WO2018196153A1 - 一种开放授权方法、装置和终端 - Google Patents

一种开放授权方法、装置和终端 Download PDF

Info

Publication number
WO2018196153A1
WO2018196153A1 PCT/CN2017/090311 CN2017090311W WO2018196153A1 WO 2018196153 A1 WO2018196153 A1 WO 2018196153A1 CN 2017090311 W CN2017090311 W CN 2017090311W WO 2018196153 A1 WO2018196153 A1 WO 2018196153A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
terminal
information
authorization
login
Prior art date
Application number
PCT/CN2017/090311
Other languages
English (en)
French (fr)
Inventor
王思善
杨帆
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201780037019.5A priority Critical patent/CN109314711B/zh
Publication of WO2018196153A1 publication Critical patent/WO2018196153A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Definitions

  • the present application relates to the field of communications technologies, and in particular, to an open authorization method, apparatus, and terminal.
  • a user accesses a user-protected resource stored by an application server through an application client (Client).
  • the A application server generally authenticates the user's identity through user credentials of the user's A application, such as an account password. If the user wants to access the user-protected resource stored on the A application server through the client of the B application, the account password of the A application is also required.
  • the account password applied by the user to the B application shared account password A may cause a risk of information leakage.
  • Open Authorization (O-Auth) 2.0 protocol is a secure, open and simple user resource authorization standard developed by the Internet Engineering Task Force (IETF).
  • IETF Internet Engineering Task Force
  • the client of the B application can access the user protected resource stored by the A application server without the account password of the user's A application.
  • some large-scale applications can support the O-Auth2.0 protocol.
  • the user can use the account of the application supporting the O-Auth2.0 protocol, such as a microblog account, to log in to the third-party application, and the third-party application can access the user-protected resource stored by the user's microblog server, such as the user's microblog avatar. ,nickname.
  • the problems in the above-mentioned manners include problems such as loss or invalidity of the login credentials and loss of the historical login record of the application in the scenario of the terminal replacement, the terminal resetting the factory settings, and the terminal reinstallation system.
  • the user needs to log in to the third-party application again.
  • the embodiment of the present application provides an open authorization login method, device, and terminal, which can obtain an authorization relationship between a first application and a second application from received data or from locally saved data, and then can utilize the first The second application that has applied the open authorization again re-authorizes the first application in this login, thereby further reducing the risk of user information leakage and improving the experience of the user opening the authorized login application.
  • the embodiment of the present application provides an open authorization login method, where the method includes: determining, by the terminal, a second application according to historical login information of the first application, where the historical login information is information received by the terminal, The historical login information includes the information of the second application, and the second application is an application that is openly authorized to authorize the first application; the terminal sends the first application to the authorized server of the determined second application. Authorizing the login authorization request to request the first application to access the protected user resource of the determined second application's resource server.
  • the method further includes: the terminal according to the terminal The determined second application updates the historical login information of the first application to an open authorization operation performed by the first application.
  • the historical login information received by the terminal is specifically received by the terminal from a cloud server, from a terminal other than the terminal, or from at least one of an external storage. information.
  • the determining, by the terminal, the second application according to the historical login information of the first application includes: the terminal from the historical information recording module, the storage path of the first application, and the storage path of the second application. At least one of the historical login information; wherein the historical information recording module is a module for recording and/or saving historical login information of a plurality of applications in the terminal.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the terminal according to the historical login information of the first application Determining the second application includes: determining, by the terminal, a second application from the at least two applications according to the occurrence time of the historical open authorization.
  • the determining, by the terminal, the second application according to the historical login information of the first application includes: the terminal according to the at least two The information of the application displays at least two applications; the terminal receives a selection operation instruction; the terminal determines a second application from the at least two applications according to the selection operation instruction.
  • the method before the terminal sends an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, the method further includes: displaying, by the terminal, the terminal Determining a second application; the terminal receiving an operation instruction for confirming that the first application is openly authorized by the determined second application; the terminal sending a location to the determined authorization server of the second application
  • the authorization request of the first application for performing the open authorization login includes: the terminal sending, according to the operation instruction for confirming that the first application is openly authorized by the determined second application, sending the An authorization request to open an authorized login.
  • the method further includes: the terminal displaying the first interface according to the historical login information, where the first interface includes an identifier of the second application.
  • the first interface further includes an identifier of the first application corresponding to the second application.
  • the method further includes: the terminal receiving a login operation instruction for the first application on the first interface; and the terminal to the determined authorization server of the second application
  • Sending an authorization request for performing the open authorization login on the first application includes: the terminal authorizing the second application on the first interface according to the login operation instruction for the first application on the first interface
  • the server sends the authorization request for performing an open authorization login to the first application.
  • the method further includes: the terminal receiving a display operation instruction for the second application on the first interface; the terminal displaying the second interface according to the display operation instruction, where The second interface includes an identifier of the first application corresponding to the second application.
  • the method further includes: the terminal receiving a login operation instruction for the first application on the second interface; the terminal sending the authorization server to the determined second application
  • the authorization request for performing the open authorization login on the first application includes: the terminal according to the login operation instruction for the first application on the first interface to the authorization server of the second application on the first interface Sending an authorization request for an open authorization login to the first application.
  • the embodiment of the present application provides an open authorization login method, where the method includes: determining, by the terminal, a second application according to historical login information of the first application, where the historical login information is The information stored in the terminal for the first application to be openly authorized, the historical login information includes the information of the second application, and the second application is an application that is openly authorized to authorize the first application; And determining, by the authorization server of the second application, an authorization request for performing an open authorization login on the first application, to request the first application to access the protected user resource in the determined resource resource of the second application.
  • the method further includes: the terminal according to the terminal The determined second application updates the historical login information of the first application to an open authorization operation performed by the first application.
  • the determining, by the terminal, the second application according to the historical login information of the first application includes: the terminal from the historical information recording module, the storage path of the first application, and the storage path of the second application. At least one of the historical login information is obtained.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the terminal according to the historical login information of the first application Determining the second application includes: determining, by the terminal, a second application from the at least two applications according to an occurrence time of the historical open authorization.
  • the method further includes: the terminal displaying the first interface according to the historical login information, where the first interface includes an identifier of the second application.
  • the first interface further includes an identifier of the first application corresponding to the second application.
  • the method further includes: the terminal receiving a login operation instruction for the first application on the first interface; the terminal sending the authorization server to the determined second application
  • the authorization request for performing the open authorization login on the first application includes: the terminal according to the login operation instruction for the first application on the first interface to the authorization server of the second application on the first interface Sending the authorization request for performing an open authorization login to the first application.
  • the method further includes: the terminal receiving a display operation instruction for the second application on the first interface; the terminal displaying the second interface according to the display operation instruction, where The second interface includes an identifier of the first application corresponding to the second application.
  • the method further includes: the terminal receiving a login operation instruction for the first application on the second interface; the terminal sending the authorization server to the determined second application
  • the authorization request for performing the open authorization login on the first application includes: the terminal according to the login operation instruction for the first application on the first interface to the authorization server of the second application on the first interface Sending the authorization request for performing an open authorization login to the first application.
  • an open authorization login device the device includes: a processing unit, configured to determine a second application according to historical login information of the first application, where the historical login information is information received by the terminal, The historical login information includes the information of the second application, the second application is an application that is openly authorized to authorize the first application, and the communication unit is configured to send the first application to the authorized server of the determined second application.
  • a processing unit configured to determine a second application according to historical login information of the first application, where the historical login information is information received by the terminal, The historical login information includes the information of the second application, the second application is an application that is openly authorized to authorize the first application, and the communication unit is configured to send the first application to the authorized server of the determined second application.
  • Authorizing the login authorization request to request the first application to access the protected user resource of the determined second application's resource server.
  • the processing unit is further configured to: perform the first according to the determined second application
  • the historical login information of the first application is updated by applying the open authorization operation performed this time.
  • the historical login information received by the terminal is specifically received by the communication unit from a cloud server, from a terminal other than the terminal, or from at least one of the memory. information.
  • the processing unit is further configured to acquire the historical login information from at least one of a history information recording module, a storage path of the first application, and a storage path of the second application.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the processing unit is further configured to use the history according to the historical The occurrence time of the open authorization determines a second application from the at least two applications.
  • the processing unit is further configured to display the at least two applications according to the information of the at least two applications;
  • the processing unit is further configured to receive a selection operation instruction;
  • the processing unit is further configured to determine a second application from the at least two applications according to the selection operation instruction.
  • the processing unit is further configured to display the determined second application, and the processing unit is further configured to: receive, to confirm, open the first application by using the determined second application.
  • Authorizing the operation instruction the communication unit is further configured to send the open authorization login to the first application according to the operation instruction for confirming that the first application is openly authorized by the determined second application Authorization request.
  • the processing unit is further configured to display the first interface according to the historical login information, where the first interface includes an identifier of the second application corresponding to the information of the second application.
  • the first interface further includes an identifier of the first application corresponding to the second application.
  • the processing unit is further configured to receive a login operation instruction for the first application on the first interface; the communication unit is configured according to the first on the first interface The login operation instruction of the application sends the authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the processing unit is further configured to receive a display operation instruction for the second application on the first interface; the processing unit is further configured to display the second interface by the display operation instruction,
  • the second interface includes an identifier of the first application corresponding to the second application.
  • the processing unit is further configured to receive a login operation instruction for the first application on the second interface; the communication unit is further configured to be configured according to the first interface
  • the login operation instruction of the first application sends an authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the embodiment of the present application provides an open authorization login device, where the device includes: a processing unit, configured to determine a second application according to historical login information of the first application, where the historical login information is the terminal record The information, the historical login information of the first application includes information of the second application, the second application is an application that is openly authorized to authorize the first application, and the communication unit is configured to use the authorization server of the determined second application. Sending an authorization request for performing an open authorization login to the first application, to request the first application to access the determined user resource of the second application's resource server.
  • the processing unit is further configured to update historical login information of the first application according to the determined open application operation performed by the second application to the first application.
  • the processing unit is further configured to save from the historical information recording module and the first application. At least one of the storage path and the storage path of the second application acquires historical login information of the first application.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the processing unit is further used to open the history The occurrence time of the authorization determines a second application from the at least two applications.
  • the processing unit is further configured to display the first interface according to the historical login information, where the first interface includes an identifier of the second application corresponding to the information of the second application.
  • the first interface further includes an identifier of the first application corresponding to the second application.
  • the processing unit is further configured to receive a login operation instruction for the first application on the first interface; the communication device is further configured to be configured according to the first interface The login operation instruction of the first application sends the authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the processing unit is further configured to receive a display operation instruction for the second application on the first interface; the processing unit is further configured to display the second interface according to the display operation instruction
  • the second interface includes an identifier of the first application corresponding to the second application.
  • the processing unit is further configured to receive a login operation instruction for the first application on the second interface; the communication unit is further configured to be configured according to the first interface
  • the login operation instruction of the first application sends the authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the embodiment of the present application further provides a terminal, where the terminal includes a processor and a storage; the memory stores a code; the processor executes the code, and is configured to perform a historical login according to the first application. Determining, by the information, the second application, where the historical login information is information received by the terminal, the historical login information includes information of the second application, and the second application is an application for historically authorizing the first application; And executing, to the authorization server of the determined second application, an authorization request for performing an open authorization login on the first application, to request the first application to access the protected user in the determined resource of the second application. Permissions for resources.
  • the historical login information received by the terminal is specifically information that the terminal receives from a cloud server, from a terminal other than the terminal, or from at least one of the memory. .
  • the processor is further configured to: obtain the historical login information from at least one of a history information recording module, a storage path of the first application, and a storage path of the second application;
  • the history information recording module is a module for recording and/or saving historical login information of a plurality of applications in the terminal.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the processor is further configured to perform according to the The occurrence time of the historical open authorization determines a second application from the at least two applications.
  • the processor is further configured to display the at least two applications according to the information of the at least two applications;
  • the processor is further configured to execute receiving a selection operation instruction;
  • the processor is further configured to perform determining one of the at least two applications from the at least two applications according to the selection operation instruction.
  • the processor is further configured to execute a second application that displays the determining; the processor is further configured to perform a receiving confirmation to use the determined second application to the first application. Performing an open authorization operation instruction; the processor is further configured to perform performing, by using the determined second application, the first application according to the confirming The open authorized operation instruction sends the authorization request for performing an open authorization login to the first application.
  • the processor is further configured to display a first interface according to the historical login information, where the first interface includes an identifier of the second application.
  • the first interface further includes an identifier of the first application corresponding to the second application.
  • the processor is further configured to: execute a login operation instruction for the first application on the first interface; the processor is further configured to perform according to the The login operation instruction of the first application on the interface sends the authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the processor is further configured to: execute a display operation instruction for the second application on the first interface; the processor is further configured to execute the display according to the expansion operation instruction
  • the second interface includes an identifier of the first application corresponding to the second application.
  • the processor is further configured to perform receiving a login operation instruction for the first application on the second interface; the processor is further configured to perform according to the The login operation instruction of the first application on the interface sends an authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the processor is further configured to: perform historical login information of the first application according to an open authorization operation performed by the determined second application to the first application.
  • the embodiment of the present application provides a terminal, where the terminal includes: a processor and a memory; the memory stores a code; the processor executes the code, and is used to perform any of the foregoing aspects. method.
  • the embodiment of the present application provides a computer readable storage medium storing a program, where the program includes an instruction, when the instruction is executed by a terminal, causing the terminal to perform the method according to any one of the first aspects or The method of any of the second aspects.
  • the embodiment of the present application provides a computer program product comprising instructions, when the computer program product is run on a terminal, causing the terminal to perform the method of any one of the first aspect or the second aspect method.
  • the open authorization login method, device, and terminal provided by the embodiment of the present application can obtain an authorization relationship between the first application and the second application from the received data or from the locally saved data, thereby helping the user to quickly and accurately determine the pair.
  • the first application performs the second application of the open authorization, so that the user can use the second application to open the first application again in the current login, thereby further reducing the risk of user information leakage and improving user adoption. Open the authorized way to log in to the app experience.
  • FIG. 1 is an application architecture diagram of an open authorization login method according to an embodiment of the present application
  • FIG. 2 is a flowchart of an open authorization of an open authorization login method according to an embodiment of the present application
  • FIG. 3 is a flowchart of an open authorization login method according to an embodiment of the present application.
  • FIG. 4 is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 5 is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 6 is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 7 is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 7b is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 7c is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 8 is a flowchart of an open authorization login method according to an embodiment of the present application.
  • FIG. 9 is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 9b is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 9c is a diagram showing an effect of an open authorization login method according to an embodiment of the present application.
  • FIG. 10 is a schematic structural diagram of an open authorization login device according to an embodiment of the present application.
  • FIG. 11 is a schematic structural diagram of an open authorization login device according to an embodiment of the present disclosure.
  • FIG. 12 is a schematic structural diagram of a terminal according to an embodiment of the present application.
  • FIG. 13 is a schematic structural diagram of a terminal according to an embodiment of the present application.
  • the terminal in the embodiment of the present application may specifically be a smart watch, a mobile phone, a tablet, a computer with wireless transceiver function, a virtual reality (VR) terminal device, and an augmented reality (AR).
  • Terminal equipment wireless terminals in industrial control, wireless terminals in self driving, wireless terminals in remote medical, wireless terminals in smart grid, transportation A wireless terminal in a transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, and the like.
  • FIG. 1 shows a possible application architecture of an open authorization login method provided by an embodiment of the present application.
  • a client for one or more applications can be installed on the terminal.
  • the authorization server may be an application server that can issue an access token after obtaining the user's permission after successfully authenticating the user identity.
  • a resource server may refer to an application server that stores protected user resources, and may receive and respond to requests for access to protected user resources using an access token.
  • the authorization server and the resource server can be the same server.
  • the terminal may receive the historical login information of the first application from the network, or may receive the historical login information of the first application from other terminals, or obtain the history of the first application from the data stored locally by the terminal. login information.
  • the historical information of the first application may include related information of the second application.
  • the second application may be an application that the user has opened authorization for the first application, and the related information of the second application may be information for the second application to openly authorize the first application.
  • the terminal may determine, according to the information of the second application, the second application that has previously opened the authorized login to the first application; and the terminal may send an authorization request for performing the open authorization login to the first application to the determined authorization server of the second application, to The authorization server requesting the determined second application authorizes the first application such that the first application can access the protected user resource in the determined resource server of the second application.
  • the first application indicates an application that is authorized to log in using information of other applications;
  • the second application indicates that the user can use the information of the application to log in to applications of other applications.
  • the second application may openly authorize the first application, so that the first application can access the resource server of the second application.
  • FIG. 2 illustrates one possible process for a first application to access a resource of a protected user stored in a resource server of a second application.
  • Step 201 Authorize a login request.
  • the terminal displays an authorized login interface of the second application to the first application,
  • the second application information of the user such as the second application account of the user, is displayed to the user, and the first application is logged in, that is, the login request is displayed to the user.
  • Step 202 Authorize the login permission.
  • the user licenses to log in to the first application using its second application information, and the terminal receives a credential, ie, an authorization code, indicating that the user is permitted to log in to the first application using its second application information.
  • Step 203 Authorize the request.
  • the terminal may send an authorization request to the authorization server of the second application by means of the login permission to request the first application to access the access token of the protected user resource in the resource server of the second application.
  • Step 204 authorize the license.
  • the authorization server may authenticate the identity of the first application and verify the authorization code, and then send an authorization to the terminal to permit the client of the first application on the terminal to access the rights of the protected user resource in the resource server of the second application.
  • the license can be an access token.
  • Step 205 resource access.
  • the terminal can access the resource server of the second application through the client of the first application by means of the license to request the protected user resource in the resource server.
  • Step 206 Sending a resource.
  • the resource server of the second application verifies the license, thereby enabling the first application to access the resource.
  • the resource server implementing the second application may open some protected to the first application without exposing the user application of the second application's account, password, and the like to the first application. User's resources.
  • the second application is Sina Weibo as an example to describe the open authorization login.
  • Sina Weibo can support the open authorization function based on O-Auth2.0 protocol, allowing users to log in to other applications, such as the first application, using Sina Weibo account.
  • the first application can invoke the open authorization interface provided by Sina Weibo to open the authorized login.
  • the first application can access and obtain the Sina Weibo.
  • the user automatically registers in the first application by using the Sina Weibo account information, and calls the basic user resource in the Sina Weibo resource server, which simplifies the operation of the user to log in to the first application and improves the user experience.
  • the first application when the user logs in to the first application by using the Sina Weibo account, the first application generates the account of the first application for the user, that is, the registration is automatically completed in the first application, and the process generally does not require user perception.
  • the user still uses the Sina Weibo account to open and authorize the first application during subsequent login.
  • Open authorization login is fast and convenient, and users do not need to register and remember accounts and passwords when logging in to the first application, thereby reducing the use of accounts and passwords, reducing the risk of account password leakage, and improving the security of users using network services. Therefore, more and more users choose to open the authorized login mode to log in to the first application.
  • Some applications can provide data migration functions, such as mobile phone cloning applications for Huawei mobile phones.
  • the mobile phone clone application can migrate data, system setting parameters and applications on the old terminal to the new terminal.
  • the backup function provided by the terminal's own system can back up the data in the terminal to the cloud server.
  • the application with data migration function and the backup function of the system greatly simplify the operation of user data backup in the scenarios of terminal replacement, terminal factory reset, terminal reinstallation system, etc., and data migration can be completed by simple operation, eliminating application. Client reinstallation and other operations.
  • the security on the terminal side has received more and more attention, and the management of data on the terminal side has become more and more strict. For example, sensitive information such as login credentials may be stored in a more secure storage environment.
  • the user may forget the second application that the user has selected to openly authorize the first application.
  • the user needs to select one application from the plurality of applications providing the open authorization function as the second application to log in to the first application. .
  • the user needs to try to provide an open-licensed application to find the second application it used last time.
  • the user experience may be poor.
  • the user re-opens an application as a new second application, and the first application is re-authorized. Obtaining user sensitive information of other applications is not conducive to the protection of user information, increasing the risk of user privacy leakage.
  • the embodiment of the present application provides a method for opening an authorized login, which can quickly determine the history when the user re-logs in to the first application in a scenario such as terminal replacement, terminal resetting, resetting of the terminal, or client of the first application.
  • the second application that is openly authorized for the first application avoids the cumbersome operation caused by the user sequentially trying from a plurality of applications and the risk of information leakage caused by reselecting the second application.
  • FIG. 3 shows a possible flow of the open authorization login method provided by the embodiment of the present application. The method includes the following steps.
  • Step 301 The terminal determines, according to the historical login information of the first application, the second application, where the historical login information is information received by the terminal, the historical login information includes information of the second application, and the second application is historical An application that is openly licensed for use.
  • the user can log in to the first application by using the open authorization in the A terminal, and the open authorization relationship of the login can be saved as the historical login information of the first application, that is, the historical login information of the first application includes The open authorization relationship of the second application to the first application.
  • the historical login information may be stored in the storage path of the first application, or may be centrally managed and saved by the historical information recording module of the terminal system.
  • the historical information recording module may be a module that can be used to record multiple application information in the terminal system, or a module that can save multiple application information in the terminal system, and the historical information recording module can also be used to manage information of multiple applications;
  • the application information may include historical login information of the application.
  • the A terminal may send the historical login information of the first application to the cloud server, other terminals, external storage, and the like.
  • the B terminal can be a new terminal used after the user replaces the terminal, or an A terminal after the factory resetting, or an A terminal after the system is reinstalled, and the B terminal can forget which one was used.
  • An application is open to any terminal that is openly authorized.
  • the B terminal may receive the historical login information of the first application by means of wireless communication and/or wired communication.
  • the B terminal may receive the historical login information of the first application from the cloud server, or may receive the historical login information of the first application from other terminals, that is, the historical login information of the first application is migrated from the other terminal to the terminal.
  • the B terminal may also receive historical login information of the first application from the storage device.
  • the historical login information of the first application may be centrally managed and saved by the historical information recording module, or may be placed in the storage path of the first application for storage.
  • the previous login information of the first application is recorded in the historical login information, and may include the information of the application that is openly authorized for the first application, that is, the open authorization relationship of the second application to the first application.
  • the information of the second application in the historical login information of the first application may be the name of the application, the icon of the application, the identity of the application, and the like, which may be used to directly or indirectly determine the application.
  • the terminal may determine the second application according to the information of the second application, where the second application is an application that has been openly authorized for the first application, and the terminal may determine the second application according to the information of the second application in the historical login information. Using the determined second application to the first application in a subsequent step Open authorization.
  • Step 302 The terminal sends an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, to request the first application to access the determined resource server of the second application. Permissions for protected user resources.
  • the method for the open authorization login provided by the embodiment of the present application further includes:
  • the terminal may update the historical login information of the first application.
  • the determining, by the terminal, the second application corresponding to the first application, according to the historical login information of the first application includes: the terminal from the historical information recording module, the storage path of the first application, and the storage of the second application. At least one of the paths acquires historical login information of the first application.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the terminal determines the first information according to the information of the second application.
  • the second application corresponding to the application includes: determining, by the terminal, the second application corresponding to the first application from the at least two applications according to the occurrence time of the historical open authorization.
  • the historical login information includes information of two applications A and B. The time when the A application performs the open authorization login for the first application is T1; the time when the B application lastly performs the open authorization login for the first application is T2. It can be assumed that T1 is closer to the current time than T2.
  • the terminal may determine that the A application is a second application that performs an open authorization login for the first application in a subsequent step. In one example, the terminal may determine that the B application is a second application that performs an open authorization login for the first application in a subsequent step.
  • the terminal determines, according to the information of the second application, the first application.
  • the second application includes: the terminal displaying the at least two applications according to the information of the at least two applications; the terminal receiving a selection operation instruction; the terminal determining, according to the selection operation instruction, from the at least two applications A second application.
  • the information of the second application in the historical login message includes information of two applications A and B.
  • the terminal may prompt the user A and B to openly authorize the first application in the login interface of the first application. The user can choose A or B to open the authorization for the first application again.
  • the terminal may determine A or B as an application for open authorization of the first application according to the user's selection operation instruction.
  • the method further includes: the terminal displaying the determined second application; the terminal receiving confirmation to openly authorize the first application by using the determined second application An operation command of the terminal to send an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, where the terminal uses the determined second application pair according to the confirmation
  • the operating instruction of the first application performing the open authorization initiates the authorization request for performing an open authorization login to the first application.
  • the terminal may automatically initiate the open authorization of the first application by using the determined second application, without confirming the user, or may be confirmed by the user. In case, the open authorization of the first application by the determined second application is initiated. This example describes the latter case.
  • the terminal may display an indication of whether to use the second application to open the first application after the second application is determined.
  • Information for example, the indication information is "authorized A login", requesting user confirmation Logging in with the indication indicated by the indication information; the user may confirm that the first application is again authorized to use the second application to log in to the first application; the terminal may initiate an open authorization to use the second application by using the second application according to the confirmation instruction of the user. Process.
  • the method provided by the embodiment of the present application further includes: the terminal displaying the first interface according to the information recorded by the historical information recording module, where the first interface includes the identifier of the second application.
  • the information recorded by the historical information recording module may include historical login information of the first application, where the first application may be one or more applications, and the historical login information of the corresponding first application is historical login information of one or more applications.
  • the historical login information of each application may include at least one record of the second application opening the authorization for the first application or the record of the at least one first application requesting the second application open authorization.
  • the first application may be a, b, c;
  • the information of the second application in the historical login information of the application is the information of the A application, and the information of the second application in the historical login information of the application b
  • the information is the information of the B application, and the information of the second application in the historical login information of the application is the A application information;
  • the terminal can display the interface including the A and B application identifiers, so that the user A and B can be notified on one interface.
  • the application is an application that has been openly authorized for other applications, and the user is allowed to select a second application that is openly authorized for the first application.
  • the first interface displaying the identity of the second application may further include an identification of the first application corresponding to the second application.
  • Figure 6 shows an example of this example, in which A, B are the second application, the A application has been openly authorized for the applications a, c; the B application has been openly authorized for the application b.
  • the correspondence between the second application and the first application can be notified to the user on one interface, which is convenient for the user's operation.
  • the method before the terminal sends an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, the method further includes: receiving, by the terminal, the first a login operation instruction of the first application on the interface; the sending, by the terminal, an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, according to the The login operation instruction of the first application on the first interface determines the second application on the first interface, and sends the authorization request for performing an open authorization login to the first application to the determined authorization server of the second application.
  • the second application is an A application
  • the first application corresponding to A is a.
  • the corresponding relationship between the A application and the a application is displayed on the first interface.
  • the user can click the identifier of the application or the login identifier of the application.
  • the terminal can initiate an open authorization of the application A to the application according to the user's click.
  • the terminal triggers the generation of the login indication information including the application history login information determined by the user according to the login instruction of the user on the first interface, and sends the login indication information to the application, to indicate that the application is based on the A application information in the login indication information. Make sure to use the A app for open authorization login.
  • the application then sends an authorization request for an open authorization login to the a application to the server of the A application according to the received login indication information.
  • the method further includes: the terminal receiving a display operation instruction for the second application on the first interface; the terminal displaying the second interface according to the display operation instruction, the second interface An identifier of the first application corresponding to the second application is included.
  • the first interface that displays the identifier of the second application may not include the identifier of the first application corresponding to the second application, and the user may display the included by clicking the identifier of the second application or the corresponding area around the identifier.
  • the identifier of the first application corresponding to the second application. 6a and 6b show an example in which a terminal displays a first interface and a second interface.
  • the first interface includes a second application A, B, and the user can click the identifier of the application A, and the terminal displays the inclusion.
  • the second interface is displayed within the first interface.
  • the second interface may be displayed in a manner of covering the first interface.
  • the terminal may display an interface including the applications a and c corresponding to the application A by clicking the identifier of the application A or its surrounding area.
  • the method before the terminal sends an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, the method further includes: the terminal receiving, for the second a login operation instruction of the first application on the interface; the sending, by the terminal, an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, according to the The login operation instruction of the first application on the first interface sends an authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the user can click the identifier of the application, and the terminal can initiate the open authorization of the application A to the application according to the click of the user.
  • the terminal can quickly and accurately determine the history of the application to be logged in by the user according to the data received from the outside world. Open the authorized application, and use the historical open authorized application to open the authorization for the user to log in again, which facilitates the user's operation, improves the user experience, and reduces the risk of user sensitive information leakage.
  • the embodiment of the present application provides another method for the open authorization login.
  • the terminal can obtain the historical login information of the first application from the local storage of the terminal, and can quickly determine that the first application is historically determined.
  • the second application of the authorization is opened, thereby avoiding the cumbersome operation caused by the user's successive attempts from numerous applications and the risk of information leakage caused by re-selecting the second application.
  • FIG. 8 shows a possible flow of another open authorization login method provided by an embodiment of the present application, and the method includes the following steps.
  • Step 801 The terminal determines, according to the historical login information of the first application, the second application, where the historical login information is information that the terminal performs open authorization on the first application according to the history saved on the terminal, where the historical login is performed.
  • the information includes information of the second application, and the second application is an application for historically authorizing the first application.
  • Step 802 The terminal sends an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, to request the first application to access the determined resource server of the second application. Permissions for protected user resources.
  • the method for the open authorization login provided by the embodiment of the present application further includes:
  • the terminal may update the historical login information of the first application.
  • the determining, by the terminal, the second application according to the historical login information of the first application comprises: obtaining, by the terminal, at least one of a storage path of the historical information recording module, a storage path of the first application, and a storage path of the second application. Historical login information for an application.
  • the historical login information includes a time when the historical open authorization login occurs; and if the information of the second application is information of at least two applications, the terminal determines the second application according to the historical login information of the first application.
  • the method includes: determining, by the terminal, a second application from the at least two applications according to an occurrence time of the historical open authorization.
  • the method further includes: the terminal displaying the first interface according to the historical login information, where the first interface includes an identifier of the second application.
  • the first interface further includes an identification of the first application corresponding to the second application.
  • the method further includes: the terminal receiving a login operation instruction for the first application on the first interface; the terminal transmitting, to the determined authorization server of the second application, the The authorization request of the application for performing the open authorization login includes: sending, by the terminal, the pair to the authorization server of the second application on the first interface according to the login operation instruction for the first application on the first interface The first application performs an authorization request for an open authorization login.
  • the method further includes: the terminal receiving a display operation instruction for the second application on the first interface; the terminal displaying the second interface according to the display operation instruction, the second The interface includes an identifier of the first application corresponding to the second application.
  • the method before the terminal sends an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, the method further includes: the terminal receiving, for the second a login operation instruction of the first application on the interface; the sending, by the terminal, an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application, according to the The login operation instruction of the first application on the first interface sends the authorization request for performing an open authorization login to the first application to an authorization server of the second application on the first interface.
  • the open authorization login method provided by the embodiment of the present application can record and save the authorization relationship between the first application and the second application, and help the user to quickly and accurately determine when the user logs in to the first application again by using the open authorization login mode.
  • the second application that has been openly authorized for the first application may further enable the user to use the second application to openly authorize the first application, thereby further reducing the risk of user information leakage and improving the manner in which the user adopts the open authorization. Sign in to the app experience.
  • the open authorization login method provided by the embodiment of the present application is specifically described.
  • the user when the user first logs in to the first application by using an open authorization login mode, or the terminal does not receive the first application that includes the information of the second application,
  • the user may select one application from at least one application supporting the open authorization function as the second.
  • the application is openly authorized for the first application.
  • the terminal may record the historical login information of the first application, including the first application. Second application information.
  • the manner in which the terminal records and saves the historical login information of the first application may be as follows.
  • the first application may record and save historical login information of the first application in its own storage path, including information of the second application that performs open authorization on the first application.
  • the storage path for storing historical login information can be migrated.
  • the stored historical login information can be migrated to other terminals or external accessors, or uploaded to the cloud server.
  • the system may record and save the historical login information of the first application, including the second application that performs the open authorization for the first application, when the second application is configured to openly authorize the first application to log in to the first application. information.
  • the system can utilize the historical information logging module to collectively record and manage historical login information for one or more applications.
  • the system determines that the second application successfully opens the authorization for the first application and logs in to the first application. The method may be: monitoring the second application to open and authorize the first application, and jumping back to the first application, where If the behavior of the second jump open authorization page does not occur within the preset time, it is determined that the first application has been successfully logged in.
  • the first application may register the historical login information with the first application after registering the history information of the first application.
  • the historical login information is such that the historical information recording module centrally saves and manages the historical login information of the first application.
  • the second application may also record historical open authorization information, including information of the first application whose open authorization is available.
  • the second application may save the historical open authorization information in its own storage path, or may register the historical open authorization information to the historical information recording module to centrally save and manage the historical login information of the first application.
  • the system can record and save the historical open authorization information of the second application when the second application is configured to openly authorize the first application to log in to the first application.
  • the terminal can upload the historical login information of the application to the cloud server.
  • the terminal may upload the historical login information of one or more applications to the cloud server.
  • the terminal may also send or back up the historical login information saved in the first application's own storage path and/or the historical login information recorded in the system to other terminals and external storage in the form of data migration.
  • the terminal may also send or back up the historical login information of the first application and/or the historical open authorization information of the second application saved in the history information recording module to other terminals and the external memory.
  • the terminal may also send or backup historical open authorization information of the second application recorded and saved by the system to other terminals and external storage.
  • the historical login information of the first application may include a correspondence between one or more user first application accounts and a second application.
  • the user has two accounts, A and B.
  • Sina Weibo and WeChat have both opened the first application, and Sina Weibo is bound to the A account, and the WeChat and B accounts are tied. set. Thereby the user selects the second application according to the account of his first application.
  • the user logging in to the first application by using an open authorization may include the following steps:
  • Step 0 The terminal may receive historical login information of the first application from at least one of a cloud server, another terminal, and an external storage.
  • the terminal may store the received historical login information of the first application in the historical information recording module and/or the first storage path of the first application.
  • the local login information of the first application may also be stored locally, and the storage location may be a self storage path or a history information recording module of the first application. It should be noted that step 0 is not performed in conjunction with each execution of subsequent steps, and may be performed one or more times. When step 0 is completed, there is no need to immediately perform subsequent steps, and subsequent steps can be performed as needed.
  • Step 1 When the first application on the terminal logs in, the terminal extracts historical login information of the first application.
  • the terminal may receive an instruction that the user makes a determination to use the open authorization login.
  • the terminal obtains the information of the second application from the historical login information of the first application, and the obtaining manner may be as follows:
  • the terminal reads the historical login information of the first application from the storage path of the first application, and obtains the information of the second application.
  • the historical login information may be information recorded in the storage directory of the first application when the second application is openly authorized for the first application; the historical login information may also be that the terminal receives historical login information from other terminals or the cloud server. And storing in the storage directory of the first application; the historical login information can be written into the storage directory of the first application by the historical information recording module through synchronization or import instructions.
  • the first application sends a query request to the historical information recording module during the preparation process of initiating the login request, from The historical login information of the first application is obtained in the response returned by the historical information recording module, and the information of the second application is obtained.
  • the terminal acquires historical login information of the first application from the historical information recording module, and then obtains information of the second application from the historical login information.
  • the first application in the terminal receives the login indication information generated by the history information recording module according to the historical login information determined by the user, where the login indication information includes the first part included in the historical login information and/or the historical login information.
  • Second application information includes the first part included in the historical login information and/or the historical login information.
  • Step 2 The terminal may determine, according to the information of the second application in the historical login information of the first application, the second application that performs the open authorization for the first application in the current open authorization login, and then request the user to confirm the use of the second application pair.
  • the first application performs an open authorization, or the terminal automatically invokes the second application to openly authorize the first application.
  • the user may temporarily use another terminal or use the public terminal to log in to the first application. Therefore, the user may not want to save the historical login information of the first application on the terminal, or open the first application.
  • step 2 the terminal determines that the second application fails according to the information of the second application in the historical login information, indicating that the information of the second application in the historical login message is invalid, and the terminal may delete the historical login of the first application. Information, or delete information of the second application in the historical login information of the first application.
  • step 2 determining that the second application fails to open the first application, indicating that the second application may no longer support the function of the open authorization, or other reasons, such that the first application cannot be opened.
  • the terminal may delete the historical login information of the first application, or delete the information of the second application in the historical login information of the first application.
  • the terminal may use the second application to open the first application to the second application in the historical login information of the first application.
  • the information is updated.
  • the information of the second application in the historical login information of the first application may be information of two or more applications, and the terminal may display, to the user, the generated according to the historical login information of the first application.
  • An identification interface of two or more applications such that the user determines from the second application that is openly authorized for the first application.
  • the historical information recording module when the historical login information is stored in the historical information recording module, the historical information recording module generates login indication information according to the historical login information determined by the user, so that the first application is configured according to the login indication information. Go to step 2.
  • the information of the second application in the historical login information of the first application may be information of two or more applications, and the historical login information further includes that the two or more applications last applied to the first application.
  • the terminal may determine the second application that is openly authorized for the first application according to the time when they perform the open authorization login.
  • the first application is a
  • the application with the open authorization function is A, B, C, and D as an example to describe the open authorization login method provided by the embodiment of the present application.
  • the user logs in to the application by using the application open authorization a application.
  • the A terminal records the login information of the current application, including the information of the A application.
  • applications A, B, C, and D can provide open authorization functions for them.
  • the B terminal can receive the login information of the application a recorded by the A terminal from the A terminal, that is, the historical login information of the application a.
  • the B terminal can determine the A application autonomously according to the information of the A application in the historical login information of the application, so that the A application can openly authorize the application, and the B terminal can also display the pop-up or text to the user according to the historical login information.
  • the user is requested to confirm the confirmation request for the open authorization of the application by using the A application, and then the application of the application for the open authorization a application is determined in conjunction with the confirmation instruction of the user.
  • the B terminal may display an open authorization page, which may enable the user to select information stored in the resource server of the A application to which the application can be authorized to access.
  • the B terminal can record the login information of the application a to update the historical login information of the application received by the B terminal from the A terminal.
  • the application information in the historical login information of the application may be multiple, such as the information of the applications A1, A2, and A3, and the information of the application may further include the historical open authorization time of the application to the application, and the application information. It may also include an association relationship between the application and the account of the a application.
  • the time for A1 open authorization a is T1
  • the time for A2 open authorization a is T2
  • the time for A3 open authorization a is T3.
  • the applications A1, A2, A3 and the times T1, T2, T3 may be displayed to the user, and an option of confirming, deleting or no longer displaying may also be displayed, so that the user selects the second application, and Edit the historical login information of the application, display settings, and so on.
  • the user's a application account has a1, a2, a3, etc., wherein the applications A1, A2, A3 are associated with the accounts a1, a2, a3, respectively.
  • the application A1, A2, A3 and the accounts a1, a2, a3 may be displayed to the user, and an option of confirming, deleting or no longer displaying may also be displayed, so that the user selects the second application, and Edit the historical login information of the application, display settings, and so on.
  • the method for the open authorization login provided by the embodiment of the present application is illustrated by taking the first application as a, b, and c, and the second application as A and B as an example.
  • the terminal can record the historical login information of the applications a, b, and c that are recorded or received by the historical information recording module. It can be assumed that the application a historical login information includes the information of the application A, and the application b historical login information includes the application. The information of B, the application c history registration information includes the information of the application A. The terminal determines that the application A is the second application corresponding to the applications a and c, and the application B is the second application corresponding to the application b.
  • the terminal may display an interface including the identifier of the application A and the identifier of the application B, and the identifiers of the applications a and c may be displayed around the application A identifier, and the identifier of the application b may be displayed around the application B identifier to indicate the application a, c belongs to application A, and application b belongs to application B.
  • the user can make a login operation instruction for the application, and according to the login operation instruction, the terminal can invoke A to open the authorization for a.
  • the terminal provided by the embodiment of the present application may display the identifier of the application without the client that installs the application. It can be assumed that although the terminal displays the identifiers of the applications a and A, the terminal may not have the client of the application a and/or the client of the application A. After the user makes a login operation instruction for the application, the terminal may call up. The application market automatically downloads the client of application a and/or application A, or prompts the user to download the client of application a and/or application A.
  • the terminal determines that the application A is the second application corresponding to the applications a and c, and the application B is the second application corresponding to the application b.
  • the terminal may display an interface including the identifier of the application a, the identifier of the application b, and the identifier of the application c, and the identifier of the application A may be displayed around the identifier of the application a, and the application B may be displayed around the identifier of the application b.
  • the identifier of the application A can be displayed in the vicinity of the identifier of the application c, so that the historical open authorized application of the application a is the application A, the historical open authorized application of the application b is the application b, and the historical open authorized application of the application c is the application. A.
  • the embodiment of the present application provides an open authorization login device 1000.
  • the open authorization login device 1000 includes a processing unit 1001 and a communication unit 1002.
  • the processing unit 1001 is configured to determine, according to the historical login information of the first application, the second application, where the historical login information is information received by the terminal, the historical login information includes information of the second application, and the second application An application for the open authorization of the first application for history.
  • the communication unit 1002 is configured to send, to the authorized server of the determined second application, an authorization request for performing an open authorization login on the first application, to request the first application to access the determined resource server of the second application. Permissions for protected user resources.
  • processing unit 1001 and the communication unit 1002 may be referred to the content of the method in the above, and are not described herein.
  • the embodiment of the present application provides an open authorization login device 1100.
  • the open authorization login device 1100 includes a processing unit 1101 and a communication unit 1102.
  • the processing unit 1101 is configured to determine, according to the historical login information of the first application, the second application, where the historical login information is information recorded by the terminal, the historical login information includes information of the second application, and the second application is An application for the open authorization of the first application in history.
  • the communication unit 1102 is configured to send, to the authorized server of the determined second application, an authorization request for performing an open authorization login on the first application, to request the first application to access the determined resource server of the second application. Permissions for protected user resources.
  • processing unit 1101 and the communication unit 1102 can be referred to the content of the method in the above, and are not described herein.
  • the embodiment of the present application provides a terminal 1200.
  • the terminal 1200 includes a processor 1201 and a memory 1202.
  • the memory 1202 stores the code.
  • the processor 1201 executes the code for performing determining, according to the historical login information of the first application, the second application, where the historical login information is information received by the terminal, and the historical login information includes information of the second application,
  • the application is an application that is openly authorized for the first application by the history; the processor 1201 executes the code, and is further configured to send an authorization request for performing an open authorization login to the first application to the determined authorization server of the second application. And requesting the first application to access the protected user resource in the determined resource resource of the second application.
  • processor 1201 to execute the code stored by the memory 1202 for execution may be referred to the above description of the method, and are not described herein.
  • the embodiment of the present application provides a terminal 1300.
  • the terminal 1300 includes a processor 1301 and a memory 1302.
  • the memory 1302 stores the code.
  • the processor 1301 executes the code, and the second application is determined according to the historical login information of the first application, where the historical login information is that the terminal performs open authorization on the first application according to the history saved on the terminal.
  • the information, the historical login information includes information of the second application, the second application is an application that is openly authorized to authorize the first application, and is further configured to send to the authorization server of the determined second application. And performing an authorization request for the first application to open the authorized login to request the first application to access the protected user resource in the determined resource resource of the second application.
  • processor 1301 may execute the code stored by the memory 1302 for execution.
  • the beneficial effects of the terminal 1300 can be referred to the content of the method in the above, and are not described herein.
  • processors in the embodiment of the present application may be a central processing unit (CPU), and may be other general-purpose processors, digital signal processors (DSPs), and application specific integrated circuits. (Application Specific Integrated Circuit, ASIC), Field Programmable Gate Array (FPGA) or other programmable logic device, transistor logic device, hardware component, or any combination thereof.
  • a general purpose processor can be a microprocessor or any conventional processor.
  • the method steps in the embodiments of the present application may be implemented by means of hardware, or may be implemented by a processor executing software instructions.
  • the software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (Programmable ROM). , PROM), Erasable PROM (EPROM), Electrically Erasable Programmable Read Only Memory (EEPROM), Register, Hard Disk, Mobile Hard Disk, CD-ROM, or well known in the art Any other form of storage medium.
  • An exemplary storage medium is coupled to the processor to enable the processor to read information from, and write information to, the storage medium.
  • the storage medium can also be an integral part of the processor.
  • the processor and the storage medium can be located in an ASIC. Additionally, the ASIC can be located in the terminal.
  • the computer program product includes one or more computer instructions.
  • the computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable device.
  • the computer instructions can be stored in or transmitted by a computer readable storage medium.
  • the computer instructions can be from a website site, computer, server or data center to another website site by wire (eg, coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (eg, infrared, wireless, microwave, etc.) Transfer from a computer, server, or data center.
  • the computer readable storage medium can be any available media that can be accessed by a computer or a data storage device such as a server, data center, or the like that includes one or more available media.
  • the usable medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (such as a Solid State Disk (SSD)) or the like.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • User Interface Of Digital Computer (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

本申请实施例涉及一种开放授权登录方法,所述方法包括:终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。

Description

一种开放授权方法、装置和终端 技术领域
本申请涉及通信技术领域,尤其涉及一种开放授权方法、装置和终端。
背景技术
在传统客户端-服务器认证模型下,用户通过A应用客户端(Client)访问A应用服务器存储的用户受保护资源。A应用服务器一般通过用户的A应用的用户凭证(credentials),例如账号密码,认证用户的身份。如果用户想通过B应用的客户端访问A应用服务器上存储的用户受保护资源,也需要A应用的账号密码。用户向B应用共享账号密码A应用的账户密码会产生信息泄漏的风险。
开放授权(Open Authorization,O-Auth)2.0协议是国际互联网工程任务组(Internet Engineering Task Force,IETF)制定的一个安全、开放并且简易的用户资源授权标准。在该协议中,B应用的客户端可以无须用户的A应用的账户密码就可以访问A应用服务器存储的用户受保护资源。
目前,一些大型应用,例如腾讯QQ、支付宝、淘宝、微信、微博等,可以支持O-Auth2.0协议。用户可以利用其支持O-Auth2.0协议的应用的账号,例如微博账号,登录第三方应用,第三方应用可以访问该用户的微博服务器存储的用户受保护资源,例如用户的微博头像、昵称。
上述方式存在的问题有,在终端更换、终端恢复出厂设置、终端重装系统等场景下,存在登录凭证丢失或无效、应用的历史登录记录丢失等问题,需要用户重新登录第三方应用。
用户再次登录第三方应用时,可能忘记了其上次是使用哪一个应用的账户登录该第三方应用的。此时,需要用户重新进行开放授权以登录该第三方应用或者依次尝试利用各个支持O-Auth2.0协议的应用的帐号去登录该第三方应用,使得用户体验差。
发明内容
本申请实施例提供了一种开放授权登录方法、装置和终端,可以从接收的数据中或者从本地保存的数据中获取第一应用和第二应用之间的授权关系,进而可以利用对第一应用进行过开放授权的第二应用在本次登录中再次对第一应用进行开放授权,从而可以进一步减少了用户信息泄露的风险和提升用户开放授权登录应用的体验。
第一方面,本申请实施例提供了一种开放授权登录方法,所述方法包括:终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一种可能的实现方式中,所述终端请求到所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限后,所述方法还包括:所述终端根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。
在一种可能的实现方式中,所述终端接收到的所述历史登录信息具体为所述终端从云服务器、从所述终端之外的其他终端、或从外部存储器中的至少一个接收到的信息。
在一种可能的实现方式中,所述终端根据第一应用的历史登录信息确定第二应用包括:所述终端从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个所述历史登录信息;其中,所述历史信息记录模块为所述终端中用于记录和/或保存多个应用的历史登录信息的模块。
在一种可能的实现方式中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括:所述终端根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括:所述终端根据所述至少两个应用的信息显示至少两个应用;所述终端接收选择操作指令;所述终端根据所述选择操作指令从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求之前,所述方法还包括:所述终端显示所述确定的第二应用;所述终端接收确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述方法还包括:所述终端根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的标识。
在一种可能的实现方式中,所述第一界面还包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,,所述方法还包括:所述终端接收针对所述第一界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述方法还包括:所述终端接收针对所述第一界面上的第二应用的展示操作指令;所述终端根据所述展示操作指令显示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述方法还包括:所述终端接收针对所述第二界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求。
第二方面,本申请实施例提供了一种开放授权登录方法,所述方法包括:所述终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端根据所述终端上保存的历史对所述第一应用进行开放授权的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一种可能的实现方式中,所述终端请求到所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限后,所述方法还包括:所述终端根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。
在一种可能的实现方式中,所述终端根据第一应用的历史登录信息确定第二应用包括:所述终端从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取所述历史登录信息。
在一种可能的实现方式中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括包括:所述终端根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,所述方法还包括:所述终端根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的标识。
在一种可能的实现方式中,所述第一界面还包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述方法还包括:所述终端接收针对所述第一界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述方法还包括:所述终端接收针对所述第一界面上的第二应用的展示操作指令;所述终端根据所述展示操作指令显示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述方法还包括:所述终端接收针对所述第二界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
第三方面,一种开放授权登录装置,所述装置包括:处理单元,用于根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;通信单元,用于向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一种可能的实现方式中,所述处理单元还用于根据所述确定的第二应用对所述第一 应用本次进行的开放授权操作更新所述第一应用的历史登录信息。
在一种可能的实现方式中,所述终端接收到的所述历史登录信息具体为所述通信单元从云服务器、从所述终端之外的其他终端、或从存储器中的至少一个接收到的信息。
在一种可能的实现方式中,所述处理单元还用于所述从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取所述历史登录信息。
在一种可能的实现方式中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述处理单元还用于根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,若所述第二应用的信息为至少两个应用的信息,所述处理单元还用于根据所述至少两个应用的信息显示所述至少两个应用;所述处理单元还用于接收选择操作指令;所述处理单元还用于根据所述选择操作指令从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,所述处理单元还用于显示所述确定的第二应用;所述处理单元还用于接收确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令;所述通信单元还用于根据所述确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述处理单元还用于根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的信息对应的第二应用的标识。
在一种可能的实现方式中,所述第一界面还包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述处理单元还用于接收针对所述第一界面上的第一应用的登录操作指令;所述通信单元根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述处理单元还用于接收针对所述第一界面上的第二应用的展示操作指令;所述处理单元还用于所述展示操作指令显示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述处理单元还用于接收针对所述第二界面上的第一应用的登录操作指令;所述通信单元还用于根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求。
第四方面,本申请实施例提供了一种开放授权登录装置,所述装置包括:处理单元,用于根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端记录的信息,所述第一应用的历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;通信单元,用于向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一种可能的实现方式中,所述处理单元还用于根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。
在一种可能的实现方式中,所述处理单元还用于从历史信息记录模块、第一应用的存 储路径、第二应用的存储路径中的至少一个获取第一应用的历史登录信息。
在一种可能的实现方式中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述处理单元还用于所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,所述处理单元还用于根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的信息对应的第二应用的标识。
在一种可能的实现方式中,所述第一界面还包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述处理单元还用于接收针对所述第一界面上的第一应用的登录操作指令;所述通信装置还用于根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述处理单元还用于接收针对所述第一界面上的第二应用的展示操作指令;所述处理单元还用于根据所述展示操作指令显示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述处理单元还用于接收针对所述第二界面上的第一应用的登录操作指令;所述通信单元还用于根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
第五方面,本申请实施例还提供了一种终端,所述终端包括处理器和储存器;所述存储器存储代码;所述处理器执行所述代码,用于执行根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;还用于执行向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一种可能的实现方式中,所述终端接收到的所述历史登录信息具体为所述终端从云服务器、从所述终端之外的其他终端、或从存储器中的至少一个接收到的信息。
在一种可能的实现方式中,所述处理器还用于执行从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取所述历史登录信息;其中,所述历史信息记录模块为所述终端中用于记录和/或保存多个应用的历史登录信息的模块。
在一种可能的实现方式中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述处理器还用于执行根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
在一种可能的实现方式中,若所述第二应用的信息为至少两个应用的信息,所述处理器还用于执行根据所述至少两个应用的信息显示所述至少两个应用;所述处理器还用于执行接收选择操作指令;所述处理器还用于执行根据所述选择操作指令从所述至少两个应用中确定一个所述第二应用。
在一种可能的实现方式中,所述处理器还用于执行显示所述确定的第二应用;所述处理器还用于执行接收确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令;所述处理器还用于执行根据所述确认利用所述确定的第二应用对所述第一应用进行 开放授权的操作指令发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述处理器还用于执行根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的标识。
在一种可能的实现方式中,所述第一界面还包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述处理器还用于执行接收针对所述第一界面上的第一应用的登录操作指令;所述处理器还用于执行根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述处理器还用于执行接收针对所述第一界面上的第二应用的展示操作指令;所述处理器还用于执行根据所述展开操作指令展示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
在一种可能的实现方式中,所述处理器还用于执行接收针对所述第二界面上的第一应用的登录操作指令;所述处理器还用于执行根据所述针对所述第二界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求。
在一种可能的实现方式中,所述处理器还用于执行根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。
第六方面,本申请实施例提供了一种终端,所述终端包括:处理器和存储器;所述存储器存储代码;所述处理器执行所述代码,用于执行第二方面任一所述的方法。
第七方面,本申请实施例提供了一种存储程序的计算机可读存储介质,所述程序包括指令,所述指令被终端执行时,使所述终端执行第一方面任一所述的方法或第二方面任一所述的方法。
本申请实施例提供了一种包含指令的计算机程序产品,当所述计算机程序产品在终端上运行时,使所述终端执行第一方面任一所述的方法或第二方面任一所述的方法。
本申请实施例提供的开放授权登录方法、装置和终端,可以从接收的数据中或者从本地保存的数据中获取第一应用和第二应用之间的授权关系,帮助用户快速、准确的确定对第一应用进行过开放授权的第二应用,进而可以使得用户可以在本次登录中再次利用该第二应用对第一应用进行开放授权,从而可以进一步减少了用户信息泄露的风险和提升用户采用开放授权的方式登录应用的体验。
附图说明
图1为本申请实施例提供的一种开放授权登录方法的应用架构图;
图2为本申请实施例提供的一种开放授权登录方法的开放授权的流程图;
图3为本申请实施例提供的一种开放授权登录方法的流程图;
图4为本申请实施例提供的一种开放授权登录方法的效果展示图;
图5为本申请实施例提供的一种开放授权登录方法的效果展示图;
图6为本申请实施例提供的一种开放授权登录方法的效果展示图;
图7a为本申请实施例提供的一种开放授权登录方法的效果展示图;
图7b为本申请实施例提供的一种开放授权登录方法的效果展示图;
图7c为本申请实施例提供的一种开放授权登录方法的效果展示图;
图8为本申请实施例提供的一种开放授权登录方法的流程图;
图9a为本申请实施例提供的一种开放授权登录方法的效果展示图;
图9b为本申请实施例提供的一种开放授权登录方法的效果展示图;
图9c为本申请实施例提供的一种开放授权登录方法的效果展示图;
图10为本申请实施例提供的一种开放授权登录装置的结构示意图;
图11为本申请实施例提供的一种开放授权登录装置的结构示意图;
图12为本申请实施例提供的一种终端的结构示意图;
图13为本申请实施例提供的一种终端的结构示意图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域技术人员所获得的所有其它实施例,都属于本申请保护的范围。
本申请实施例中的终端具体可以为智能手表、手机(mobile phone)、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(Virtual Reality,VR)终端设备、增强现实(Augmented Reality,AR)终端设备、工业控制(industrial control)中的无线终端、无人驾驶(self driving)中的无线终端、远程医疗(remote medical)中的无线终端、智能电网(smart grid)中的无线终端、运输安全(transportation safety)中的无线终端、智慧城市(smart city)中的无线终端、智慧家庭(smart home)中的无线终端等等。
图1示出了本申请实施例提供的开放授权登录的方法的一种可能的应用架构。终端上可以安装一个或多个应用的客户端。授权服务器可以为在成功认证了用户身份后,当获得用户的许可后可以发放访问令牌(Access Token)的应用服务器。资源服务器可以指存储有受保护的用户资源的应用服务器,可以接收并响应使用访问令牌的访问受保护的用户资源的请求。在一个示例中,授权服务器和资源服务器可以为同一个服务器。
以第一应用为例,终端可以从网络接收第一应用的历史登录信息,或者可以从其他终端接收第一应用的历史登录信息,或者可以从该终端本地存储的数据中获取第一应用的历史登录信息。第一应用的历史登录信息中可以包括第二应用的相关信息。第二应用可以为用户曾经对第一应用进行开放授权的应用,第二应用的相关信息可以为第二应用对第一应用进行开放授权的信息。终端可以根据第二应用的信息确定之前对第一应用进行了开放授权登录的第二应用;进而终端可以向确定的第二应用的授权服务器发送对第一应用进行开放授权登录的授权请求,以请求确定的第二应用的授权服务器对第一应用进行授权,以使得第一应用可以访问确定的第二应用的资源服务器中受保护的用户资源。
需要说明的是,在本申请的实施例中,如无特殊说明,第一应用表示被授权使用其他应用的信息进行登录的应用;第二应用表示用户可以利用该应用的信息登录其他应用的应用,第二应用可以对第一应用进行开放授权,以使第一应用可以访问第二应用的资源服务器。
图2示出了,第一应用访问第二应用的资源服务器中存储的受保护的用户的资源的一种可能的过程。步骤201、授权登录请求。终端显示第二应用对第一应用的授权登录界面, 向用户显示可以使用用户的第二应用信息,例如用户的第二应用帐号等,登录第一应用,即向用户显示登录请求。步骤202、授权登录许可。用户许可使用其第二应用信息登录第一应用,终端接收用于表示用户许可使用其第二应用信息登录第一应用的凭证,即授权码。步骤203、授权请求。终端可以凭借登录许可向第二应用的授权服务器发送授权请求,以请求第一应用访问第二应用的资源服务器中的受保护的用户资源的访问令牌。步骤204、授权许可。授权服务器可以认证第一应用的身份并验证授权码,然后向终端发送授权许可,以许可终端上的第一应用的客户端访问第二应用的资源服务器中受保护的用户资源的权限。在一个示例中,授权许可可以为访问令牌。步骤205、资源访问。终端可以凭借授权许可通过第一应用的客户端访问第二应用的资源服务器,以请求资源服务器中的受保护的用户资源。步骤206、资源发送。第二应用的资源服务器验证授权许可后,从而使得第一应用可以访问该资源。
通过图2示出的资源访问过程,可以在不需要向第一应用暴露用户第二应用的账号、密码等隐私信息的情况下,实现第二应用的资源服务器向第一应用开放一些受保护的用户的资源。
在一个示例中,以第二应用为新浪微博为例对开放授权登录进行具体说明。新浪微博可以支持基于O-Auth2.0协议的开放授权功能,允许用户使用新浪微博帐号登录其他应用,例如第一应用。在用户使用新浪微博登录第一应用的情况下,第一应用可以调用新浪微博提供的开放授权接口进行开放授权登录,第一应用获取访问令牌后,可以访问并获取的新浪微博的资源服务器中受保护的用户的头像、昵称等基础资源。从而实现了用户使用新浪微博账号信息自动在第一应用完成注册,并调用新浪微博的资源服务器中基础用户资源,简化了用户登录第一应用的操作,改善了用户体验。需要说明的是,实际上,在用户利用新浪微博账号登录第一应用时,第一应用为用户生成了第一应用的账号,即自动在第一应用完成注册,这一过程一般无需用户感知,用户在后续登录时仍使用新浪微博账号对第一应用进行开放授权登录。
微信、腾讯QQ、淘宝、支付宝等很多大型应用也具有类似开放授权登录的功能,可以作为第二应用对第一应用进行开放授权。开放授权登录快速便捷,并且无需用户在登录第一应用时注册以及记忆账号、密码等,从而减少了账户、密码的使用,减少了账户密码泄漏等风险,提高了用户使用网络服务的安全性。因此,越来越多的用户选择开放授权登录的方式去登录第一应用。
一些应用可以提供数据迁移的功能,比如华为手机的手机克隆应用。通过手机克隆应用,可以将旧终端上的数据、系统设置参数和应用等迁移到新终端。另外,终端自身系统提供的备份功能可以将终端中的数据备份到云服务器。具有数据迁移功能的应用以及系统的备份功能极大简化了终端更换、终端恢复出厂设置、终端重装系统等场景下用户数据备份的操作,通过简单的操作就能完成数据的迁移,免去应用客户端重新安装等操作。但是,终端侧的安全越来越受到重视,对终端侧数据的管理也越来越严格。例如登录凭证等敏感信息,会储存在较安全的存储环境中,在进行数据迁移时,可能无法随应用客户端等一起迁移到新的终端,或者,登录凭证等敏感信息可能与终端绑定,使新的终端无法重复使用登录凭证。因此,在终端更换、终端恢复出厂设置、终端重装系统、终端重装第一应用的客户端等场景下,存在登录凭证丢失或无效、应用的历史登录记录丢失等问题,需要用户 重新登录应用。当需要重新登录使用开放授权登录的方式登录过的第一应用时,仍需要通过第二应用以开放授权的方式登录第一应用。
此时,用户可能忘记了其曾经选择的对第一应用进行开放授权的第二应用,此时,用户需要从众多提供开放授权功能的应用中选择一个应用作为第二应用,以登录第一应用。在这种情况下,用户需要挨个尝试提供开放授权的应用,以找到其上次所使用的第二应用。当存在的提供开放授权功能的应用较多时,用户的体验会比较差;或者,用户重新将一个应用作为新的第二应用对第一应用重新进行开放授权,此时,使得第一应用过多的获取其他应用的用户敏感信息,不利于用户信息的保护,增加了用户隐私泄漏的风险。
本申请实施例提供了一种开放授权登录的方法,可以在终端更换、终端恢复出厂设置、终端重装系统或第一应用的客户端等场景下,用户重新登录第一应用时,快速确定历史上对第一应用进行开放授权的第二应用,从而避免了用户从众多应用中依次尝试而带来的繁琐操作以及重新选择第二应用而带来的信息泄漏的风险。
图3示出了本申请实施例提供的开放授权登录方法的一种可能的流程。该方法包括以下步骤。
步骤301、终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用。
在步骤301之前,用户可以在A终端采用开放授权的方式登录第一应用,该次登录的开放授权关系可以被保存下来,作为第一应用的历史登录信息,即第一应用的历史登录信息包括了第二应用对第一应用的开放授权关系。历史登录信息可以存储在第一应用的自身存储路径下,也可以由终端系统的历史信息记录模块集中管理和保存。历史信息记录模块可以为终端系统中可以用于记录多个应用信息的模块,也可以为终端系统中可以保存多个应用信息的模块,历史信息记录模块也可以用于管理多个应用的信息;其中,应用信息可以包括应用的历史登录信息。A终端可以将第一应用的历史登录信息发送给云服务器、其他终端以及外部存储器等。
B终端可以为用户更换终端之后所使用的新的终端、也可以为进行了恢复出厂设置之后的A终端,也可以为重装了系统之后的A终端,B终端可以为忘记了曾经使用的哪一个应用进行了开放授权的任意终端。B终端可以通过无线通信和/或有线通信的方式接收第一应用的历史登录信息。B终端可以从云服务器接收第一应用的历史登录信息,也可以从其他终端接收第一应用的历史登录信息,即将第一应用的历史登录信息从其他终端迁移到该终端。B终端也可以从存储装置接收第一应用的历史登录信息。
B终端接收到第一应用的历史登录信息后,可以将第一应用的历史登录信息交由历史信息记录模块集中管理和保存,也可以放置在第一应用的自身存储路径下进行保存。
在历史登录信息中记录了第一应用的之前的登录信息,可以包括历史对第一应用进行开放授权的应用的信息,即包括了第二应用对第一应用的开放授权关系。
第一应用的历史登录信息中的第二应用的信息可以为应用的名称、应用的图标、应用的身份标识等可以用于直接或间接确定应用的信息。终端可以根据第二应用的信息确定出第二应用,该第二应用为曾对第一应用进行过开放授权的应用,终端可以根据历史登录信息中的第二应用的信息确定第二应用。在后续步骤中利用确定出的第二应用对第一应用进 行开放授权。
步骤302、所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一个示例中,所述终端请求到所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限后,本申请实施例提供的开放授权登录的方法还包括:
所述终端根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。当第二应用对第一应用进行开放授权后,终端可以对第一应用的历史登录信息进行更新。
在一个示例中,所述终端根据第一应用的历史登录信息确定所述第一应用对应的第二应用包括:所述终端从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取第一应用的历史登录信息。
在一个示例中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述终端根据所述第二应用的信息确定所述第一应用对应的第二应用包括:所述终端根据所述历史开放授权的发生时间从所述至少两个应用中确定所述第一应用对应的第二应用。具体地,可以假设历史登录信息中包括A、B两个应用的信息。其中,A应用最近一次对第一应用进行开放授权登录的时间为T1;B应用最近一次对第一应用进行开放授权登录的时间为T2。可以假设T1相比较T2更接近当前的时间。在一个例子中,终端可以确定A应用为在后续步骤对第一应用进行开放授权登录的第二应用。在一个例子中,终端可以确定B应用为在后续步骤对第一应用进行开放授权登录的第二应用。
在一个示例中,若所述第一应用的历史登录信息中的第二应用的信息为至少两个应用的信息,所述终端根据所述第二应用的信息确定所述第一应用对应的第二应用包括:所述终端根据所述至少两个应用的信息显示所述至少两个应用;所述终端接收选择操作指令;所述终端根据所述选择操作指令从所述至少两个应用中确定一个第二应用。具体地,可以如图4所示,可以假设历史登录消息中的第二应用的信息包括了A、B两个应用的信息。终端在接收了历史登录消息后,在第一应用的登录界面可以以弹窗或文字等方式提示用户A、B曾对第一应用进行过开放授权。用户可以自主选择A或B对第一应用再次进行开放授权。终端可以根据用户的选择操作指令确定A或B作为对第一应用进行开放授权的应用。
在一个示例中,在步骤302之前,所述方法还包括:所述终端显示所述确定的第二应用;所述终端接收确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令发起所述对所述第一应用进行开放授权登录的授权请求。在终端根据历史登录信息确定了第一应用对应的第二应用后,可以在无需用户确认的情况下,终端自动发起利用确定的第二应用对第一应用的开放授权;也可以在经过用户确认的情况下,再发起利用确定的第二应用对第一应用的开放授权。本示例描述了后一种情况,具体地,可以如图5所示终端在确定了第二应用后,可以在第一应用的登录界面显示是否使用第二应用对第一应用进行开放授权的指示信息,例如,指示信息为“授权A登录”,请求用户确认 使用所述指示信息指示的方式登录;用户可以确认利用第二应用对第一应用再次进行开放授权以登录第一应用;终端可以根据用户的确认指令发起利用第二应用对第一应用的开放授权的流程。
在一个示例中,本申请实施例提供的方法还包括:所述终端根据历史信息记录模块记录的信息,显示第一界面,所述第一界面包括所述第二应用的标识。具体地,历史信息记录模块记录的信息可以包括第一应用的历史登录信息,第一应用可以为一个或多个应用,相应的第一应用的历史登录信息为一个或多个应用的历史登录信息,每个应用的历史登录信息中可以包括至少一条第二应用对第一应用开放授权的记录或至少一条第一应用请求第二应用开放授权的记录。在一个例子中,可以假设,第一应用可以为a、b、c;a应用的历史登录信息中的第二应用的信息为A应用的信息,b应用的历史登录信息中的第二应用的信息为B应用的信息,c应用的历史登录信息中的第二应用的信息为A应用信息;终端可以显示包括了A、B应用标识的界面,以在一个界面上就可以告知用户A、B应用为曾对其他应用进行过开放授权的应用,方便用户选择对第一应用进行开放授权的第二应用。
在一个示例中,显示第二应用的标识的第一界面还可以包括与第二应用对应的第一应用的标识。图6示出了该示例的一个例子,在该例子中,A、B为第二应用,A应用曾对应用a、c进行过开放授权;B应用曾对应用b进行过开放授权。在该示例中,可以在一个界面上告知用户第二应用和第一应用之间的对应关系,方便用户的操作。
在一个示例中,所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求之前,所述方法还包括:所述终端接收针对所述第一界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令确定所述第一界面上的第二应用,并且向确定的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。以第二应用为A应用,与A对应的第一应用为a为例,在第一界面上显示了A应用和a应用的对应关系;用户可以通过点击a应用的标识或者a应用的登录标识以指示登录a应用,则终端可以根据用户的单击发起A应用对a应用的开放授权。具体来说,终端根据用户在第一界面的登录指令触发生成包含用户确定的a应用历史登录信息的登录指示信息,并发送给a应用,以指示a应用根据登录指示信息中的A应用信息来确定使用A应用进行开放授权登录。a应用随后根据接收到的登录指示信息向A应用的服务器发送对a应用进行开放授权登录的授权请求。
在一个示例中,所述方法还包括:所述终端接收针对所述第一界面上的第二应用的展示操作指令;所述终端根据所述展示操作指令展示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。具体地,显示第二应用的标识的第一界面可以不包括与第二应用对应的第一应用的标识,用户通过点击第二应用的标识或标识周围的相应区域,终端可以展示出包括了与该第二应用对应的第一应用的标识。图6a和图6b示出了一个终端显示第一界面和第二界面的例子,在该例子中,第一界面包括第二应用A、B,用户可以点击应用A的标识,终端显示出了包括了与应用A对应的应用a、c的第二界面。在该例子中,第二界面是在第一界面内进行显示的。第二界面可以以覆盖第一界面的方式显示,可以如图7c所示,可以通过点击应用A的标识或其周围区域,终端显示出包括了应用A对应的应用a、c的界面。
在一个示例中,所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求之前,所述方法还包括:所述终端接收针对所述第二界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求。具体地,仍以图7c示出的例子为例,用户可以点击a应用的标识,则终端可以根据用户的单击发起A应用对a应用的开放授权。
通过本申请实施例提供的开放授权登录方法,在用户需要采用开放授权登录的方式登录应用的情况下,终端可以根据其从外界接收的数据,快速准确的确定历史对用户将要登录的应用进行过开放授权的应用,并且可以使用历史开放授权的应用对用户将要登录的应用再次进行开放授权,从而方便了用户的操作,提升了用户的体验,减少了用户敏感信息泄漏的风险。
本申请实施例提供了另一种开放授权登录方法,在用户重新登录第一应用时,终端可以从终端本地存储中获取第一应用的历史登录信息,进而可以快速确定历史上对第一应用进行开放授权的第二应用,从而避免了用户从众多应用中依次尝试而带来的繁琐操作以及重新选择第二应用而带来的信息泄漏的风险。
图8示出了本申请实施例提供的另一种开放授权登录方法的一种可能流程,该方法包括以下步骤。
步骤801、终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端根据所述终端上保存的历史对所述第一应用进行开放授权的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用。
步骤802、所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
在一个示例中,所述终端请求到所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限后,本申请实施例提供的开放授权登录的方法还包括:
所述终端根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。当第二应用对第一应用进行开放授权后,终端可以对第一应用的历史登录信息进行更新。
在一个示例中,所述终端根据第一应用的历史登录信息确定第二应用包括:所述终端从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取第一应用的历史登录信息。
在一个示例中,所述历史登录信息包括历史开放授权登录的发生时间;若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括包括:所述终端根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
在一个示例中,所述方法还包括:所述终端根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的标识。
在一个示例中,所述第一界面还包括与第二应用对应的第一应用的标识。
在一个示例中,所述方法还包括:所述终端接收针对所述第一界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
在一个示例中,所述方法还包括:所述终端接收针对所述第一界面上的第二应用的展示操作指令;所述终端根据所述展示操作指令展示示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
在一个示例中,所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求之前,所述方法还包括:所述终端接收针对所述第二界面上的第一应用的登录操作指令;所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
本申请实施例提供的开放授权登录方法,可以记录并保存第一应用和第二应用之间的授权关系,在用户再次采用开放授权登录的方式登录第一应用时,帮助用户快速、准确的确定对第一应用进行过开放授权的第二应用,进而可以使得用户可以再次利用该第二应用对第一应用进行开放授权,从而可以进一步减少了用户信息泄露的风险和提升用户采用开放授权的方式登录应用的体验。
在一个具体的实例中,对本申请实施例提供的开放授权登录方法进行具体说明。在本申请实施例的开放授权登录的方法的前置步骤中,在用户首次采用开放授权的登录方式登录第一应用情况下,或者终端没有接收到包含了第二应用的信息的第一应用的历史登录信息以及终端的本地存储中也没有存储包含了第二应用的信息的第一应用的历史登录信息的情况下,用户可以从至少一个支持开放授权功能的应用中选择一个应用,作为第二应用对第一应用进行开放授权。当第一应用从第二应用的授权服务器出成功获得访问令牌,或者第二应用对第一应用成功开放授权并登录第一应用后,终端可以记录第一应用的历史登录信息,其中包括第二应用的信息。
终端记录并保存第一应用的历史登录信息的实现方式可以有以下几种。
1、第一应用可以在其自身的存储路径下记录并保存第一应用的历史登录信息,其中包括对第一应用进行开放授权的第二应用的信息。存储历史登录信息的存储路径可以迁移,例如存储的历史登录信息可以迁移到其他终端或者外部存取器中,也可以上传到云服务器中。
2、系统可以在监测到第二应用在对第一应用进行开放授权以登录第一应用时,记录并保存第一应用的历史登录信息,其中包括对第一应用进行开放授权的第二应用的信息。在一个例子中,系统可以利用历史信息记录模块统一记录和管理一个或多个应用的历史登录信息。在一个例子中,系统判断第二应用对第一应用成功开放授权并登录了第一应用的方式可以为,监测到第二应用开放授权第一应用,并跳转回第一应用,在此后的预设的时间内没有发生二次跳转开放授权页面的行为,则判断已成功登录第一应用。
3、第一应用可以在记录了第一应用的历史登录信息后,向历史信息记录模块注册该 历史登录信息,以使历史信息记录模块对第一应用的历史登录信息进行集中保存和管理。
4、第二应用也可以记录历史开放授权信息,其中包括其开放授权的第一应用的信息。第二应用可以在其自身的存储路径下保存历史开放授权信息,也可以将历史开放授权信息向历史信息记录模块注册以对第一应用的历史登录信息进行集中保存和管理。
5、系统可以在监测到第二应用在对第一应用进行开放授权以登录第一应用时,可以记录并保存第二应用的历史开放授权信息。
终端可以将应用的历史登录信息上传到云服务器中。具体地,在利用历史信息记录模块集中管理一个或多个应用的历史登录信息的情景下,终端可以将一个或多个应用的历史登录信息集中上传到云服务器中。
终端也可以将应用的历史登录信息通过数据迁移的形式将第一应用自身存储路径下保存的历史登录信息和/或系统记录的历史登录信息发送或者备份到其他终端以及外部存储器中。
终端也可以将历史信息记录模块中保存的第一应用的历史登录信息和/或第二应用的历史开放授权信息发送或者备份到其他终端以及外部存储器中。
终端也可以将系统记录和保存的第二应用的历史开放授权信息发送或者备份到其他终端以及外部存储器中。
在一个例子中,第一应用的历史登录信息中可以包括一条或多条用户第一应用的账号和第二应用的对应关系。例如,可以假设,对于第一应用,用户拥有A、B两个账号,新浪微博、微信都曾对第一应用进行了开放授权,其中新浪微博与A账号绑定,微信与B账号绑定。从而使得用户根据其第一应用的账户而选择第二应用。
在发生了上述前置步骤之后,用户采用开放授权的方式登录第一应用可以包括以下步骤:
步骤0、终端可以从云服务器、其他终端、外部储存器中的至少一种接收第一应用的历史登录信息。终端可以将接收到的第一应用的历史登录信息存储在历史信息记录模块和/或第一应用的自身存储路径。终端的本地也可以存储有第一应用的历史登录信息,存储位置可以为第一应用的自身存储路径或者历史信息记录模块。需要说明的是,步骤0并非是连同后续步骤的每次执行而执行,可以执行一次或多次。步骤0其执行完毕时,无需立即执行后续步骤,后续步骤可以在需要时再执行。
步骤1、在终端上的第一应用登录时,终端提取所述第一应用的历史登录信息。在一个例子中,在所述终端提取所述第一应用的历史登录信息之前,终端可以接收用户做出确定使用开放授权登录的指令。
具体来说,终端在第一应用登录时,从第一应用的历史登录信息中获取第二应用的信息,获取方式可以通过以下几种方式:
1.1、终端从第一应用的自身存储路径处读取第一应用的历史登录信息,并获取其中的第二应用的信息。其中,历史登录信息可以为上次第二应用对第一应用进行开放授权时记录在第一应用的存储目录中的信息;历史登录信息也可以为终端从其他终端或云服务器接收到历史登录信息后存储到第一应用的存储目录中;历史登录信息可以由历史信息记录模块通过同步或者导入指令写入到第一应用的存储目录中。
1.2、第一应用在发起登录请求的准备过程中向历史信息记录模块发出查询请求,从 历史信息记录模块返回的响应中获取第一应用的历史登录信息,进而获取第二应用的信息。
1.3、终端从历史信息记录模块获取第一应用的历史登录信息,进而从其中获取第二应用的信息。具体来说,终端中的第一应用接收历史信息记录模块根据用户确定的历史登录信息生成的登录指示信息,所述登录指示信息包含了所述历史登录信息和/或历史登录信息中包含的第二应用的信息
步骤2、终端可以根据第一应用的历史登录信息中的第二应用的信息确定在本次开放授权登录中对第一应用进行开放授权的第二应用,然后请求用户确认使用该第二应用对第一应用进行开放授权,或者终端自动调用该第二应用对第一应用进行开放授权。
在一个例子中,用户可能临时使用了别人的终端、或者使用了公众终端登录了第一应用,因此,用户可能不想在终端上保存第一应用的历史登录信息,或对第一应用进行了开放授权登录的第二应用的信息。因此,用户注销对第一应用的登录后,终端可以删除第一应用的历史登录信息,或者删除第一应用的历史登录信息中的第二应用的信息。从而可以进一步提升用户的体验。
在一个例子中,在步骤2中,终端根据历史登录信息中的第二应用的信息确定第二应用失败,说明历史登录消息中的第二应用的信息失效,终端可以删除第一应用的历史登录信息,或者删除第一应用的历史登录信息中的第二应用的信息。
在一个例子中,在步骤2中,确定第二应用对第一应用的开放授权失败,说明该第二应用可能不再支持开放授权的功能,或者其他原因,致使其不能对第一应用进行开放授权,终端可以删除第一应用的历史登录信息,或者删除第一应用的历史登录信息中的第二应用的信息。
在一个例子中,确定的第二应用对第一应用成功进行了开放授权后,终端可以利用本次的第二应用对第一应用的开放授权对第一应用的历史登录信息中的第二应用的信息进行更新。
在一个例子中,第一应用的历史登录信息中的第二应用的信息可以为两个或更多个应用的信息,终端可以向用户显示根据所述第一应用的历史登录信息生成的包括该两个或更多个应用的标识界面,以使用户从其中确定本次对第一应用进行开放授权的第二应用。在一个例子中,当所述历史登录信息储存在历史信息记录模块时,所述历史信息记录模块根据用户确定的历史登录信息生成登录指示信息,以使所述第一应用根据所述登录指示信息执行步骤2。
在一个例子中,第一应用的历史登录信息中的第二应用的信息可以为两个或更多个应用的信息,历史登录信息还包括该两个或更多个应用上次对第一应用进行开放授权登录的时间,终端可以根据它们进行开放授权登录的时间从其中确定本次对第一应用进行开放授权的第二应用。
在一个实例中,结合图9a、9b、9c,以第一应用为a,具有开放授权功能的应用为A、B、C、D为例对本申请实施例提供的开放授权登录方法进行举例说明。
如图9a所示,在A终端上,根据上文介绍的前置步骤,用户采用A应用开放授权a应用的方式登录了a应用。A终端了记录了本次a应用的登录信息,其中包括了A应用的信息。
如图9b所示,对于应用a,应用A、B、C、D都可以为其提供开放授权功能。B终端可以从A终端接收A终端记录的a应用的登录信息,即a应用的历史登录信息。B终端可以根据a应用的历史登录信息中的A应用的信息自主确定A应用,以使A应用对a应用进行开放授权;B终端也可以根据历史登录信息向用户以弹窗或文字的方式显示请求用户确认使用A应用对a应用进行开放授权的确认请求,然后结合用户的确认指令确定A应用为本次开放授权a应用的应用。
如果9c所示,A应用对a应用进行开放授权时,B终端可以显示开放授权页面,可以使用户选择a应用可以被授权访问的A应用的资源服务器中存储的信息。
在一个例子中,在B终端上进行了A应用对a应用的开放授权后,B终端可以记录本次a应用的登录信息,以更新B终端从A终端接收到的a应用的历史登录信息。
在一个例子中,在a应用的历史登录信息中的应用信息可以为多个,比如应用A1、A2、A3的信息,应用的信息还可以包括应用对a应用的历史开放授权时间,应用的信息还可以包括应用和a应用的账号的关联关系。
可以假设A1开放授权a的时间为T1,A2开放授权a的时间为T2,A3开放授权a的时间为T3。在B终端确定第二应用时,可以向用户显示应用A1、A2、A3以及时间T1、T2、T3,并且还可以显示确认、删除或不再显示等选项,以使用户选择第二应用、以及对a应用的历史登录信息进行编辑、显示设置等处理。
可以假设用户的a应用账户有a1、a2、a3等,其中应用A1、A2、A3分别与账户a1、a2、a3关联。在B终端确定第二应用时,可以向用户显示应用A1、A2、A3以及账户a1、a2、a3,并且还可以显示确认、删除或不再显示等选项,以使用户选择第二应用、以及对a应用的历史登录信息进行编辑、显示设置等处理。
在一个实例中,以第一应用为a、b、c,第二应用为A、B为例对本申请实施例提供的开放授权登录的方法进行举例说明。
终端可以将其记录或接收到的应用a、b、c的历史登录信息交由历史信息记录模块统一管理,可以假设应用a历史登录信息中包括应用A的信息,应用b历史登录信息中包括应用B的信息,应用c历史登录信息中包括应用A的信息。终端确定了应用A为应用a、c对应的第二应用,应用B为应用b对应的第二应用。终端可以显示包括了应用A的标识、应用B的标识的界面,并且在应用A标识周边可以显示应用a、c的标识,在应用B标识的周边可以显示应用b的标识,以表示应用a、c隶属于应用A,应用b隶属于应用B。
利用a应用的标识,用户可以做出针对a应用的登录操作指令,根据该登录操作指令,终端可以调用A对a进行开放授权。
在一个例子中,本申请实施例提供的终端可以在没有安装应用的客户端的情况下,显示应用的标识。可以假设,虽然终端显示了应用a、A的标识,但是终端可能没有安装应用a的客户端和/或应用A的客户端,在用户做出针对a应用的登录操作指令后,终端可以调出应用市场,自动下载应用a和/或应用A的客户端,或者提示用户下载应用a和/或应用A的客户端。
在一个例子中,终端确定了应用A为应用a、c对应的第二应用,应用B为应用b对应的第二应用。终端可以显示包括了应用a的标识、应用b的标识、应用c的标识的界面,并且在应用a的标识周边可以显示应用A的标识,在应用b的标识的周边可以显示应用B 的标识,在应用c的标识的周边可以显示应用A的标识,以表示应用a的历史开放授权应用为应用A,应用b的历史开放授权应用为应用b,应用c的历史开放授权应用为应用A。
本申请实施例提供了一种开放授权登录装置1000,如图10所示,开放授权登录装置1000包括处理单元1001和通信单元1002。其中,处理单元1001,用于根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用。通信单元1002,用于向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
处理单元1001和通信单元1002的其他功能可参照上文中有关方法的内容介绍,此处不在赘述。
开放授权登录装置1000的有益效果可参照上文中有关方法的内容介绍,此处不在赘述。
本申请实施例提供了一种开放授权登录装置1100,如图11所示,开放授权登录装置1100包括处理单元1101和通信单元1102。其中,处理单元1101,用于根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端记录的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用。通信单元1102,用于向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
处理单元1101和通信单元1102的其他功能可参照上文中有关方法的内容介绍,此处不在赘述。
开放授权登录装置1100的有益效果可参照上文中有关方法的内容介绍,此处不在赘述。
本申请实施例提供了一种终端1200,如图12所示,终端1200包括处理器1201和存储器1202。存储器1202存储代码。处理器1201执行所述代码用于执行根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;处理器1201执行所述代码还用于执行向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
处理器1201执行存储器1202存储的代码用于执行的其他可选方案可参照上文中有关方法的内容介绍,此处不在赘述。
终端1200的有益效果可参照上文中有关方法的内容介绍,此处不在赘述。
本申请实施例提供了一种终端1300,如图13所示,终端1300包括处理器1301和存储器1302。存储器1302存储代码。处理器1301执行所述代码用于执行根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端根据所述终端上保存的历史对所述第一应用进行开放授权的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;还用于执行向所述确定的第二应用的授权服务器发送 对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
处理器1301执行存储器1302存储的代码用于执行的的其他可选方案可参照上文中有关方法的内容介绍,此处不在赘述。
终端1300的有益效果可参照上文中有关方法的内容介绍,此处不在赘述。
可以理解的是,本申请的实施例中的处理器可以是中央处理单元(Central Processing Unit,CPU),还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field Programmable Gate Array,FPGA)或者其他可编程逻辑器件、晶体管逻辑器件,硬件部件或者其任意组合。通用处理器可以是微处理器,也可以是任何常规的处理器。
本申请的实施例中的方法步骤可以通过硬件的方式来实现,也可以由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于随机存取存储器(Random Access Memory,RAM)、闪存、只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)、寄存器、硬盘、移动硬盘、CD-ROM或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于终端中。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者通过所述计算机可读存储介质进行传输。所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质(例如固态硬盘(Solid State Disk,SSD))等。
可以理解的是,在本申请的实施例中涉及的各种数字编号仅为描述方便进行的区分,并不用来限制本申请的实施例的范围。
可以理解的是,在本申请的实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请的实施例的实施过程构成任何限定。
以上所述,仅为本申请的实施例的具体实施方式,任何熟悉本技术领域的技术人员在本申请公开揭露的技术范围内,可轻易想到的变化或替换,都应涵盖在本申请的实施例的 保护范围之内。

Claims (26)

  1. 一种开放授权登录方法,其特征在于,所述方法包括:终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
  2. 根据权利要求1所述的方法,其特征在于,所述终端接收到的所述历史登录信息具体为所述终端从云服务器、从所述终端之外的其他终端、或从存储器中的至少一个接收到的信息。
  3. 根据权利要求1或2任一项所述的方法,其特征在于,所述终端根据第一应用的历史登录信息确定第二应用包括:
    所述终端从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取所述历史登录信息;
    其中,所述历史信息记录模块为所述终端中用于记录和/或保存多个应用的历史登录信息的模块。
  4. 根据权利要求1-3任一所述的方法,其特征在于,所述历史登录信息包括历史开放授权登录的发生时间;
    若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括:
    所述终端根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应用。
  5. 根据权利要求4所述的方法,其特征在于,若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括::
    所述终端根据所述至少两个应用的信息显示所述至少两个应用;
    所述终端接收选择操作指令;
    所述终端根据所述选择操作指令从所述至少两个应用中确定一个所述第二应用。
  6. 根据权利要求1-5任一项所述的方法,其特征在于,所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求之前,所述方法还包括:
    所述终端显示所述确定的第二应用;
    所述终端接收确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:
    所述终端根据所述确认利用所述确定的第二应用对所述第一应用进行开放授权的操作指令发送所述对所述第一应用进行开放授权登录的授权请求。
  7. 根据权利要求1-6任一项所述的方法,其特征在于,所述方法还包括:
    所述终端根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的标 识。
  8. 根据权利要求7所述的方法,其特征在于,所述第一界面还包括与第二应用对应的第一应用的标识。
  9. 根据权利要求8所述的方法,其特征在于,所述方法还包括:
    所述终端接收针对所述第一界面上的第一应用的登录操作指令;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:
    所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
  10. 根据权利要求7所述的方法,其特征在于,所述方法还包括:
    所述终端接收针对所述第一界面上的第二应用的展示操作指令;
    所述终端根据所述展开操作指令展示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
  11. 根据权利要求10所述的方法,其特征在于,所述方法还包括:
    所述终端接收针对所述第二界面上的第一应用的登录操作指令;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:
    所述终端根据所述针对所述第二界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求。
  12. 根据权利要求1-11任一项所述的方法,其特征在于,所述终端请求到所述第一应用访问所述一个第二应用的资源服务器中受保护的用户资源的权限后,所述方法还包括:
    所述终端根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述第一应用的历史登录信息。
  13. 一种开放授权登录方法,其特征在于,所述方法包括:
    终端根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端根据所述终端上保存的历史对所述第一应用进行开放授权的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
  14. 根据权利要求13所述的方法,其特征在于,所述终端根据第一应用的历史登录信息确定第二应用包括:所述终端从历史信息记录模块、第一应用的存储路径、第二应用的存储路径中的至少一个获取所述历史登录信息。
  15. 根据权利要求13或14所述的方法,其特征在于,所述历史登录信息包括历史开放授权登录的发生时间;
    若所述第二应用的信息为至少两个应用的信息,所述终端根据第一应用的历史登录信息确定第二应用包括:
    所述终端根据所述历史开放授权的发生时间从所述至少两个应用中确定一个第二应 用。
  16. 根据权利要求13-15任一项所述的方法,其特征在于,所述方法还包括:
    所述终端根据所述历史登录信息显示第一界面,所述第一界面包括所述第二应用的标识。
  17. 根据权利要求16所述的方法,其特征在于,所述第一界面还包括与第二应用对应的第一应用的标识。
  18. 根据权利要求17所述的方法,其特征在于,所述方法还包括:
    所述终端接收针对所述第一界面上的第一应用的登录操作指令;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:
    所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
  19. 根据权利要求16所述的方法,其特征在于,所述方法还包括:
    所述终端接收针对所述第一界面上的第二应用的展示操作指令;
    所述终端根据所述展示操作指令展示第二界面,所述第二界面包括与第二应用对应的第一应用的标识。
  20. 根据权利要求19所述的方法,其特征在于,所述方法还包括:
    所述终端接收针对所述第二界面上的第一应用的登录操作指令;
    所述终端向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求包括:
    所述终端根据所述针对所述第一界面上的第一应用的登录操作指令向所述第一界面上的第二应用的授权服务器发送所述对所述第一应用进行开放授权登录的授权请求。
  21. 根据权利要求13-20任一项所述的方法,其特征在于,所述终端请求到所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限后,所述方法还包括:
    所述终端根据所述确定的第二应用对所述第一应用本次进行的开放授权操作更新所述历史登录信息。
  22. 一种开放授权登录装置,其特征在于,所述装置包括:
    处理单元,用于根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端接收到的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;
    通信单元,用于向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
  23. 一种开放授权登录装置,其特征在于,所述装置包括:
    处理单元,用于根据第一应用的历史登录信息确定第二应用,所述历史登录信息为所述终端记录的信息,所述历史登录信息包括第二应用的信息,第二应用为历史对第一应用进行开放授权的应用;
    通信单元,用于向所述确定的第二应用的授权服务器发送对所述第一应用进行开放授 权登录的授权请求,以请求所述第一应用访问所述确定的第二应用的资源服务器中受保护的用户资源的权限。
  24. 一种终端,其特征在于,所述终端包括处理器和存储器;
    所述存储器存储代码;
    所述处理器执行所述代码,用于执行权利要求1-12或13-21任一项所述的方法。
  25. 一种存储程序的计算机可读存储介质,其特征在于,所述程序包括指令,所述指令被终端执行时,使所述终端执行权利要求1-12任一项的方法或权利要求13-21任一项所述的方法。
  26. 一种包含指令的计算机程序产品,其特征在于,当所述计算机程序产品在终端上运行时,使所述终端执行权利要求1-12任一项的方法或权利要求13-21任一项所述的方法。
PCT/CN2017/090311 2017-04-25 2017-06-27 一种开放授权方法、装置和终端 WO2018196153A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201780037019.5A CN109314711B (zh) 2017-04-25 2017-06-27 一种开放授权方法、装置和终端

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710277610.X 2017-04-25
CN201710277610 2017-04-25

Publications (1)

Publication Number Publication Date
WO2018196153A1 true WO2018196153A1 (zh) 2018-11-01

Family

ID=63917935

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/090311 WO2018196153A1 (zh) 2017-04-25 2017-06-27 一种开放授权方法、装置和终端

Country Status (2)

Country Link
CN (1) CN109314711B (zh)
WO (1) WO2018196153A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111401395A (zh) * 2019-01-02 2020-07-10 中国移动通信有限公司研究院 一种数据处理方法、终端设备及存储介质

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111062024B (zh) * 2019-11-25 2022-07-19 泰康保险集团股份有限公司 一种应用登录方法和装置
CN114722377A (zh) * 2020-12-22 2022-07-08 华为技术有限公司 一种利用其它设备授权的方法、电子设备和系统

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100041481A1 (en) * 2008-02-06 2010-02-18 Sony Online Entertainment Llc System and method for integrating ancillary content into applications
CN105282126A (zh) * 2014-07-24 2016-01-27 腾讯科技(北京)有限公司 登录认证方法、终端及服务器
CN105827600A (zh) * 2016-03-11 2016-08-03 腾讯科技(深圳)有限公司 登录客户端的方法及装置

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102739708B (zh) * 2011-04-07 2015-02-04 腾讯科技(深圳)有限公司 一种基于云平台访问第三方应用的系统及方法
US20140066044A1 (en) * 2012-02-21 2014-03-06 Manoj Ramnani Crowd-sourced contact information and updating system using artificial intelligence
CN105429979A (zh) * 2015-11-17 2016-03-23 上海礼源网络科技有限公司 一种跨平台用户认证方法及智能路由器、上网系统
CN105553972A (zh) * 2015-12-14 2016-05-04 苏州天平先进数字科技有限公司 一种使用第三方账号登录锁屏app社区的方法
CN105871838B (zh) * 2016-03-30 2019-03-01 努比亚技术有限公司 一种第三方账号的登录控制方法及用户中心平台
CN105847277A (zh) * 2016-04-29 2016-08-10 乐视控股(北京)有限公司 用于第三方应用的服务账号共享管理方法及系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100041481A1 (en) * 2008-02-06 2010-02-18 Sony Online Entertainment Llc System and method for integrating ancillary content into applications
CN105282126A (zh) * 2014-07-24 2016-01-27 腾讯科技(北京)有限公司 登录认证方法、终端及服务器
CN105827600A (zh) * 2016-03-11 2016-08-03 腾讯科技(深圳)有限公司 登录客户端的方法及装置

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111401395A (zh) * 2019-01-02 2020-07-10 中国移动通信有限公司研究院 一种数据处理方法、终端设备及存储介质
CN111401395B (zh) * 2019-01-02 2023-05-09 中国移动通信有限公司研究院 一种数据处理方法、终端设备及存储介质

Also Published As

Publication number Publication date
CN109314711A (zh) 2019-02-05
CN109314711B (zh) 2020-09-11

Similar Documents

Publication Publication Date Title
US11838324B2 (en) Secure web container for a secure online user environment
US11019048B2 (en) Password state machine for accessing protected resources
US20240106865A1 (en) Secure Web Container for a Secure Online User Environment
US11736292B2 (en) Access token management method, terminal, and server
US10349272B2 (en) Virtual SIM card cloud platform
US20190268155A1 (en) Method for Ensuring Terminal Security and Device
EP3364629B1 (en) Providing virtualized private network tunnels
JP5998284B2 (ja) エンタプライズシステムへのアプリケーションの動的登録
US11075900B2 (en) Associating user accounts with enterprise workspaces
WO2019036012A1 (en) SINGLE SIGNATURE OF A USER OF AN APPLICATION
JP7241814B2 (ja) 認証及び承認方法並びに認証サーバー
US20140109171A1 (en) Providing Virtualized Private Network tunnels
CN113630377B (zh) 托管移动设备的单点登录
CN115021991A (zh) 未经管理的移动设备的单点登录
JP2017513274A (ja) ローカルネットワークデバイスへの安全なアクセスを提供するためのシステム及び方法
CN109196891B (zh) 一种签约数据集的管理方法、终端及服务器
WO2018196153A1 (zh) 一种开放授权方法、装置和终端
US11669626B2 (en) Resource access with use of bloom filters
CN112685719B (zh) 单点登录方法、装置、系统、计算机设备和存储介质
WO2022246343A1 (en) Computing device and related methods providing virtual session launching from previously cached assets

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17908007

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17908007

Country of ref document: EP

Kind code of ref document: A1