A page jump method, system and device

By two-factor verification of the page jump request of HTML5 application and obtaining encrypted credentials, the problem of cumbersome and low security in the financial field is solved, and a login-free and secure page jump is achieved.

CN113312576BActive Publication Date: 2025-07-22WEBANK (CHINA)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110604337.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-31
Publication Date
2025-07-22
Estimated Expiration
2041-05-31

AI Technical Summary

Technical Problem

In the prior art, HTML5 applications require two logins during page redirection in the financial field, resulting in cumbersome business processes and low security.

Method used

By performing the first-level network security verification and the second-level partner information verification on the jump request, the encrypted credentials can be obtained to achieve login-free jumps to ensure information security.

Benefits of technology

Simplifies the jump process, improves security, avoids repeated login steps and enhances the security of information delivery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113312576B_ABST
    Figure CN113312576B_ABST
Patent Text Reader

Abstract

The present invention discloses a page jump method, system and device. The method is as follows: receiving a login initial credential and partner information obtained based on a jump request corresponding to a first page; performing a first-level security verification on the jump request; the first-level security verification is used for network security verification; when the first-level verification passes, performing a second-level verification process on the application ID and key in the partner information; the second-level verification is used to verify whether the partner information is preset available information; when the second-level verification passes, obtaining the login initial credential, and encrypting the basic account information for logging in to the first page to obtain an encrypted credential; the basic account information for logging in to the first page is the information in the login initial credential; sending the encrypted credential to the server corresponding to the first page, so that the first page can jump to the second page without password based on the encrypted credential.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of financial technology (Fintech), and in particular, to a page jump method, system and device. Background Art

[0002] With the development of computer technology, more and more technologies are applied in the financial field. The traditional financial industry is gradually transforming into financial technology. However, due to the security and real-time requirements of the financial industry, higher requirements are also put forward for technologies.

[0003] HTML5 applications have been increasingly used due to their advantages such as no need to download installation packages and real-time updates. Based on this feature of HTML5 applications, HTML5 applications are gradually applied to the field of financial technology to provide more convenient services for financial enterprises or their customers. Some financial institutions often rely on HTML5 applications to implement auxiliary functions to make it more convenient and flexible for users to operate.

[0004] Specifically, when a user operates on an H5 page corresponding to a partner cooperating with a financial institution and jumps from the H5 page to the financial institution page, it is necessary to log in again based on the user account and key corresponding to the partner. Such a jump method has a cumbersome business process, that is, 1 product requires 2 sets of account password login systems, which reduces the user experience. Summary of the Invention

[0005] The present invention provides a page jump method, system and device, which solve the problems of cumbersome page jump verification and low security in the prior art.

[0006] In a first aspect, the present invention provides a page jump method, including: obtaining a login initial credential and partner information from a received jump request; wherein, the jump request is triggered based on a first page; performing a first-level security verification on the jump request; the first-level security verification is used for network security verification; when the first-level verification passes, performing a second-level verification process on the application ID and key in the partner information; the second-level verification is used to verify whether the partner information is preset available information; when the second-level verification passes, obtaining the login initial credential, and encrypting the basic account information for logging in to the first page to obtain an encrypted credential; sending the encrypted credential to the server corresponding to the first page, so that the server triggers the first page to jump to the second page without logging in while carrying the encrypted credential.

[0007] In the above method, before directly jumping from the first page to the second page without logging in, first, network security verification is performed on the first page to ensure that the first page is a secure page. Then, the partner information is verified to determine whether it is the information of a pre-established partner. When both verifications pass, the basic information of the account logged in to the first page is encrypted. Thus, the first page jumps to the second page without logging in again while carrying an encrypted credential, reducing the number of jump steps. Moreover, since both the partner information and the initial login credential are verified, it is ensured as much as possible that the information corresponding to the page before the jump is secure, enhancing the security of page jumps.

[0008] Optionally, the first-level security verification of the jump request includes: determining whether the certificate of the partner corresponding to the jump request is a pre-issued certificate; when it is determined that the certificate of the partner corresponding to the jump request is a pre-issued certificate, determining the IP address of the partner; determining whether the IP address belongs to a preset whitelist. If the IP address belongs to the preset whitelist, it is determined that the first-level security verification passes.

[0009] In the above method, the certificate of the partner is verified, and the first-level security verification is performed based on the IP address of the partner belonging to the preset whitelist, that is, the first-level security verification is performed by using the method of https two-way certificate authentication and whitelist verification. Such a method can quickly and efficiently implement the first-level security verification.

[0010] Optionally, the second-level verification process for the application ID and key in the partner information includes: determining whether the application ID and key in the partner information belong to a preset data pair, where the preset data pair includes the one-to-one correspondence relationship between the pre-set application ID and key; if it is determined that the application ID and key in the partner information belong to the preset data pair, determining the background IP information corresponding to the application ID; determining whether the background IP information is available; if it is determined that the background IP information is available, it is determined that the second-level verification process passes.

[0011] In the above method, it is first determined whether the application ID and key in the partner information belong to a preset data pair, that is, based on the one-to-one correspondence between the application ID and the key, it is jointly determined whether the partner information is the information of the pre-established cooperation object. In this way, the problem of the application ID being stolen and resulting in the verification being passed can be avoided, which increases the difficulty of verification. Further, when it is determined that the application ID and key in the partner information belong to the preset data pair, it can be determined whether the background IP information corresponding to the application ID is available. When it is determined to be available, it is determined that the second verification is passed. In other words, after determining that the partner information is pre-established information, it is also necessary to determine whether the background IP information corresponding to the application ID is legal. When it is determined to be legal, the verification is passed, that is, the verification steps are more detailed and security is improved.

[0012] Optionally, the encrypting the basic information of the account used to log in to the first page to obtain an encrypted credential includes: using an AES algorithm, taking a predetermined number of bits of the key in the partner information and a predetermined number of bits of the random value as a key, encrypting the basic information of the account to obtain a first encryption result; performing base64 encoding on the first encryption result to obtain an encrypted credential.

[0013] In the above method, the basic account information is encrypted twice, which increases the complexity of decrypting the basic account information, thereby ensuring the security of the transmission of the basic account information as much as possible.

[0014] Optionally, after the first page carries the encrypted credential and jumps to the second page without logging in, the method further includes: obtaining the encrypted credential carried by the first page; querying from the browser cache cookie whether the encrypted credential is not expired and has not been verified; if it is determined that the encrypted credential is not expired and has not been verified, obtaining the user login state capToken corresponding to the encrypted credential in the cookie, and determining the basic account information based on the capToken, so as to perform business processing based on the basic account information.

[0015] The above method provides a solution for obtaining basic account information after jumping from the first page to the second page without logging in. This solution can directly obtain basic account information from capToken without the need to carry the basic account information directly when jumping to the page, thus preventing the basic account information from being stolen.

[0016] Optionally, the capToken is obtained by encrypting the application ID in the partner information, the basic account information and the current timestamp.

[0017] In the above method, a way to obtain the capToken is provided, that is, the capToken is obtained by encrypting the application ID in the partner information, the basic account information, and the current timestamp, providing a good implementation basis for obtaining the basic account information based on the capToken subsequently.

[0018] Optionally, the encryption credential is stored in the database corresponding to the browser cache cookie and / or the redis server.

[0019] In the above method, the encryption credential is stored in the database and / or the redis server, and the database and / or the redis server are good disaster recovery backup storage spaces, so as to ensure the security of the encryption credential as much as possible.

[0020] In a second aspect, the present invention provides a page jump device, including: an acquisition unit, configured to acquire a login initial credential and partner information from a received jump request; wherein, the jump request is triggered based on a first page; a first verification unit, configured to perform a first-level security verification on the jump request; the first-level security verification is used for network security verification; a second verification unit, configured to, when the first-level verification passes, perform a second-level verification process on the application ID and the key in the partner information; the second-level verification is used to verify whether the partner information is preset available information; a processing unit, configured to, when the second-level verification passes, acquire the login initial credential, and encrypt the basic account information for logging in to the first page to obtain an encryption credential; a jump unit, configured to send the encryption credential to the server corresponding to the first page, so that the server triggers the first page to carry the encryption credential and jump to the second page without logging in.

[0021] Optionally, the first verification unit is configured to: determine whether the certificate of the partner corresponding to the jump request is a pre-issued certificate; after determining that the certificate of the partner corresponding to the jump request is a pre-issued certificate, determine the IP address of the partner; determine whether the IP address belongs to a preset white list, and if the IP address belongs to the preset white list, determine that the first-level security verification passes.

[0022] Optionally, the second verification unit is configured to: determine whether the application ID and the key in the partner information belong to a preset data pair, where the preset data pair includes a one-to-one correspondence between a preset application ID and a key; if it is determined that the application ID and the key in the partner information belong to the preset data pair, determine the background IP information corresponding to the application ID; determine whether the background IP information is available; if it is determined that the background IP information is available, determine that the second-level verification process passes.

[0023] Optionally, the processing unit is configured to: use the AES algorithm, use the predetermined number of digits of the key in the partner information and the predetermined number of digits of the random value as the key, encrypt the basic account information to obtain a first encryption result; perform base64 encoding on the first encryption result to obtain an encryption credential.

[0024] Optionally, the apparatus further includes a third verification unit, configured to: obtain the encryption credential carried by the first page; query from the browser cache cookie whether the encryption credential has not expired and has not been verified; if it is determined that the encryption credential has not expired and has not been verified, obtain the user login state capToken corresponding to the encryption credential in the cookie, and determine the basic account information based on the capToken, so as to perform service processing based on the basic account information.

[0025] Optionally, the capToken is obtained by encrypting the application ID in the partner information, the basic account information, and the current timestamp.

[0026] Optionally, the encryption credential is stored in the database corresponding to the browser cache cookie and / or the redis server.

[0027] For the beneficial effects of the second aspect and each optional device of the second aspect, reference may be made to the beneficial effects of the first aspect and each optional method of the first aspect, which will not be elaborated here.

[0028] In a third aspect, the present invention provides a page jump system, the system includes a first server and a second server, wherein: the first server is configured to send a credential acquisition request to the second server based on a jump request triggered by a received first page; the second server is configured to perform a first-level security verification on the jump request based on the credential acquisition request, and when it is determined that the first-level verification passes, perform a second-level security verification on the application ID and the key in the partner information obtained based on the jump request; and when it is determined that the second-level verification passes, obtain a login initial credential obtained based on the jump request, encrypt the basic account information for logging in to the first page to obtain an encryption credential, and send the encryption credential to the first server; the first server is further configured to receive the encryption credential and trigger the first page to jump to the second page without logging in while carrying the encryption credential.

[0029] In a fourth aspect, the present invention provides a computer device, including a program or instruction, which when executed, is used to execute the first aspect and each optional method of the first aspect.

[0030] Fifth aspect, the present invention provides a storage medium, including programs or instructions, which are used to execute the methods of the first aspect and each optional method of the first aspect when the programs or instructions are executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the accompanying drawings required for the description of the embodiments.

[0032] Figure 1 A schematic diagram of a page jump system provided by an embodiment of the present invention;

[0033] Figure 2 A schematic diagram of the step flow of a page jump method provided by an embodiment of the present invention;

[0034] Figure 3 A schematic diagram of an interaction process between a first server, a first page, a second page, and a second server shown according to an exemplary embodiment;

[0035] Figure 4 A schematic diagram of the structure of a page jump device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] In order to better understand the above technical solutions, the following will combine the accompanying drawings of the specification and specific embodiments to detail the above technical solutions. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solutions of the present invention, rather than limitations on the technical solutions of the present invention. Without conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.

[0037] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such use can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.

[0038] Currently, in the prior art, when the H5 page corresponding to the partner jumps to the page corresponding to the financial institution, it is necessary to re-register and log in with the user account and password of the partner, or the H5 page corresponding to the partner directly carries the user information and jumps to the page corresponding to the financial institution. However, in the foregoing methods, either the jump is based on two sets of account and password systems, which reduces the user experience, or the jump directly carries the user information, which may lead to malicious attacks on the user information, resulting in the theft of user information and low security.

[0039] In view of this, the embodiments of the present invention provide a page jump method. Through this method, it is possible to achieve a jump with verification-free login, and the front end does not need to transmit user information, that is, the H5 page does not directly carry user information, ensuring the security of user information.

[0040] After introducing the design concept of the embodiments of the present invention, the following briefly introduces the application scenarios applicable to the page jump technical solution in the embodiments of the present invention. It should be noted that the application scenarios described in the embodiments of the present invention are for more clearly explaining the technical solutions of the embodiments of the present invention, and do not constitute a limitation on the technical solutions provided by the embodiments of the present invention. Those skilled in the art can know that with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present invention are also applicable to similar technical problems.

[0041] In the embodiments of the present invention, please refer to Figure 1 A page jump system as described above. The system includes a terminal 101, a partner server 102, and a server 103 corresponding to a financial institution. The terminal 101 can communicate with the partner server 102 and the server corresponding to the financial institution, and the partner server 102 and the server 103 corresponding to the financial institution can also communicate with each other. For example, they are directly or indirectly connected through wired or wireless communication methods, and the present invention does not make any restrictions. Among them, the terminal 101 is installed with an application, and the application can support H5 page jumps. The partner server 102 and the server 103 corresponding to the financial institution are service devices that provide background services for H5 page jumps.

[0042] In this scenario, the user can trigger a jump from the H5 page corresponding to the partner to the H5 page corresponding to the financial institution based on the terminal. It should be noted that for the convenience of description, the H5 page corresponding to the partner will be referred to as the first page, and the H5 page corresponding to the financial institution will be referred to as the second page hereinafter. Specifically, when the user triggers the jump of the first page based on the terminal, the first page correspondingly triggers a jump request to the partner server 102. Thereby, the partner server 102 obtains the basic account information for logging in to the first page and the initial login credential, and binds the basic account information with the initial login credential. Among them, the basic account information includes at least the user name, mobile phone number, and ID card.

[0043] Further, the partner server 102 will send the information in the login initial credential to the server 103 corresponding to the financial institution for verification. When the server 103 corresponding to the financial institution conducts the verification, and when the verification is passed, an encrypted credential is generated, and the encrypted credential bound with the partner information is fed back to the partner server 103. The partner server sends the encrypted credential to the terminal 101, so that the first page can skip the login process and jump to the second page. Also, the server 103 corresponding to the financial institution verifies the encrypted credential, generates a user login state and stores the user login state in the browsing buffer, so that when a financial service interface requirement is triggered based on the second page, the basic account information can be determined based on the stored browsing buffer. It should be noted that the server 103 corresponding to the financial institution includes at least a bank-end server 103-1, an application server 103-2, and a disaster recovery server 103-3. Specifically, the disaster recovery server can be a redis server. It should be noted that for the convenience of description, the partner server 102 is hereinafter referred to as the first server, and the server 103 corresponding to the financial institution is referred to as the second server.

[0044] Among them, the partner server 102 and the server 103 corresponding to the financial institution can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal 101 can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart TV, a smart wearable device, etc., but is not limited thereto.

[0045] In the page jump method provided by the embodiment of the present invention, the above-mentioned first server is used to send a credential acquisition request to the second server based on the jump request triggered by the received first page; the second server is used to perform a first-level security verification on the jump request based on the credential acquisition request, and when it is determined that the first-level verification is passed, perform a second-level security verification on the application ID and key in the partner information obtained based on the jump request; and when it is determined that the second-level verification is passed, obtain the login initial credential obtained based on the jump request, and encrypt the basic account information for logging in to the first page to obtain an encrypted credential, and send the encrypted credential to the first server; the first server is further used to receive the encrypted credential and trigger the first page to skip the login process and jump to the second page with the encrypted credential.

[0046] To further illustrate the solution of the page jump method provided by the embodiments of the present invention, the following will be described in detail with reference to the accompanying drawings and specific embodiments. Although the embodiments of the present invention provide method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on routine or non-creative labor. In steps where there is no necessary causal relationship logically, the execution order of these steps is not limited to the execution order provided by the embodiments of the present invention. In the actual processing process of the method or when the device executes, it may be executed in the method order shown in the embodiments or drawings or executed in parallel (such as in an application environment with parallel processors or multi-threaded processing).

[0047] The following will be described Figure 2 the page jump method in the embodiments of the present invention with reference to the method flow chart shown below, and the method flow of the embodiments of the present invention will be introduced below.

[0048] Step 201: Obtain the initial login credential and partner information from the received jump request; wherein, the jump request is triggered based on the first page.

[0049] In the embodiments of the present invention, when the terminal determines that it needs to jump from the first page to the second page, it can trigger the partner server to call the data in the financial institution server to obtain the initial login credential, and bind the initial login credential and the basic account information, and then trigger a jump request based on the first page and the jump request carries the initial login credential and partner information, wherein the partner information at least includes the application ID and key corresponding to the partner. Then, the terminal can send the jump request to the server corresponding to the financial institution, so that the server corresponding to the financial institution can obtain the initial login credential and partner information from the received jump request.

[0050] Step 202: Perform a first-level security verification on the jump request; the first-level security verification is used to perform network security verification on the first page.

[0051] In the embodiments of the present invention, the server corresponding to the partner can determine whether to send a jump request to the server corresponding to the financial institution, that is, the server corresponding to the partner verifies the server corresponding to the financial institution, and then the server of the financial institution judges the certificate of the partner corresponding to the jump request sent by the server corresponding to the partner, that is, determines whether the certificate of the partner corresponding to the jump request is a pre-issued certificate. When it is determined that the certificate of the partner corresponding to the initial login credential is a pre-issued certificate, the server corresponding to the financial institution can also determine the IP address of the partner, and then can judge whether the IP address belongs to the preset whitelist. When it is determined that the IP address of the partner belongs to the preset whitelist, it is determined that the first-level security verification passes. For example, the preset whitelist is stored in the nginx server.

[0052] It can be seen that in the embodiment of the present invention, when performing the first-level security verification, the https two-way certificate authentication and the IP whitelist can be adopted to verify network security, thereby ensuring network security.

[0053] In the specific implementation process, the preset whitelist can be determined based on the IP addresses included in the information of the cooperation parties corresponding to the financial institutions. In addition, the preset whitelist can be updated. The update method can be periodic update, for example, updated after a time period of 1 month or half a year, etc., or an update interface can be provided to update the IP addresses in the preset whitelist based on the actual implementation requirements. There is no limitation in the embodiment of the present invention.

[0054] Step 203: When the first-level verification passes, perform a second-level verification process on the application ID and the key in the cooperation party information; the second-level verification is used to verify whether the cooperation party information is preset available information.

[0055] In the embodiment of the present invention, when the first-level verification passes, it can be determined whether the application ID and the key in the cooperation party information belong to the preset data pair, where the preset data pair includes the one-to-one correspondence relationship between the preset application ID and the key. If it is determined that the application ID and the key in the cooperation party information belong to the preset data pair, the background IP information corresponding to the application ID is determined.

[0056] It can be seen that in the embodiment of the present invention, the relationship between the application ID and the IP of the cooperation party can also be verified. In this way, the situation where other cooperation parties in the same industry use the cooperation party application ID when it is leaked can be avoided, enhancing security.

[0057] Further, after determining the background IP information corresponding to the application ID, it can also be determined whether the background IP information is available. If it is determined that the background IP information is available, it is determined that the second-level verification process passes.

[0058] It can be seen that in the embodiment of the present invention, after verifying the application ID and the IP of the cooperation party, the legality of the background IP information is also verified, so as to ensure as much as possible that the jump request is triggered by the cooperation party, that is, the security is higher when verifying the cooperation party.

[0059] Exemplarily, the following method can be adopted for the second-level verification:

[0060]

[0061]

[0062] Based on this, it can be known that the secondary verification in the embodiments of the present invention is to verify whether the partner information is preset available information, that is, to perform a security check on the partner information, providing a good implementation basis for subsequent login-free redirection.

[0063] Step 204: When the secondary verification passes, obtain the initial login credential, and encrypt the basic account information on the first login page to obtain an encrypted credential.

[0064] In the embodiments of the present invention, when the secondary verification passes, the basic account information on the first login page can be encrypted. Specifically, the AES algorithm can be used, and the preset number of digits of the key in the partner information and the preset number of digits of the random value are used as the key to encrypt the basic account information to obtain a first encryption result, and then perform base64 encoding on the first encryption result to obtain an encrypted credential.

[0065] For example, the first 16 bits of the application key issued by the financial institution can be used as the key, and the first 16 bits of the Nonce random number are used as the IV offset. The AES encryption algorithm is used to encrypt the basic account information to obtain a first encryption result, and then perform base64 encoding on the first encryption result to obtain an encrypted credential. Here, Nonce is the abbreviation of Number once, and in cryptography, Nonce is an arbitrary or non-repeating random value that is only used once.

[0066] Step 205: Send the encrypted credential to the server corresponding to the first page, so that the server triggers the first page to jump to the second page without password with the encrypted credential.

[0067] After step 205, it is also possible to obtain the encrypted credential carried by the first page; query from the browser cache cookie whether the encrypted credential has not expired and has not been verified; if it is determined that the encrypted credential has not expired and has not been verified, then obtain the user login state capToken corresponding to the encrypted credential in the cookie, and determine the basic account information based on the capToken.

[0068] Specifically, after jumping from the first page to the second page, the encrypted credential can be carried to the second server for verification. The second server queries the encrypted credential from the browser cache cookie. If the encrypted credential has not expired and has not been verified, it is determined that it can be used. It should be noted that the encrypted credential becomes invalid immediately after being verified once. The second server obtains the capToken in the cookie, determines the bound basic account information according to the capToken, and then performs corresponding financial services according to the basic account information. This can avoid having the front end carry the basic account information and ensure that the basic account information cannot be tampered with.

[0069] Optionally, the capToken is obtained by encrypting the application ID, basic account information, and the current timestamp in the partner information. The encryption algorithm for the encryption process may be the SHA256 algorithm.

[0070] For example, when the first server, i.e., the server corresponding to the partner, requests the credential, i.e., the ticket interface, it can obtain the access_token using the application ID and the secret key, and set the type to obtain the user-level credential, i.e., type = user. When the second server receives the request, it uses the SHA256 algorithm on the access_token and the timestamp (the current timestamp) to obtain the encrypted credential, i.e., the appId and the userId. Then, the appId and the userId are used as the unique key to bind and save the login initial credential, as well as the basic account information such as the user name, ID card, and mobile phone number, to the redis server and the database. It can be seen that the encrypted credential is stored in the database corresponding to the browser cache cookie and / or the redis server.

[0071] Exemplarily, the following method can be used to generate the encrypted credential and cache the basic account information:

[0072]

[0073]

[0074]

[0075] It can be seen that by using the foregoing method for determining the encrypted credential, it is possible to ensure that the encrypted credential or the capToken is not leaked as much as possible.

[0076] To better illustrate the page jump method provided by the embodiments of the present invention, the following further describes the page jump method involved in the embodiments of the present invention from the perspective of the interaction between the first server, the first page, the second page, and the second server.

[0077] As an embodiment, please refer to Figure 3 , the specific interaction between the first server, the first page, the second page, and the second server is as follows.

[0078] Step 301: The first page triggers a jump request to the first server.

[0079] Step 302: Based on the received jump request, the first server sends a credential acquisition request to the second server.

[0080] Step 303: Based on the received credential acquisition request, the second server performs a first-level security verification on the jump request.

[0081] Step 304: When the second server determines that the first-level verification is passed, it performs a second-level security verification on the application ID and key in the partner information obtained based on the jump request.

[0082] Step 305: When the second server determines that the second-level verification is passed, it obtains the initial login credential obtained based on the jump request, and encrypts the basic account information for logging in to the first page to obtain an encrypted credential.

[0083] Step 306: The second server sends the encrypted credential to the first server.

[0084] Step 307: The first server sends the encrypted credential to the first page.

[0085] Step 308: The first page jumps to the second page without logging in, and the first page carries the encrypted credential.

[0086] Step 309: The second page sends the encrypted credential to the second server.

[0087] Step 310: The second server verifies the encrypted credential, generates a capToken based on the encrypted credential, and caches the capToken in the cookie.

[0088] Step 311: The second page triggers a financial service request to the second server.

[0089] Step 312: Based on the financial service request, the second server obtains the capToken in the cookie, determines the basic account information based on the capToken, and processes the financial service based on the basic account information and the financial service request.

[0090] It can be seen that in the embodiments of the present invention, a triple security verification mechanism is provided when obtaining a secure jump encrypted credential, that is, a first-level security verification mechanism that uses https two-way certificate authentication and a preset whitelist to ensure network security, a second-level security verification mechanism that verifies the application ID and key in the partner information and verifies the background IP corresponding to the application ID, and a third-level security verification mechanism that encrypts the basic account information, so as to implement a page jump solution that does not require logging in and does not directly carry the basic account information.

[0091] Such as Figure 4As shown in the figure, the present invention provides a page jump device, including: an acquisition unit 401, configured to acquire a login initial credential and partner information from a received jump request; wherein, the jump request is triggered based on a first page; a first verification unit 402, configured to perform a first-level security verification on the jump request; the first-level security verification is used for network security verification; a second verification unit 403, configured to, when the first-level verification passes, perform a second-level verification process on the application ID and key in the partner information; the second-level verification is used to verify whether the partner information is preset available information; a processing unit 404, configured to, when the second-level verification passes, acquire the login initial credential, and encrypt the basic account information for logging in to the first page to obtain an encrypted credential; a jump unit 405, configured to send the encrypted credential to the server corresponding to the first page, so that the server triggers the first page to carry the encrypted credential and jump to the second page without logging in.

[0092] Optionally, the first verification unit 402 is configured to: determine whether the certificate of the partner corresponding to the jump request is a pre-issued certificate; when it is determined that the certificate of the partner corresponding to the jump request is a pre-issued certificate, determine the IP address of the partner; determine whether the IP address belongs to a preset whitelist, and if the IP address belongs to the preset whitelist, determine that the first-level security verification passes.

[0093] Optionally, the second verification unit 403 is configured to: determine whether the application ID and key in the partner information belong to a preset data pair, wherein the preset data pair includes a one-to-one correspondence relationship between a preset application ID and a key; if it is determined that the application ID and key in the partner information belong to the preset data pair, determine the background IP information corresponding to the application ID; determine whether the background IP information is available; if it is determined that the background IP information is available, determine that the second-level verification process passes.

[0094] Optionally, the processing unit 404 is configured to: adopt the AES algorithm, use the preset number of digits of the key in the partner information and the preset number of digits of the random value as the key, encrypt the basic account information to obtain a first encryption result; perform base64 encoding processing on the first encryption result to obtain an encrypted credential.

[0095] Optionally, the device further includes a third verification unit, configured to: obtain the encrypted credential carried by the first page; query in the browser cache cookie whether the encrypted credential has not expired and has not been verified; if it is determined that the encrypted credential has not expired and has not been verified, obtain the user login state capToken corresponding to the encrypted credential in the cookie, and determine the basic account information based on the capToken, so as to perform service processing based on the basic account information.

[0096] Optionally, the capToken is obtained by encrypting the application ID in the partner information, the basic account information, and the current timestamp.

[0097] Optionally, the encrypted credential is stored in the database corresponding to the browser cache cookie and / or the redis server.

[0098] An embodiment of the present invention provides a computer device, including a program or instruction, which when executed, is used to execute a page jump method provided by an embodiment of the present invention and any optional method.

[0099] An embodiment of the present invention provides a storage medium, including a program or instruction, which when executed, is used to execute a page jump method provided by an embodiment of the present invention and any optional method.

[0100] Finally, it should be noted that those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) containing computer-usable program code.

[0101] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0102] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means embodying the function specified in the flowchart Figure 1 one or more flowcharts and / or Figure 1 boxes or multiple boxes.

[0103] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A page jump method, characterized in that, It includes: Obtain the login initial credential and the partner information from the received jump request; wherein, the jump request is triggered based on the first page; Perform a first-level security verification on the jump request; the first-level security verification is used for network security verification; When the first-level security verification passes, perform a second-level verification process on the application ID and key in the partner information; the second-level verification is used to verify whether the partner information is preset available information; When the second-level verification passes, obtain the login initial credential, and encrypt the basic account information for logging in to the first page to obtain an encrypted credential; Send the encrypted credential to the server corresponding to the first page, so that the server triggers the first page to carry the encrypted credential and jump to the second page without logging in; Among them, the performing a first-level security verification on the jump request includes: Determine whether the certificate of the partner corresponding to the jump request is a pre-issued certificate; After determining that the certificate of the partner corresponding to the jump request is a pre-issued certificate, determine the IP address of the partner; Determine whether the IP address belongs to a preset whitelist. If the IP address belongs to the preset whitelist, determine that the first-level security verification passes.

2. The method according to claim 1, characterized in that, The performing a second-level verification process on the application ID and key in the partner information includes: Determine whether the application ID and key in the partner information belong to a preset data pair, wherein the preset data pair includes a one-to-one correspondence relationship between a preset application ID and a key; If it is determined that the application ID and key in the partner information belong to a preset data pair, determine the background IP information corresponding to the application ID; Determine whether the background IP information is available; If it is determined that the background IP information is available, determine that the second-level verification process passes.

3. The method according to claim 2, characterized in that The encrypting the basic account information for logging in to the first page to obtain an encrypted credential includes: Adopt the AES algorithm, use the preset number of digits of the key in the partner information and the preset number of digits of the random value as the key, and encrypt the basic account information to obtain a first encryption result; Perform base64 encoding processing on the first encryption result to obtain an encrypted credential.

4. The method according to claim 1, characterized in that, After the first page carries the encrypted credential and jumps to the second page without logging in, the method further includes: Obtain the encrypted credential carried by the first page; Query from the browser cache cookie whether the encrypted credential has not expired and has not been verified; If it is determined that the encrypted credential has not expired and has not been verified, obtain the user login state capToken corresponding to the encrypted credential in the cookie, and determine the basic account information based on the capToken, so as to perform business processing based on the basic account information.

5. The method according to claim 4, characterized in that, The capToken is obtained by encrypting the application ID in the partner information, the basic account information, and the current timestamp.

6. The method according to claim 1, characterized in that The encrypted credential is stored in the database corresponding to the browser cache cookie and / or the redis server.

7. A page jump device, characterized in that, It includes: An acquisition unit, configured to acquire a login initial credential and partner information from a received jump request; wherein, the jump request is triggered based on a first page. A first verification unit, configured to perform a first-level security verification on the jump request; the first-level security verification is used for network security verification. A second verification unit, configured to, when the first-level security verification passes, perform a second-level verification process on the application ID and key in the partner information; the second-level verification is used to verify whether the partner information is preset available information. A processing unit, configured to, when the second-level verification passes, acquire the login initial credential, and encrypt the basic account information for logging in to the first page to obtain an encrypted credential. A jump unit, configured to send the encrypted credential to the server corresponding to the first page, so that the server triggers the first page to carry the encrypted credential and skip to the second page without logging in. Wherein, when the first verification unit is configured to perform the first-level security verification on the jump request, it is specifically configured to: determine whether the certificate of the partner corresponding to the jump request is a pre-issued certificate; when it is determined that the certificate of the partner corresponding to the jump request is a pre-issued certificate, determine the IP address of the partner; determine whether the IP address belongs to a preset whitelist, and if the IP address belongs to the preset whitelist, determine that the first-level security verification passes.

8. A page jump system, characterized in that, The system includes a first server and a second server, wherein: The first server is configured to send a credential acquisition request to the second server based on the jump request triggered by the first page. The second server is configured to perform a first-level security verification on the jump request based on the credential acquisition request, and when it is determined that the first-level security verification passes, perform a second-level verification on the application ID and key in the partner information acquired based on the jump request; and, when it is determined that the second-level verification passes, acquire the login initial credential acquired based on the jump request, and encrypt the basic account information for logging in to the first page to obtain an encrypted credential, and send the encrypted credential to the first server. The first server is further configured to receive the encrypted credential, and trigger the first page to carry the encrypted credential and skip to the second page without logging in. Wherein, when the second server is configured to perform the first-level security verification on the jump request, it is specifically configured to determine whether the certificate of the partner corresponding to the jump request is a pre-issued certificate; when it is determined that the certificate of the partner corresponding to the jump request is a pre-issued certificate, determine the IP address of the partner; determine whether the IP address belongs to a preset whitelist, and if the IP address belongs to the preset whitelist, determine that the first-level security verification passes.

9. A storage medium, characterized in that, Includes a program or instruction, when the program or instruction is executed, the method according to any one of claims 1 to 6 is executed.

Citation Information

Patent Citations

  • Two-factor authentication method and system based on fingerprint and digital certificate

    CN108737376A

  • User registration and login management system based on game platform

    CN110620781A