[go: up one dir, main page]

CN102420808B - Method for realizing single signon on telecom on-line business hall - Google Patents

Method for realizing single signon on telecom on-line business hall Download PDF

Info

Publication number
CN102420808B
CN102420808B CN201110183099.XA CN201110183099A CN102420808B CN 102420808 B CN102420808 B CN 102420808B CN 201110183099 A CN201110183099 A CN 201110183099A CN 102420808 B CN102420808 B CN 102420808B
Authority
CN
China
Prior art keywords
uam
information
user
business hall
online business
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN201110183099.XA
Other languages
Chinese (zh)
Other versions
CN102420808A (en
Inventor
许锐豪
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Whale Cloud Technology Co Ltd
Original Assignee
ZTEsoft Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTEsoft Technology Co Ltd filed Critical ZTEsoft Technology Co Ltd
Priority to CN201110183099.XA priority Critical patent/CN102420808B/en
Publication of CN102420808A publication Critical patent/CN102420808A/en
Application granted granted Critical
Publication of CN102420808B publication Critical patent/CN102420808B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

The invention relates to a method for realizing single signon on a telecom on-line business hall. The method comprises the following steps of: building a UAM (Unified Authentication Module) on a telecom server, and configuring an interface module from the telecom on-line business hall to each service subsystem; and realizing the centralized authentication of telecom three-user data, namely client data, account data and user data, and the single signon of the telecom on-line business hall. By utilizing the method for realizing the single signon on the telecom on-line business hall, the centralized management is realized by aiming at the telecom three-user data, thus an IT (Information Technology) structure of a telecom interior is improved. Simultaneously, the single signon is realized when a telecom user deals service on the on-line business hall by use of multiple service systems, repeated login is avoided in the process of using and switching the multiple service systems, and the user experience is improved.

Description

A kind of method that realizes single-sign-on at Internet BOSS
Technical field
The present invention relates to telecom business support system, especially can realize the synchronous method of data of Collective qualification, single-sign-on, telecom client information, accounts information and the user profile of each support system operation system, specifically a kind of method that realizes single-sign-on at Internet BOSS.
Background technology
At present, there is the authentication system of various ways in the channel contact systems such as the current online business hall of China Telecom, business hall, No. 10000, self-aided terminal, there is the certification based on CRM customer ID and client password, based on the certification of product identification and product cipher, the certification based on account etc.; Also develop the on this basis form of authentication that makes new advances of some province: as the certification of the certification of product identification and client password, Customer ID and two-stage client password etc.This makes existing authentication mode complexity various.Within verify data is distributed in the core support system in MBOSS territory mostly, objectively make the support system such as CRM, charging account except finishing service operation support function, also need to provide for channel contact system the authentication service of the entities such as client, account, product, thereby increase the weight of the burden of core support system.
Meanwhile, the enterprise transformation of China Telecom has also driven the fast development of value-added service, needs the service resources of integrating value-added service by portal website badly, uses channel for telecom client provides centralized and unified business to present with business.The online business hall of China Telecom is as the important channel of telecom client contact, in the urgent need to further promoting its status as portal website, drive business integration with door construction, progressively develop into the client comprehensive service door that integrates customer service, service propaganda, product use.
In addition, along with the development of value-added telecom services and increasing of business platform, user is except the customer service class account number of memory channel contact system, also need to remember multiple value increasing service product and use account number, before a business platform of each login, all need to provide corresponding authentication information, the use impression that this brings user's inconvenience, is also unfavorable for the bundle sale of telecommunications popularization multiple business simultaneously.
Therefore need to set up the unified certification center (hereinafter to be referred as " unification authentication platform ") for MBOSS external client, integrate on the one hand existing various authentication system, the certification of the core support systems such as shielding CRM, unifying provides authentication service for channel contact system.On the other hand when user from network the channel contact system such as business hall concentrate while using each value-added service, unified certification and the single-sign-on of trans-sectoral business and platform are provided, thereby reach the lifting that user experiences.
Summary of the invention
The object of the invention is for the login process of existing Internet BOSS complicated, telecommunication user need to be remembered registration account number and the password of multiple operation systems, and in Internet BOSS is routed to the process of each operation system, needs repeatedly to carry out the problems such as login authentication provide a kind of Technical Architecture based on Web and Digital Certificate Security processing that possesses the features such as rational in infrastructure, excellent extensibility, fail safe.
Technical scheme of the present invention is:
A kind of method that realizes single-sign-on at Internet BOSS:
A, on telecommunication server, set up unified single sign-on system UAM, configuration Internet BOSS is to the interface module between each service sub-system;
B, be customer information, accounts information, user profile by three family information of telecommunications, be unified in UAM and store, UAM provides the sync cap of three user data to each service sub-system of telecommunications; Telecommunications three family information are carried out Collective qualification, and UAM provides unified Collective qualification interface to service sub-system;
The digital certificate of authentication between data certificate, configuration UAM and each service sub-system between C, configuration UAM SIM and Internet BOSS.
In A of the present invention, configuration Internet BOSS comprises the following steps to the interface module between each service sub-system:
(1) configuration UAM essential information, comprises service sub-system plateau coding, platform access address, platform login state, platform access state information;
(2) configuration UAM business platform information, comprises service sub-system coding, business platform title, the local address of releasing of business platform;
(3) configuration UAM parameter information, comprises UAM address, Online Business System coding, the effective duration of authentication assertion, the UAM of group interface IP address.
In C of the present invention, the digital certificate of configuration authentication comprises the following steps:
(1) generate UAM digital certificate and dispose, deployment be by digital integer copying and saving to the application server of UAM;
(2) generate the data certificate between UAM SIM and Internet BOSS and offer online business hall;
(3) generate the digital certificate of authentication between UAM and each service sub-system and offer each operation system;
Following steps of the present invention:
(1) user accesses Internet BOSS limited resources;
(2) online business hall checks that in telecommunication server, whether having the local T oken corresponding with subscription client is the authentication information that user accesses corresponding service subsystem, if existed, and the success of registering service subsystem; Otherwise, go to step 3;
(3) unification authentication platform UA is asked to user again in online business hall;
(4) UA check whether exist in telecommunication server the overall Token corresponding with subscription client be user in online business hall or any one operation system realized the authentication information of logining the authentication information generating;
If overall Token does not exist, UA provides certification login page to user, and prompting user inputs the arbitrary authentication information in three family information, and UA authenticates user, and certification, by generating overall Token, goes to step 5; If authentification failure, ejects login error message by UA;
If overall Token exists, go to step 5;
(5) UA generates this authenticated user at the Ticket of online business hall and asserts information; The information of asserting refers to the descriptor that this authenticate-acknowledge is legal, and Ticket is this index of asserting;
(6) user browser is redirected to online business hall by UA, simultaneously the Ticket of subsidiary this certification;
(7) online business hall inquires about to UA the information of asserting that this Ticket is corresponding according to the Ticket passing back;
(8) information of asserting corresponding this Ticket is returned to online business hall by UA, and destroy this Ticket;
(9) online business hall generates local T oken, and mark user logins identity, logins successfully;
(10) online business hall shows and logins successfully the page to user browser.
Because overall Token exists, can authenticate by UAM, UAM will generate a legal authentication information to online business hall or operation system, and this legal authentication information is called asserts, and each has asserted an index ID, and this index ID is called Ticket.
Beneficial effect of the present invention:
1, promote client's experience: after client logins in same channel platform, between business platform, realize once certification, full-service access.
2, promote account number operation customer-centric: along with the fast development of value-added telecom services, account number operation customer-centric becomes development trend, need to integrate multiple account number system; Equally also need to promote the door status of customer-oriented online business hall, drive the integration of service resources, realize unified certification and the single-sign-on of cross-system and platform, meet the coherence request of the integrated and customer experience of service interface.
3, optimize IT architecture: the certification pressure that has alleviated on the one hand core support system (as CRM, charging account etc.); Build on the other hand unified certification, centralized management, data sharing, authentication system safely and efficiently, for the access of other business platform reduces costs.
Brief description of the drawings
Fig. 1 is UAM(unified certification) be related to schematic diagram between system and support system and Internet BOSS, each operation system.
Fig. 2 is UAM(unified certification) realize the schematic diagram of single-sign-on.
Fig. 3 is UAM(unified certification) realize the sequence chart of federal style single-sign-on.
Embodiment
Below in conjunction with drawings and Examples, the present invention is further illustrated.
As shown in Figure 1, a kind of method that realizes single-sign-on at Internet BOSS, it comprises the following steps:
Three family information of A, telecommunications are customer information, accounts information, user profile, are unified in UAM and store, and UAM provides the sync cap of three user data;
B, telecommunications three family information are carried out Collective qualification, and UAM provides unified Collective qualification interface;
C, user, after Internet BOSS is once logined, use the service sub-system above business hall, do not need again to authenticate, and realize single-sign-on by UAM;
D, federal style single-sign-on pattern, the business platform of online business hall, UAM, business domains forms star-like identity federation;
E, single-sign-on process are made the sensitive data bag relating to, and carry out digital signature by digital certificate, ensure integrality and the fail safe of data.
As shown in Figure 2,3, the net Room belongs to gate system, and ChinaVnet belongs to the service sub-system being linked in door.
UAM of the present invention is positioned at the star-like center of federal certification, be responsible for client identity to authenticate, the net Room and business platform, all trust the authentication result of unification authentication platform: client has been responsible for login authentication by UAM in the time that the net Room is logined, and identifies client identity and relations between ownership and management of enterprises corresponding to this client; When client clicks on the net Room when this business platform of business platform links and accesses, UAM identifies its corresponding business platform account number according to client's relations between ownership and management of enterprises, and illustrates that account number logined and have access legitimacy; The authentication result that business platform sends UAM represents to trust, and allows user no longer to input account number cipher and directly accesses.
Performing step of the present invention comprises:
A, configure online business hall to the interface module between each operation system, treatment step:
1) configuration UAM essential information, comprises plateau coding, platform access address, platform login state, the information such as platform access state;
2) configuration UAM business platform information, comprises business platform coding, business platform title, the local address of releasing of business platform;
3) configuration UAM parameter information, comprises UAM address, Online Business System coding, the effective duration of authentication assertion, the UAM of group interface IP address etc.;
Digital certificate between data certificate, configuration UAM and individual operation system between B, configuration UAM and online business hall, implementation step comprises:
1) generate UAM digital certificate and dispose;
2) generate online business hall digital certificate and offer online business hall;
3) generate operation system digital certificate and offer each operation system;
C, realize the treatment step of Internet BOSS single-sign-on to operation system:
1) user accesses online business hall limited resources;
2) online business hall checks whether local Token exists, if existed, directly arrives step 13;
3) if there is no, be redirected user and ask UA;
4) UA checks whether overall Token exists;
5) overall Token does not exist, and UA provides certification login page to user, and prompting user inputs the authentication informations such as account number type, account number, password type, password;
If overall Token exists, directly continue from the 8th step;
6) user inputs login authentication information, submits to UA;
7) UA authenticates user, and certification is by generating overall Token.If authentification failure, ejects login error message by UA;
8) UA generates this authenticated user at the Ticket in the net Room and asserts information;
9) user browser is redirected to online business hall by UA, simultaneously the Ticket of subsidiary this certification;
10) online business hall inquires about to UA the information of asserting that this Ticket is corresponding according to the Ticket passing back;
11) information of asserting corresponding this Ticket is returned to online business hall by UA, and destroy this Ticket;
12) online business hall generates local T oken, and mark user logins identity, logins successfully;
13) online business hall shows and logins successfully the page to user browser.
The part that the present invention does not relate to all prior art that maybe can adopt same as the prior art is realized.

Claims (3)

1. a method that realizes single-sign-on at Internet BOSS, is characterized in that:
A, on telecommunication server, set up unified single sign-on system UAM, configuration Internet BOSS is to the interface module between each service sub-system;
B, be customer information, accounts information, user profile by three family information of telecommunications, be unified in UAM and store, UAM provides the sync cap of three user data to each service sub-system of telecommunications; Telecommunications three family information are carried out Collective qualification, and UAM provides unified Collective qualification interface to each operation system;
The digital certificate of authentication between digital certificate, configuration UAM and each service sub-system between C, configuration UAM SIM and Internet BOSS;
It comprises the following steps:
(1) user accesses Internet BOSS limited resources;
(2) online business hall checks that in telecommunication server, whether having the local T oken corresponding with subscription client is the authentication information that user accesses corresponding service subsystem, if existed, and the success of registering service subsystem; Otherwise, go to step (3);
(3) unification authentication platform UA is asked to user again in online business hall;
(4) UA check whether exist in telecommunication server the overall Token corresponding with subscription client be user in online business hall or any one operation system realized and logined the authentication information generating;
If overall Token does not exist, UA provides certification login page to user, and prompting user inputs the arbitrary authentication information in three family information, and UA authenticates user, and certification, by generating overall Token, goes to step (5); If authentification failure, ejects login error message by UA;
If overall Token exists, go to step (5);
(5) UA generates this authenticated user at the Ticket of online business hall and asserts information;
(6) user browser is redirected to online business hall by UA, simultaneously the Ticket of subsidiary this certification;
(7) online business hall inquires about to UA the information of asserting that this Ticket is corresponding according to the Ticket passing back;
(8) information of asserting corresponding this Ticket is returned to online business hall by UA, and destroy this Ticket;
(9) online business hall generates local T oken, and mark user logins identity, logins successfully;
(10) online business hall shows and logins successfully the page to user browser;
Because overall Token exists, can authenticate by UAM, UAM will generate a legal authentication information to online business hall or operation system, and this legal authentication information is called asserts, and each has asserted an index ID, and this index ID is called Ticket.
2. a kind of method that realizes single-sign-on at Internet BOSS according to claim 1, is characterized in that in A, and configuration Internet BOSS comprises the following steps to the interface module between each service sub-system:
(1) configuration UAM essential information, comprises operation system coding, platform access address, platform login state, platform access state information;
(2) configuration UAM business platform information, comprises operation system coding, operation system title, and address is exited in operation system part;
(3) configuration UAM parameter information, comprises UAM address, Online Business System coding, the effective duration of authentication assertion, the UAM of group interface IP address.
3. a kind of method that realizes single-sign-on at Internet BOSS according to claim 1, is characterized in that in C, and the digital certificate of configuration authentication comprises the following steps:
(1) generate UAM digital certificate and dispose, deployment be by digital certificate copying and saving to the application server of UAM;
(2) generate the digital certificate between UAM SIM and Internet BOSS and offer online business hall;
(3) generate the digital certificate of authentication between UAM and each service sub-system and offer each operation system.
CN201110183099.XA 2011-06-30 2011-06-30 Method for realizing single signon on telecom on-line business hall Expired - Fee Related CN102420808B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110183099.XA CN102420808B (en) 2011-06-30 2011-06-30 Method for realizing single signon on telecom on-line business hall

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110183099.XA CN102420808B (en) 2011-06-30 2011-06-30 Method for realizing single signon on telecom on-line business hall

Publications (2)

Publication Number Publication Date
CN102420808A CN102420808A (en) 2012-04-18
CN102420808B true CN102420808B (en) 2014-07-23

Family

ID=45945043

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110183099.XA Expired - Fee Related CN102420808B (en) 2011-06-30 2011-06-30 Method for realizing single signon on telecom on-line business hall

Country Status (1)

Country Link
CN (1) CN102420808B (en)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104468749A (en) * 2014-11-23 2015-03-25 国云科技股份有限公司 A Method of Realizing the Single Sign-on of DotNET Client and CAS Integration
CN104639548B (en) * 2015-02-03 2018-09-18 北京羽乐创新科技有限公司 A kind of method and apparatus logging in application
SG10201606061PA (en) 2016-07-22 2018-02-27 Huawei Int Pte Ltd A method for unified network and service authentication based on id-based cryptography
CN108040090A (en) * 2017-11-27 2018-05-15 上海上实龙创智慧能源科技股份有限公司 A kind of system combination method of more Web
CN108989276B (en) * 2018-03-27 2021-09-28 深圳市小赢信息技术有限责任公司 Inter-system secure pseudo login method
CN110535652A (en) * 2019-07-01 2019-12-03 广州昆仑科技有限公司 A kind of system and method by each operation system data integration displaying and unified login

Citations (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1738241A (en) * 2005-04-28 2006-02-22 上海交通大学 Security Control Method Based on Identity Authentication of Remote Distributed Components
CN1750568A (en) * 2005-09-09 2006-03-22 中国移动通信集团公司 Data service control system, control network, and service control method
CN1937662A (en) * 2005-09-21 2007-03-28 中兴通讯股份有限公司 A method for unified authentication of users in telecommunication voice value-added services
CN101018259A (en) * 2006-02-08 2007-08-15 中国电信股份有限公司 Telecom integrated information system and method
CN101064717A (en) * 2006-04-26 2007-10-31 北京华科广通信息技术有限公司 Safety protection system of information system or equipment and its working method
CN101106466A (en) * 2006-07-11 2008-01-16 华为技术有限公司 Content business support system and method for realizing user single-point authentication interoperable access
CN101110984A (en) * 2007-08-07 2008-01-23 华为技术有限公司 A method and system for providing mobile data service
CN101227470A (en) * 2008-01-30 2008-07-23 中兴通讯股份有限公司 A business management system and business management method
CN101262590A (en) * 2007-12-21 2008-09-10 深圳市同洲电子股份有限公司 Multi-service integration system, device and method
CN101364289A (en) * 2008-09-24 2009-02-11 中国移动通信集团福建有限公司 Enterprise common process platform
CN101441734A (en) * 2007-11-19 2009-05-27 上海久隆电力科技有限公司 Unite identification authentication system
CN101599144A (en) * 2009-03-19 2009-12-09 杭州思锐网络有限公司 Network type civil affairs multi-department information integrated assistance platform
CN101742505A (en) * 2009-11-24 2010-06-16 广东宇天信通通信科技有限公司 System and method for providing integration of multiple data services
CN102082992A (en) * 2009-11-30 2011-06-01 中国移动通信集团山西有限公司 Mobile office system and implementation method thereof

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6954799B2 (en) * 2000-02-01 2005-10-11 Charles Schwab & Co., Inc. Method and apparatus for integrating distributed shared services system
US7530099B2 (en) * 2001-09-27 2009-05-05 International Business Machines Corporation Method and system for a single-sign-on mechanism within application service provider (ASP) aggregation
US20040123144A1 (en) * 2002-12-19 2004-06-24 International Business Machines Corporation Method and system for authentication using forms-based single-sign-on operations

Patent Citations (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1738241A (en) * 2005-04-28 2006-02-22 上海交通大学 Security Control Method Based on Identity Authentication of Remote Distributed Components
CN1750568A (en) * 2005-09-09 2006-03-22 中国移动通信集团公司 Data service control system, control network, and service control method
CN1937662A (en) * 2005-09-21 2007-03-28 中兴通讯股份有限公司 A method for unified authentication of users in telecommunication voice value-added services
CN101018259A (en) * 2006-02-08 2007-08-15 中国电信股份有限公司 Telecom integrated information system and method
CN101064717A (en) * 2006-04-26 2007-10-31 北京华科广通信息技术有限公司 Safety protection system of information system or equipment and its working method
CN101106466A (en) * 2006-07-11 2008-01-16 华为技术有限公司 Content business support system and method for realizing user single-point authentication interoperable access
CN101110984A (en) * 2007-08-07 2008-01-23 华为技术有限公司 A method and system for providing mobile data service
CN101441734A (en) * 2007-11-19 2009-05-27 上海久隆电力科技有限公司 Unite identification authentication system
CN101262590A (en) * 2007-12-21 2008-09-10 深圳市同洲电子股份有限公司 Multi-service integration system, device and method
CN101227470A (en) * 2008-01-30 2008-07-23 中兴通讯股份有限公司 A business management system and business management method
CN101364289A (en) * 2008-09-24 2009-02-11 中国移动通信集团福建有限公司 Enterprise common process platform
CN101599144A (en) * 2009-03-19 2009-12-09 杭州思锐网络有限公司 Network type civil affairs multi-department information integrated assistance platform
CN101742505A (en) * 2009-11-24 2010-06-16 广东宇天信通通信科技有限公司 System and method for providing integration of multiple data services
CN102082992A (en) * 2009-11-30 2011-06-01 中国移动通信集团山西有限公司 Mobile office system and implementation method thereof

Also Published As

Publication number Publication date
CN102420808A (en) 2012-04-18

Similar Documents

Publication Publication Date Title
EP2898441B1 (en) Mobile multifactor single-sign-on authentication
CN103282909B (en) Authentication Federation System and ID Provider Device
US9038138B2 (en) Device token protocol for authorization and persistent authentication shared across applications
CN105357242B (en) Access the method and system of WLAN, short message pushes platform, gate system
US20090205032A1 (en) Identification and access control of users in a disconnected mode environment
CN109413032A (en) A kind of single-point logging method, computer readable storage medium and gateway
US20150149530A1 (en) Redirecting Access Requests to an Authorized Server System for a Cloud Service
CN107508837A (en) A kind of cross-platform heterogeneous system login method based on intelligent code key certification
CN102420808B (en) Method for realizing single signon on telecom on-line business hall
CN101645775A (en) Over-the-air download-based dynamic password identity authentication system
CN109165500A (en) A kind of single sign-on authentication system and method based on cross-domain technology
CN106534219A (en) Security authentication method and device for desktop cloud portal
CN103209168A (en) Method and system for achieving single sign-on
CN103986734B (en) Authentication management method and authentication management system applicable to high-security service system
CN107770192A (en) Identity authentication method and computer-readable recording medium in multisystem
CN103139181A (en) Authorization method, authorization device and authorization system of open type authentication
US10601809B2 (en) System and method for providing a certificate by way of a browser extension
US20250112961A1 (en) Techniques for generating policy recommendations and insights using generative ai
CN110247758A (en) The method, apparatus and code management device of Password Management
CN105354482A (en) Single sign-on method and device
CN108243164B (en) Cross-domain access control method and system for E-government cloud computing
EP2207303B1 (en) Method, system and entity for bill authentication in network serving
CN102255904A (en) Communication network and terminal authentication method thereof
CN103428161A (en) Phone authentication service system
US12182251B2 (en) Web-based authentication for desktop applications

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
C56 Change in the name or address of the patentee
CP01 Change in the name or title of a patent holder

Address after: Yuhuatai District of Nanjing City, Jiangsu province 210012 Bauhinia Road No. 68

Patentee after: ZTESOFT TECHNOLOGY Co.,Ltd.

Address before: Yuhuatai District of Nanjing City, Jiangsu province 210012 Bauhinia Road No. 68

Patentee before: NANJING ZTESOFT TECHNOLOGY Co.,Ltd.

CP03 Change of name, title or address

Address after: 210012 room 627, Ning Shuang Road, Yuhuatai District, Nanjing, Jiangsu, 627

Patentee after: WHALE CLOUD TECHNOLOGY Co.,Ltd.

Address before: 210012 No. 68 Bauhinia Road, Yuhuatai District, Jiangsu, Nanjing

Patentee before: ZTESOFT TECHNOLOGY Co.,Ltd.

CP03 Change of name, title or address
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20140723

CF01 Termination of patent right due to non-payment of annual fee