Authorization verification method and computing device
By establishing mutual trust between the authorization system and the primary business system, and between the primary business system and the secondary business system, and by utilizing diverse mutual trust mechanisms to forward and verify authorization codes, the problem of inconsistent authorization between the authorization system and business subsystems is solved, the risk of information leakage is reduced, and the flexibility and applicability of authorization verification are improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2026-04-02
AI Technical Summary
In existing technologies, unified authorization cannot be achieved between the authorization system and the business system and business subsystems, increasing the risk of information leakage.
By establishing mutual trust between the authorization system and the primary business system, and between the primary business system and the secondary business system, unified authorization is achieved among the authorization system, the primary business system, and the secondary business system. Various mutual trust mechanisms, such as whitelists, keys, or mutual trust configurations, are used to achieve the forwarding and verification of authorization codes.
It achieves unified authorization among the authorization system, primary business system, and secondary business system, reducing the risk of information leakage and improving the flexibility and applicability of authorization verification methods.
Smart Images

Figure CN2025086555_02042026_PF_FP_ABST
Abstract
Description
An authorization verification method and a computing device
[0001] This application claims priority to Chinese Patent Application No. 202411380191.9, filed on September 29, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0002] The present application relates to the technical field of computers, and in particular to an authorization verification method and a computing device. BACKGROUND
[0003] Uniform authorization is a secure authentication method that allows a user to authorize a third-party application to access resources stored on a service provider without providing sensitive information such as a username and password.
[0004] In related technologies, mutual trust between the authorization system and the business system requires mutual trust to be established between each business system and the authorization system. However, not all business systems can establish mutual trust with the authorization system, for example, a business subsystem generated by a business system. Therefore, uniform authorization cannot be achieved between the authorization system, the business system, and the business subsystem, thereby increasing the risk of information leakage. SUMMARY
[0005] Embodiments of the present application provide an authorization method and a computing device to achieve uniform authorization between an authorization system, a primary business system, and a secondary business system, thereby reducing the risk of information leakage.
[0006] In a first aspect, embodiments of the present application provide an authorization verification method applied to a computing device, the computing device including an authorization system, a primary business system, and a secondary business system; wherein the authorization system and the primary business system are mutually trusted, and the primary business system and the secondary business system are mutually trusted; the primary business system receives an authorization code and information of a target secondary business system sent by a client; wherein the authorization code is sent by the authorization system to the client in response to the client successfully logging into the authorization system; the target secondary business system and the authorization system have not established mutual trust; the primary business system forwards the authorization code to the target secondary business system according to a mutual trust mechanism between the primary business system and the target secondary business system, and the information of the target secondary business system; and the target secondary business system receives the authorization code and performs authorization verification on the client based on the authorization code.
[0007] For some secondary business systems that cannot establish mutual trust with the authorization system, the authorization system, the primary business system and the secondary business system cannot achieve unified authorization. In order to achieve unified authorization between the authorization system, the primary business system and the secondary business system, in the embodiment of the application, the secondary business system establishes mutual trust with the primary business system, and the primary business system establishes mutual trust with the authorization system, thereby achieving unified authorization between the authorization system, the primary business system and the secondary business system. In the embodiment of the application, the primary business system receives the authorization code and the information of the target secondary business system sent by the client, and forwards the authorization code to the target secondary business system based on the mutual trust mechanism between the primary business system and the target secondary business system, so that the target secondary business system performs authorization verification on the client, thereby achieving unified authorization between the authorization system, the primary business system and the secondary business system, and further reducing the risk of information leakage.
[0008] Optionally, the primary business system authenticates the target secondary business system according to the entry information of the target secondary business system; and the primary business system forwards the authorization code to the target secondary business system according to the mutual trust mechanism between the primary business system and the target secondary business system and the identification information of the target secondary business system, in the case that the target secondary business system is successfully authenticated.
[0009] Optionally, the secondary business system includes multiple secondary business systems, in the case that the access target of the client changes from a first target secondary business system to a second target secondary business system and the authorization code is valid, the primary business system receives the authorization code and the information of the second target secondary business system sent by the client; the primary business system forwards the authorization code to the second target secondary business system according to the mutual trust mechanism between the primary business system and the second target secondary business system and the information of the second target secondary business system; and the second target secondary business system receives the authorization code and performs authorization verification on the client based on the authorization code.
[0010] In the case that the access object of the client changes from a first target secondary business system to a second target secondary business system and the authorization code is valid, the previous authorization code is used to achieve unified authorization between the authorization system, the primary business system and the second target secondary business system.
[0011] Optionally, in the case that the access target of the client changes from a first target secondary business system to a second target secondary business system and the authorization code is invalid, the authorization system sends a new authorization code to the client in response to that the client successfully logs in the authorization system.
[0012] Optionally, the mutual trust mechanism includes any one of a white list, a mutual trust configuration and a key.
[0013] In the embodiment, the diversified mutual trust mechanisms improve the flexibility and applicability of the authorization verification method.
[0014] Optionally, the target secondary business system sends the authorization code to the authorization system; the authorization system checks the authorization code, and sends user information to the target secondary business system in the case of successful checking; the target secondary business system receives the user information, and authorizes the client based on the user information through the authorization request of the client.
[0015] In a second aspect, the embodiments of the present application provide a computing device, comprising: an authorization system, a primary business system and a secondary business system; wherein the authorization system and the primary business system are mutually trusted, and the primary business system and the secondary business system are mutually trusted; the primary business system is configured to receive an authorization code and information of a target secondary business system sent by a client; according to a mutual trust mechanism between the target secondary business system and the primary business system, and the information of the target secondary business system, the primary business system forwards the authorization code to the target secondary business system; wherein the authorization code is sent by the authorization system to the client in response to successful login of the client to the authorization system; the target secondary business system and the authorization system do not establish mutual trust; and the target secondary business system is configured to receive the authorization code, and authorize the client based on the authorization code.
[0016] For some secondary business systems that cannot establish mutual trust with the authorization system, the authorization system, the primary business system and the secondary business system cannot achieve unified authorization. In order to achieve unified authorization between the authorization system, the primary business system and the secondary business system, in the embodiments of the present application, the secondary business system and the primary business system establish mutual trust, and the primary business system and the authorization system establish mutual trust, so as to achieve unified authorization between the authorization system, the primary business system and the secondary business system. In the embodiments of the present application, the primary business system receives an authorization code and information of a target secondary business system sent by a client, and forwards the authorization code to the target secondary business system based on a mutual trust mechanism between the primary business system and the target secondary business system, so as to enable the target secondary business system to authorize the client, achieve unified authorization between the authorization system, the primary business system and the secondary business system, and further reduce the risk of information leakage.
[0017] Optionally, the primary business system is specifically configured to authenticate the target secondary business system according to entry information of the target secondary business system; and in the case of successful authentication of the target secondary business system, the primary business system forwards the authorization code to the target secondary business system according to a mutual trust mechanism between the primary business system and the target secondary business system, and identification information of the target secondary business system.
[0018] Optionally, the secondary business system comprises a plurality of; the primary business system is further configured to, in a case that the access target of the client changes from the first target secondary business system to the second target secondary business system and the authorization code is valid, receive the authorization code and information of the second target secondary business system sent by the client; the primary business system forwards the authorization code to the second target secondary business system according to a mutual trust mechanism between the primary business system and the second target secondary business system and the information of the second target secondary business system; and the second target secondary business system is further configured to receive the authorization code and perform authorization verification on the client based on the authorization code.
[0019] Optionally, the authorization system is configured to, in a case that the access target of the client changes from the first target secondary business system to the second target secondary business system and the authorization code is invalid, send a new authorization code to the client in response to that the client successfully logs in the authorization system.
[0020] Optionally, the mutual trust mechanism comprises any one of a white list, a mutual trust configuration and a key.
[0021] In the embodiment, the flexibility and applicability of the authorization verification method are improved through diversified mutual trust mechanisms.
[0022] Optionally, the target secondary business system sends the authorization code to the authorization system; the authorization system verifies the authorization code and sends user information to the target secondary business system in a case that the verification is successful; and the target secondary business system receives the user information and processes the authorization request of the client based on the user information. BRIEF DESCRIPTION OF DRAWINGS
[0023] To make the technical solutions in the embodiments or the prior art clearer, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only show some embodiments of the present application, and for those skilled in the art, other drawings can be obtained from these drawings without any creative effort.
[0024] Fig. 1 is a schematic diagram of an application scenario provided by the embodiment of the present application;
[0025] Fig. 2 is a schematic diagram of the structure of a server provided by the embodiment of the present application;
[0026] Fig. 3 is a signaling diagram of an authorization verification method provided by the embodiment of the present application;
[0027] Fig. 4 is a signaling diagram of another authorization verification method provided by the embodiment of the present application;
[0028] Fig. 5 is a signaling diagram of still another authorization verification method provided by the embodiment of the present application;
[0029] FIG. 6 is a signaling diagram of another authorization verification method according to an embodiment of the present application;
[0030] FIG. 7 is a structural diagram of a computing device according to an embodiment of the present application. DETAILED DESCRIPTION
[0031] It should be noted that the embodiments described in the present application are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.
[0032] The terms "first" and "second" and the like in the specification and claims of the present application are used to distinguish different objects, not to describe a specific order of the objects. For example, the first data and the second data are used to distinguish different data, not to describe a specific order of the data.
[0033] In the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration, in any non-limiting and non-exhaustive sense. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or advantageous than other embodiments or design schemes. Rather, the use of the words "exemplary" or "for example" is intended to present concepts in a concrete manner.
[0034] In the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more, for example, a plurality of processing units means two or more processing units, and the like; a plurality of elements means two or more elements, and the like.
[0035] To make the following embodiments clear, the technical terms involved in the present application are introduced first.
[0036] OAuth2 is an authorization proxy protocol, which allows a user to authorize resources (such as personal information and social relationships) on one service provider to another service provider.
[0037] The authorization system is responsible for verifying the identity of the client and issuing an authorization code.
[0038] The business system is a system for processing and managing specific business functions, such as tenant management business or user management business.
[0039] The client device is a terminal device such as a computer, a mobile phone, a smart watch, and a tablet.
[0040] The client is an application or service loaded in a client device for requesting access to user resources. The client can be a public website or mobile application, or a private background service.
[0041] Unified authorization, i.e., unified authorization between the authorization system and the business system, requires that all business systems trust the authorization system. However, not all business systems can establish mutual trust with the authorization system. In some scenarios, the business system includes a primary business system and a secondary business system, and the secondary business system is temporarily generated by the primary business system. Therefore, the secondary business system cannot apply to the authorization system to establish mutual trust. Or, the secondary system is generated by other secondary business systems (replicate other secondary business systems or be generated by fission of other secondary business systems). Therefore, the secondary business system cannot apply to the authorization system to establish mutual trust. Therefore, unified authorization cannot be achieved between the authorization system, the primary business system, and the secondary business system.
[0042] The primary management system is used to manage the secondary management system. For example, the primary business system can be a general management system, and the secondary business system can be a user management system. The general management system is used to manage the user management system.
[0043] Therefore, the embodiments of the present application provide an authorization verification method. The primary business system receives an authorization code and information of a target secondary business system sent by a client. The authorization code is sent by the authorization system to the client in response to successful login of the client to the authorization system. Mutual trust is not established between the target secondary business system and the authorization system. The primary business system forwards the authorization code to the target secondary business system according to a mutual trust mechanism between the target secondary business system and the primary business system, and the information of the target secondary business system. The target secondary business system receives the authorization code and performs authorization verification on the client based on the authorization code, thereby achieving unified authorization between the authorization system, the primary business system, and the secondary business system.
[0044] In order to facilitate understanding of the technical solutions of the present application, the application scenarios of the embodiments of the present application are introduced below.
[0045] The number of primary business systems and the number of secondary business systems are not specifically limited in the embodiments of the present application. For ease of understanding, one primary business system and three secondary business systems are taken as an example to introduce authorization verification.
[0046] For example, an application scenario of the embodiments of the present application is shown in FIG. 1.
[0047] The primary business system can be a general management system 300, and the secondary business system can be a user management system 310.
[0048] It should be noted that in FIG. 1, the light-colored bidirectional arrow represents mutual trust between systems, for example, the authorization system 200 trusts the total management system 300, the total management system 300 trusts the first user management system 310, the total management system 300 trusts the second user management system 320, and the total management system 300 trusts the third user management system 330; the dark-colored arrow identifies a data flow or a signal flow.
[0049] The client 100 initiates an authorization request to the authorization system 200; the authorization system 200 authenticates the client 100 and sends an authorization code to the client 100 after successful authentication; since the authorization system 200 trusts the total management system 300, the client 100 can send the identification of the second user management system 320 and the authorization code to the total management system 300; since the second user management system 320 trusts the total management system 300, the total management system 300 forwards the authorization code to the second user management system 320 according to the identification of the second user management system 320; and the second user management system 320 performs authorization verification on the client 100 according to the obtained authorization code.
[0050] It can be understood that the authorization system 200, the total management system 300, the first user management system 310, the second user management system 320, and the third user management system 330 can be physical servers, cloud servers, or virtual devices (such as virtual machines), but are not limited thereto.
[0051] It should be noted that the server where the authorization system and the business system are located is not specifically limited in the embodiments of the present application, for example, the authorization system is arranged in an authorization server, the first-level business system is arranged in a first server, the second-level business system is arranged in a second server, or the first-level business system and the second-level business system are both arranged in the first server.
[0052] In addition, the server where the second-level business system is arranged is not specifically limited in the embodiments of the present application, for example, a plurality of second-level business systems are arranged in the same server, or can be arranged in different servers respectively.
[0053] Referring to FIG. 2, which is a structural schematic diagram of a server provided by an embodiment of the present application.
[0054] As shown in FIG. 2, the server includes a processor 410, a memory 420, and a communication interface 430; the memory 420 is used to store computer instructions; and the processor 410 is used to execute the computer instructions, so that the server performs an authorization verification method.
[0055] In some embodiments, the processor 410 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, etc. The general-purpose processor can also be a microprocessor or any conventional processor.
[0056] In some embodiments, the memory 420 can be a volatile memory or a non-volatile memory, such as a register, etc. Specifically, the volatile memory refers to the memory in which the data stored therein will be lost when the power supply is interrupted. The volatile memory is mainly random access memory (RAM), including static random access memory (SRAM) and dynamic random access memory (DRAM). The non-volatile memory refers to the memory in which the data stored therein will not be lost when the power supply is interrupted. Common non-volatile memories include read only memory (ROM), optical disc, magnetic disc, solid state disk, and various memory cards based on flash memory technology, etc.
[0057] In some embodiments, the memory 420 stores executable code, and the processor 410 executes the code to implement the authorization verification method.
[0058] The communication interface 430 is used to implement server communication, and the server obtains the authorization verification method through the communication interface 430.
[0059] The bus can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or a peripheral component interconnect express (PCIE) bus, etc. The bus can be divided into an address bus, a data bus, and a control bus, etc. For ease of understanding, FIG. 2 only uses one thick line to represent, but does not mean that there is only one bus or one type of bus.
[0060] In the embodiment of the present application, a mutual trust mechanism is established between the authorization system and the primary business system, and a mutual trust mechanism is established between the primary business system and the secondary business system, so as to realize unified authorization among the authorization system, the primary business system and the secondary business system. The authorization verification method will be introduced in combination with specific embodiments.
[0061] Referring to FIG. 3, it is a signaling diagram of the authorization verification method provided by the embodiment of the present application.
[0062] As shown in FIG. 3, the method is applied to a computing device, which includes an authorization system, a primary business system and a secondary business system; wherein the authorization system and the primary business system are mutually trusted, and the primary business system and the secondary business system are mutually trusted.
[0063] The embodiment of the present application does not specifically limit the form of the mutual trust mechanism between the authorization system and the primary business system, and the form of the mutual trust mechanism between the primary business system and the secondary business system, for example, a white list, a key or a mutual trust configuration.
[0064] For example, the form of the mutual trust mechanism between the authorization system and the primary business system is a white list, and the authorization system can save and maintain the corresponding white list. For example, the authorization system can add or delete the mutual trust mechanism with any primary business system, that is, add the primary business system to the white list or delete it from the white list. In the case that the primary business system A is added to the white list, the client can send the authorization code to the primary business system A; correspondingly, in the case that the primary business system B is deleted from the white list, the client can no longer send the authorization code to the primary business system B.
[0065] The method includes:
[0066] S301: The primary business system receives the authorization code sent by the client and the information of the target secondary business system.
[0067] Wherein, the authorization code is sent by the authorization system to the client in response to the success of the client logging in the authorization system; and the target secondary business system does not establish mutual trust with the authorization system.
[0068] It should be noted that in the embodiment of the present application, the authorization system only allows the client to send the authorization code to the primary business system which is mutually trusted with the authorization system.
[0069] It should be noted that the secondary business system in the embodiments of the present application can be a business system that cannot establish mutual trust with the authorization system. For example, the business system includes a primary business system and a secondary business system, the secondary business system is temporarily generated by the primary business system, and the secondary business system cannot apply to the authorization system for establishing mutual trust with it; or the secondary system is generated by other secondary business systems (replicating other secondary business systems or being generated by fission of other secondary business systems), and the secondary business system cannot apply to the authorization system for establishing mutual trust. In addition to this, the secondary business system can also be a business system that can establish mutual trust with the authorization system, but has not established mutual trust.
[0070] In the embodiments of the present application, the information of the target secondary business system includes interface information of the target secondary business system and identification information of the target secondary business system.
[0071] For example, the interface information of the target secondary business system can be a uniform resource location (URL), and the identification information of the target secondary business system can be a server name where the target secondary business system is located or a server address where the target secondary business system is located.
[0072] The form of the authorization code is not specifically limited in the embodiments of the present application. For example, the authorization code can be a string composed of numbers, a string composed of letters, or a string composed of numbers, letters and characters.
[0073] The type of the client is not specifically limited in the embodiments of the present application. For example, the client can be a browser or a mobile phone application software.
[0074] For example, in the case of the mobile phone application software, the mobile phone application software logs in the authorization system with the account and the password, and requests the authorization system to issue the authorization code.
[0075] After the client obtains the authorization code sent by the authorization system, if the client needs to access the primary business system, the client can send the authorization code to the primary business system based on the mutual trust mechanism between the authorization system and the primary business system, so as to realize the access of the client to the primary business system; if the client needs to access the secondary business system, the client needs to send the information of the target secondary business system and the authorization code to the primary business system, so that the primary business system can make further judgment.
[0076] It should be understood that there is a corresponding relationship between the secondary business system name and the information of the secondary business system. When the client inputs the name of the target secondary business system, the client can obtain the information of the target secondary business system according to the corresponding relationship, and send the information of the target secondary business system and the authorization code to the primary business system.
[0077] After the primary service system obtains the information of the target secondary service system to be accessed by the client and the authorization code sent by the client, the primary service system needs to authorize and verify the client through the following step S302.
[0078] S302: According to the mutual trust mechanism between the target secondary service system and the primary service system and the identification information of the target secondary service system, the primary service system forwards the authorization code to the target secondary service system, so that the target secondary service system authenticates the client through the authorization code.
[0079] The embodiment of the present application does not specifically limit the form of the mutual trust mechanism between the target secondary service system and the primary service system, for example, a white list, a key or a mutual trust configuration.
[0080] For example, the form of the mutual trust mechanism between the target secondary service system and the primary service system is a white list, and the primary service system can save and maintain the corresponding white list. For example, the primary service system adds or deletes the mutual trust mechanism with any secondary service system.
[0081] In a possible implementation, the primary service system authenticates the target secondary service system according to the entry information of the target secondary service system; and the primary service system forwards the authorization code to the target secondary service system according to the mutual trust mechanism between the primary service system and the target secondary service system and the identification information of the target secondary service system, in the case that the target secondary service system is authenticated successfully.
[0082] It should be noted that the primary service system can forward the authorization code to the target secondary service system only on the premise that the primary service system and the target secondary service system are mutually trusted.
[0083] In a possible implementation, the primary service system receives the entry information of the target secondary service system and authenticates the target secondary service system; the primary service system directs the client to the target secondary service system according to the mutual trust mechanism between the primary service system and the target secondary service system, in the case that the target secondary service system is authenticated successfully; and the client sends the authorization code to the target secondary service system, so that the target secondary service system authenticates the client through the authorization code.
[0084] The embodiment of the present application does not specifically limit the implementation manner of the direction, for example, the implementation is realized through the 302 redirection manner. The client sends the authorization code to the corresponding target secondary service system based on the 302 redirection, so that the target secondary service system authenticates the client through the authorization code.
[0085] It should be noted that the primary service system can be directed to the target secondary service system only on the premise that the primary service system and the target secondary service system are mutually trusted.
[0086] In the embodiment of the application, the secondary business system and the primary business system trust each other, and the primary business system and the authorization system trust each other, so as to realize unified authorization among the authorization system, the primary business system and the secondary business system. The client sends an authorization code and information of a target secondary business system to be accessed to the primary business system based on the trust mechanism between the authorization system and the primary business system, and the primary business system forwards the authorization code to the target secondary business system based on the trust mechanism between the primary business system and the secondary business system, so that the target secondary business system authorizes the client by using the authorization code, thereby reducing the risk of information leakage.
[0087] Referring to FIG. 4, it is a signaling diagram of another authorization verification method provided by the embodiment of the application.
[0088] As shown in FIG. 4, the method comprises the following steps.
[0089] S401: The client logs in the authorization system.
[0090] For example, the client jumps to a login page in response to a click operation of a user, so that the user inputs account information and a password on the login page, and then the authorization system can verify the account and the password.
[0091] S402: The authorization system verifies the client, and sends a first authorization code to the client if the verification is passed.
[0092] S403: The client sends information (interface information and identification information) of a target secondary business system to be accessed and the first authorization code to the primary business system based on the trust mechanism between the client and the primary business system.
[0093] S404: The primary business system authenticates the target secondary business system according to the interface information of the target secondary business system, and forwards the first authorization code to the target secondary business system according to the trust mechanism between the target secondary business system and the primary business system and the identification information of the target secondary business system after the authentication is passed.
[0094] S405: The target secondary business system sends the first authorization code to the authorization system.
[0095] S406: The authorization system verifies the first authorization code, and returns user information to the target secondary business system if the verification is passed.
[0096] It should be understood that the first authorization code is stored in the authorization system, and the authorization system compares the first authorization code sent by the target secondary business system with the stored first authorization code. If they are consistent, the verification is passed; if they are not consistent, the verification is not passed.
[0097] In a possible implementation, the authorization system returns user information to the target secondary service system if the first authorization code passes the verification. The embodiments of the present application do not limit the content of the user information. For example, the user information can be a user account and a password.
[0098] S407: The target secondary service system returns an instruction to the client based on the user information, indicating that the access request of the client passes.
[0099] For example, the target secondary service system sends an HTTP cookie to the client through a setcookie() function. The cookie is a variable sent by the server to the browser, indicating that the access request of the client passes.
[0100] S408: The client accesses the target secondary service system.
[0101] In the embodiments of the present application, the first authorization code is forwarded to the target secondary service system through the primary service system, so that the target secondary service system authorizes and verifies the client through the first authorization code, avoids authenticating the client through the user information, and further reduces the risk of information leakage.
[0102] The foregoing embodiments introduce an authorization verification method in the case of one secondary service system, for example, secondary service system A. The embodiments of the present application will introduce an authorization verification method in the case of at least two secondary service systems, for example, secondary service system A and secondary service system B.
[0103] It should be noted that the secondary service system A and the secondary service system B in the embodiments of the present application are two independent service systems and do not interfere with each other. For example, the secondary service system A manages user A, and the secondary service system B manages user B.
[0104] In a possible implementation, if the client implements the secondary service system A and the first authorization code is valid, the object accessed by the client is switched from the secondary service system A to the secondary service system B. The validity of the first authorization code can be determined by the time limit of the first authorization code. If the first authorization code is within the valid time limit, the first authorization code is valid. If the first authorization code is not within the valid time limit, the first authorization code is invalid.
[0105] It should be noted that the time limit of the first authorization code can be set in the authorization system.
[0106] The signaling diagram of the authorization verification method is shown in FIG. 5, and further includes the following steps:
[0107] S501: The client sends the first authorization code and the information (interface information and identification information) of the target secondary service system B to the primary service system.
[0108] S502: The primary business system forwards the first authorization code to the target secondary business system B according to the identification information of the target secondary business system B.
[0109] S503: The target secondary business system B sends the first authorization code to the authorization system.
[0110] S504: The authorization system checks the first authorization code, and returns user information to the target secondary business system B if the checking is successful.
[0111] S505: The target secondary business system B returns an instruction to the client based on the user information, indicating that the access request of the client is passed.
[0112] S506: The client accesses the target secondary business system B.
[0113] In a possible implementation, if the client implements the secondary business system A and the first authorization code is invalid, the client is switched to the secondary business system B.
[0114] The signaling diagram of the authorization checking method is shown in FIG. 6, and further includes the following steps:
[0115] S601: The client logs in the authorization system.
[0116] S602: The authorization system checks the client, and sends a second authorization code to the client if the checking is passed.
[0117] It should be understood that the second authorization code sent by the authorization system to the client in this step S602 is of the same format as the first authorization code sent by the authorization system to the client in step S402, but has a different content value.
[0118] S603: The client sends the information (interface information and identification information) of the target secondary business system B to be accessed and the second authorization code to the primary business system based on the mutual trust mechanism between the authorization system and the primary business system.
[0119] S604: The primary business system authenticates the secondary business system B according to the interface information of the secondary business system B, and forwards the second authorization code to the target secondary business system B according to the mutual trust mechanism between the target secondary business system B and the primary business system and the identification information of the target secondary business system B after the authentication is passed.
[0120] S605: The target secondary business system B sends the second authorization code to the authorization system.
[0121] S606: The authorization system checks the second authorization code, and returns user information to the target secondary business system B if the checking is successful.
[0122] S607: The target secondary service system B returns an instruction to the client based on the user information, indicating that the access request of the client is passed.
[0123] S608: The client accesses the target secondary service system B.
[0124] It should be understood that the authorization checking method for more than two secondary service systems will not be repeated.
[0125] In the embodiments of the present application, by means of reusing the first authorization code or reapplying the second authorization code, the client can switch between multiple secondary service systems, and unified authorization between the authorization system, the primary service system and the secondary service systems (the secondary service system A and the secondary service system B) is realized. In addition, on the basis of unified authorization, the client can flexibly access each secondary service system.
[0126] In addition, the present application provides a computing device, and a structural schematic diagram thereof is shown in FIG. 7.
[0127] As shown in FIG. 7, the computing device includes an authorization system 710, a primary service system 720 and secondary service systems 730; wherein the authorization system 710 and the primary service system 720 trust each other, and the primary service system 720 and the secondary service systems 730 trust each other.
[0128] In FIG. 7, the secondary service systems 730 include a secondary service system A, a secondary service system B, … and a secondary service system N; the secondary service systems 730 include the secondary service system A, the secondary service system B, … and the secondary service system N, all of which trust the primary service system 720.
[0129] The primary service system 720 is configured to receive an authorization code and information of a target secondary service system sent by a client; according to a mutual trust mechanism between the target secondary service system and the primary service system 720 and the information of the target secondary service system, the authorization code is forwarded to the target secondary service system; wherein the authorization code is sent by the authorization system 710 to the client in response to that the client logs in the authorization system 710 successfully; and the target secondary service system and the authorization system 710 do not establish mutual trust.
[0130] The target secondary service system is configured to receive the authorization code and perform authorization checking on the client based on the authorization code.
[0131] For some secondary business systems that cannot establish mutual trust with the authorization system, the authorization system, the primary business system and the secondary business system cannot achieve unified authorization. In order to achieve unified authorization between the authorization system, the primary business system and the secondary business system, in the embodiment of the application, the secondary business system establishes mutual trust with the primary business system, and the primary business system establishes mutual trust with the authorization system, so as to achieve unified authorization between the authorization system, the primary business system and the secondary business system. In the embodiment of the application, the primary business system receives the authorization code and the information of the target secondary business system sent by the client, and forwards the authorization code to the target secondary business system based on the mutual trust mechanism between the primary business system and the target secondary business system, so as to enable the target secondary business system to perform authorization verification on the client, achieve unified authorization between the authorization system, the primary business system and the secondary business system, and further reduce the risk of information leakage.
[0132] Optionally, the primary business system 720 is specifically configured to authenticate the target secondary business system according to the entry information of the target secondary business system; and in the case that the target secondary business system is authenticated successfully, forward the authorization code to the target secondary business system according to the mutual trust mechanism between the primary business system and the target secondary business system and the identification information of the target secondary business system.
[0133] Optionally, the secondary business system 730 includes a plurality of primary business systems 720, and the primary business system 720 is further configured to receive the authorization code and the information of the second target secondary business system sent by the client in the case that the access target of the client changes from the first target secondary business system to the second target secondary business system and the authorization code is valid; and the primary business system 720 forwards the authorization code to the second target secondary business system according to the mutual trust mechanism between the primary business system and the second target secondary business system and the information of the second target secondary business system; and the second target secondary business system is further configured to receive the authorization code and perform authorization verification on the client based on the authorization code.
[0134] Optionally, the authorization system 710 is configured to, in the case that the access target of the client changes from the first target secondary business system to the second target secondary business system and the authorization code is invalid, send a new authorization code to the client in response to that the client logs in the authorization system successfully.
[0135] Optionally, the mutual trust mechanism includes any one of a white list, mutual trust configuration and a key.
[0136] In the embodiment, the diversified mutual trust mechanism improves the flexibility and applicability of the authorization verification method.
[0137] Optionally, the target secondary business system sends the authorization code to the authorization system; the authorization system checks the authorization code, and sends user information to the target secondary business system in the case of successful checking; the target secondary business system receives the user information, and sends the authorization request of the client based on the user information.
[0138] From the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the above-mentioned embodiment methods can be implemented by means of software and a general hardware platform. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in the various embodiments or some parts of the embodiments.
[0139] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the description of the method embodiments. According to the actual needs, some or all of the modules can be selected to achieve the purpose of the embodiment. Those skilled in the art can understand and implement without creative labor.
[0140] The above description is only exemplary embodiments of the present application, and is not intended to limit the protection scope of the present application.
Claims
1. An authorization check method, characterized by, The method is applied to a computing device comprising an authorization system, a primary service system and a secondary service system; wherein the authorization system is mutually trusted with the primary service system, the primary service system is mutually trusted with the secondary service system, and the method comprises: The primary service system receives an authorization code and information of a target secondary service system sent by a client; wherein the authorization code is sent by the authorization system to the client in response to the client logging in the authorization system successfully; and the target secondary service system is not mutually trusted with the authorization system; The primary service system forwards the authorization code to the target secondary service system according to a mutual trust mechanism between the target secondary service system and the primary service system and the information of the target secondary service system; The target secondary service system receives the authorization code and performs authorization verification on the client based on the authorization code.
2. The method of claim 1, wherein, The information of the target secondary service system comprises identification information and entry information, and the primary service system forwards the authorization code to the target secondary service system according to the mutual trust mechanism between the target secondary service system and the primary service system and the information of the target secondary service system, comprising: The primary service system authenticates the target secondary service system according to the entry information of the target secondary service system; The primary service system forwards the authorization code to the target secondary service system according to the mutual trust mechanism between the target secondary service system and the primary service system and the identification information of the target secondary service system in the case that the target secondary service system is authenticated successfully.
3. The method according to claim 1 or 2, characterized in that, The secondary service system comprises a plurality of, in the case that the access target of the client changes from a first target secondary service system to a second target secondary service system and the authorization code is valid, the method further comprises: The primary service system receives the authorization code and information of the second target secondary service system sent by the client; The primary service system forwards the authorization code to the second target secondary service system according to a mutual trust mechanism between the second target secondary service system and the primary service system and the information of the second target secondary service system; The second target secondary service system receives the authorization code and performs authorization verification on the client based on the authorization code.
4. The method of claim 3, wherein, In the case that the access target of the client changes from the first target secondary service system to the second target secondary service system and the authorization code is invalid, the method further comprises: The authorization system sends a new authorization code to the client in response to the client logging in the authorization system successfully.
5. The method of claim 4, wherein, The mutual trust mechanism comprises any one of a white list, a mutual trust configuration and a key.
6. The method of claim 3, wherein, The target secondary service system receives the authorization code and performs authorization verification on the client based on the authorization code, specifically comprising: The target secondary service system sends the authorization code to the authorization system; The authorization system verifies the authorization code and sends user information to the target secondary service system in the case that the verification is successful; The target secondary service system receives the user information, and performs an authorization request based on the user information through the client.
7. A computing device, comprising: Comprise: An authorization system, a primary service system and a secondary service system; wherein the authorization system and the primary service system are mutually trusted, and the primary service system and the secondary service system are mutually trusted; The primary service system is configured to receive an authorization code and information of a target secondary service system sent by a client, and forward the authorization code to the target secondary service system according to a mutual trust mechanism between the target secondary service system and the primary service system and the information of the target secondary service system; wherein the authorization code is sent by the authorization system to the client in response to that the client successfully logs in the authorization system; and the target secondary service system and the authorization system are not mutually trusted; The target secondary service system is configured to receive the authorization code and perform authorization verification on the client based on the authorization code.
8. The computing device of claim 7, wherein, The information of the target secondary service system comprises identification information and entry information; The primary service system is specifically configured to authenticate the target secondary service system according to the entry information of the target secondary service system, and forward the authorization code to the target secondary service system according to the mutual trust mechanism between the target secondary service system and the primary service system and the identification information of the target secondary service system in the case that the target secondary service system is successfully authenticated.
9. The computing device of claim 7 or 8, wherein, The secondary service system comprises a plurality of The primary service system is further configured to receive the authorization code and information of a second target secondary service system sent by the client in the case that the access target of the client changes from a first target secondary service system to the second target secondary service system and the authorization code is valid; and forward the authorization code to the second target secondary service system according to a mutual trust mechanism between the second target secondary service system and the primary service system and the information of the second target secondary service system. The second target secondary service system is further configured to receive the authorization code and perform authorization verification on the client based on the authorization code.
10. The computing device of claim 9, wherein, The authorization system is configured to send a new authorization code to the client in response to that the client successfully logs in the authorization system in the case that the access target of the client changes from the first target secondary service system to the second target secondary service system and the authorization code is invalid.
Citation Information
Patent Citations
Cross-domain single-point registration system and method facing system integration
CN106936853A
Gateway authentication and identity authentication platform and method thereof
CN111865920A
Authorization authentication method and device, gateway, medium and computer equipment
CN115913568A
Authorization verification method and computing device
CN119135427A
Single sign-on between 2 independent states
US20230103886A1