-mentioned method embodiments.

[0192] The memory can include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required by a function; and the data storage area can store data created by the processor and the like. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0193] One embodiment of the present disclosure further provides a computer readable storage medium for storing a computer program, wherein the computer program is executed by the processor to implement the above-mentioned method.

[0194] The present disclosure further provides a computer program product comprising a computer program, wherein the computer program is executed by the processor to implement the above-mentioned method.

[0195] Although the embodiments of the present disclosure are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present disclosure, and such modifications and changes fall within the scope defined by the appended claims.

Claims

1. A login control method applied to an application client, the method comprising: in response to receiving a password modification instruction, displaying a first password modification interface and receiving password modification information through the first password modification interface, wherein the password modification information comprises a system password of a terminal device where the application client is located, an application account registered in an identity source by a first object for logging into a target application, and a first application password; authenticating the password modification information, and in case of passing the authentication, modifying the system password to the first application password; associating the application account with a system account of the terminal device, and sending an association relationship between the application account and the system account to an application server. 2.The method of claim 1, wherein in case that the first application password is modified to a second application password, the method comprises: obtaining the second application password; modifying the system password from the first application password to the second application password. 3.The method of claim 2, wherein after obtaining the second application password, the method further comprises: saving the second application password; the modifying the system password from the first application password to the second application password comprises: displaying a second password modification interface and receiving a second application password and a system password through the second password modification interface; in response to the second application password received through the second password modification interface being the same as the saved second application password, and the system password received through the second password modification interface being the same as the first application password, modifying the system password from the first application password to the second application password. 4.The method of claim 2, wherein after modifying the system password from the first application password to the second application password, the method further comprises: displaying a password update prompt, wherein the password update prompt comprises the application account, to prompt that the system password has been modified to a password currently corresponding to the application account. 5.The method of claim 2, wherein the terminal device comprises a password management tool configured to store login passwords of one or more applications in the terminal device; in case of passing the authentication of the password modification information, the method further comprises: modifying passwords of at least part of the applications in the password management tool to the first application password; in response to the first application password being modified to a second application password, the method further comprises: modifying the passwords of at least part of the applications in the password management tool from the first application password to the second application password. 6.The method of claim 1, wherein in case that the first application password is not modified but the system password is modified, the method further comprises: re-modifying the system password to the first application password. 7.The method of claim 6, wherein after receiving the password modification information, the method further comprises: saving the first application password; the re-modifying the system password to the first application password comprises: display a third password modification interface and receive a first application password and a system password through the third password modification interface; in response to the first application password received through the third password modification interface being the same as the saved first application password and the system password received through the third password modification interface being the same as the modified system password, re-modify the system password to the first application password.

8. The method of any one of claims 1 to 7, wherein saving the first application password or the second application password comprises: determining a password digest of any one of the first application password and the second application password; saving the password digest of the application password.

9. The method of claim 1, wherein the authenticating the password modification information comprises: sending the application account and the first application password to an application server of the target application, so that the application server authenticates the application account and the first application password based on account password information obtained from the identity source, or sending the application account and the first application password to the identity source through the application server, so that the identity source authenticates the application account and the first application password.

10. The method of claim 1, wherein before displaying the first password modification interface, the method further comprises: in response to the first object performing an operation of logging in to the target application in the terminal device, displaying a login interface; in response to receiving the application account and the first application password through the login interface, sending the application account and the first application password to the application server, so that the application server determines, based on a management policy corresponding to the application account, that the password modification operation needs to be performed in the terminal device and issues the password modification instruction to the application client.

11. An application client, comprising: a login information obtaining module configured to display a first password modification interface and receive password modification information through the first password modification interface in response to receiving a password modification instruction, wherein the password modification information comprises a system password of a terminal device where the application client is located, an application account registered by a first object in an identity source for logging in to a target application, and a first application password; a password modification module configured to authenticate the password modification information and modify the system password to the first application password if the authentication is passed; an account association module configured to associate the application account with a system account of the terminal device and send an association relationship between the application account and the system account to an application server.

12. A computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to implement the method of any one of claims 1 to 10.

13. An electronic device comprising a processor and a memory for storing a computer program, which, when executed by the processor, implements the method of any one of claims 1 to 10.

14. A computer program product comprising a computer program, which, when executed by a processor, implements the method of any one of claims 1 to 10.

Citation Information

Patent Citations

  • Password management method

    CN110401529A

  • AD domain account password modification method and equipment

    CN112115436A

  • Method and equipment for realizing domain authentication of cloud desktop client

    CN115801351A

  • Login control method, application client, device, medium and program product

    CN118611936A

  • Apparatus and method for managing password

    KR101627078B1