Authentication method, device and storage medium for accessing a forensic device to a platform
By real-name authentication, generation of unique serial number and device consistency verification when the forensic equipment is connected to the platform, combined with back-end security control and authorization time limit, the security risks and insufficient communication problems of the forensic equipment access platform are solved, and safe and reliable data resource requests and real-time communication are achieved.
Patent Information
- Application Number
- CN201911380973.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-12-27
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2039-12-27
AI Technical Summary
The authentication method of the existing evidence-for-sale device access platform is single, with security risks and lack of real-time communication, so it is impossible to effectively manage and monitor the online status and operation information of the equipment.
By registering and real-name authentication of evidence forensic devices on the platform, combining voiceprint and face authentication, a unique device serial number is generated, and device information is obtained through browser plug-ins for consistency verification. Back-end security control and authorization time limit are adopted, and a variety of authentication methods are supported, including binding devices and IP addresses, providing real-time messaging and logging.
It improves the security of the forensic device access platform and the legality of data resource requests, prevents the misappropriation of device authorization information, realizes IoT operations and real-time communication between the platform and the device, and ensures the legality and traceability of data access.
Smart Images

Figure CN111030816B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of evidence collection equipment, and in particular to an authentication method, device and storage medium for accessing an evidence collection equipment to a platform. Background Art
[0002] The use of front-end forensic devices connected to platforms and interoperating with them is becoming increasingly common. This interoperability allows the platform to more effectively leverage its data and better empower front-end forensic devices with its data resources. Therefore, research on an IoT-enabled security authentication system for front-end forensic devices connected to platforms is extremely important.
[0003] By default, front-end forensic devices perform evidence collection and analysis operations independently of the platform. Their primary data source is data captured by the devices, which is then uploaded to the platform for aggregation. The data resources available on the devices are relatively limited and limited. To access the platform's resource data, the devices must be connected to the platform. Furthermore, the platform should monitor and manage each device, monitoring its online status and recording its operational information. Because each front-end forensic device has different application scenarios, manufacturers, and models, compatibility with various front-end devices is required, requiring consideration of universal access standards and authorization authentication methods.
[0004] The existing methods of connecting front-end forensic equipment to the platform mainly include the following:
[0005] (1) The front-end evidence collection device does not require any authentication and can access the platform through the service interface provided by the platform to request data and interact with the platform.
[0006] (2) The front-end forensic device is verified using the authorization code provided by the platform, and can access the platform after passing the verification.
[0007] (3) The front-end forensic equipment is verified through the license, and the platform is also verified through the license, but the verification is based on the platform or the forensic equipment itself, and the access authentication method is not verified.
[0008] The above three methods are currently the primary authentication methods for front-end forensic equipment accessing the platform. These single authentication methods make it easy to fabricate information and gain anonymous access, posing certain security risks. Furthermore, the data communication between the forensic equipment and the platform is limited, lacking bidirectional, IoT-enabled, real-time communication. Summary of the Invention
[0009] In response to the aforementioned problems of single authentication method for front-end evidence collection equipment in accessing the platform, high security risks, and inability to conduct real-time communication, the embodiment of this application aims to propose an authentication method and apparatus for accessing the platform of evidence collection equipment to solve the technical problems mentioned in the above background technology section.
[0010] In a first aspect, an embodiment of the present application provides an authentication method for accessing a forensic device to a platform, comprising the following steps:
[0011] S1: Register the evidence collection device on the platform and register the user using the evidence collection device with real name for identity authentication;
[0012] S2: When a resource request is made to the platform, risk management is performed on the resource request by submitting a query for approval and logging access via forensic devices;
[0013] S3: After the query is approved, the evidence collection device logs into the platform and performs login verification on the user's identity information and the data interface required for resource requests;
[0014] S4: After passing the login verification, perform local verification on the browser to obtain real-time information of the forensic device for verification; and
[0015] S5: After passing local verification, back-end security control is used to restrict access to the forensic device.
[0016] In some embodiments, step S1 includes the following steps:
[0017] S11: Generate a forensic device serial number that uniquely identifies the forensic device through an encryption algorithm based on the device information of the forensic device;
[0018] S12: The user registers with real name and enters voiceprint information and facial information; and
[0019] S13: Authenticate the user through voiceprint authentication or face authentication.
[0020] Through encryption algorithms, voiceprint authentication and face authentication, the security of registered user information can be guaranteed during registration, and the user's identity information can be verified.
[0021] In some embodiments, the real-time information includes the MAC address of the forensic device. The MAC address can be used to identify the location of a network device and uniquely identify a network card within the network. This prevents the device's authorization information from being misappropriated and used after login verification has been passed.
[0022] In some embodiments, after identity authentication, the platform generates a unique token corresponding to the user and includes the token in all subsequent resource requests. The token information has a certain timeliness, which can ensure the legality and security of data resource requests.
[0023] In some embodiments, step S2 includes the following steps:
[0024] S21: When making a resource request to the platform, the user submits the query approval to the user's superior for approval confirmation;
[0025] S22: When approving a request, the user's supervisor queries the log records of the forensic device to prohibit access to any forensic device with unusual access behavior. Approval verification is first performed to verify the legitimacy of the user and resource request. Furthermore, manual intervention can be performed on devices with unusual access behavior to achieve effective risk management.
[0026] In some embodiments, step S3 includes the following steps:
[0027] S31: The platform receives a resource request and indicates whether the resource request proposed by the user needs to be intercepted and verified by annotating the interface;
[0028] S32: Jump to the interception verification class through the interceptor corresponding to the interface annotation to perform identity authentication and permission verification.
[0029] After approval by the user's superior, you can log in to the device to request resources, and perform login verification by setting up an interception verification rule engine.
[0030] In some embodiments, step S4 includes the following steps:
[0031] S41: obtaining real-time information of the forensic device through the browser plug-in, and generating a verification serial number of the forensic device according to the generation rules of the machine information;
[0032] S42: Determine whether the verification serial number is consistent with the serial number of the evidence collection device. If so, the evidence collection device requests access; otherwise, the evidence collection device's request for access is restricted.
[0033] To prevent the unauthorized use of device authorization information, when the forensic device information is requested through the browser, the browser plug-in will automatically obtain the MAC address of the device information to verify the consistency of the device, thereby effectively improving the security of resource requests.
[0034] In some embodiments, after passing the local verification, the process further includes: waking up the software on the evidence collection device locally through the browser, operating the evidence collection device through the software, and communicating with the platform through the software. The evidence collection device is operated and connected through real-time messaging.
[0035] In some embodiments, backend security management and control include binding the device to the evidence collection device using its MAC address, binding an IP address, or a combination of both. Binding the device to the evidence collection device uses the device's MAC address, while IP binding allows the evidence collection device to request operations at the corresponding IP address. Backend security management and control can effectively prevent the theft of device authorization information and scenarios where device serial numbers and identity tokens can be used to anonymously access data resources.
[0036] In some embodiments, step S5 further includes restricting access to the evidence collection device using authorization time control after backend security control has been passed. The authorization time is a time period set based on the application scenario of the evidence collection device, and access to the evidence collection device after the authorization time period has expired is restricted. Authorization time control can maintain different time periods for different application scenarios of the evidence collection device, effectively controlling and preventing resource waste and leakage.
[0037] In some embodiments, the platform uses an interceptor corresponding to the interface annotation to jump to the logging implementation class to record all resource request information to form a log record. The logging implementation class logs the intercepted logging request and records the data request in a unified log format, ensuring that the process of accessing the platform after the device is connected can be tracked and the data can be traced.
[0038] In the second aspect, an embodiment of the present application also proposes an authentication device for accessing a forensic device to a platform, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of any one of the methods in the first aspect when executing the computer program.
[0039] In a third aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in any implementation manner in the first aspect.
[0040] Embodiments of the present application provide a method and apparatus for authenticating forensic devices accessing a platform. This method generates a unique serial number for the device according to specific encryption rules and algorithms during device registration. It also provides real-name identity authentication control via voiceprint and facial recognition. Furthermore, data resource requests from the device can be manually verified through manual query and approval. Risk management is implemented by manually disabling device access to devices exhibiting abnormal behavior. Login verification is performed through a unified rule engine, verifying the logged-in identity and requested resource data. This method and apparatus provides device consistency verification when front-end data resource requests are made, obtaining device information through a browser plug-in. The platform can directly wake up the device client to perform business operations, providing IoT-connected operations between the platform and the device. This method and apparatus supports multiple authentication methods, such as device binding and IP binding, providing back-end security control and authorization time control within a specified time period. This is suitable for resource requests from trial devices and also enables real-time messaging between the platform and the device. All resource requests are logged through defined unified log audit rules. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0042] Figure 1 is a diagram of an exemplary device architecture to which an embodiment of the present application may be applied;
[0043] Figure 2 A flowchart of an authentication method for accessing a forensic device to a platform according to an embodiment of the present invention;
[0044] Figure 3 Schematic diagram of the process of step S1 of the authentication method for accessing a forensic device to a platform according to an embodiment of the present invention;
[0045] Figure 4 Schematic diagram of the process of step S2 of the authentication method for accessing a forensic device to a platform according to an embodiment of the present invention;
[0046] Figure 5 Schematic diagram of the process of step S3 of the authentication method for accessing the evidence collection device to the platform according to an embodiment of the present invention;
[0047] Figure 6 Schematic diagram of the process of step S4 of the authentication method for accessing a forensic device to a platform according to an embodiment of the present invention;
[0048] Figure 7It is a structural diagram of a computer device suitable for implementing the electronic device of the embodiment of the present application. DETAILED DESCRIPTION
[0049] To make the objectives, technical solutions, and advantages of the present invention more apparent, the present invention will be further described in detail below with reference to the accompanying drawings. It is apparent that the embodiments described are only some, not all, of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort are intended to fall within the scope of protection of the present invention.
[0050] Figure 1 An exemplary device architecture 100 is shown, to which an authentication method for accessing a forensic device to a platform or an authentication device for accessing a forensic device to a platform according to an embodiment of the present application can be applied.
[0051] like Figure 1 As shown, the device architecture 100 may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0052] Users can use terminal devices 101, 102, 103 to interact with server 105 via network 104 to receive or send messages, etc. Various applications, such as data processing applications and file processing applications, can be installed on terminal devices 101, 102, 103.
[0053] Terminal devices 101, 102, and 103 can be hardware or software. When terminal devices 101, 102, and 103 are hardware, they can be various electronic devices, including but not limited to smartphones, tablet computers, laptop computers, and desktop computers. When terminal devices 101, 102, and 103 are software, they can be installed in the electronic devices listed above. They can be implemented as multiple software or software modules (for example, software or software modules used to provide distributed services), or they can be implemented as a single software or software module. No specific limitations are given here.
[0054] The server 105 may be a server that provides various services, such as a background data processing server that processes files or data uploaded by the terminal devices 101, 102, and 103. The background data processing server may process the acquired files or data and generate processing results.
[0055] It should be noted that the authentication method for a forensic device access platform provided in the embodiment of the present application can be executed by the server 105 or by the terminal devices 101, 102, and 103. Accordingly, an authentication device for a forensic device access platform can be set in the server 105 or in the terminal devices 101, 102, and 103.
[0056] It should be understood that Figure 1 The number of terminal devices, networks, and servers in the above description is merely illustrative. Any number of terminal devices, networks, and servers may be provided as needed. If the processed data does not need to be acquired remotely, the above-described apparatus architecture may not include a network, but only require servers or terminal devices.
[0057] Figure 2 The embodiment of the present application discloses an authentication method for accessing a forensic device to a platform, including the following steps:
[0058] S1: Register the evidence collection device on the platform and register the user using the evidence collection device with real name for identity authentication.
[0059] In a specific embodiment, device registration is the first step for a forensic device to access the platform. Only after the forensic device is registered on the platform can it have access to the relevant resource information provided by the platform. Figure 3 As shown, step S1 includes the following steps:
[0060] S11: Generate a unique device serial number that uniquely identifies the device using an encryption algorithm based on the device information. In a preferred embodiment, the device information is the MAC address, which is used to identify the device's location and also uniquely identifies the device's network card. A unique 32-bit device serial number is generated using an encryption algorithm. In a preferred embodiment, the encryption algorithm includes the MD5 algorithm or the DES algorithm. The device serial number is used to identify the device, and a registration application is submitted on the platform.
[0061] S12: The user registers with real name and enters voiceprint information and facial information.
[0062] S13: Authenticate the user through voiceprint authentication or face authentication.
[0063] Voiceprint and facial authentication can be selected based on the specific scenario. Both require real-name registration and the entry of voiceprint and facial information. Only individuals with real-name authentication can operate the device and access the platform, ensuring human-machine integration for data access. In a preferred embodiment, after identity authentication, the platform generates a unique token corresponding to the user and includes this token in all subsequent resource requests. This token information is time-sensitive, ensuring the legality and security of data resource requests.
[0064] S2: When a resource request is made to the platform, risk management is performed on the resource request by submitting a query for approval and logging access via forensic devices.
[0065] In a specific embodiment, Figure 4 As shown, step S2 includes the following steps:
[0066] S21: When making a resource request to the platform, the user submits the query approval to the user's superior for approval and confirmation; only after the user's superior approves it can the data resource query application be initiated.
[0067] S22: When approving a request, the user's supervisor queries the log records of the forensic device to prohibit access to any device with abnormal access behavior. The log records include the current resource request log and previous resource request logs. When approving a request, the user's supervisor can review the resource request logs of the forensic device and manually intervene to disable all access to any device with abnormal access behavior. Once the access behavior is confirmed to be normal, access to the device can be restored.
[0068] S3: After passing the query approval, the evidence collection device logs into the platform and performs login verification on the user's identity information and the data interface required for resource requests.
[0069] In a specific embodiment, after the user's superior has approved it, the user can log in to the device to request resources, and perform login verification by setting a rule engine for interception verification. Figure 5 As shown, step S3 includes the following steps:
[0070] S31: The platform receives a resource request and indicates whether the resource request proposed by the user needs to be intercepted and verified by annotating the interface;
[0071] S32: Jump to the interception verification class through the interceptor corresponding to the interface annotation to perform identity authentication and permission verification.
[0072] S4: After passing the login verification, perform local verification on the browser to obtain real-time information of the forensic device for verification.
[0073] In a specific embodiment, Figure 6 As shown, step S4 includes the following steps:
[0074] S41: obtaining real-time information of the forensic device through the browser plug-in, and generating a verification serial number of the forensic device according to the generation rules of the machine information;
[0075] S42: Determine whether the verification serial number is consistent with the serial number of the evidence collection device. If so, the evidence collection device requests access; otherwise, the evidence collection device's request for access is restricted.
[0076] In a preferred embodiment, real-time information includes the MAC address of the forensic device. To prevent the unauthorized access and use of device authorization information, when requesting forensic device information through a browser, a browser plug-in automatically obtains the device's MAC address to verify device consistency, effectively improving the security of resource requests.
[0077] In a specific embodiment, after local verification, the process also includes: waking up the software on the forensic device locally through a browser, operating the forensic device through the software, and communicating with the platform through the software. The forensic device is operated and connected via real-time messaging. The platform supports instrumented operations with the device, allowing direct operation of related services on the device and pushing data to the forensic device client software. This instrumented operation between the device and the platform simplifies the device's authentication, login, and operation processes.
[0078] S5: After passing local verification, back-end security control is used to restrict access to the forensic device.
[0079] In specific embodiments, backend security management and control include binding a forensic device, binding an IP address, or a combination of binding a forensic device and binding an IP address. Binding a forensic device binds the device to the forensic device via its MAC address, while binding an IP address allows the forensic device to request an operation at the corresponding IP address. Binding a forensic device and binding an IP address is a combination of the two methods, requiring both MAC address compliance and access requests from a fixed IP address. Backend security management and control can effectively prevent the theft of device authorization information and scenarios where device serial numbers and identity tokens are used to anonymously access data resources.
[0080] In a specific embodiment, step S5 also includes restricting access to the evidence collection device using authorization time control after back-end security control. Each piece of evidence collection device authorization requires a set authorization time, which is a time period set based on the application scenario of the evidence collection device. Access to the evidence collection device after the authorization time period has expired is restricted. Authorization time control can maintain different time periods for different application scenarios of the evidence collection device, effectively controlling and preventing resource waste and leakage. For example, resource requests primarily for trial devices can be assigned a shorter time period, while formal purchases can be assigned a longer time period or no restrictions.
[0081] In a specific embodiment, the platform uses an interceptor corresponding to the interface annotation to jump to the logging implementation class to record all resource request information to form a log record. The logging implementation class logs the intercepted logging requests and logs the data requests in a unified log format, ensuring that the process of accessing the platform after the device is connected can be tracked and the data can be traced.
[0082] According to another aspect of the present invention, there is provided an authentication device for accessing a forensic device to a platform, comprising a storage device and a processor;
[0083] The storage device stores program codes for implementing corresponding steps in the authentication method for accessing a forensic device to a platform according to an embodiment of the present invention;
[0084] The processor is configured to run the program code stored in the storage device to execute corresponding steps of the authentication method for accessing a forensic device to a platform according to an embodiment of the present invention.
[0085] In one embodiment, when the program code is executed by the processor, corresponding steps of the authentication method for accessing the forensic device to the platform according to the embodiment of the present invention are executed.
[0086] Embodiments of the present application provide a method and apparatus for authenticating forensic devices accessing a platform. This method generates a unique serial number for the device according to specific encryption rules and algorithms during device registration. It also provides real-name identity authentication control via voiceprint and facial recognition. Furthermore, data resource requests from the device can be manually verified through manual query and approval. Risk management is implemented by manually disabling device access to devices exhibiting abnormal behavior. Login verification is performed through a unified rule engine, verifying the logged-in identity and requested resource data. This method and apparatus provides device consistency verification when front-end data resource requests are made, obtaining device information through a browser plug-in. The platform can directly wake up the device client to perform business operations, providing IoT-connected operations between the platform and the device. This method and apparatus supports multiple authentication methods, such as device binding and IP binding, providing back-end security control and authorization time control within a specified time period. This is suitable for resource requests from trial devices and also enables real-time messaging between the platform and the device. All resource requests are logged through defined unified log audit rules.
[0087] Reference below Figure 7 , which shows an electronic device (eg Figure 1 A structural diagram of a computer device 700 (server or terminal device shown). Figure 7 The electronic device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0088] like Figure 7 As shown, the computer device 700 includes a central processing unit (CPU) 701 and a graphics processing unit (GPU) 702, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 703 or the program loaded from the storage part 709 to the random access memory (RAM) 704. Various programs and data required for the operation of the device 700 are also stored in the RAM 704. The CPU 701, GPU 702, ROM 703 and RAM 704 are connected to each other via a bus 705. An input / output (I / O) interface 706 is also connected to the bus 705.
[0089] The following components are connected to the I / O interface 706: an input section 707 including a keyboard, a mouse, and the like; an output section 708 including a display such as a liquid crystal display (LCD), a speaker, and the like; a storage section 709 including a hard disk and the like; and a communication section 710 including a network interface card such as a LAN card or a modem. The communication section 710 performs communication processing via a network such as the Internet. A drive 711 may also be connected to the I / O interface 706 as needed. A removable medium 712, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, and the like, is installed in the drive 711 as needed, so that a computer program read therefrom can be installed into the storage section 709 as needed.
[0090] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication part 710, and / or installed from a removable medium 712. When the computer program is executed by the central processing unit (CPU) 701 and the graphics processing unit (GPU) 702, the above-mentioned functions defined in the method of the present application are executed.
[0091] It should be noted that the computer-readable medium described in this application may be a computer-readable signal medium or a computer-readable medium, or any combination of the two. Computer-readable media may be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor devices, apparatuses, or components, or any combination thereof. More specific examples of computer-readable media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this application, a computer-readable medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution device, apparatus, or component. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution apparatus, device, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wireline, optical cable, RF, or any suitable combination thereof.
[0092] Computer program code for performing the operations of the present application can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0093] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the devices, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based device that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0094] The modules described in the embodiments of the present application may be implemented by software or hardware.
[0095] As another aspect, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or it may exist independently and not be assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by the electronic device, the electronic device: registers the forensic device on the platform, and performs real-name registration for the user using the forensic device for identity authentication; when a resource request is made to the platform, the resource request is risk-controlled by submitting a query approval and logging the access of the forensic device; after the query approval, the forensic device logs in to the platform and performs login verification on the user's identity information and the data interface required for the resource request; after the login verification, a local verification is performed on the browser to obtain real-time information of the forensic device for verification; and after the local verification, the access to the forensic device is restricted by back-end security control.
[0096] The above description is merely a preferred embodiment of the present application and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also encompasses other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned inventive concept. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. A method for authenticating a forensic device access platform, characterized in that: The following steps are involved: S1: Register the evidence collection device on the platform and register the user using the evidence collection device with real name for identity authentication; S2: When a resource request is made to the platform, risk management is performed on the resource request by submitting a query for approval and logging accessed by the forensic device; S3: After the query is approved, the evidence collection device logs into the platform and performs login verification on the user's identity information and the data interface required for the resource request; S4: After passing the login verification, perform local verification on the browser to obtain real-time information of the evidence collection device for verification; and S5: After passing the local verification, back-end security control is used to restrict access to the evidence collection device.
2. The authentication method for accessing a forensic device to a platform according to claim 1, characterized in that: The step S1 comprises the following steps: S11: Generate a forensic device serial number that uniquely identifies the forensic device through an encryption algorithm based on the device information of the forensic device; S12: The user performs real-name registration and enters voiceprint information and facial information; and S13: Authenticate the user through voiceprint authentication or face authentication.
3. The authentication method for accessing a forensic device to a platform according to claim 2, characterized in that: The real-time information includes the MAC address of the evidence collection device.
4. The authentication method for accessing a forensic device to a platform according to claim 1, wherein: After the identity authentication is passed, the platform generates unique token information corresponding to the user and carries the token information in all subsequent resource requests.
5. The authentication method for accessing a forensic device to a platform according to claim 1, wherein: The step S2 comprises the following steps: S21: When issuing a resource request to the platform, the user submits the query approval to the user's superior for approval confirmation; S22: The superior of the user queries the log record of the evidence collection device when performing the approval operation to prohibit the evidence collection device with abnormal access behavior from accessing.
6. The authentication method for accessing a forensic device to a platform according to claim 1, characterized in that: The step S3 comprises the following steps: S31: The platform receives the resource request and indicates whether to intercept and verify the resource request submitted by the user by marking an interface annotation; S32: Jump to the interception verification class through the interceptor corresponding to the interface annotation to perform identity authentication and permission verification.
7. The authentication method for accessing a forensic device to a platform according to claim 2, wherein: The step S4 comprises the following steps: S41: obtaining real-time information of the evidence collection device through a browser plug-in, and generating a verification serial number of the evidence collection device according to a generation rule of the machine information; S42: Determine whether the verification serial number is consistent with the serial number of the evidence collection device. If so, the evidence collection device requests access; otherwise, the evidence collection device's request for access is restricted.
8. The authentication method for accessing a forensic device to a platform according to claim 1, wherein: After passing the local verification, the method further includes: locally waking up the software on the forensic device through the browser, operating the forensic device through the software, and communicating messages with the platform through the software.
9. The authentication method for accessing a forensic device to a platform according to claim 1, wherein: The back-end security management and control includes binding the evidence device, binding the IP or combining the binding of the evidence device and the binding IP. The binding of the evidence device is performed by binding the evidence device through the MAC address of the evidence device, and the binding of the IP is performed by requesting operations on the corresponding IP address through the evidence device.
10. The authentication method for accessing a forensic device to a platform according to claim 1, wherein: The step S5 also includes restricting access to the evidence collection device by using authorization time control after passing the back-end security control. The authorization time is a time period set according to the application scenario of the evidence collection device, and access to the evidence collection device that exceeds the authorization time is restricted.
11. The authentication method for accessing a forensic device to a platform according to claim 6, wherein: On the platform, the interceptor corresponding to the interface annotation jumps to the logging implementation class to record information of all resource requests to form the log record.
12. An authentication device for accessing a forensic device to a platform, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.
13. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a computer, the steps of the method according to any one of claims 1 to 11 are implemented.
Citation Information
Patent Citations
Automated acquisition of volatile forensic evidence from network devices
US20100299430A1
Terminal verification method and apparatus based on narrowband internet of things
WO2019134565A1