Two-factor identity verification system, method, device and equipment
Password-free authentication through employee working cards solves the security, integration difficulty and cost problems in the existing technology, and realizes high security and low cost two-factor authentication, which is suitable for access protection of sensitive pages within the enterprise.
Patent Information
- Application Number
- CN202510239523.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-07-08
AI Technical Summary
The existing two-factor authentication methods have shortcomings in terms of security, integration difficulty and development and deployment costs, especially the four digits behind the ID number are easily leaked, the SMS verification code is inconvenient for high-frequency deployment, the asymmetric encryption technology requires hardware upgrades, and the user registration and binding is complex.
Password-free authentication is used for employee working cards based on short-distance communication, and identity information is read through employee working cards and verified with the identity verification server. The existing hardware and infrastructure are used to avoid the use of ID card numbers and realize physical separation of the equipment.
Two-factor authentication with high security, low integration difficulty and low development and deployment cost is realized, avoiding hardware upgrades and additional registration binding, and improving the security and verification efficiency of identity information.
Smart Images

Figure CN120281469A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and specifically relates to a two-factor authentication system, method and device, an instant messaging client, a privacy data processing client, an information publishing client, and an electronic device. Background Art
[0002] In an office scenario, employees are usually allowed to use their mobile phones to access sensitive internal enterprise pages, such as viewing salary and benefits using a mobile phone, logging in to the intranet to post messages, and posting messages in a work group. To avoid the situation where a mobile phone is stolen by people around and used to illegally access sensitive pages, a two-factor authentication scheme is needed to protect the security of mobile phone access to sensitive pages.
[0003] Currently, in the case where a user has logged in to the sensitive page server through a password, the second authentication of two-factor authentication can adopt the following three methods: Method 1, when the user opens the sensitive page, enter the last four digits of the ID card number, that is, enter the password when logging in and enter the last four digits of the ID card number when using; Method 2, when the user opens the sensitive page, enter the SMS verification code, that is, enter the password when logging in and enter the SMS verification code when using; Method 3, verify the user's identity by using the "public key" and "private key" in asymmetric encryption technology, such as the Passkey scheme of the FIDO Alliance.
[0004] However, the inventor found that the above three second authentication methods have the following problems respectively: The last four digits of the ID card number in Method 1 have privacy compliance risks and are easy to obtain, with low security; The SMS verification code in Method 2 is not physically separated from the mobile phone, has a long receiving time, and has a capital cost, so it cannot be deployed frequently, resulting in problems such as high development and deployment costs; The development cost of Method 3 is slightly higher, and additional hardware upgrades may be required. Even after deployment, there are still operation costs for users to register and bind, resulting in problems such as difficulty in integration.
[0005] In summary, for the second authentication (passwordless authentication) stage of an application system that requires two-factor authentication, how to balance high security, low integration difficulty, and development and deployment costs is an issue that urgently needs to be studied and tackled. Summary of the Invention
[0006] This application provides a two-factor authentication system to solve the problem in the prior art that it is impossible to balance high security, low integration difficulty, and development and deployment costs. This application also provides a two-factor authentication system, method and device, an instant messaging client, a privacy data processing client, an information publishing client, and an electronic device.
[0007] This application provides a two-factor authentication system, including:
[0008] An application system client is used to log in to the application system server according to the user password; respond to the user's usage instruction, read the employee identity information from the employee work ID based on near-field communication; send a passwordless authentication request to the identity authentication server according to the employee identity information; if the identity authentication server passes the passwordless authentication, display the client page;
[0009] The identity authentication server is used to obtain the employee work ID data set; receive the request; perform passwordless authentication according to the employee work ID data set and the employee identity information carried in the request; provide the passwordless authentication result to the client.
[0010] This application also provides a two-factor authentication method for the application system client, including:
[0011] Log in to the application system server according to the user password;
[0012] Respond to the user's usage instruction, read the employee identity information from the employee work ID based on near-field communication;
[0013] Send a passwordless authentication request to the identity authentication server according to the employee identity information;
[0014] If the identity authentication server passes the passwordless authentication, display the client page.
[0015] Optionally, it further includes:
[0016] Obtain the network environment information used by the client device;
[0017] Judge whether to perform passwordless authentication processing on the use of the client according to the network environment information;
[0018] If the judgment result is yes, send a passwordless authentication request to the identity authentication server.
[0019] Optionally, it further includes:
[0020] Detect whether the client device supports a near-field communication device;
[0021] If the detection result is yes, read the employee identity information from the employee work ID based on near-field communication.
[0022] Optionally, it further includes:
[0023] Perform encryption processing on the employee identity information;
[0024] The step of sending a passwordless authentication request to the identity authentication server according to the employee identity information includes:
[0025] Send a passwordless authentication request to the identity authentication server according to the encrypted employee identity information.
[0026] Optionally, the encrypting the employee identity information includes:
[0027] Obtain the signature information of the application system;
[0028] Encrypt the employee identity information according to the signature information.
[0029] Optionally, the request includes first replay detection data;
[0030] The encrypting the employee identity information includes:
[0031] Obtain first replay detection data;
[0032] Encrypt the employee identity information according to the first replay detection data.
[0033] Optionally, the first replay detection data includes at least one of the following: request sending time, passwordless authentication times.
[0034] This application also provides a two-factor authentication method for the identity authentication server, including:
[0035] Obtain the employee work card data set;
[0036] Receive a passwordless authentication request sent by the application system client, the request includes employee identity information, the employee identity information is read by the client from the employee work card based on near-field communication, the client reads the employee identity information from the employee work card according to the user usage instruction, and the client has logged in to the application system server according to the user password;
[0037] Perform passwordless authentication according to the employee work card data set and the employee identity information carried in the request;
[0038] Provide the passwordless authentication result to the client.
[0039] Optionally, the performing passwordless authentication according to the employee work card data set and the employee identity information carried in the request includes:
[0040] Determine the employee identity information of the client login employee according to the employee work card data set;
[0041] Perform passwordless authentication according to the employee identity information of the logged-in employee and the employee identity information of the client-using employee carried in the request.
[0042] Optionally, the employee identity information of the using employee carried in the request is the encrypted employee identity text;
[0043] The passwordless authentication based on the employee identity information of the logged-in employee and the employee identity information of the client using employee carried in the request includes:
[0044] Decrypt the encrypted employee identity text of the using employee;
[0045] Perform passwordless authentication based on the employee identity information of the logged-in employee and the decrypted employee identity information of the using employee.
[0046] Optionally, the employee identity information of the using employee carried in the request is the encrypted employee identity text;
[0047] The passwordless authentication based on the employee identity information of the logged-in employee and the employee identity information of the client using employee carried in the request includes:
[0048] Obtain the signature information of the application system;
[0049] Encrypt the employee identity information of the logged-in employee according to the signature information;
[0050] If the encrypted employee identity text of the logged-in employee is different from the encrypted employee identity text of the using employee, the passwordless authentication result fails.
[0051] Optionally, the employee identity information of the using employee carried in the request is the encrypted employee identity text, and the request further includes first replay detection data, and the encrypted employee identity text of the using employee is encrypted according to the first replay detection data;
[0052] The passwordless authentication based on the employee identity information of the logged-in employee and the employee identity information of the client using employee carried in the request includes:
[0053] Obtain second replay detection data;
[0054] Obtain the replay detection data difference between the first replay detection data and the second replay detection data;
[0055] Encrypt the employee identity information of the logged-in employee according to the first replay detection data;
[0056] If the encrypted employee identity text of the logged-in employee is different from the encrypted employee identity text of the using employee, or the replay detection data difference does not meet the difference condition, the passwordless authentication result fails.
[0057] Optionally, the second replay detection data includes at least one of the following:
[0058] The request reception time, the historical number of passwordless authentications of the logged-in employee.
[0059] This application also provides a two-factor authentication device for the application system client, including:
[0060] A user login unit for logging in to the application system server according to the user password;
[0061] A data reading unit for reading employee identity information from an employee work card based on near-field communication in response to a user usage instruction;
[0062] A request sending unit for sending a passwordless authentication request to the authentication server according to the employee identity information;
[0063] A page display unit for displaying the client page if the authentication server passes the passwordless authentication.
[0064] This application also provides a two-factor authentication device for the authentication server, including:
[0065] A data acquisition unit for acquiring an employee work card data set;
[0066] A request reception unit for receiving a passwordless authentication request sent by the application system client, the request including employee identity information, the employee identity information being read by the client from an employee work card based on near-field communication, the client reading the employee identity information from the employee work card according to a user usage instruction, and the client having logged in to the application system server according to the user password;
[0067] An authentication unit for performing passwordless authentication according to the employee work card data set and the employee identity information carried in the request;
[0068] A result providing unit for providing the passwordless authentication result to the client.
[0069] This application also provides an instant messaging client, including:
[0070] A user login unit for logging in to the instant messaging server according to the user password;
[0071] A data reading unit for reading employee identity information from an employee work card based on near-field communication in response to a user usage instruction;
[0072] A request sending unit for sending a passwordless authentication request to the authentication server according to the employee identity information;
[0073] A page display unit, configured to display a user page of an instant messaging tool if the authentication server passes passwordless authentication.
[0074] This application further provides a privacy data processing client, including:
[0075] A user login unit, configured to log in to a privacy data processing server according to a user password;
[0076] A data reading unit, configured to read employee identity information from an employee work card based on near-field communication in response to a user usage instruction;
[0077] A request sending unit, configured to send a passwordless authentication request to an authentication server according to the employee identity information;
[0078] If the authentication server passes passwordless authentication for privacy data, display a privacy data processing page.
[0079] This application further provides an information publishing client, including:
[0080] A user login unit, configured to log in to an information publishing server according to a user password;
[0081] A data reading unit, configured to read employee identity information from an employee work card based on near-field communication in response to a user usage instruction;
[0082] A request sending unit, configured to send a passwordless authentication request to an authentication server according to the employee identity information;
[0083] If the authentication server passes passwordless authentication for privacy data, display an information publishing page.
[0084] This application further provides an electronic device, including:
[0085] A processor; and
[0086] A memory, configured to store a program for implementing the method according to any one of the above, and the device is powered on and runs the program of the method through the processor.
[0087] This application further provides a computer-readable storage medium, in which instructions are stored, and when the instructions run on a computer, the computer is caused to execute the above various methods.
[0088] This application further provides a computer program product including instructions, and when the computer program product runs on a computer, the computer is caused to execute the above various methods.
[0089] Compared with the prior art, this application has the following advantages:
[0090] The two-factor authentication system provided by the embodiment of the present application includes an application system client and an authentication server. Among them, the application system client is used to log in to the application system server according to the user password; it is also used to respond to the user's usage instruction, read the employee identity information from the employee work card based on near-field communication; according to the employee identity information, send a passwordless authentication request to the authentication server; if the authentication server passes the passwordless authentication, display the client page; the authentication server is used to obtain the employee work card data set; receive the request; perform passwordless authentication according to the employee work card data set and the employee identity information carried in the request; provide the passwordless authentication result to the client. By adopting this processing method, two-factor authentication (Two-Factor Authentication, 2FA) based on the employee work card is realized. Since this processing method can reuse the existing hardware, infrastructure, and employee work card data set, without hardware upgrade, without additional registration and binding, and does not use the employee's ID number information, and the device required for passwordless authentication (employee work card) is physically separated from the client device (such as a mobile phone), therefore, when verifying whether the user using the client is the logged-in user, it can effectively balance high security, low integration difficulty, and development and deployment costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] Figure 1 Schematic diagram of device interaction of the embodiment of the two-factor authentication system provided by the present application;
[0092] Figure 2 Schematic diagram of the process of the embodiment of the two-factor authentication method provided by the present application;
[0093] Figure 3 Schematic diagram of the process of the embodiment of the two-factor authentication method provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0094] Many specific details are set forth in the following description in order to provide a thorough understanding of the present application. However, the present application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the present application. Therefore, the present application is not limited by the specific implementations disclosed below.
[0095] In the present application, a two-factor authentication system, method and device, an instant messaging client, a privacy data processing client, an information publishing client, and an electronic device are provided. The following will describe various solutions in detail in each embodiment.
[0096] The First Embodiment
[0097] Please refer to Figure 1, which is a schematic diagram of device interaction of the two-factor authentication system of the present application. In this embodiment, the two-factor authentication system includes: an application system client 1, an authentication server 2, and an employee ID card 3. The application system client 1 and the employee ID card 3 communicate with each other in a short-range communication manner, and the application system client 1 and the authentication server 2 communicate through a network (such as the Internet or a local area network, etc.).
[0098] In the two-factor authentication system provided by the present application, the application system client 1 is used to log in to the application system server according to the user password; in response to the user usage instruction, read the employee identity information from the employee ID card 3 based on short-range communication; according to the employee identity information, send a passwordless authentication request to the authentication server 2; if the authentication server 2 passes the passwordless authentication, display the client page and allow the user to use the client. Correspondingly, the authentication server 2 is used to obtain the employee ID card data set; receive the passwordless authentication request from the application system client 1; perform passwordless authentication according to the employee ID card data set and the employee identity information carried in the request; provide the passwordless authentication result to the application system client 1.
[0099] The application system in the present application includes sensitive pages, and two-factor authentication (Two-Factor Authentication, 2FA) technology is required to protect the usage security of the sensitive pages. In actual applications, the application system can be an instant messaging system (also known as an instant messaging tool), an information publishing system (such as forum posting), a privacy data processing system (such as a salary system), etc.
[0100] The operation of the application system involves the application system client 1 and the application system server. The client 1 is used to display the user interface and is usually deployed on the user device side. The user device can be a smart communication device (such as a smart phone, etc.), a tablet computer, a personal computer, etc. The application system server is used to provide background services and is usually deployed on the server side, such as a server within a local area network, a server in a data center, etc.
[0101] Two-factor authentication is an identity and access management security method that requires two forms of authentication to access resources and data. The two factors include a primary authentication factor and a secondary authentication factor. The primary authentication factor includes the login password of the application system, and the secondary authentication factor is passwordless and is the employee identity information from the ID card. Enterprises use 2FA to help protect employees' personal and corporate assets, prevent cybercriminals from stealing, destroying, or accessing employees' internal data records for their own use, and 2FA enables enterprises to monitor and help protect their most vulnerable information and networks.
[0102] One verification factor for two-factor authentication includes the login password of the application system, and the user can enter the password to log in to the application system server. In this application, the secondary verification factor for two-factor authentication is the employee identity information from the employee ID card. When the user uses the client 1 to log in to the application system server, a primary authentication is required. After that, as long as the application system is not exited, the user can use the application system through the client 1 at any time. When the user wants to use the application system, the client 1 will receive a user usage instruction, and at this time, a secondary authentication is required. The client 1 responds to this instruction and reads the employee identity information from the employee ID card based on near-field communication.
[0103] In this application, the employee ID card stores the employee identity information, which is a proof of the employee's identity, such as the unique identifier assigned by the enterprise to the employee (employee identifier User ID, UID) or the name, etc. A near-field communication method is adopted between the employee ID card 3 and the client 1. The near-field communication method can be Near Field Communication (NFC), Bluetooth, etc. Correspondingly, the employee ID card 3 can be an NFC ID card, a Bluetooth ID card, etc. The client 1 reads the employee identity information in the employee ID card by using the near-field communication method and uses it as the second authentication factor in the two-factor authentication to perform passwordless authentication through the authentication server 2.
[0104] In one example, the employee ID card is an NFC ID card. Specifically, when implemented, the following method can be used to read the employee identity information: The client 1 pulls up the NFC reading system pop-up layer, and then calls the operating system API to read the NFC ID card and obtain the returned employee identifier UID field. By adopting this processing method, the software development and transformation of the system are small. For the development of the client device side (such as a mobile phone), only the NFC mechanism needs to be called unidirectionally, and the interaction mechanism is simple.
[0105] After the client 1 reads the employee identity information from the employee ID card, it sends a passwordless authentication request to the authentication server 2 according to the employee identity information, and this request includes the employee identity information.
[0106] The authentication server 2 obtains the employee ID card data set. In practical applications, enterprises usually store the employee ID card data set, which is generally used for access control, etc. The authentication server 2 can directly use this data set.
[0107] After receiving the passwordless authentication request from Client 1, Authentication Server 2 performs passwordless authentication based on the employee ID dataset and the employee identity information carried in the passwordless authentication request. Specifically, during implementation, the employee identity information of the employee logging in to the client can be determined according to the employee ID dataset; passwordless authentication is performed based on the employee identity information of the logged-in employee and the employee identity information of the employee using the client carried in the request. If the employee identity information of the logged-in employee is the same as the employee identity information of the using employee, it can be determined that the passwordless authentication is passed; otherwise, it can be determined that the passwordless authentication fails. Authentication Server 2 provides the passwordless authentication result to the client. Client 1 receives the passwordless authentication result. If the passwordless authentication is passed, the client page is displayed.
[0108] In one example, Client 1 is also used to obtain the network environment information used by the client device; according to the network environment information, it is determined whether to perform passwordless authentication processing on the use of the client; if the determination result is yes, a passwordless authentication request is sent to the authentication server. The network environment information may include at least one of the following information: wireless network information, Internet Protocol (IP) address, virtual private network information. Adopting this processing method enables the client to determine whether the current environment is a trusted environment according to the network environment information. According to the control policy, when two-factor authentication is required, a passwordless authentication request is sent to Authentication Server 2.
[0109] In one example, Client 1 is also used to detect whether the client device supports a near-field communication device; if the detection result is yes, the employee identity information is read from the employee ID based on near-field communication. Adopting this processing method enables the client to determine whether the client device (such as a mobile phone) supports an NFC ID card. If it supports an NFC ID card, secondary authentication based on the ID card is preferentially used to improve the security level; otherwise, existing methods such as the last four digits of the ID card and the SMS verification code can be used for secondary authentication.
[0110] In one example, the plaintext of the employee identity information of the employee using the client can be directly carried in the passwordless authentication request, which can effectively improve the efficiency of passwordless authentication.
[0111] In another example, the client 1 is also used to encrypt the employee identity information, and the employee identity information carried in the request is the ciphertext of the employee identity; the sending of the passwordless authentication request to the identity authentication server according to the employee identity information includes: sending a passwordless authentication request to the identity authentication server 2 according to the encrypted employee identity information. In specific implementation, relatively mature encryption algorithms in the prior art can be used, such as symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms, etc. Adopting this processing method can prevent the direct transmission of the employee identity information during network transmission and prevent the leakage of the employee identity information. Therefore, the security of the employee identity information can be effectively improved.
[0112] In one example, the employee identity information used by the client carried in the request is the ciphertext of the employee identity; the server 2 is specifically used to decrypt the ciphertext of the employee identity used by the employee; passwordless authentication is performed according to the employee identity information of the logged-in employee and the decrypted employee identity information used by the employee. Adopting this processing method enables the encryption process and the decryption process to be performed separately on both the client 1 and the server 2.
[0113] In one example, the client 1 can encrypt the employee identity information in the following manner: obtain the signature information of the application system; encrypt the employee identity information according to the signature information. The employee identity information used by the client carried in the request is the ciphertext of the employee identity. Correspondingly, the server 2 can perform passwordless authentication according to the employee identity information of the logged-in employee and the employee identity information used by the client carried in the request in the following manner: obtain the signature information of the application system; encrypt the employee identity information of the logged-in employee according to the signature information; if the encrypted ciphertext of the employee identity of the logged-in employee is different from the ciphertext of the employee identity used by the employee carried in the request, the passwordless authentication result is not passed; if the two ciphertexts are the same, it can be determined that the passwordless authentication result is passed. Adopting this processing method can not only avoid the interception and leakage of the employee identity information in the request and improve the security of the employee identity information when verifying whether the user using the client is the logged-in user, but also sign the employee identity information in the passwordless authentication request with the application system, so that it can be known whether the employee identity information carried in the passwordless authentication request comes from an application outside the application system (such as a web crawler), effectively preventing the work permit from being separated from the application system and accessed by external applications, and avoiding the possibility of being cracked by external malicious programs (such as crawlers); thus achieving the effect of "killing two birds with one stone" and effectively improving the security and performance of passwordless authentication.
[0114] In specific implementation, the client 1 can introduce the HMAC mechanism to encrypt the employee identity information. HMAC is a one-way function. For example, the HMAC algorithm that uses SHA-256 to generate the hash value (HMAC-SHA256 algorithm) is used to encrypt the employee identity information. The encrypted employee identity information is reported to the passwordless authentication server side through the reporting mechanism. In practical applications, any relatively mature reporting mechanism can be adopted, such as filling in the input field of the Hidden type in HTML, such as HTTPS Post.
[0115] In an example, the passwordless authentication request includes not only the encrypted employee identity information used by the client for the employee, but also the first replay detection data; the client 1 can encrypt the employee identity information in the following way: obtain the first replay detection data; encrypt the employee identity information according to the first replay detection data. Correspondingly, the server 2 can perform passwordless authentication based on the employee identity information of the logged-in employee and the employee identity information used by the client carried in the request in the following way: obtain the second replay detection data; obtain the replay detection data difference between the first replay detection data and the second replay detection data; encrypt the employee identity information of the logged-in employee according to the first replay detection data; if the encrypted employee identity ciphertext of the logged-in employee is different from the employee identity ciphertext of the using employee carried in the request or the replay detection data difference does not meet the difference condition, the passwordless authentication result is failed. The first replay detection data is client data used for replay detection, including but not limited to at least one of the following: request sending time, number of passwordless authentication times. The second replay detection data is server data used for replay detection, including but not limited to at least one of the following: request receiving time, historical number of passwordless authentication of the logged-in employee. By adopting this processing method, when verifying whether the user using the client is the logged-in user, it can not only prevent the employee identity information in the request from being intercepted and leaked, improving the security of the employee identity information; but also perform replay detection on the passwordless authentication request and detect the authenticity of the first replay detection data included in the request to prevent the first replay detection data from being tampered with; thus achieving the effect of "killing three birds with one stone", which can effectively improve the security and performance of passwordless authentication.
[0116] In one example, the first replay detection data is the request sending time, the second replay detection data is the request receiving time, the difference in replay detection data is the time difference between the request receiving time and the request sending time, and the difference condition can be a time difference condition. The time difference condition can be that the time difference is less than a time difference threshold (such as 30 seconds). This design takes into account the inaccurate time synchronization of the client and the time delay caused during network transmission. Thus, if the time difference is greater than or equal to the time difference threshold, it means that the time difference does not meet the time difference condition, the passwordless authentication request is a replay request, and the passwordless authentication result is not passed; if the time difference is less than the time difference threshold, it means that the time difference meets the time difference condition, and the passwordless authentication request is a normal request.
[0117] In one example, the first replay detection data is the cumulative number of passwordless authentication times of Client 1, the second replay detection data is the historical number of passwordless authentication times of the logged-in employee of Client 1 recorded by Server 2, the difference in replay detection data is the difference in the number of times between the number of passwordless authentication times and the historical number of times, and the difference condition can be a difference-in-number condition. The difference-in-number condition can be that the difference in number is less than a difference-in-number threshold. The difference-in-number threshold should be greater than or equal to 1, and can be 2, 3, 4, etc., because network packet loss needs to be considered. Thus, if the difference in number is greater than or equal to the difference-in-number threshold, it means that the difference in number does not meet the difference-in-number condition, the passwordless authentication request is a replay request, and the passwordless authentication result is not passed; if the difference in number is less than the difference-in-number threshold, it means that the difference in number meets the difference-in-number condition, and the passwordless authentication request is a normal request.
[0118] During specific implementation, Client 1 can introduce the HMAC mechanism to encrypt the employee identity information. HMAC is a one-way function. For example, use the HMAC algorithm (HMAC-SHA256 algorithm) that generates a hash value using SHA-256 to encrypt the employee identity information. Report the encrypted employee identity ciphertext, the time based on which the ciphertext is generated, and the number of passwordless authentication times to the passwordless authentication server side through the reporting mechanism.
[0119] In one example, the passwordless authentication request includes not only the ciphertext of the employee identity used by the client but also the first replay detection data. The client 1 can encrypt the employee identity information in the following manner: obtain the signature information of the application system; obtain the first replay detection data; and encrypt the employee identity information based on the signature information and the first replay detection data. Correspondingly, the server 2 can perform passwordless authentication based on the employee identity information of the logged-in employee and the employee identity information of the employee used by the client carried in the request in the following manner: obtain the signature information of the application system; obtain the second replay detection data; obtain the difference in replay detection data between the first replay detection data and the second replay detection data; encrypt the employee identity information of the logged-in employee based on the signature information and the first replay detection data; if the encrypted ciphertext of the employee identity of the logged-in employee is different from the ciphertext of the employee identity of the using employee carried in the request or the difference in replay detection data does not meet the difference condition, the passwordless authentication result is failed. By adopting this processing method, when verifying whether the user using the client is the logged-in user, it can not only prevent the interception and leakage of the employee identity information in the request, improving the security of the employee identity information, but also avoid the possibility of being cracked by external malicious programs (such as crawlers), and can also perform replay detection on the passwordless authentication request and detect the authenticity of the first replay detection data included in the request to prevent the first replay detection data from being tampered with. Thus, it achieves the effect of "killing four birds with one stone", effectively improving the security and performance of passwordless authentication.
[0120] As can be seen from the above embodiments, the two-factor authentication system provided by the embodiments of the present application includes an application system client and an authentication server. Among them, the application system client is used to log in to the application system server according to the user password; it is also used to respond to the user's usage instruction, read the employee identity information from the employee work card based on near-field communication; according to the employee identity information, send a passwordless authentication request to the authentication server; if the authentication server passes the passwordless authentication, display the client page; the authentication server is used to obtain the employee work card data set; receive the request; perform passwordless authentication according to the employee work card data set and the employee identity information carried in the request; provide the passwordless authentication result to the client. By adopting this processing method, two-factor authentication (Two-Factor Authentication, 2FA) based on the employee work card is realized. Since this processing method can reuse the existing hardware, infrastructure, and employee work card data set, without hardware upgrade, without additional registration and binding, and does not use the employee's ID number information, and the device required for passwordless authentication (employee work card) is physically separated from the client device (such as a mobile phone), therefore, when verifying whether the user using the client is the logged-in user, it can effectively balance high security, low integration difficulty, and development and deployment costs.
[0121] Second Embodiment
[0122] In the above embodiment, a two-factor authentication system is provided. Correspondingly, the present application also provides a two-factor authentication method for the application system client. This method corresponds to the embodiment of the above system. Since the method embodiment is basically similar to the system embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the system embodiment. The method embodiment described below is only illustrative.
[0123] Please refer to Figure 2 , which is a schematic flowchart of the two-factor authentication method of the present application. In this embodiment, the two-factor authentication method may include the following steps:
[0124] Step S201: Log in to the application system server according to the user password.
[0125] Step S203: Respond to the user's usage instruction, and read the employee identity information from the employee work card based on near-field communication.
[0126] Step S205: According to the employee identity information, send a passwordless authentication request to the authentication server.
[0127] Step S207: If the authentication server passes the passwordless authentication, display the client page.
[0128] In one example, the method may further include the following steps: obtaining network environment information used by the client device; determining whether to perform passwordless authentication processing for using the client according to the network environment information; if the determination result is yes, sending a passwordless authentication request to the authentication server. The network environment information may include at least one of the following information: wireless network information, Internet Protocol (IP) address, virtual private network information. By adopting this processing method, the client will determine whether the current environment is a trusted environment according to the network environment information. According to the control policy, when two-factor authentication is required, a passwordless authentication request is sent to the authentication server 2.
[0129] In one example, the method may further include the following steps: detecting whether the client device supports a near-field communication device; if the detection result is yes, reading the employee identity information from the employee work badge based on near-field communication. By adopting this processing method, the client will determine whether the client device (such as a mobile phone) supports an NFC work badge. If it supports the NFC work badge, the work-badge-based secondary authentication is preferentially used to improve the security level; otherwise, existing methods such as the last four digits of the ID card and SMS verification code can be used for secondary authentication.
[0130] In one example, the plaintext of the employee identity information used by the client can be directly carried in the passwordless authentication request, which can effectively improve the efficiency of passwordless authentication.
[0131] In one example, the method may further include the following steps: encrypting the employee identity information, and the employee identity information carried in the request is the encrypted employee identity text; the step of sending a passwordless authentication request to the authentication server according to the employee identity information includes: sending a passwordless authentication request to the authentication server according to the encrypted employee identity information. In specific implementation, relatively mature encryption algorithms in the prior art can be used, such as symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms. By adopting this processing method, the employee identity information will not be directly transmitted during network transmission, preventing the leakage of employee identity information. Therefore, the security of employee identity information can be effectively improved.
[0132] In one example, the encryption process for the employee identity information can be carried out in the following manner: obtain the signature information of the application system; and encrypt the employee identity information according to the signature information. By adopting this processing method, when verifying whether the user using the client is the logged-in user, it can not only prevent the interception and leakage of the employee identity information in the request, enhancing the security of the employee identity information, but also sign the employee identity information in the passwordless authentication request, so that it can be known whether the employee identity information carried in the passwordless authentication request comes from an application outside the application system (such as a web crawler), effectively preventing the work card from being accessed outside the application system and avoiding the possibility of being cracked by external malicious programs (such as crawlers); thus achieving a "two birds with one stone" effect and effectively improving the security and performance of passwordless authentication.
[0133] In one example, the passwordless authentication request includes not only the ciphertext of the employee identity of the employee using the client, but also the first replay detection data; the encryption process for the employee identity information can be carried out in the following manner: obtain the first replay detection data; and encrypt the employee identity information according to the first replay detection data. The first replay detection data is client data used for replay detection, including but not limited to at least one of the following: request sending time, number of passwordless authentication times. The second replay detection data is server-side data used for replay detection, including but not limited to at least one of the following: request receiving time, historical number of passwordless authentications of the logged-in employee. By adopting this processing method, when verifying whether the user using the client is the logged-in user, it can not only prevent the interception and leakage of the employee identity information in the request, enhancing the security of the employee identity information, but also perform replay detection on the passwordless authentication request and detect the authenticity of the first replay detection data included in the request to prevent the first replay detection data from being tampered with; thus achieving a "three birds with one stone" effect and effectively improving the security and performance of passwordless authentication.
[0134] Third Embodiment
[0135] In the above embodiments, a two-factor authentication method is provided. Correspondingly, the present application also provides a two-factor authentication device for the application system client. This device corresponds to the method embodiments above. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple. For related parts, refer to the partial description of the method embodiments. The device embodiments described below are merely illustrative.
[0136] The present application further provides a two-factor authentication device, including:
[0137] A user login unit for logging in to the application system server according to the user password;
[0138] A data reading unit for responding to a user usage instruction and reading employee identity information from an employee work card based on near-field communication;
[0139] A request sending unit for sending a passwordless authentication request to the identity authentication server according to the employee identity information;
[0140] A page display unit for displaying the client page if the identity authentication server passes the passwordless authentication.
[0141] Optionally, the device may further include:
[0142] A network environment information acquisition unit for acquiring the network environment information used by the client device;
[0143] A network environment information processing unit for judging whether to perform passwordless authentication processing on the use of the client according to the network environment information;
[0144] The request sending unit is specifically configured to send a passwordless authentication request to the identity authentication server if the judgment result is yes.
[0145] Optionally, the device may further include:
[0146] An NFC support detection unit for detecting whether the client device supports a near-field communication device;
[0147] The data reading unit is specifically configured to read the employee identity information from the employee work card based on near-field communication if the detection result is yes.
[0148] Optionally, the device may further include:
[0149] A data confidentiality unit for encrypting the employee identity information;
[0150] The request sending unit is specifically configured to send a passwordless authentication request to the identity authentication server according to the encrypted employee identity information.
[0151] Optionally, the data confidentiality unit is specifically configured to obtain the signature information of the application system; and encrypt the employee identity information according to the signature information.
[0152] Optionally, the request includes first replay detection data; the data confidentiality unit is specifically configured to obtain the first replay detection data; and encrypt the employee identity information according to the first replay detection data.
[0153] Optionally, the first replay detection data includes at least one of the following: request sending time, number of passwordless authentication attempts.
[0154] Fourth Embodiment
[0155] In the above embodiments, a two-factor authentication method is provided. Correspondingly, the present application also provides an instant messaging client. This device corresponds to the embodiments of the above method. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple. For related parts, refer to the partial description of the method embodiments. The device embodiments described below are only illustrative.
[0156] The present application further provides an instant messaging client, including:
[0157] A user login unit for logging in to the instant messaging server according to the user password;
[0158] A data reading unit for reading employee identity information from an employee work ID based on near-field communication in response to a user usage instruction;
[0159] A request sending unit for sending a passwordless authentication request to the authentication server according to the employee identity information;
[0160] A page display unit for displaying the user page of the instant messaging tool if the authentication server passes the passwordless authentication.
[0161] Fifth Embodiment
[0162] In the above embodiments, a two-factor authentication method is provided. Correspondingly, the present application also provides a privacy data processing client. This device corresponds to the embodiments of the above method. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple. For related parts, refer to the partial description of the method embodiments. The device embodiments described below are only illustrative.
[0163] The present application further provides a privacy data processing client, including:
[0164] A user login unit for logging in to the privacy data processing server according to the user password;
[0165] A data reading unit for reading employee identity information from an employee work ID based on near-field communication in response to a user usage instruction;
[0166] A request sending unit for sending a passwordless authentication request to the authentication server according to the employee identity information;
[0167] If the authentication server passes passwordless authentication for private data, a private data processing page is displayed.
[0168] Sixth Embodiment
[0169] In the above embodiments, a two-factor authentication method is provided. Correspondingly, the present application also provides an information publishing client. This device corresponds to the embodiments of the above method. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple. For related parts, refer to the partial description of the method embodiments. The device embodiments described below are merely illustrative.
[0170] The present application further provides an information publishing client, including:
[0171] A user login unit for logging in to the information publishing server according to the user password;
[0172] A data reading unit for reading employee identity information from an employee ID card based on near-field communication in response to a user usage instruction;
[0173] A request sending unit for sending a passwordless authentication request to the authentication server according to the employee identity information;
[0174] If the authentication server passes passwordless authentication for private data, an information publishing page is displayed.
[0175] Seventh Embodiment
[0176] In the above embodiments, a two-factor authentication system is provided. Correspondingly, the present application also provides a two-factor authentication method for the authentication server. This method corresponds to the embodiments of the above system. Since the method embodiments are basically similar to the system embodiments, the description is relatively simple. For related parts, refer to the partial description of the system embodiments. The method embodiments described below are merely illustrative.
[0177] Please refer to Figure 3 , which is a schematic flowchart of the two-factor authentication method of the present application. In this embodiment, the two-factor authentication method may include the following steps:
[0178] Step S301: Obtain an employee ID card data set.
[0179] Step S303: Receive a passwordless authentication request sent by the application system client. The request includes employee identity information, which is read by the client from an employee ID card based on near-field communication. The client reads the employee identity information from the employee ID card according to a user usage instruction, and the client has logged in to the application system server according to the user password.
[0180] Step S305: Perform passwordless authentication based on the employee ID dataset and the employee identity information carried in the request.
[0181] Step S307: Provide the passwordless authentication result to the client.
[0182] In specific implementation, Step S305 can be implemented in the following manner: Determine the employee identity information of the employee logging in to the client based on the employee ID dataset; perform passwordless authentication based on the employee identity information of the logging-in employee and the employee identity information of the employee using the client carried in the request. If the employee identity information of the logging-in employee is the same as the employee identity information of the using employee, it can be determined that the passwordless authentication passes; otherwise, it can be determined that the passwordless authentication fails. The identity authentication server 2 provides the passwordless authentication result to the client. The client 1 receives the passwordless authentication result. If the passwordless authentication passes, the client page is displayed.
[0183] In one example, the employee identity information of the using employee carried in the request is an employee identity ciphertext; the performing passwordless authentication based on the employee identity information of the logging-in employee and the employee identity information of the employee using the client carried in the request includes: decrypting the employee identity ciphertext of the using employee; performing passwordless authentication based on the employee identity information of the logging-in employee and the decrypted employee identity information of the using employee. Adopting this processing method enables encryption processing and decryption processing to be performed separately on both sides of the client 1 and the server 2.
[0184] In one example, the employee identity information of the using employee carried in the request is an employee identity ciphertext; the performing passwordless authentication based on the employee identity information of the logging-in employee and the employee identity information of the employee using the client carried in the request includes: obtaining the signature information of the application system; encrypting the employee identity information of the logging-in employee based on the signature information; if the encrypted employee identity ciphertext of the logging-in employee is different from the employee identity ciphertext of the using employee, the passwordless authentication result is not passed. Adopting this processing method not only enables the interception and leakage of the employee identity information in the request to be avoided when verifying whether the user using the client is the logged-in user, improving the security of the employee identity information, but also enables the employee identity information in the passwordless authentication request to be signed by the application system, so that it can be known whether the employee identity information carried in the passwordless authentication request comes from an application outside the application system (such as a web crawler), effectively preventing the ID card from being separated from the application system and accessed by external applications, and avoiding the possibility of being cracked by external malicious programs (such as crawlers); thus achieving the effect of "killing two birds with one stone", effectively improving the security and performance of passwordless authentication.
[0185] In one example, the employee identity information of the using employee carried in the request is the encrypted employee identity, and the request further includes first replay detection data. The encrypted employee identity of the using employee is obtained by encrypting the first replay detection data. The passwordless authentication based on the employee identity information of the logged-in employee and the employee identity information of the client's using employee carried in the request includes: obtaining second replay detection data; obtaining the difference in replay detection data between the first replay detection data and the second replay detection data; encrypting the employee identity information of the logged-in employee according to the first replay detection data; if the encrypted employee identity of the logged-in employee is different from the encrypted employee identity of the using employee, or the difference in replay detection data does not meet the difference condition, the passwordless authentication result fails. The second replay detection data includes at least one of the following: the request reception time, and the historical number of passwordless authentications of the logged-in employee. By adopting this processing method, when verifying whether the using user of the client is the logged-in user, it is not only possible to prevent the employee identity information in the request from being intercepted and leaked, improving the security of the employee identity information, but also possible to perform replay detection on the passwordless authentication request and detect the authenticity of the first replay detection data included in the request to prevent the first replay detection data from being tampered with. Thus, the effect of "killing three birds with one stone" is achieved, and the security and performance of passwordless authentication can be effectively improved.
[0186] Eighth Embodiment
[0187] In the above embodiment, a two-factor authentication method is provided. Correspondingly, the present application also provides a two-factor authentication device for an authentication server. This device corresponds to the method embodiment. Since the device embodiment is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment. The device embodiments described below are merely illustrative.
[0188] The present application further provides a two-factor authentication device, including:
[0189] A data acquisition unit for acquiring an employee badge data set;
[0190] A request reception unit for receiving a passwordless authentication request sent by an application system client. The request includes employee identity information read by the client from an employee badge based on near-field communication. The client reads the employee identity information from the employee badge according to a user usage instruction, and the client has logged in to the application system server according to a user password.
[0191] An authentication unit for performing passwordless authentication based on the employee ID dataset and the employee identity information carried in the request;
[0192] A result providing unit for providing the passwordless authentication result to the client.
[0193] Optionally, the authentication unit is specifically configured to determine the employee identity information of the employee logging in to the client according to the employee ID dataset; and perform passwordless authentication based on the employee identity information of the logging-in employee and the employee identity information of the employee using the client carried in the request.
[0194] Optionally, the employee identity information of the employee using the client carried in the request is an employee identity ciphertext; the authentication unit is specifically configured to decrypt the employee identity ciphertext of the employee using the client; and perform passwordless authentication based on the employee identity information of the logging-in employee and the decrypted employee identity information of the employee using the client.
[0195] Optionally, the employee identity information of the employee using the client carried in the request is an employee identity ciphertext; the authentication unit is specifically configured to obtain the signature information of the application system; encrypt the employee identity information of the logging-in employee according to the signature information; if the encrypted employee identity ciphertext of the logging-in employee is different from the employee identity ciphertext of the employee using the client, the passwordless authentication result fails.
[0196] Optionally, the employee identity information of the employee using the client carried in the request is an employee identity ciphertext, and the request further includes first replay detection data, and the employee identity ciphertext of the employee using the client is encrypted according to the first replay detection data; the authentication unit is specifically configured to obtain second replay detection data; obtain the replay detection data difference between the first replay detection data and the second replay detection data; encrypt the employee identity information of the logging-in employee according to the first replay detection data; if the encrypted employee identity ciphertext of the logging-in employee is different from the employee identity ciphertext of the employee using the client, or the replay detection data difference does not meet the difference condition, the passwordless authentication result fails.
[0197] Optionally, the second replay detection data includes at least one of the following: request reception time, historical number of passwordless authentications of the logging-in employee.
[0198] The ninth embodiment
[0199] In the above embodiments, a two-factor authentication method is provided. Correspondingly, the present application also provides an electronic device. This device corresponds to the method embodiments described above. Since the device embodiments are basically similar to the method embodiments, the description is relatively simple. For related parts, please refer to the description of the method embodiments. The device embodiments described below are only illustrative.
[0200] The electronic device of this embodiment includes: a memory and a processor; the memory is used to store a program for implementing any of the above two-factor authentication methods, and when the device is powered on, the program of the above two-factor authentication method runs through the processor.
[0201] The memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk or an optical disk.
[0202] Specifically, the electronic device may further include one or more of the following components: a power supply component, an input / output (I / O) interface, and a communication component. The power supply component provides power for various components of the electronic device. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device. The I / O interface provides an interface between the processor 503 and the peripheral interface module, and the above peripheral interface module may be a keyboard, a click wheel, a button, etc. The communication component is configured to facilitate communication between the electronic device and a user device (such as a smart phone, a tablet computer, etc.) in a wired or wireless manner.
[0203] Tenth Embodiment
[0204] The present application also provides a computer-readable storage medium. Since the computer-readable storage medium embodiments are basically similar to the method embodiments, the description is relatively simple. For related parts, please refer to the description of the method embodiments. The computer-readable storage medium embodiments described below are only illustrative.
[0205] In this embodiment, a non-transitory computer-readable storage medium including instructions is provided, such as a memory including instructions, and the above instructions can be executed by a processor of an electronic device to complete the two-factor authentication method provided by the technical solution of the present disclosure. For example, the non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.
[0206] It should be noted that the embodiments of this application may involve the use of user data. In actual applications, user-specific personal data can be used in the solutions described herein within the scope permitted by applicable laws and regulations of the country where it is located (for example, with the user's explicit consent, giving the user a practical notice, etc.).
[0207] Although this application is disclosed above in preferred embodiments, it is not intended to limit this application. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of this application. Therefore, the protection scope of this application should be determined by the scope defined by the claims of this application.
[0208] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0209] Memory may include non-permanent memory in computer-readable media, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0210] 1. Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media, such as modulated data signals and carrier waves.
[0211] 2. Persons skilled in the art should understand that the embodiments of this application can be provided as a method, a system, or a computer program product. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
Claims
1. A two-factor authentication system, characterized in that, Including: The application system client is used to log in to the application system server according to the user password; respond to the user usage instruction, and read the employee identity information from the employee work card based on near-field communication; According to the employee identity information, send a passwordless authentication request to the identity authentication server; If the identity authentication server passes the passwordless authentication, display the client page; The identity authentication server is used to obtain the employee work card data set; receive the request; perform passwordless authentication according to the employee work card data set and the employee identity information carried in the request; Provide the passwordless authentication result to the client.
2. A two-factor authentication method for an application system client, characterized in that, Including: Log in to the application system server according to the user password; Respond to the user usage instruction, and read the employee identity information from the employee work card based on near-field communication; According to the employee identity information, send a passwordless authentication request to the identity authentication server; If the identity authentication server passes the passwordless authentication, display the client page.
3. The method according to claim 2, wherein It further includes: Obtain the network environment information used by the client device; According to the network environment information, determine whether to perform passwordless authentication processing on the use of the client; If the judgment result is yes, send a passwordless authentication request to the identity authentication server.
4. The method according to claim 2, wherein It further includes: Detect whether the client device supports a near-field communication device; If the detection result is yes, read the employee identity information from the employee work card based on near-field communication.
5. The method according to claim 2, wherein It further includes: Perform encryption processing on the employee identity information; The step of sending a passwordless authentication request to the identity authentication server according to the employee identity information includes: Send a passwordless authentication request to the identity authentication server according to the encrypted employee identity information.
6. The method according to claim 5, characterized in that, The step of performing encryption processing on the employee identity information includes: Obtain the signature information of the application system; According to the signature information, perform encryption processing on the employee identity information.
7. According to the method described in claim 5, characterized in that The request includes first replay detection data; The step of performing encryption processing on the employee identity information includes: Obtain the first replay detection data; According to the first replay detection data, perform encryption processing on the employee identity information.
8. A two-factor authentication method for an authentication server, characterized in that, Including: Obtain the employee work card data set; Receive the passwordless authentication request sent by the application system client, the request includes employee identity information, the employee identity information is read by the client from the employee work card based on near-field communication, the client reads the employee identity information from the work card according to the user usage instruction, and the client has logged in to the application system server according to the user password; Perform passwordless authentication according to the employee work card data set and the employee identity information carried in the request; Provide the passwordless authentication result to the client.
9. A page access device for an application system client, characterized in that, Including: The user login unit is used to log in to the application system server according to the user password; The data reading unit is used to respond to the user usage instruction and read the employee identity information from the employee work card based on near-field communication; The request sending unit is used to send a passwordless authentication request to the identity authentication server according to the employee identity information; A page display unit, configured to display a client page if the authentication server passes passwordless authentication.
10. A page access device for an authentication server, characterized in that, Comprising: A data acquisition unit, configured to acquire an employee work ID dataset; A request receiving unit, configured to receive a passwordless authentication request sent by a client of an application system, where the request includes employee identity information read by the client from an employee work ID based on near-field communication, the client reads the employee identity information from the employee work ID according to a user usage instruction, and the client has logged in to the application system server according to a user password; An authentication unit, configured to perform passwordless authentication according to the employee work ID dataset and the employee identity information carried in the request; A result providing unit, configured to provide a passwordless authentication result to the client.
11. An instant messaging client, characterized in that, Comprising: A user password login unit, configured to log in to an instant messaging server according to a user password; A user data reading unit, configured to respond to a user usage instruction and read employee identity information from an employee work ID based on near-field communication; A request sending unit, configured to send a passwordless authentication request to the authentication server according to the employee identity information; A page display unit, configured to display a user page of an instant messaging tool if the authentication server passes passwordless authentication.
12. A privacy data processing client, characterized in that, Comprising: A user password login unit, configured to log in to a privacy data processing server according to a user password; A user data reading unit, configured to respond to a user usage instruction and read employee identity information from an employee work ID based on near-field communication; A request sending unit, configured to send a passwordless authentication request to the authentication server according to the employee identity information; If the authentication server passes passwordless authentication, display a privacy data processing page.
13. An information publishing client, characterized in that, Comprising: A user password login unit, configured to log in to an information publishing server according to a user password; A user data reading unit, configured to respond to a user usage instruction and read employee identity information from an employee work ID based on near-field communication; A request sending unit, configured to send a passwordless authentication request to the authentication server according to the employee identity information; If the authentication server passes passwordless authentication, display an information publishing page.
14. An electronic device, characterized in that, Comprising: A processor; And A memory, configured to store a program for implementing the method according to any one of claims 2 to 8, and the device is powered on and runs the program of the method through the processor.