CN104301285B - Login method for web system - Google Patents
Login method for web system Download PDFInfo
- Publication number
- CN104301285B CN104301285B CN201310295288.5A CN201310295288A CN104301285B CN 104301285 B CN104301285 B CN 104301285B CN 201310295288 A CN201310295288 A CN 201310295288A CN 104301285 B CN104301285 B CN 104301285B
- Authority
- CN
- China
- Prior art keywords
- login
- user
- url
- server
- current system
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/04—Real-time or near real-time messaging, e.g. instant messaging [IM]
- H04L51/046—Interoperability with other network applications or services
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/08—Protocols specially adapted for terminal emulation, e.g. Telnet
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Information Transfer Between Computers (AREA)
Abstract
本发明提出了用于web系统的登录方法。其中,所述方法包括:用户终端基于来自用户的登录信息构造登录启动报文,并将所述登录启动报文传送到登录服务器;所述登录服务器基于接收到的所述登录请求并经由邮件服务器和邮件客户端完成后续的登录过程。本发明所公开的用于web系统的登录方法具有高的安全性和操作简便性。
The invention proposes a login method for a web system. Wherein, the method includes: the user terminal constructs a login initiation message based on the login information from the user, and transmits the login initiation message to the login server; and mail client to complete the subsequent login process. The login method for the web system disclosed by the invention has high security and easy operation.
Description
技术领域technical field
本发明涉及登录方法,更具体地,涉及用于web系统的登录方法。The present invention relates to a login method, and more particularly, to a login method for a web system.
背景技术Background technique
目前,随着网络应用的日益广泛以及不同领域的业务种类的日益丰富,用户执行针对web系统的登录操作变得越来越重要和频繁。At present, with the increasingly wide application of the network and the increasing variety of business types in different fields, it becomes more and more important and frequent for the user to perform a login operation for the web system.
在现有的技术方案中,用户通常在注册以后通过用户名和密码的方式进行登录。In the existing technical solution, the user usually logs in by means of a user name and a password after registration.
然而,现有的技术方案存在如下问题:由于用户在执行注册操作时需要填写各种个人信息,例如需要输入用于激活帐户的邮箱号以及用于获取验证码的手机号等等,故操作繁琐且个人信息易于被非法使用,此外,由于需要频繁地输入用户名和密码,故安全性较低。However, the existing technical solutions have the following problems: Since the user needs to fill in various personal information when performing the registration operation, for example, the mailbox number used to activate the account and the mobile phone number used to obtain the verification code need to be entered, etc., so the operation is cumbersome Moreover, personal information is easy to be used illegally. In addition, since user names and passwords need to be frequently input, the security is low.
因此,存在如下需求:提供具有高的安全性和操作简便性的用于web系统的登录方法。Therefore, there is a need to provide a login method for a web system with high security and ease of operation.
发明内容Contents of the invention
为了解决上述现有技术方案所存在的问题,本发明提出了具有高的安全性和操作简便性的用于web系统的登录方法。In order to solve the problems in the above prior art solutions, the present invention proposes a login method for web systems with high security and easy operation.
本发明的目的是通过以下技术方案实现的:The purpose of the present invention is achieved through the following technical solutions:
一种用于web系统的登录方法,所述方法包括下列步骤:A login method for a web system, said method comprising the following steps:
(A1)用户终端基于来自用户的登录信息构造登录启动报文,并将所述登录启动报文传送到登录服务器;(A1) The user terminal constructs a login initiation message based on the login information from the user, and transmits the login initiation message to the login server;
(A2)所述登录服务器基于接收到的所述登录请求并经由邮件服务器和邮件客户端完成后续的登录过程。(A2) The login server completes a subsequent login process via the mail server and the mail client based on the received login request.
在上面所公开的方案中,优选地,所述步骤(A1)进一步包括:In the solution disclosed above, preferably, the step (A1) further includes:
(1)所述用户终端基于用户指令并通过web浏览器访问所述web系统的登录页面;(1) The user terminal accesses the login page of the web system through a web browser based on user instructions;
(2)用户通过所述登录页面输入所述登录信息,其中,所述登录信息包括所述用户的有效邮箱的帐号;(2) The user enters the login information through the login page, wherein the login information includes the account number of the user's valid mailbox;
(3)所述用户终端基于用户指令构造所述登录启动报文并将所述登录启动报文传送到所述登录服务器,其中,所述登录启动报文包括所述登录信息。(3) The user terminal constructs the login initiation message based on a user instruction and transmits the login initiation message to the login server, where the login initiation message includes the login information.
在上面所公开的方案中,优选地,所述步骤(A2)进一步包括下列步骤:In the solution disclosed above, preferably, the step (A2) further includes the following steps:
(B1)在接收到所述登录启动报文后,所述登录服务器校验所述登录启动报文所包含的登录信息的有效性;(B1) After receiving the login initiation message, the login server verifies the validity of the login information included in the login initiation message;
(B2)如果所述登录信息的有效性验证成功,则动态地生成针对所述用户的登录URL并将所述登录URL以加密的方式传送到所述邮件服务器,其中,所述登录URL包含至少一个参数,并且所述至少一个参数包括当前系统时间;(B2) If the verification of the validity of the login information is successful, dynamically generate a login URL for the user and transmit the login URL to the mail server in an encrypted manner, wherein the login URL contains at least one parameter, and the at least one parameter includes the current system time;
(B3)用户通过所述邮件客户端登录位于所述邮件服务器中的所述有效邮箱以查看所述登录URL。(B3) The user logs in the valid mailbox located in the mail server through the mail client to view the login URL.
在上面所公开的方案中,优选地,所述步骤(A2)进一步包括:在用户经由所述邮件客户端查看到所述登录URL后,所述邮件客户端基于用户指令构造登录请求,并将所述登录请求传送到所述登录服务器,其中,所述登录请求包括所述登录URL。In the solution disclosed above, preferably, the step (A2) further includes: after the user views the login URL via the email client, the email client constructs a login request based on the user instruction, and sends The login request is transmitted to the login server, wherein the login request includes the login URL.
在上面所公开的方案中,优选地,所述步骤(A2)进一步包括:在接收到所述登录请求后,所述登录服务器提取所述登录请求中的登录URL的所述至少一个参数以得到生成所述登录URL时的当前系统时间并随后将当前系统时间与生成所述登录URL时的当前系统时间相比较,如果当前系统时间与生成所述登录URL时的当前系统时间之间的时间差小于或等于预定值,则直接跳转到所述web系统的主页面并提示登录成功,如果当前系统时间与生成所述登录URL时的当前系统时间之间的时间差大于所述预定值,则返回登录页面并提示用户重新获取登录URL。In the solution disclosed above, preferably, the step (A2) further includes: after receiving the login request, the login server extracts the at least one parameter of the login URL in the login request to obtain the current system time when the login URL was generated and then comparing the current system time with the current system time when the login URL was generated, if the time difference between the current system time and the current system time when the login URL was generated is less than or is equal to the predetermined value, then jump directly to the main page of the web system and prompt that the login is successful, if the time difference between the current system time and the current system time when the login URL is generated is greater than the predetermined value, then return to login page and prompt the user to retrieve the login URL again.
在上面所公开的方案中,优选地,所述邮件客户端以基于证书的加密方式与所述登录服务器进行数据通信。In the solution disclosed above, preferably, the mail client performs data communication with the login server in a certificate-based encryption manner.
在上面所公开的方案中,优选地,所述web浏览器和所述邮件客户端位于同一用户终端中。In the solutions disclosed above, preferably, the web browser and the mail client are located in the same user terminal.
本发明所公开的用于web系统的登录方法具有以下优点:具有高的安全性并且操作简便。The login method for the web system disclosed by the invention has the following advantages: high security and easy operation.
附图说明Description of drawings
结合附图,本发明的技术特征以及优点将会被本领域技术人员更好地理解,其中:With reference to the accompanying drawings, the technical features and advantages of the present invention will be better understood by those skilled in the art, wherein:
图1是根据本发明的实施例的用于web系统的登录方法的流程图。Fig. 1 is a flowchart of a login method for a web system according to an embodiment of the present invention.
具体实施方式Detailed ways
图1是根据本发明的实施例的用于web系统的登录方法的流程图。如图1所示,本发明所公开的用于web系统的登录方法包括下列步骤:(A1)用户终端基于来自用户的登录信息构造登录启动报文,并将所述登录启动报文传送到登录服务器;(A2)所述登录服务器基于接收到的所述登录请求并经由邮件服务器和邮件客户端完成后续的登录过程。Fig. 1 is a flowchart of a login method for a web system according to an embodiment of the present invention. As shown in Figure 1, the login method for the web system disclosed by the present invention includes the following steps: (A1) The user terminal constructs a login initiation message based on the login information from the user, and transmits the login initiation message to the login Server; (A2) The login server completes the subsequent login process based on the received login request via the mail server and the mail client.
优选地,在本发明所公开的用于web系统的登录方法中,所述步骤(A1)进一步包括:(1)所述用户终端基于用户指令并通过web浏览器访问所述web系统的登录页面;(2)用户通过所述登录页面输入所述登录信息,其中,所述登录信息包括所述用户的有效邮箱的帐号(即该邮箱帐号是用户已申请并且可以正常使用的帐号);(3)所述用户终端基于用户指令(例如用户点击“发送”按钮)构造所述登录启动报文并将所述登录启动报文传送到所述登录服务器,其中,所述登录启动报文包括所述登录信息。Preferably, in the login method for a web system disclosed in the present invention, the step (A1) further includes: (1) the user terminal accesses the login page of the web system through a web browser based on a user instruction ;(2) The user enters the login information through the login page, wherein the login information includes the user's valid email account (that is, the email account is an account that the user has applied for and can use normally); (3 ) The user terminal constructs the login initiation message based on a user instruction (for example, the user clicks a "send" button) and transmits the login initiation message to the login server, wherein the login initiation message includes the login information.
优选地,在本发明所公开的用于web系统的登录方法中,所述步骤(A2)进一步包括下列步骤:(B1)在接收到所述登录启动报文后,所述登录服务器校验所述登录启动报文所包含的登录信息的有效性(即校验用户的有效邮箱的帐号的有效性);(B2)如果所述登录信息的有效性验证成功,则动态地生成针对所述用户的登录URL(统一资源定位符)并将所述登录URL以加密的方式传送到所述邮件服务器,其中,所述登录URL包含至少一个参数,并且所述至少一个参数包括当前系统时间;(B3)用户通过所述邮件客户端登录位于所述邮件服务器中的所述有效邮箱以查看所述登录URL。Preferably, in the web system login method disclosed in the present invention, the step (A2) further includes the following steps: (B1) after receiving the login start message, the login server verifies the (B2) If the validity verification of the login information is successful, dynamically generate an email address for the user The login URL (uniform resource locator) and transmit the login URL to the mail server in an encrypted manner, wherein the login URL contains at least one parameter, and the at least one parameter includes the current system time; (B3 ) the user logs in the valid mailbox located in the mail server through the mail client to view the login URL.
优选地,在本发明所公开的用于web系统的登录方法中,所述步骤(A2)进一步包括:在用户经由所述邮件客户端查看到所述登录URL后,所述邮件客户端基于用户指令(例如所述用户点击由所述登录URL指示的链接)构造登录请求,并将所述登录请求传送到所述登录服务器,其中,所述登录请求包括所述登录URL。Preferably, in the login method for a web system disclosed in the present invention, the step (A2) further includes: after the user views the login URL via the mail client, the mail client based on the user An instruction (eg, the user clicks on a link indicated by the login URL) constructs a login request and transmits the login request to the login server, wherein the login request includes the login URL.
优选地,在本发明所公开的用于web系统的登录方法中,所述步骤(A2)进一步包括:在接收到所述登录请求后,所述登录服务器提取所述登录请求中的登录URL的所述至少一个参数以得到生成所述登录URL时的当前系统时间并随后将当前系统时间与生成所述登录URL时的当前系统时间相比较,如果当前系统时间与生成所述登录URL时的当前系统时间之间的时间差小于或等于预定值(例如100秒),则直接跳转到所述web系统的主页面并提示登录成功,如果当前系统时间与生成所述登录URL时的当前系统时间之间的时间差大于所述预定值,则返回登录页面并提示用户重新获取登录URL。Preferably, in the login method for a web system disclosed in the present invention, the step (A2) further includes: after receiving the login request, the login server extracts the URL of the login URL in the login request The at least one parameter is to obtain the current system time when the login URL is generated and then compare the current system time with the current system time when the login URL is generated, if the current system time is different from the current system time when the login URL is generated If the time difference between the system times is less than or equal to a predetermined value (for example, 100 seconds), it will directly jump to the main page of the web system and prompt that the login is successful. If the current system time is different from the current system time when the login URL is generated If the time difference between them is greater than the predetermined value, return to the login page and prompt the user to obtain the login URL again.
示例性地,在本发明所公开的用于web系统的登录方法中,所述邮件客户端以基于证书的加密方式与所述登录服务器进行数据通信。Exemplarily, in the login method for a web system disclosed in the present invention, the mail client performs data communication with the login server in a certificate-based encryption manner.
示例性地,在本发明所公开的用于web系统的登录方法中,所述web浏览器和所述邮件客户端位于同一用户终端中。Exemplarily, in the login method for a web system disclosed in the present invention, the web browser and the mail client are located in the same user terminal.
示例性地,在本发明所公开的用于web系统的登录方法中,所述用户终端是个人计算机或移动终端(例如手机)。Exemplarily, in the web system login method disclosed in the present invention, the user terminal is a personal computer or a mobile terminal (such as a mobile phone).
由上可见,本发明所公开的用于web系统的登录方法具有下列优点:具有高的安全性并且操作简便。It can be seen from the above that the login method for the web system disclosed by the present invention has the following advantages: high security and easy operation.
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不局限于上述的实施方式。应该认识到:在不脱离本发明主旨和范围的情况下,本领域技术人员可以对本发明做出不同的变化和修改。Although the present invention has been described through the above-mentioned preferred embodiments, its implementation forms are not limited to the above-mentioned embodiments. It should be appreciated that those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention.
Claims (5)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310295288.5A CN104301285B (en) | 2013-07-15 | 2013-07-15 | Login method for web system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310295288.5A CN104301285B (en) | 2013-07-15 | 2013-07-15 | Login method for web system |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN104301285A CN104301285A (en) | 2015-01-21 |
| CN104301285B true CN104301285B (en) | 2018-04-27 |
Family
ID=52320857
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201310295288.5A Active CN104301285B (en) | 2013-07-15 | 2013-07-15 | Login method for web system |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN104301285B (en) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107196893A (en) * | 2016-03-15 | 2017-09-22 | 百度在线网络技术(北京)有限公司 | Login method, login service device and login client |
| CN107395622A (en) * | 2017-08-18 | 2017-11-24 | 四川长虹电器股份有限公司 | Method without cipher safety authentication |
| CN107295024A (en) * | 2017-08-24 | 2017-10-24 | 四川长虹电器股份有限公司 | It is a kind of to realize the method that web front end is landed safely and accessed |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101540674A (en) * | 2008-03-17 | 2009-09-23 | 北京亿企通信息技术有限公司 | Method for logging on Web end in instant communication device |
| CN102801687A (en) * | 2011-05-24 | 2012-11-28 | 鸿富锦精密工业(深圳)有限公司 | Single sign-on system and method |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| TWI220715B (en) * | 2002-02-22 | 2004-09-01 | Taiwan Knowledge Bank Co Ltd | Video/audio multimedia web mail system, editing and processing method |
-
2013
- 2013-07-15 CN CN201310295288.5A patent/CN104301285B/en active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101540674A (en) * | 2008-03-17 | 2009-09-23 | 北京亿企通信息技术有限公司 | Method for logging on Web end in instant communication device |
| CN102801687A (en) * | 2011-05-24 | 2012-11-28 | 鸿富锦精密工业(深圳)有限公司 | Single sign-on system and method |
Also Published As
| Publication number | Publication date |
|---|---|
| CN104301285A (en) | 2015-01-21 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN103609090B (en) | Identity login method and equipment | |
| EP3044987B1 (en) | Method and system for verifying an account operation | |
| JP6355742B2 (en) | Signature verification method, apparatus, and system | |
| US9294479B1 (en) | Client-side authentication | |
| CN104038503B (en) | Across the method for website log, device and system | |
| CN108701309A (en) | A distributed user profile authentication system for e-commerce transaction security | |
| WO2017076214A1 (en) | A sms-based website login method and login system thereof | |
| CN104158818B (en) | A kind of single-point logging method and system | |
| US9544317B2 (en) | Identification of potential fraudulent website activity | |
| CN104579671B (en) | Auth method and system | |
| CN105337949A (en) | SSO (Single Sign On) authentication method, web server, authentication center and token check center | |
| CN109257321B (en) | Secure login method and device | |
| CN105025041A (en) | Method, device and system for uploading files | |
| CN103618717A (en) | Multi-account client information dynamic authentication method, device and system | |
| CN115022047B (en) | Account login method and device based on multi-cloud gateway, computer equipment and medium | |
| CN104202345A (en) | Verification code generating method, device and system | |
| CN108200040A (en) | Mobile client exempts from method, system, browser and the mobile terminal of close login | |
| CN102624687A (en) | Networking program user authentication method based on mobile terminal | |
| CN105871853A (en) | Portal authenticating method and system | |
| CN102946396B (en) | User agent's device, host web server and user authen method | |
| CN104301285B (en) | Login method for web system | |
| CN103152344B (en) | Cryptographic algorithm method and device based on digital certificate | |
| CN102946397B (en) | User authen method and system | |
| CN106713257A (en) | Method and device for service processing based on mobile device | |
| CN104283691B (en) | A kind of Bidirectional identity authentication method and system based on dynamic password |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant |