WO2019218747A1 - 一种第三方授权登录方法及系统 - Google Patents

一种第三方授权登录方法及系统 Download PDF

Info

Publication number
WO2019218747A1
WO2019218747A1 PCT/CN2019/076021 CN2019076021W WO2019218747A1 WO 2019218747 A1 WO2019218747 A1 WO 2019218747A1 CN 2019076021 W CN2019076021 W CN 2019076021W WO 2019218747 A1 WO2019218747 A1 WO 2019218747A1
Authority
WO
WIPO (PCT)
Prior art keywords
party
authorization
user
authorized
authorized website
Prior art date
Application number
PCT/CN2019/076021
Other languages
English (en)
French (fr)
Inventor
张德峰
Original Assignee
阿里巴巴集团控股有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 阿里巴巴集团控股有限公司 filed Critical 阿里巴巴集团控股有限公司
Publication of WO2019218747A1 publication Critical patent/WO2019218747A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0807Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K7/00Methods or arrangements for sensing record carriers, e.g. for reading patterns
    • G06K7/10Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation
    • G06K7/10544Methods or arrangements for sensing record carriers, e.g. for reading patterns by electromagnetic radiation, e.g. optical sensing; by corpuscular radiation by scanning of the records by radiation in the optical part of the electromagnetic spectrum
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0815Network architectures or network communication protocols for network security for authentication of entities providing single-sign-on or federations

Definitions

  • the embodiments of the present disclosure relate to the field of Internet technologies, and in particular, to a third-party authorized login method and system.
  • a third-party authorization login method appears, which means that users can log in to different websites through third-party authorization.
  • Third parties act as authorized parties, and the website acts as an authorized party.
  • users can use QQ, WeChat, Sina Wei.
  • a third party such as Bo is authorized to log in to different websites.
  • Existing third-party authorization login method In the process of third-party authorization to log in to the authorized website, the user needs to jump to the third-party website to log in to his third-party account and password for authorization, and then jump back to the authorized after confirming the authorization. website.
  • the existing third-party authorization login method is cumbersome for the user and reduces the user experience.
  • the embodiment of the present specification provides a third-party authorization login method and system, and the technical solution is as follows:
  • a third-party authorization login method includes:
  • the authorized website When the authorized website detects that the third-party account login operation of the user is triggered, the authorized website generates a two-dimensional code corresponding to the third-party account;
  • the authorized website presents the two-dimensional code to the user
  • the third-party client When the third-party client detects that the user's QR code scanning operation is triggered, the third-party client identifies the two-dimensional code to prompt the user whether to authorize;
  • the third-party server authenticates with the authorized website
  • a third-party authorized login system includes: a third-party client, a third-party server, and an authorized website;
  • the authorized website When the authorized website detects that the third-party account login operation of the user is triggered, the authorized website generates a two-dimensional code corresponding to the third-party account;
  • the authorized website presents the two-dimensional code to the user
  • the third-party client When the third-party client detects that the user's QR code scanning operation is triggered, the third-party client identifies the two-dimensional code to prompt the user whether to authorize;
  • the third-party server authenticates with the authorized website
  • the authorized website when a user logs in to an authorized website by using a third-party account, the authorized website generates a two-dimensional code, and the user can scan the two-dimensional code by using a third-party client, and confirm the authorization to log in.
  • the authorized website can complete the authorized login operation without having to jump to the third-party website to log in to its third-party account and password, thereby simplifying the operation process and improving the user experience.
  • any of the embodiments of the present specification does not need to achieve all of the above effects.
  • FIG. 1 is a schematic diagram of interaction of a third-party authorized login method in the embodiment of the present specification
  • FIG. 2 is a schematic diagram showing a two-dimensional code provided by an embodiment of the present specification
  • FIG. 3 is a schematic diagram of interaction between a third-party server and an authorized website for performing third-party authorization authentication in the embodiment of the present specification
  • FIG. 4 is a schematic diagram of a preferred interaction of a third-party authorized login method in the embodiment of the present specification
  • FIG. 5 is a schematic structural diagram of a third-party authorization login device applied to a third-party client according to an embodiment of the present disclosure
  • FIG. 6 is a schematic structural diagram of a third-party authorized login device applied to a third-party server in the embodiment of the present specification
  • Figure 7 is a block diagram showing the structure of an apparatus for configuring an apparatus of an embodiment of the present specification.
  • the general PC serves as a daily office tool for the user, especially as a public PC, a third-party account and a password as the user's own sensitive information, and will not make his own long-term on the PC.
  • the third-party account is online.
  • the third-party account can be Alipay account, QQ account, WeChat account, Weibo account, etc., and only log in to your third-party account when needed. Therefore, when a user accesses an authorized website and needs to log in, select a third-party account to log in. You need to jump to a third-party website to log in to your third-party account and password for authorization, and then jump back to the authorized website.
  • the authorized website shows that the user is logged in. For the user, the operation process is cumbersome and reduces the user experience.
  • the authorized website When the authorized website detects that the third-party account login operation of the user is triggered, the authorized website generates a two-dimensional code corresponding to the third-party account, and displays the two-dimensional code to the user, and the user scans the two-dimensional code by using a third-party client. After confirming the authorization, the authorized website will show that the user has logged in.
  • the terminal serves as a privacy tool used by the user for daily use, such as a mobile phone or a tablet.
  • the user installs various third-party clients on the terminal, such as a QQ client, a WeChat client, an Alipay client, etc., in order to facilitate the use of the above.
  • the third-party client the user will keep his third-party account online for a long time, for the user, only need to use the QR code scanning function carried by the third-party client on the terminal to scan the authorized website display.
  • the QR code and confirm the authorization to log in to the authorized website. This simplifies the user's operating process and enhances the user experience.
  • the third-party authorized login process involves a third client, a third-party server, and an authorized website
  • the third-party client may be an application installed on the terminal, such as an Alipay client or a QQ client.
  • the authorized website can be any website that supports any third-party account login, such as Sina Weibo, Taobao, Baidu, etc.
  • the third-party server can be a specific server or In the form of a server cluster, the third client and the third-party server, the third-party server, and the authorized website can implement communication connection through various forms of networks, which is not limited in this specification.
  • the authorized website displays the two-dimensional code for the user to scan the two-dimensional code to authorize the login.
  • an interaction diagram of a third-party authorized login method may include the following steps:
  • the authorized website detects that the third-party account login operation of the user is triggered, the authorized website generates a two-dimensional code corresponding to the third-party account.
  • the currently authorized website gradually supports users to log in using a third-party account, which means that the authorized website allows the user to log in without using the third-party account.
  • the third-party account may be a QQ account, a WeChat account, an Alipay account, a Weibo account, etc. as described above.
  • the user may select any third-party account supported by the authorized website to log in.
  • the authorized website When the user selects a third-party account to log in to the authorized website, the authorized website generates a URL for obtaining the authorization code according to the oAuth protocol, and generates a two-dimensional code corresponding to the third-party account selected by the user.
  • the oAuth protocol provides a secure, open and simple standard for authorizing user resources.
  • the difference from the previous authorization method is that the authorized website does not touch the user's account information, such as the user's account number and password, that is, the authorized website can apply for the authorization of the user resource without using the user's account and password.
  • the forum website when the user selects the Alipay account to log in to the currently visited forum website, the forum website generates a URL according to the oAuth protocol, and generates a two-dimensional code corresponding to the Alipay account selected by the user.
  • the authorized website displays the two-dimensional code to the user.
  • the authorized website After the authorized website generates the two-dimensional code corresponding to the third-party account selected by the user when logging in to the authorized website, the two-dimensional code needs to be displayed to the user, and the implementation of the two-dimensional code is displayed to the user.
  • the embodiment provides an implementation manner. It should be noted that the embodiment of the present specification merely exemplifies one of the implementation manners, and does not limit how to display the two-dimensional code to the user.
  • One of the implementation manners for displaying the two-dimensional code to the user is: after the authorized website generates the two-dimensional code corresponding to the third-party account selected by the user when logging in to the authorized website, the two-dimensional code is displayed in the form of a dialog box. To the user, a dialog box that can be arbitrarily stretched is popped up on the current page. The QR code is in the center of the dialog box, as shown in Figure 2. In particular, you can set the life cycle for this dialog box. After a period of time, the dialog box will disappear automatically.
  • the third-party client detects that the user's QR code scanning operation is triggered, the third-party client identifies the two-dimensional code to prompt the user whether to authorize;
  • the user After seeing the two-dimensional code displayed on the authorized website, the user scans the two-dimensional code by using the scanning function carried by the third-party client installed on the terminal, and the third-party client detects that the user's QR code scanning operation is triggered, and the identification is authorized.
  • the QR code displayed on the website indicates whether the user is authorized after the QR code is successfully identified.
  • the user scans the QR code displayed on the forum website by using the scanning function carried by the Alipay client installed on the mobile phone, and the Alipay client monitors the user's QR code scanning operation trigger, and identifies the QR code in the current scanning area. After the identification is successful, the user will be prompted whether to authorize.
  • the embodiment of the present specification can display the URL for generating the two-dimensional code on the user terminal, but does not prompt the user for authorization, and cannot continue the subsequent process.
  • the user selects the Alipay account to log in to the forum website, and the forum website generates a two-dimensional code corresponding to the Alipay account.
  • the user selects the Alipay client on the terminal to scan the QR code, but the user may select the terminal.
  • the WeChat client scans the QR code, and the corresponding user terminal displays the URL for generating the QR code, and does not prompt the user for authorization, unless the user reselects the Alipay client on the selected terminal to scan the two-dimensional code. Code, otherwise it means that the third party authorization login failed.
  • the third-party server authenticates with the authorized website.
  • the third-party client After the third-party client scans the two-dimensional code successfully, and confirms the authorization of the authorized website, the third-party client sends the identified two-dimensional code to the third-party server when the user authorization confirmation operation is triggered.
  • the information after receiving the identified two-dimensional code information, performs third-party authorization authentication between the third-party server and the authorized website.
  • the third-party client After the user confirms the authorization of the authorized website, the third-party client sends the identified two-dimensional code information to the third-party server, and the two-dimensional code information includes but is not limited to callback address information.
  • third-party clients need to send other messages. For example, on the one hand, it is required to send a user confirmation authorization information to a third-party server, and the user authorization confirmation information is used to notify a third-party server user that the authorization has been confirmed, and may perform third-party authorization authentication with the authorized website;
  • the three-party server sends information such as the third-party client identifier and the user account currently logged in to the third-party client, so that the third-party server returns the user information corresponding to the user account to the subsequent authorized website when requesting the user information.
  • Authorized website As an example, the Alipay client sends its own ID and the Alipay account currently registered in the Alipay client to the Alipay server, so that the forum website returns the user information corresponding to the Alipay account to the forum website when requesting the user information.
  • a third-party authorization authentication is performed between the third-party server and the authorized website.
  • the specific process is shown in Figure 3.
  • the third-party authorization authentication process can include the following steps:
  • Step S104a after receiving the identified two-dimensional code information, according to the callback address information carried on the identified two-dimensional code, the third-party server sends the generated authorization code to the authorized website;
  • the third-party server sends the callback address information carried on the two-dimensional code, and the callback address information may be the IP address information of the authorized website, and the generated authorization code is sent to the authorized website.
  • the authorization code generated by the third-party server has a certain period of validity, and during the valid time, the authorization verification for the authorized website means that the authorized website needs to use the authorization code to the third-party server within the valid time. The verification is performed, and the authorization token is obtained after the verification, and then the authorization token can be used as a certificate for authorizing the authorized website.
  • the authorization code may be any combination of numbers and/or characters, the length of which is not limited.
  • the Alipay server sends the generated authorization code to the forum website according to the callback address information, and the authorization code is as0123, and the authorization code is valid for 1 minute.
  • Step S104b The authorized website receives the authorization code, and sends a request for obtaining an authorization token to the third-party server by using the received authorization code.
  • the authorized website Since the authorization code is used as an authentication for the authorization of the authorized website, the authorized website obtains the authorization token through the authorization code after receiving the authorization code.
  • the authorization token is not only a basis for obtaining user information, but also a certificate for the authorized website to be authorized by the third party server.
  • the authorization token may be any combination of numbers and/or characters, and the length thereof is not limited.
  • the authorization token can be 1234asdf45.
  • the forum website after receiving the authorization code, the forum website sends a request for obtaining an authorization token to the Alipay server through the authorization code within the valid time of the authorization code, and the Alipay server verifies the authorization code. After the verification is passed, the authorization token is returned to the forum website.
  • Step S104c The authorized website receives the authorization token returned by the third party server
  • Step S104d After receiving the authorization token returned by the third-party server, the authorized website sends a request for obtaining the unique identifier of the user to the third-party server.
  • the user information includes but is not limited to: a user nickname, a user avatar, a user friend, and the like. Therefore, after receiving the authorization token, the authorized website needs to further obtain the unique identifier of the user, and the user identifier is used as one of the basis for obtaining the user information.
  • Step S104e The authorized website receives the unique identifier of the user returned by the third-party server.
  • the third-party server After receiving the request for obtaining the unique identifier of the user sent by the authorized website, the third-party server returns the unique identifier of the user corresponding to the user account sent by the third-party client to the authorized website.
  • Step S104f The authorized website sends a request for acquiring user information to the third-party server by using the authorization token and the user unique identifier;
  • the authorization token and the user unique identifier are used as the basis for obtaining the user information.
  • the authorized website may obtain the user information according to the authorization token and the unique identifier of the user.
  • the forum website sends a request for obtaining user information such as a user nickname, a user avatar, and a user friend to the Alipay server through the authorization token 1234asdf45 and the user unique identifier 1236.
  • Step S104g The authorized website receives the user information returned by the third party server.
  • the third-party server receives the request for obtaining the user information sent by the authorized website, determines the user information according to the authorization token and the unique identifier of the user, and returns the user information to the authorized website, and the authorized website receives the return from the third-party server. After the user information, the third party authorization is passed.
  • the authorized website After receiving the user information returned by the third-party server, the authorized website means that the third-party authorization and authentication between the third-party server and the authorized website are passed, and the third-party authorized login of the authorized website is successful, and the user can perform the authorization on the authorized website. Subsequent operations, such as reviewing downloads and so on.
  • the embodiment of the present specification may further include:
  • the third-party client After receiving the message, the third-party client shows the user that the authorization is successful.
  • the third-party server After the third-party server returns the user information to the authorized website, it means that the third-party authorization is passed, and the third-party server sends the successful authorization message to the third-party client, and the third-party client displays the authorization success to the user. In turn, the user can go to the authorized website for subsequent operations.
  • the user when the user logs in using a third-party account, the user scans the two-dimensional code displayed by the authorized website through the scanning function carried by the third-party client on the terminal, after confirming the authorization, Can log in.
  • the user is prevented from jumping to the third-party website to log in to the third-party account and the password is authorized.
  • the operation process is simplified and the user experience is improved.
  • Step a when the third-party client detects that the user's QR code scanning operation is triggered, identifying the two-dimensional code displayed by the authorized website, prompting the user whether to authorize;
  • Step b When the third-party client detects that the user's authorization confirmation operation is triggered, the third-dimensional code information is sent to the third-party server, so that the third-party server receives the QR code information, and then The authorized website performs third-party authorization certification.
  • Step A receiving two-dimensional code information sent by a third-party client
  • Step B After receiving the two-dimensional code information sent by the third-party client, sending the generated authorization code to the authorized website according to the callback address information carried on the identified two-dimensional code;
  • Step C Receive a request for obtaining an authorization token sent by the authorized website by using the authorization code, and return an authorization token;
  • Step D receiving a request for obtaining a unique identifier of the user sent by the authorized website, and returning the unique identifier of the user;
  • Step E Receive a request for obtaining the user information sent by the authorized website through the authorization token and the user unique identifier, and return the user information.
  • the main tasks that need to be performed for an authorized website are as follows:
  • Step 1 When the authorized website detects that the third-party account login operation of the user is triggered, generating a two-dimensional code corresponding to the third-party account;
  • Step 2 displaying the two-dimensional code to the user
  • Step 3 Receive an authorization code sent by the third-party server, and send a request for obtaining an authorization token to the third-party server by using the received authorization code.
  • Step 4 Receive an authorization token returned by the third-party server, and after receiving the authorization token returned by the third-party server, send a request for obtaining the unique identifier of the user to the third-party server.
  • Step 5 Receive a unique identifier of the user returned by the third-party server.
  • Step 6 Send a request for acquiring user information to the third-party server by using the authorization token and the user unique identifier;
  • Step 7 Receive user information returned by the third-party server, and the third-party authorization is successfully logged in.
  • the embodiment of the present disclosure further provides a third-party authorization login device, which is applied to a third-party client.
  • the method may include: a two-dimensional code identification module 510 and an information sending module 520.
  • the two-dimensional code recognition module 510 is configured to: when the third-party client detects the triggering of the user's QR code scanning operation, identify the two-dimensional code displayed by the authorized website, and prompt the user whether to authorize;
  • the information sending module 520 is configured to: when the third-party client detects that the user's authorization confirmation operation is triggered, send the identified two-dimensional code information to the third-party server, so that the third-party server receives the two-dimensional code. After the information, perform third-party authorization certification with the authorized website.
  • the embodiment of the present specification further provides a third-party authorization login device, which is applied to a third-party server.
  • the information may be included in the information receiving module 610 and the authentication module 620.
  • the information receiving module 610 is configured to receive two-dimensional code information sent by a third-party client.
  • the authentication module 620 is configured to perform third-party authorization authentication with the authorized website after receiving the two-dimensional code information sent by the third-party client.
  • the embodiment of the present specification further provides a third-party authorized login system, which may include: a third-party client, a third-party server, and an authorized website.
  • the authorized website When the authorized website detects that the third-party account login operation of the user is triggered, the authorized website generates a two-dimensional code corresponding to the third-party account;
  • the authorized website presents the two-dimensional code to the user
  • the third-party client When the third-party client detects that the user's QR code scanning operation is triggered, the third-party client identifies the two-dimensional code to prompt the user whether to authorize;
  • the third-party server authenticates with the authorized website
  • the user when the user logs in using a third-party account, the user scans the two-dimensional code displayed by the authorized website through the scanning function carried by the third-party client on the terminal, after confirming the authorization, Can log in.
  • the user is prevented from jumping to the third-party website to log in to the third-party account and the password is authorized.
  • the operation process is simplified and the user experience is improved.
  • the embodiment of the present specification further provides a computer device.
  • the device may include a processor 710, a memory 720, an input/output interface 730, a communication interface 740, and a bus 750.
  • the processor 710, the memory 720, the input/output interface 730, and the communication interface 740 implement a communication connection between the devices via the bus 750.
  • the processor 710 can be implemented by using a general-purpose CPU (Central Processing Unit), a microprocessor, an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits for performing correlation.
  • the program is implemented to implement the technical solutions provided by the embodiments of the present specification.
  • the memory 720 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, or the like.
  • the memory 720 can store the operating system and other applications.
  • the technical solution provided by the embodiment of the present specification is implemented by software or firmware, the related program code is saved in the memory 720 and is called and executed by the processor 710.
  • the input/output interface 730 is used to connect an input/output module to implement information input and output.
  • the input/output/module can be configured as a component in the device (not shown) or externally connected to the device to provide the corresponding function.
  • the input device may include a keyboard, a mouse, a touch screen, a microphone, various types of sensors, and the like, and the output device may include a display, a speaker, a vibrator, an indicator light, and the like.
  • the communication interface 740 is used to connect a communication module (not shown) to implement communication interaction between the device and other devices.
  • the communication module can communicate by wired means (such as USB, network cable, etc.), or can communicate by wireless means (such as mobile network, WIFI, Bluetooth, etc.).
  • Bus 750 includes a path for transferring information between various components of the device, such as processor 710, memory 720, input/output interface 730, and communication interface 740.
  • the above device only shows the processor 710, the memory 720, the input/output interface 730, the communication interface 740, and the bus 750, in a specific implementation, the device may also include necessary for normal operation. Other components.
  • the above-mentioned devices may also include only the components necessary for implementing the embodiments of the present specification, and do not necessarily include all the components shown in the drawings.
  • the embodiment of the present specification further provides a computer readable storage medium, on which a computer program is stored, and when the program is executed by the processor, the foregoing third party authorized login method is implemented.
  • the method at least includes:
  • the third-party client detects that the user's QR code scanning operation is triggered, the two-dimensional code displayed by the authorized website is identified, and the user is prompted to authorize;
  • the third-dimensional code information is sent to the third-party server to enable the third-party server to contact the authorized website after receiving the two-dimensional code information. Perform third-party authorization certification.
  • the embodiment of the present specification further provides a computer readable storage medium, on which a computer program is stored, and when the program is executed by the processor, the foregoing third party authorized login method is implemented.
  • the method at least includes:
  • Computer readable media includes both permanent and non-persistent, removable and non-removable media.
  • Information storage can be implemented by any method or technology.
  • the information can be computer readable instructions, data structures, modules of programs, or other data.
  • Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, Magnetic tape cartridges, magnetic tape storage or other magnetic storage devices or any other non-transportable media can be used to store information that can be accessed by a computing device.
  • computer readable media does not include temporary storage of computer readable media, such as modulated data signals and carrier waves.
  • the embodiments of the present specification can be implemented by means of software plus a necessary general hardware platform. Based on such understanding, the technical solution of the embodiments of the present specification may be embodied in the form of a software product in essence or in the form of a software product, which may be stored in a storage medium such as a ROM/RAM. Disks, optical disks, and the like, including instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform the methods described in various embodiments of the embodiments of the present specification or embodiments.
  • a computer device which may be a personal computer, server, or network device, etc.
  • the system, device, module or unit illustrated in the above embodiments may be implemented by a computer chip or an entity, or by a product having a certain function.
  • a typical implementation device is a computer, and the specific form of the computer may be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, and a game control.
  • the various embodiments in the specification are described in a progressive manner, and the same or similar parts between the various embodiments may be referred to each other, and each embodiment focuses on the differences from the other embodiments.
  • the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
  • the device embodiments described above are merely illustrative, and the modules described as separate components may or may not be physically separated, and the functions of the modules may be the same in the implementation of the embodiments of the present specification. Or implemented in multiple software and/or hardware. It is also possible to select some or all of the modules according to actual needs to achieve the purpose of the solution of the embodiment. Those of ordinary skill in the art can understand and implement without any creative effort.

Abstract

公开了一种第三方授权登录方法,该方法包括:当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;被授权网站向用户展示所述二维码;当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。

Description

一种第三方授权登录方法及系统 技术领域
本说明书实施例涉及互联网技术领域,尤其涉及一种第三方授权登录方法及系统。
背景技术
用户登录某一网站时,通常需要在该网站上注册登录账号及设置相应的登录密码。例如用户在A网站注册的账号只能登录A网站,不可以登录B网站,因此,用户若需要登录多个网站,则需要注册多个相应的账号,使得用户需要管理多个账号,给用户造成不便。为了解决上述问题,出现了第三方授权登录的方式,意味着用户可以通过第三方授权登录不同的网站,其中第三方作为授权方,网站作为被授权方,例如用户可以通过QQ、微信、新浪微博等第三方授权登录不同的网站。
现有的第三方授权登录方法:在第三方授权登录被授权网站的过程中,需要用户跳转到第三方网站登录自己的第三方账号以及密码进行授权,在确认授权后跳转回该被授权网站。现有的第三方授权登录方法,对于用户而言,操作流程比较繁琐,降低了用户的体验。
发明内容
针对上述技术问题,本说明书实施例提供一种第三方授权登录方法及系统,技术方案如下:
一种第三方授权登录方法,该方法包括:
当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;
被授权网站向用户展示所述二维码;
当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;
当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;
在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。
一种第三方授权登录系统,该系统包括:第三方客户端、第三方服务端及被授权网站;
当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;
被授权网站向用户展示所述二维码;
当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;
当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;
在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。
本说明书实施例所提供的技术方案,当用户使用第三方账号登录被授权网站时,被授权网站生成二维码,用户可以使用第三方客户端扫描该二维码,并确认授权后即可登录该被授权网站,由此用户不必跳转到第三方网站登录自己的第三方账号以及密码进行授权,就可以完成授权登录操作,对于用户而言,简化了操作流程,提高了用户的体验。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本说明书实施例。
此外,本说明书实施例中的任一实施例并不需要达到上述的全部效果。
附图说明
为了更清楚地说明本说明书实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本说明书实施例中记载的一些实施例,对于本领域普通技术人员来讲,还可以根据这些附图获得其他的附图。
图1是本说明书实施例的第三方授权登录方法的交互示意图;
图2是本说明书实施例提供的一种展示二维码的示意图;
图3是本说明书实施例的第三方服务端与被授权网站之间进行第三方授权认证的交互示意图;
图4是本说明书实施例的第三方授权登录方法的优选交互示意图;
图5是本说明书实施例的应用于第三方客户端的第三方授权登录装置的结构示意图;
图6是本说明书实施例的应用于第三方服务端的第三方授权登录装置的结构示意图;
图7是用于配置本说明书实施例装置的一种设备的结构示意图。
具体实施方式
由于用户经常在PC上去访问网站查阅下载资料,一般PC作为用户日常办公的工具,特别是作为公用的PC,第三方账号以及密码作为用户自己的敏感信息,并不会在PC上长期使自己的第三方账号处于在线状态,这里第三方账号可以是支付宝账号、QQ账号、微信账号、微博账号等,只有需要的时候才会登录自己的第三方账号。故此当用户访问某个被授权网站需要登录时,选择第三方账号进行登录,需要跳转到第三方网站登录自己的第三方账号以及密码进行授权,然后在跳回到该被授权网站,这时该被授权网站显示用户已登录。对于用户而言,操作流程比较繁琐,降低了用户的体验。
针对以上问题,本说明书实施例提供如下技术方案:
当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与第三方账号对应的二维码,并向用户展示该二维码,用户使用第三方客户端扫描该二维码,并确认授权后,被授权网站会显示用户已登录。
终端作为用户日常使用的私密性工具,例如手机、平板等,用户在终端上会安装各种各样的第三方客户端,如QQ客户端、微信客户端、支付宝客户端等,为了方便使用上述所说的第三方客户端,用户会长期使自己的第三方账号处于在线状态,对于用户而言,仅仅只需要使用终端上第三方客户端携带的二维码扫描功能,去扫描被授权网站显示的二维码,并确认授权后即可登录被授权网站。由此简化了用户的操作流程,提升了用户的体验。
在本说明书的实施例中,第三方授权登录的流程涉及第三客户端、第三方服务端、被授权网站,第三方客户端可以是安装在终端上的应用程序,如支付宝客户端、QQ客户端、微信客户端、微博客户端等,被授权网站可以是当前任意支持第三方账号登录的网站,如新浪微博、淘宝、百度等网站,第三方服务端可以是特定的一台服务器或服务器集群的形式,第三客户端与第三方服务端、第三方服务端与被授权网站可通过各种形式的网络实现通信连接,本说明书对此不作限定。
为了使本领域技术人员更好地理解本说明书实施例中的技术方案,下面将结合本说明书实施例中的附图,对本说明书实施例中的技术方案进行详细地描述,显然,所描述的实施例仅仅是本说明书的一部分实施例,而不是全部的实施例。基于本说明书中的实施例,本领域普通技术人员所获得的所有其他实施例,都应当属于保护的范围。
本说明书实施例被授权网站通过向用户展示二维码,供用户扫描二维码授权登录,具体的本说明书实施例提供的技术方案如下:
如图1所示,为本说明书实施例提供的第三方授权登录方法的交互示意图,该方法可以包括以下步骤:
S101,当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;
当前被授权网站为了减少因注册而流失的用户,逐渐支持用户使用第三方账号进行登录,意味着被授权网站允许用户不必注册账号,可以使用第三方账号进行登录。这里第三方账号可以是如上述所说的QQ账号、微信账号、支付宝账号、微博账号等等,用户在登录被授权网站时,可以选择任意一种被授权网站支持的第三方账号进行登录。当用户选择第三方账号登录被授权网站时,被授权网站会按照oAuth协议生成用于获取授权码的URL,并将该URL生成与用户所选择的第三方账号对应的二维码。
这里oAuth协议为用户资源的授权提供了一个安全的、开放而又简易的标准。与以往的授权方式不同之处在于不会使被授权网站触及到用户的账号信息,例如用户的账号及密码,即被授权网站无需使用用户的账号及密码就可以申请获得该用户资源的授权。
作为一个例子,当用户选择支付宝账号登录当前访问的论坛网站时,论坛网站将按照oAuth协议生成URL,并将该URL生成二维码,该二维码与用户所选择的支付宝账号对应。
S102,被授权网站向用户展示所述二维码;
被授权网站生成与用户登录被授权网站时所选择的第三方账号对应的二维码之后,需要向用户展示该二维码,其中向用户展示该二维码的实现方式有很多种,本说明书实施例提供一种实现方式,值得注意的是,本说明书实施例仅仅是对其中一种实现方式做示例性说明,并不是限定如何向用户展示二维码。
其中一种向用户展示二维码的实现方式为:被授权网站在生成与用户登录被授权网站时所选择的第三方账号对应的二维码之后,以对话框的形式将该二维码展示给用户,在当前页面弹出一个可以任意拉伸的对话框,该二维码在该对话框中央位置,如图2所示。特别的可以为该对话框设置生命周期,在经过一段时间之后,该对话框可以自动消失。
S103,当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;
用户在看到被授权网站展示二维码之后,利用终端上安装的第三方客户端携带的扫描功能扫描该二维码,第三方客户端监测到用户的二维码扫描操作触发,识别被授权网站展示的二维码,识别二维码成功之后,提示用户是否授权。作为一个例子,用户利用手机上安装的支付宝客户端携带的扫描功能扫描论坛网站展示的二维码,支付宝客户端监测到用户的二维码扫描操作触发,会识别当前扫描区域内的二维码,识别成功之后会提示用户是否授权。
特殊的,由于被授权网站生成的二维码与用户登录被授权网站时所选择的第三方账号对应,一般情况下用户会选择相应的第三方客户端去扫描该二维码,不可避免的,用户有可能使用终端上其它的第三方客户端去扫描该二维码。针对这种特殊情况,本说明书实施例在用户终端上可以显示生成该二维码的URL,但并不会提示用户是否授权,也无法继续后续流程。作为一个例子,用户选择支付宝账号登录论坛网站,论坛网站生成与支付宝账号对应的二维码,正常情况下用户会选择终端上的支付宝客户端去扫描该二维码,但用户有可能选择终端上的微信客户端去扫描该二维码,相应的用户终端上就会显示生成该二维码的URL,并不会提示用户是否授权,除非用户重选选择终端上的支付宝客户端去扫描二维码,否则意味着第三方授权登录失败。
S104,当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;
用户在使用第三方客户端扫描二维码成功之后,并确认对被授权网站进行授权, 第三方客户端在监测到上述用户授权确认操作触发时,向第三方服务端发送所识别的二维码信息,在接收到所识别的二维码信息后,第三方服务端与被授权网站之间进行第三方授权认证。
用户确认对被授权网站授权之后,第三方客户端向第三方服务端发送所识别的二维码信息,该二维码信息包括但不限于回调地址信息。
第三方客户端除向第三方服务端发送二维码信息之外,还需要发送其它消息。例如,一方面需要向第三方服务端发送用户确认授权信息,该用户授权确认信息用于告知第三方服务端用户已经确认授权,可以与被授权网站进行第三方授权认证;另一方面需要向第三方服务端发送第三方客户端标识以及当前在第三方客户端所登录的用户账号等信息,以便于后续被授权网站在请求用户信息时,第三方服务端将该用户账号对应的用户信息返回给被授权网站。作为一个例子,支付宝客户端将自身ID以及当前在支付宝客户端登录的支付宝账号发送至支付宝服务端,以便论坛网站在请求用户信息时,将该支付宝账号对应的用户信息返回给论坛网站。
第三方服务端与被授权网站之间进行第三方授权认证,其具体流程如图3所示,该第三方授权认证流程可以包括以下步骤:
步骤S104a,在接收到所识别的二维码信息后,根据所识别的二维码上携带的回调地址信息,第三方服务端将生成的授权码发送至被授权网站;
第三方服务端根据二维码上携带的回调地址信息,该回调地址信息可以是被授权网站的IP地址信息,将生成的授权码发送至被授权网站。第三方服务端生成的授权码具有一定时间的有效期,在该有效时间内,用于对被授权网站的授权验证,意味着在该有效时间内被授权网站需要利用该授权码到第三方服务端进行验证,验证通过之后获取授权令牌,之后授权令牌可以作为对被授权网站授权的一种凭证。该授权码可以是任意数字和/或字符的组合,其长度不作限定。
作为一个例子,支付宝服务端根据回调地址信息,将生成的授权码发送至论坛网站,该授权码是as0123,该授权码的有效期为1分钟。
步骤S104b,被授权网站接收该授权码,并通过所接收的授权码向第三方服务端发送获取授权令牌的请求;
由于授权码作为对被授权网站授权的一种验证,被授权网站在接收到授权码之后,通过该授权码去获取授权令牌。
授权令牌不仅作为获取用户信息的其中一种依据,也是第三方服务端对被授权网站授权的一种凭证,授权令牌可以是任意数字和/或字符的组合,其长度不作限定。例如,授权令牌可以是1234asdf45。
作为一个例子,论坛网站在接收到授权码之后,在该授权码的有效时间内,论坛网站通过该授权码向支付宝服务端发送获取授权令牌的请求,支付宝服务端对该授权码进行验证,验证通过之后,向论坛网站返回授权令牌。
步骤S104c,被授权网站接收第三方服务端返回的授权令牌;
步骤S104d在接收到第三方服务端返回的授权令牌后,被授权网站向第三方服务端发送获取用户唯一标识的请求;
由于被授权网站需要获取用户信息,用户信息包括但不限于:用户昵称、用户头像、用户好友等。因此被授权网站在接收到授权令牌之后,需要进一步去获取用户唯一标识,该用户标识作为获取用户信息的其中一种依据。
步骤S104e,被授权网站接收第三方服务端返回的用户唯一标识;
第三方服务端接收到被授权网站发送的获取用户唯一标识的请求后,将与第三方客户端发送的用户账户对应的用户唯一标识返回给被授权网站。
步骤S104f,被授权网站通过授权令牌以及用户唯一标识向第三方服务端发送获取用户信息的请求;
授权令牌以及用户唯一标识作为获取用户信息的依据,被授权网站在接收到授权令牌以及用户唯一标识之后,可以根据授权令牌以及用户唯一标识获取用户信息。作为一个例子,论坛网站通过授权令牌1234asdf45以及用户唯一标识1236向支付宝服务端发送获取用户昵称、用户头像、用户好友等用户信息的请求。
步骤S104g,被授权网站接收第三方服务端返回的用户信息。
第三方服务端接收被授权网站发送的获取用户信息的请求,根据授权令牌以及用户唯一标识确定用户信息,将该用户信息返回给被授权网站,被授权网站在接收到第三方服务端返回的用户信息之后,至此第三方授权认证通过。
S105,在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。
被授权网站在接收到第三方服务端返回的用户信息之后,意味着第三方服务端与 被授权网站之间第三方授权认证通过,被授权网站第三方授权登录成功,用户可以在被授权网站进行后续的操作,例如查阅下载资料等。
在上述实施例的基础之上,参见图4所示,本说明书实施例还可以进一步包括:
S106,在第三方服务端与被授权网站之间第三方授权认证通过之后,第三方服务端将授权成功的消息发送至第三方客户端;
第三方客户端在接收到所述消息后,向用户展示授权成功。
在第三方服务端将用户信息返回给被授权网站之后,意味着第三方授权认证通过,第三方服务端将授权成功的消息发送至第三方客户端,由第三方客户端向用户展示授权成功,进而用户可以去被授权网站进行后续的操作。
由上述对本说明书实施例的技术方案的描述,当用户使用第三方账号登录时,用户通过终端上的第三方客户端携带的扫描功能,扫描被授权网站展示的二维码,在确认授权之后即可登录。
应用本说明书实施例提供的技术方案,避免用户跳转到第三方网站登录自己的第三方账号以及密码进行授权,对于用户而言,简化了操作流程,提高了用户的体验。
为了更清楚地说明本说明书实施例的方案,下面分别再从单侧的角度,对执行的方法进行说明:
对于第三方客户端,需要执行的任务主要如下:
步骤a,当第三方客户端监测到用户的二维码扫描操作触发时,识别被授权网站所展示的二维码,提示用户是否授权;
步骤b,当第三方客户端监测到用户的授权确认操作触发时,向第三方服务端发送所识别的二维码信息,以使第三方服务端在接收到所述二维码信息之后,与被授权网站进行第三方授权认证。
对于第三方服务端,需要执行的任务主要如下:
步骤A,接收第三方客户端发送的二维码信息;
步骤B,在接收到第三方客户端发送的二维码信息之后,根据所识别的二维码上携带的回调地址信息,将生成的授权码发送至被授权网站;
步骤C,接收被授权网站通过所述授权码发送的获取授权令牌的请求,并返回授权 令牌;
步骤D,接收被授权网站发送的获取用户唯一标识的请求,并返回用户唯一标识;
步骤E,接收被授权网站通过授权令牌以及用户唯一标识发送的获取用户信息的请求,并返回用户信息。
对于被授权网站,需要执行的主要任务如下:
步骤1,当被授权网站监测到用户的第三方账号登录操作触发时,生成与所述第三方账号对应的二维码;
步骤2,向用户展示所述二维码;
步骤3,接收第三方服务端发送的授权码,并通过所接收的授权码向第三方服务端发送获取授权令牌的请求;
步骤4,接收第三方服务端返回的授权令牌,并在接收到第三方服务端返回的授权令牌后,向第三方服务端发送获取用户唯一标识的请求;
步骤5,接收第三方服务端返回的用户唯一标识;
步骤6,通过授权令牌以及用户唯一标识向第三方服务端发送获取用户信息的请求;
步骤7,接收第三方服务端返回的用户信息,第三方授权登录成功。
关于第三方客户端、第三方服务端、被授权网站的单侧执行方法细节,可以参见前面实施例的描述,这里不再赘述。
相应于上述方法实施例,本说明书实施例还提供一种第三方授权登录装置,应用于第三方客户端,参见图5所示,可以包括:二维码识别模块510、信息发送模块520。
二维码识别模块510,用于当第三方客户端监测到用户的二维码扫描操作触发时,识别被授权网站所展示的二维码,提示用户是否授权;
信息发送模块520,用于当第三方客户端监测到用户的授权确认操作触发时,向第三方服务端发送所识别的二维码信息,以使第三方服务端在接收到所述二维码信息之后,与被授权网站进行第三方授权认证。
本说明书实施例还提供一种第三方授权登录装置,应用于第三方服务端,参见图6所示,可以包括:信息接收模块610、认证模块620。
信息接收模块610,用于接收第三方客户端发送的二维码信息;
认证模块620,用于在接收到第三方客户端发送的二维码信息之后,与被授权网站进行第三方授权认证。
本说明书实施例还提供一种第三方授权登录系统,该系统可以包括:第三方客户端、第三方服务端及被授权网站。
当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;
被授权网站向用户展示所述二维码;
当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;
当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;
在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。
上述装置中各个模块的功能和作用的实现过程具体详见上述方法中对应步骤的实现过程,在此不再赘述。
由上述对本说明书实施例的技术方案的描述,当用户使用第三方账号登录时,用户通过终端上的第三方客户端携带的扫描功能,扫描被授权网站展示的二维码,在确认授权之后即可登录。
应用本说明书实施例提供的技术方案,避免用户跳转到第三方网站登录自己的第三方账号以及密码进行授权,对于用户而言,简化了操作流程,提高了用户的体验。
本说明书实施例还提供一种计算机设备,如图7所示,该设备可以包括:处理器710、存储器720、输入/输出接口730、通信接口740和总线750。其中处理器710、存储器720、输入/输出接口730和通信接口740通过总线750实现彼此之间在设备内部的通信连接。
处理器710可以采用通用的CPU(Central Processing Unit,中央处理器)、微处理器、应用专用集成电路(Application Specific Integrated Circuit,ASIC)、或者一个或多个集成电路等方式实现,用于执行相关程序,以实现本说明书实施例所提供的技术方案。
存储器720可以采用ROM(Read Only Memory,只读存储器)、RAM(Random Access  Memory,随机存取存储器)、静态存储设备,动态存储设备等形式实现。存储器720可以存储操作系统和其他应用程序,在通过软件或者固件来实现本说明书实施例所提供的技术方案时,相关的程序代码保存在存储器720中,并由处理器710来调用执行。
输入/输出接口730用于连接输入/输出模块,以实现信息输入及输出。输入输出/模块可以作为组件配置在设备中(图中未示出),也可以外接于设备以提供相应功能。其中输入设备可以包括键盘、鼠标、触摸屏、麦克风、各类传感器等,输出设备可以包括显示器、扬声器、振动器、指示灯等。
通信接口740用于连接通信模块(图中未示出),以实现本设备与其他设备的通信交互。其中通信模块可以通过有线方式(例如USB、网线等)实现通信,也可以通过无线方式(例如移动网络、WIFI、蓝牙等)实现通信。
总线750包括一通路,在设备的各个组件(例如处理器710、存储器720、输入/输出接口730和通信接口740)之间传输信息。
需要说明的是,尽管上述设备仅示出了处理器710、存储器720、输入/输出接口730、通信接口740以及总线750,但是在具体实施过程中,该设备还可以包括实现正常运行所必需的其他组件。此外,本领域的技术人员可以理解的是,上述设备中也可以仅包含实现本说明书实施例方案所必需的组件,而不必包含图中所示的全部组件。
本说明书实施例还提供一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现前述的第三方授权登录方法。该方法至少包括:
当第三方客户端监测到用户的二维码扫描操作触发时,识别被授权网站所展示的二维码,提示用户是否授权;
当第三方客户端监测到用户的授权确认操作触发时,向第三方服务端发送所识别的二维码信息,以使第三方服务端在接收到所述二维码信息之后,与被授权网站进行第三方授权认证。
本说明书实施例还提供一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现前述的第三方授权登录方法。该方法至少包括:
接收第三方客户端发送的二维码信息;
在接收到第三方客户端发送的二维码信息之后,与被授权网站进行第三方授权认证。
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。
通过以上的实施方式的描述可知,本领域的技术人员可以清楚地了解到本说明书实施例可借助软件加必需的通用硬件平台的方式来实现。基于这样的理解,本说明书实施例的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品可以存储在存储介质中,如ROM/RAM、磁碟、光盘等,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本说明书实施例各个实施例或者实施例的某些部分所述的方法。
上述实施例阐明的系统、装置、模块或单元,具体可以由计算机芯片或实体实现,或者由具有某种功能的产品来实现。一种典型的实现设备为计算机,计算机的具体形式可以是个人计算机、膝上型计算机、蜂窝电话、相机电话、智能电话、个人数字助理、媒体播放器、导航设备、电子邮件收发设备、游戏控制台、平板计算机、可穿戴设备或者这些设备中的任意几种设备的组合。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于装置实施例而言,由于其基本相似于方法实施例,所以描述得比较简单,相关之处参见方法实施例的部分说明即可。以上所描述的装置实施例仅仅是示意性的,其中所述作为分离部件说明的模块可以是或者也可以不是物理上分开的,在实施本说明书实施例方案时可以把各模块的功能在同一个或多个软件和/或硬件中实现。也可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。本领域普通技术人员在不付出创造性劳动的情况下,即可以理解并实施。
以上所述仅是本说明书实施例的具体实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本说明书实施例原理的前提下,还可以做出若干改进和润饰, 这些改进和润饰也应视为本说明书实施例的保护范围。

Claims (18)

  1. 一种第三方授权登录方法,该方法包括:
    当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;
    被授权网站向用户展示所述二维码;
    当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;
    当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;
    在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。
  2. 根据权利要求1所述的方法,所述当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码,包括:
    当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站将按照oAuth协议生成的URL生成与所述第三方账号对应的二维码。
  3. 根据权利要求1所述的方法,所述当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证,包括:
    当第三方客户端监测到用户的授权确认操作触发时,第三方客户端向第三方服务端发送所识别的二维码信息;
    在接收到所识别的二维码信息后,第三方服务端与被授权网站之间进行第三方授权认证。
  4. 根据权利要求3所述的方法,所述在接收到所识别的二维码信息后,第三方服务端与被授权网站之间进行第三方授权认证,包括:
    根据所识别的二维码上携带的回调地址信息,第三方服务端将生成的授权码发送至被授权网站,所述授权码用于对被授权网站进行授权验证;
    被授权网站接收所述授权码,并通过所述授权码向第三方服务端发送获取用户信息的请求;
    被授权网站接收第三方服务端返回的用户信息;
    所述在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功,包括:
    被授权网站在接收到第三方服务端返回的用户信息之后,被授权网站第三方授权登录成功。
  5. 根据权利要求4所述的方法,所述被授权网站接收所述授权码,并通过所述授权码向第三方服务端发送获取用户信息的请求,包括:
    被授权网站接收所述授权码,并通过所接收的授权码向第三方服务端发送获取授权令牌的请求,所述授权令牌作为获取用户信息的其中一种依据;
    被授权网站接收第三方服务端返回的授权令牌,并在接收到第三方服务端返回的授权令牌后,向第三方服务端发送获取用户唯一标识的请求;
    被授权网站接收第三方服务端返回的用户唯一标识;
    被授权网站通过授权令牌以及用户唯一标识向第三方服务端发送获取用户信息的请求。
  6. 根据权利要求1至5任一项所述的方法,所述方法还包括:
    在第三方服务端与被授权网站之间第三方授权认证通过之后,第三方服务端将授权成功的消息发送至第三方客户端;
    第三方客户端在接收到所述消息后,向用户展示授权成功。
  7. 一种第三方授权登录方法,应用于第三方客户端,该方法包括:
    当第三方客户端监测到用户的二维码扫描操作触发时,识别被授权网站所展示的二维码,提示用户是否授权;
    当第三方客户端监测到用户的授权确认操作触发时,向第三方服务端发送所识别的二维码信息,以使第三方服务端在接收到所述二维码信息之后,与被授权网站进行第三方授权认证。
  8. 一种第三方授权登录方法,应用于第三方服务端,该方法包括:
    接收第三方客户端发送的二维码信息;
    在接收到第三方客户端发送的二维码信息之后,与被授权网站进行第三方授权认证。
  9. 一种第三方授权登录系统,该系统包括:第三方客户端、第三方服务端及被授权网站;
    当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站生成与所述第三方账号对应的二维码;
    被授权网站向用户展示所述二维码;
    当第三方客户端监测到用户的二维码扫描操作触发时,第三方客户端识别所述二维码,提示用户是否授权;
    当第三方客户端监测到用户的授权确认操作触发时,第三方服务端与被授权网站之间进行第三方授权认证;
    在第三方服务端与被授权网站之间第三方授权认证通过之后,被授权网站第三方授权登录成功。
  10. 根据权利要求9所述的系统,所述被授权网站具体用于通过以下方式生成与所述第三方账号对应的二维码:
    当被授权网站监测到用户的第三方账号登录操作触发时,被授权网站将按照oAuth协议生成的URL生成与所述第三方账号对应的二维码。
  11. 根据权利要求9所述的系统,所述第三方服务端与被授权网站之间在以下情况进行第三方授权认证:
    当第三方客户端监测到用户的授权确认操作触发时,第三方客户端向第三方服务端发送所识别的二维码信息;
    在接收到所识别的二维码信息后,第三方服务端与被授权网站之间进行第三方授权认证。
  12. 根据权利要求11所述的系统,所述第三方服务端与被授权网站之间具体通过以下方式进行第三方授权认证:
    根据所识别的二维码上携带的回调地址信息,第三方服务端将生成的授权码发送至被授权网站,所述授权码用于对被授权网站进行授权验证;
    被授权网站接收所述授权码,并通过所述授权码向第三方服务端发送获取用户信息的请求;
    被授权网站接收第三方服务端返回的用户信息;
    所述被授权网站具体用于通过以下方式第三方授权登录成功:
    被授权网站在接收到第三方服务端返回的用户信息之后,被授权网站第三方授权登录成功。
  13. 根据权利要求12所述的系统,所述被授权网站具体用于通过以下方式发送获取用户信息的请求:
    被授权网站接收所述授权码,并通过所接收的授权码向第三方服务端发送获取授权令牌的请求,所述授权令牌作为获取用户信息的其中一种依据;
    被授权网站接收第三方服务端返回的授权令牌,并在接收到第三方服务端返回的授权令牌后,向第三方服务端发送获取用户唯一标识的请求;
    被授权网站接收第三方服务端返回的用户唯一标识;
    被授权网站通过授权令牌以及用户唯一标识向第三方服务端发送获取用户信息的请求。
  14. 根据权利要求9至13任一项所述的系统,所述第三方客户端具体用于通过以下方式展示授权成功:
    在第三方服务端与被授权网站之间第三方授权认证通过之后,第三方服务端将授权成功的消息发送至第三方客户端;
    第三方客户端在接收到所述消息后,向用户展示授权成功。
  15. 一种第三方授权登录装置,应用于第三方客户端,该装置包括:
    二维码识别模块,用于当第三方客户端监测到用户的二维码扫描操作触发时,识别被授权网站所展示的二维码,提示用户是否授权;
    信息发送模块,用于当第三方客户端监测到用户的授权确认操作触发时,向第三方服务端发送所识别的二维码信息,以使第三方服务端在接收到所述二维码信息之后,与被授权网站进行第三方授权认证。
  16. 一种第三方授权登录装置,应用于第三方服务端,该装置包括:
    信息接收模块,用于接收第三方客户端发送的二维码信息;
    认证模块,用于在接收到第三方客户端发送的二维码信息之后,与被授权网站进行第三方授权认证。
  17. 一种计算机设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,其中,所述处理器执行所述程序时实现如权利要求7所述的方法。
  18. 一种计算机设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,其中,所述处理器执行所述程序时实现如权利要求8所述的方法。
PCT/CN2019/076021 2018-05-16 2019-02-25 一种第三方授权登录方法及系统 WO2019218747A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201810465208.9A CN108632291A (zh) 2018-05-16 2018-05-16 一种第三方授权登录方法及系统
CN201810465208.9 2018-05-16

Publications (1)

Publication Number Publication Date
WO2019218747A1 true WO2019218747A1 (zh) 2019-11-21

Family

ID=63693599

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/076021 WO2019218747A1 (zh) 2018-05-16 2019-02-25 一种第三方授权登录方法及系统

Country Status (3)

Country Link
CN (1) CN108632291A (zh)
TW (1) TWI706265B (zh)
WO (1) WO2019218747A1 (zh)

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108632291A (zh) * 2018-05-16 2018-10-09 阿里巴巴集团控股有限公司 一种第三方授权登录方法及系统
CN109347855B (zh) * 2018-11-09 2020-06-05 南京医渡云医学技术有限公司 数据访问方法、装置、系统、电子设计及计算机可读介质
CN111182015A (zh) * 2018-11-12 2020-05-19 北京场景互娱传媒科技有限公司 用户信息的获取及统一方法、装置和电子设备
CN110336870B (zh) * 2019-06-27 2024-03-05 深圳前海微众银行股份有限公司 远程办公运维通道的建立方法、装置、系统及存储介质
CN112448917B (zh) * 2019-08-29 2023-08-04 北京京东尚科信息技术有限公司 网站登录方法、装置、可读介质及电子设备
CN110909330A (zh) * 2019-11-28 2020-03-24 安徽江淮汽车集团股份有限公司 车联网平台授权方法、装置、设备及存储介质
CN111193718A (zh) * 2019-12-13 2020-05-22 航天信息股份有限公司 一种基于第三方授权的安全登录方法及系统
CN111177690B (zh) * 2019-12-31 2022-07-05 中国工商银行股份有限公司 一种二维码扫码登录方法及装置
CN111654468A (zh) * 2020-04-29 2020-09-11 平安国际智慧城市科技股份有限公司 免密登录方法、装置、设备及存储介质
CN112738797B (zh) * 2020-12-24 2023-06-30 上海华申智能卡应用系统有限公司 基于蓝牙的web应用认证登录方法及系统
CN113347197B (zh) * 2021-06-22 2022-07-15 重庆广播电视大学重庆工商职业学院 一种基于微信平台的web应用扫码授权登录方法
CN113794678A (zh) * 2021-07-29 2021-12-14 深圳思为科技有限公司 一种兼容多种登录方式的方法、装置及计算机储存介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120240204A1 (en) * 2011-03-11 2012-09-20 Piyush Bhatnagar System, design and process for strong authentication using bidirectional OTP and out-of-band multichannel authentication
CN103067381A (zh) * 2012-12-26 2013-04-24 百度在线网络技术(北京)有限公司 使用平台方账号登录第三方服务的方法、系统和装置
CN103986720A (zh) * 2014-05-26 2014-08-13 网之易信息技术(北京)有限公司 一种登录方法及装置
CN107835160A (zh) * 2017-10-20 2018-03-23 浙江工商大学 基于二维码的第三方用户认证方法
CN108632291A (zh) * 2018-05-16 2018-10-09 阿里巴巴集团控股有限公司 一种第三方授权登录方法及系统

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102821104B (zh) * 2012-08-09 2014-04-16 腾讯科技(深圳)有限公司 授权的方法、装置和系统
US9479499B2 (en) * 2013-03-21 2016-10-25 Tencent Technology (Shenzhen) Company Limited Method and apparatus for identity authentication via mobile capturing code
CN104348777B (zh) * 2013-07-24 2019-04-09 腾讯科技(深圳)有限公司 一种移动终端对第三方服务器的访问控制方法及系统
CN106559384A (zh) * 2015-09-25 2017-04-05 阿里巴巴集团控股有限公司 一种利用公众号实现登录的方法及装置
CN106961415B (zh) * 2016-01-11 2020-05-08 广州市动景计算机科技有限公司 登录方法、设备、浏览器、客户端和服务器

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120240204A1 (en) * 2011-03-11 2012-09-20 Piyush Bhatnagar System, design and process for strong authentication using bidirectional OTP and out-of-band multichannel authentication
CN103067381A (zh) * 2012-12-26 2013-04-24 百度在线网络技术(北京)有限公司 使用平台方账号登录第三方服务的方法、系统和装置
CN103986720A (zh) * 2014-05-26 2014-08-13 网之易信息技术(北京)有限公司 一种登录方法及装置
CN107835160A (zh) * 2017-10-20 2018-03-23 浙江工商大学 基于二维码的第三方用户认证方法
CN108632291A (zh) * 2018-05-16 2018-10-09 阿里巴巴集团控股有限公司 一种第三方授权登录方法及系统

Also Published As

Publication number Publication date
TW201947438A (zh) 2019-12-16
CN108632291A (zh) 2018-10-09
TWI706265B (zh) 2020-10-01

Similar Documents

Publication Publication Date Title
WO2019218747A1 (zh) 一种第三方授权登录方法及系统
US20220239637A1 (en) Secure authentication for accessing remote resources
US10708053B2 (en) Coordinating access authorization across multiple systems at different mutual trust levels
US10541992B2 (en) Two-token based authenticated session management
TWI725958B (zh) 雲端主機服務權限控制方法、裝置和系統
US10462124B2 (en) Authenticated session management across multiple electronic devices using a virtual session manager
US9787664B1 (en) Methods systems and articles of manufacture for implementing user access to remote resources
KR101929598B1 (ko) 운영체제 및 애플리케이션 사이에서 사용자 id의 공유 기법
US10136315B2 (en) Password-less authentication system, method and device
US20190124076A1 (en) Method and system for verifying an account operation
TWI637286B (zh) 隨選密碼方法及其系統
CN112136303B (zh) 用于耗时操作的刷新令牌的安全委托
JP5429912B2 (ja) 認証システム、認証サーバ、サービス提供サーバ、認証方法、及びプログラム
EP3723341A1 (en) Single sign-on for unmanaged mobile devices
CN105991614B (zh) 一种开放授权、资源访问的方法及装置、服务器
CN110278179B (zh) 单点登录方法、装置和系统以及电子设备
US11658963B2 (en) Cooperative communication validation
JP2009032070A (ja) 認証システム及び認証方法
EP3272093B1 (en) Method and system for anti-phishing using smart images
US11611551B2 (en) Authenticate a first device based on a push message to a second device
CN106254319B (zh) 一种轻应用登录控制方法和装置
Ferry et al. Security evaluation of the OAuth 2.0 framework
US11165768B2 (en) Technique for connecting to a service
US20150180851A1 (en) Method, device, and system for registering terminal application
CN108809969B (zh) 一种认证方法、系统及其装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19803019

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19803019

Country of ref document: EP

Kind code of ref document: A1