A data processing method, device, equipment and storage medium
By generating and verifying the real data and redundant data on the web page on the server, and using the key generated by the biological fingerprint for authentication, the security and reliability problems of traditional web page authentication methods are solved, and higher data confidentiality and security are achieved.
Patent Information
- Application Number
- CN202110930566.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-13
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-08-13
AI Technical Summary
The traditional WEB web authentication method has security and reliability problems. User passwords or mobile phone SMS verification codes that are easily stolen are used for illegal operations. WEB technology has defects in end encryption and decryption, and it is impossible to fully utilize physical and biological factors as the basis for authentication.
After receiving the web page data request on the server, real data and redundant data are generated, and verification data is generated using the key generated by the user's biological fingerprint on the web page to generate verification data, and returned to the web page. The web page side processes the verification data by re-collecting the biological fingerprint to generate dynamic keys to obtain the real data.
Relying on fingerprint verification greatly improves the security and reliability of web page authentication, prevents illegal operations and enhances data confidentiality.
Smart Images

Figure CN113591153B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to a data processing method, device, equipment and storage medium. Background Art
[0002] As a technology with many advantages such as fast development speed, high distribution efficiency, and support for hot updates, WEB pages have become the preferred carrier for developing various software applications. In production and life, it is often necessary to manage some highly sensitive and high-level data in software systems. However, on the one hand, traditional WEB page authentication methods are usually limited to username and password verification, mobile phone SMS verification codes, etc. Once the user's password or mobile phone is stolen, criminals can immediately disguise themselves as the user and view all the data and operations belonging to the user. On the other hand, WEB technology has disadvantages in terms of end-to-end encryption and decryption, such as the source code being publicly available for download, the data being eavesdropped on the user side, and the inability to fully utilize physical and biological factors as authentication bases. Moreover, in some specific applications, users may violate the user agreement and share a single account with multiple people, bringing potential risks to issues such as protecting audio and video digital copyrights.
[0003] Therefore, how to improve the security and reliability during web page authentication is a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a data processing method, device, equipment and storage medium, which can greatly improve the security and reliability during web page authentication by relying on fingerprint verification. The specific solutions are as follows:
[0005] The first aspect of the present application provides a data processing method applied to a server, including:
[0006] Receiving a data request sent by a web page, and generating real data corresponding to the web page request corresponding to the data request and redundant data corresponding to the real data;
[0007] Obtaining a user key of the logged-in user of the web page, and using the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web page based on the biological fingerprint of the logged-in user;
[0008] Returning the verification data to the web page, so that the web page can generate a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data.
[0009] Optionally, obtaining the user key of the logged-in user on the web page and generating verification data including the real data and the redundant data includes:
[0010] Obtaining the user public key of the logged-in user on the web page; wherein, the user public key is a public key pre-generated by the web page based on the biometric fingerprint of the logged-in user;
[0011] Performing encryption processing on the real data and the redundant data respectively using the user public key to obtain the encrypted real data and the encrypted redundant data.
[0012] Optionally, returning the verification data to the web page so that the web page generates a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user and processes the received verification data using the dynamic key to obtain the real data, includes:
[0013] Returning the encrypted real data and the encrypted redundant data to the web page so that the web page generates a corresponding user private key by re-collecting the biometric fingerprint of the logged-in user and decrypts the received encrypted real data and the encrypted redundant data using the user private key to obtain the real data.
[0014] Optionally, obtaining the user key of the logged-in user on the web page and generating verification data including the real data and the redundant data includes:
[0015] Obtaining the user public key of the logged-in user on the web page; wherein, the user public key is a public key pre-generated by the web page based on the biometric fingerprint of the logged-in user;
[0016] Generating challenge data corresponding to the real data and challenge data corresponding to the redundant data respectively using the user public key.
[0017] Optionally, returning the verification data to the web page so that the web page generates a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user and processes the received verification data using the dynamic key to obtain the real data, includes:
[0018] Returning the real data, the redundant data and their corresponding challenge data to the web page so that the web page generates a corresponding user private key by re-collecting the biometric fingerprint of the logged-in user and decrypts the received challenge data using the user private key to obtain the real data.
[0019] The second aspect of the present application provides a data processing method applied to the web side, including:
[0020] Sending a data request to the server, so that the server generates the real data requested by the web side corresponding to the data request and redundant data corresponding to the real data, and obtains the user key of the logged-in user of the web side, and uses the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web side based on the biological fingerprint of the logged-in user; and returning the verification data to the web side;
[0021] Receiving the verification data returned by the server, generating a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and using the dynamic key to process the received verification data to obtain the real data.
[0022] Optionally, before sending the data request to the server, it further includes:
[0023] Obtaining the registration information of different users, so that different users can use the registration information to log in to the web side;
[0024] Collecting the biological fingerprint of the user logging in to the web side, and generating the user key based on the biological fingerprint through webauthn technology;
[0025] Establishing a corresponding relationship between the registration information of different users and the user key respectively, so that the server can obtain the user key of the logged-in user of the web side according to the corresponding relationship.
[0026] The third aspect of the present application provides a data processing device applied to the server side, including:
[0027] A request receiving module, configured to receive a data request from the web side, and generate real data requested by the web side corresponding to the data request and redundant data corresponding to the real data;
[0028] A data generation module, configured to obtain the user key of the logged-in user of the web side, and use the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web side based on the biological fingerprint of the logged-in user;
[0029] A data return module, configured to return the verification data to the web side, so that the web side can generate a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data.
[0030] The fourth aspect of the present application provides an electronic device, which includes a processor and a memory; wherein the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the foregoing data processing method.
[0031] The fifth aspect of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are loaded and executed by a processor, the foregoing data processing method is implemented.
[0032] In the present application, the server first receives a data request sent by the web page end, and generates the real data requested by the web page end corresponding to the data request and redundant data corresponding to the real data; then obtains the user key of the logged-in user of the web page end, and uses the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web page end based on the biological fingerprint of the logged-in user; finally, the verification data is returned to the web page end, so that the web page end can generate a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data. It can be seen that after the server of the present application receives a data request from the web page end, it generates real data and redundant data corresponding to the data request, further uses the user key of the logged-in user of the web page end to generate verification data including the real data and the redundant data and returns the verification data. The web page end uses the dynamic key generated by re-collecting the biological fingerprint of the logged-in user to process the verification data to obtain the real data, relying on fingerprint verification to greatly improve the security and reliability during web page end authentication. Description of the Drawings
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0034] Figure 1 It is a flowchart of a data processing method applied to a server provided by the present application;
[0035] Figure 2 It is a flowchart of a data processing method applied to a web page end provided by the present application;
[0036] Figure 3 It is a code example for calling a fingerprint recognizer provided by the present application;
[0037] Figure 4 A schematic structural diagram of a data processing device applied to a server provided by this application;
[0038] Figure 5 A structural diagram of a data processing electronic device provided by this application. Specific implementation manners
[0039] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0040] Traditional WEB page authentication methods are usually limited to username and password verification, mobile phone SMS verification codes, etc. Once the user's password or mobile phone is stolen, criminals can immediately disguise themselves as the user and view all the data and operations belonging to the user. On the other hand, WEB technology has disadvantages in terms of end encryption and decryption, such as the source code being publicly available for download, the data being eavesdropped by the user side, and the inability to fully utilize physical and biological factors as authentication bases. Moreover, in some specific applications, users may violate the user agreement and share a single account with multiple people, bringing potential risks to issues such as protecting audio and video digital copyrights. In view of the above defects, this application provides a data processing solution. After receiving a data request from the web page end, the server generates real data corresponding to the data request and redundant data, and further generates verification data including the real data and the redundant data by using the user key of the logged-in user on the web page end and returns the verification data. The web page end processes the verification data by using a dynamic key generated by re-collecting the biological fingerprint of the logged-in user to obtain the real data, relying on fingerprint verification to greatly improve the security and reliability during web page end authentication.
[0041] Figure 1 A flowchart of a data processing method provided by an embodiment of this application. See Figure 1 As shown, this data processing method is applied to a server and includes:
[0042] S11: Receive a data request sent by the web page end, and generate real data requested by the web page end corresponding to the data request and redundant data corresponding to the real data.
[0043] In this embodiment, the server receives a data request sent by the web client, and generates the real data requested by the web client corresponding to the data request and redundant data corresponding to the real data. It is not difficult to understand that the data request is a data request sent by the user currently logged in to the web client to the server through the web client. Each time the user operates the front end of the WEB website to communicate with the server, after receiving the data request, the server does not directly return the data required by the logged-in user, but generates multiple sets of obfuscated data on the basis of generating the real data, that is, the server issues more redundant data than requested. The web client can obtain the real data only after successful biometric fingerprint authentication of the logged-in user, adding a biometric recognition factor to provide data confidentiality.
[0044] S12: Obtain the user key of the logged-in user of the web client, and use the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web client based on the biometric fingerprint of the logged-in user.
[0045] S13: Return the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data.
[0046] In this embodiment, first obtain the user key of the logged-in user of the web client, and use the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web client based on the biometric fingerprint of the logged-in user. On this basis, return the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data. It can provide a biometric identification user identity solution for ordinary website applications, and can greatly improve the reliability of WEB applications in data encryption.
[0047] In one embodiment, the real data and the redundant data are encrypted using an asymmetric encryption algorithm (such as an RSA algorithm, etc.), and correspondingly, the encrypted real data and the encrypted redundant data are decrypted on the web page. Specifically, the user public key of the logged-in user of the web page is first obtained; wherein the user public key is a public key generated by the web page in advance based on the biometric fingerprint of the logged-in user. It is not difficult to understand that before this, the user needs to register his fingerprint identifier on the web page in advance and associate it with his personal account, and the server program saves the public key of the fingerprint identifier. Then, the real data and the redundant data are encrypted using the user public key to obtain the encrypted real data and the encrypted redundant data; finally, the encrypted real data and the encrypted redundant data are returned to the web page, so that the web page can generate the corresponding user private key by re-collecting the biometric fingerprint of the logged-in user, and decrypt the received encrypted real data and the encrypted redundant data using the user private key to obtain the real data. The hardware authenticator is used in conjunction with the user's human biometrics to dynamically create a user private key, and the private key is used to identify the real signature, where only one set of data is true and the signature can be verified, and only the user with the corresponding private key can verify it. Existing web encryption technology usually uses symmetric encryption (such as AES algorithm, etc.) or asymmetric encryption to process data. Once the user key is lost, the person who obtains the key can decrypt the ciphertext data at any time. This embodiment takes advantage of the ability of the WEB website to access the hardware device fingerprint identifier, adding an authentication factor to verify the user's biometric fingerprint, thereby greatly improving security.
[0048] In another embodiment, instead of encrypting the real data and the redundant data to be transmitted themselves, challenge data is generated based on the real data and the redundant data by using an asymmetric encryption algorithm. Correspondingly, corresponding decryption processing is performed on the challenge data at the web end. Specifically, first obtain the user public key of the logged-in user at the web end; wherein, the user public key is a public key pre-generated by the web end based on the biological fingerprint of the logged-in user; then use the user public key to generate challenge data corresponding to the real data and challenge data corresponding to the redundant data respectively; finally, return the real data, the redundant data and their corresponding challenge data to the web end, so that the web end can generate a corresponding user private key by re-collecting the biological fingerprint of the logged-in user, and use the user private key to decrypt the received challenge data to obtain the real data. In this embodiment, each time a user operates the front end of a WEB site to communicate with the server, the server adds a challenge data to each data unit. At the web end, if the logged-in user clicks an operation to view a certain data, the corresponding interface of the WEB site front end is invoked, the user fingerprint recognizer is accessed, and the user is reminded to verify. If the verification is passed, the fingerprint recognizer will enable the data challenge function. At this time, all the data sent by the server is transmitted for challenge. If the challenge is passed, it is the real data, and at this time the real data is displayed on the user page.
[0049] In summary, the above embodiments combine data obfuscation and biometric fingerprint recognition, which can be used to support both ciphertext transmission and plaintext transmission scenarios only. It can ensure data security on the premise of transmitting data in plaintext. At the same time, technologies such as fingerprint recognition technology applied in this embodiment can be implemented on major mainstream platforms. Only one set of server and client programs are required to be compatible with various computers and mobile devices. Part of the program runs on the server and part runs on the user browser, which is a data security solution at the user level.
[0050] It can be seen that in the embodiment of the present application, the server first receives a data request sent by the web client, and generates the real data requested by the web client corresponding to the data request and redundant data corresponding to the real data; then obtains the user key of the logged-in user of the web client, and uses the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web client based on the biological fingerprint of the logged-in user; finally, returns the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data. In the embodiment of the present application, after the server receives the data request from the web client, it generates the real data and redundant data corresponding to the data request, further generates verification data including the real data and redundant data by using the user key of the logged-in user of the web client, and returns the verification data. The web client uses the dynamic key generated by re-collecting the biological fingerprint of the logged-in user to process the verification data to obtain the real data, relying on fingerprint verification to greatly improve the security and reliability during web client authentication.
[0051] Figure 2 It is a flowchart of a data processing method provided by an embodiment of the present application. Refer to Figure 2 As shown, this data processing method is applied to the web client and includes:
[0052] S21: Send a data request to the server, so that the server generates the real data requested by the web client corresponding to the data request and redundant data corresponding to the real data, obtains the user key of the logged-in user of the web client, and uses the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web client based on the biological fingerprint of the logged-in user; and returns the verification data to the web client.
[0053] In this embodiment, the web client first sends a data request to the server, so that the server generates the real data requested by the web client corresponding to the data request and redundant data corresponding to the real data, obtains the user key of the logged-in user of the web client, and uses the user key to generate verification data including the real data and the redundant data; wherein, the user key is a key pre-generated by the web client based on the biological fingerprint of the logged-in user; and returns the verification data to the web client.
[0054] To ensure that the server can correctly obtain the corresponding user key, different users need to register and bind their biometric fingerprints in the web client in advance. The web client first obtains the registration information of different users so that different users can use the registration information to log in to the web client; then it collects the biometric fingerprints of the users logging in to the web client and generates the user key based on the biometric fingerprints through webauthn technology; finally, it establishes a corresponding relationship between the registration information of different users and the user key respectively, so that the server can obtain the user key of the logged-in user on the web client according to the corresponding relationship. By utilizing the ability of Web sites to access hardware device fingerprint scanners in the webauthn standard and adding the step of verifying the user's fingerprint, the security is greatly enhanced.
[0055] Specifically, a set of database tables can be designed, and the table fields should at least include the user's unique label, the fingerprint scanner key (user key), etc. On this basis, the user first performs the password recognition of the system itself to obtain the login status. In the logged-in state, the fingerprint scanner is called to obtain the corresponding user key. Finally, the binding relationship between the user account (registration information) and the fingerprint scanner public key (user key) is saved. Among them, the example code for calling the fingerprint browser is as Figure 3 shown. In modern browsers and devices, the utilization of fingerprint scanners is usually well supported, and mainstream desktop computers, smartphones, etc. all support calling built-in or third-party fingerprint scanners. For some systems that do not support the webauthn standard or devices without built-in fingerprint scanners, the system version can be updated or an external third-party fingerprint scanner can be purchased to use the present invention, and the same security can be obtained.
[0056] S22: Receive the verification data returned by the server, generate a corresponding dynamic key by re-collecting the biometric fingerprints of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data.
[0057] In this embodiment, the verification data returned by the server is received, and then the biometric fingerprints of the logged-in user are re-collected to generate a corresponding dynamic key, and the dynamic key is used to process the received verification data to obtain the real data. For the specific process of the above step S22, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated here.
[0058] It can be seen that in the embodiment of the present application, a user key is created through the WebAuthn technology, and the user key is saved to the server. The logged-in user performs authentication by invoking WebAuthn and obtains correct data. Based on the WebAuthn standard, fingerprint verification is added as an authentication factor to the traditional username and password verification mechanism, thereby greatly improving the security and reliability of Web site user authentication.
[0059] See Figure 4 As shown, the embodiment of the present application also correspondingly discloses a data processing device, which is applied to the server side and includes:
[0060] A request receiving module 11, configured to receive a data request from the web page side, and generate real data corresponding to the web page side request corresponding to the data request and redundant data corresponding to the real data;
[0061] A data generating module 12, configured to obtain the user key of the logged-in user on the web page side, and generate verification data including the real data and the redundant data by using the user key; wherein, the user key is a key pre-generated by the web page side based on the biological fingerprint of the logged-in user;
[0062] A data returning module 13, configured to return the verification data to the web page side, so that the web page side generates a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and processes the received verification data by using the dynamic key to obtain the real data.
[0063] It can be seen that in the embodiment of the present application, the server side first receives the data request sent by the web page side, and generates real data corresponding to the web page side request corresponding to the data request and redundant data corresponding to the real data; then obtains the user key of the logged-in user on the web page side, and generates verification data including the real data and the redundant data by using the user key; wherein, the user key is a key pre-generated by the web page side based on the biological fingerprint of the logged-in user; finally, returns the verification data to the web page side, so that the web page side generates a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and processes the received verification data by using the dynamic key to obtain the real data. In the embodiment of the present application, after receiving the data request from the web page side, the server side generates real data and redundant data corresponding to the data request, further generates verification data including real data and redundant data by using the user key of the logged-in user on the web page side and returns the verification data. The web page side processes the verification data by using the dynamic key generated by re-collecting the biological fingerprint of the logged-in user to obtain the real data, relying on fingerprint verification to greatly improve the security and reliability of web page side authentication.
[0064] In some specific embodiments, the data generation module 11 specifically includes:
[0065] A public key acquisition unit, configured to acquire the user public key of the logged-in user on the web page; wherein, the user public key is a public key pre-generated by the web page based on the biological fingerprint of the logged-in user;
[0066] A data encryption unit, configured to respectively encrypt the real data and the redundant data by using the user public key to obtain encrypted real data and encrypted redundant data;
[0067] Correspondingly, the data return module 12 is specifically configured to return the encrypted real data and the encrypted redundant data to the web page, so that the web page generates a corresponding user private key by re-collecting the biological fingerprint of the logged-in user, and uses the user private key to decrypt the received encrypted real data and encrypted redundant data to obtain the real data.
[0068] In some specific embodiments, the data generation module 11 specifically includes:
[0069] A public key acquisition unit, configured to acquire the user public key of the logged-in user on the web page; wherein, the user public key is a public key pre-generated by the web page based on the biological fingerprint of the logged-in user;
[0070] A challenge data generation unit, configured to respectively generate challenge data corresponding to the real data and challenge data corresponding to the redundant data by using the user public key;
[0071] Correspondingly, the data return module 12 is specifically configured to return the real data, the redundant data and their corresponding challenge data to the web page, so that the web page generates a corresponding user private key by re-collecting the biological fingerprint of the logged-in user, and uses the user private key to decrypt the received challenge data to obtain the real data.
[0072] Furthermore, an embodiment of the present application further provides an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the scope of use of the present application.
[0073] Figure 5Schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the data processing method disclosed in any of the foregoing embodiments.
[0074] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed thereon here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.
[0075] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon can include an operating system 221, a computer program 222, and data 223, etc., and the storage method can be temporary storage or permanent storage.
[0076] Among them, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222 to implement the operation and processing of a large amount of data 223 in the memory 22 by the processor 21. It can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the data processing method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks. The data 223 can include data requests collected by the electronic device 20, etc.
[0077] Furthermore, an embodiment of the present application also discloses a storage medium in which a computer program is stored. When the computer program is loaded and executed by a processor, the steps of the data processing method disclosed in any of the foregoing embodiments are implemented.
[0078] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0079] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
[0080] The data processing method, apparatus, device and storage medium provided by the present invention have been introduced in detail above. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A data processing method, characterized in that, Applied to the server side, including: Receiving a data request sent by the web client, and generating real data corresponding to the web client request corresponding to the data request and redundant data corresponding to the real data; the web client request is a request obtained based on the web client and the corresponding data request; the redundant data is obfuscated data related to the real data; Obtaining the user key of the logged-in user of the web client, and generating verification data including the real data and the redundant data by using the user key; wherein, the user key is a key pre-generated by the web client based on the biometric fingerprint of the logged-in user; Returning the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user, and process the received verification data by using the dynamic key to obtain the real data; Wherein, the obtaining the user key of the logged-in user of the web client, and generating verification data including the real data and the redundant data by using the user key, includes: Obtaining the user public key of the logged-in user of the web client; wherein, the user public key is a public key pre-generated by the web client based on the biometric fingerprint of the logged-in user; Performing encryption processing on the real data and the redundant data respectively by using the user public key to obtain encrypted real data and encrypted redundant data; Wherein, the returning the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user, and process the received verification data by using the dynamic key to obtain the real data, includes: Returning the encrypted real data and the encrypted redundant data to the web client, so that the web client can generate a corresponding user private key by re-collecting the biometric fingerprint of the logged-in user, and perform decryption processing on the received encrypted real data and encrypted redundant data by using the user private key to obtain the real data.
2. The data processing method according to claim 1, wherein The obtaining the user key of the logged-in user of the web client, and generating verification data including the real data and the redundant data by using the user key, includes: Obtaining the user public key of the logged-in user of the web client; wherein, the user public key is a public key pre-generated by the web client based on the biometric fingerprint of the logged-in user; Generating challenge data corresponding to the real data and challenge data corresponding to the redundant data respectively by using the user public key.
3. The data processing method according to claim 2, wherein The returning the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biometric fingerprint of the logged-in user, and process the received verification data by using the dynamic key to obtain the real data, includes: Returning the real data, the redundant data and their corresponding challenge data to the web client, so that the web client can generate a corresponding user private key by re-collecting the biometric fingerprint of the logged-in user, and perform decryption processing on the received challenge data by using the user private key to obtain the real data.
4. A data processing method, characterized in that, Applied to the web side, including: Sending a data request to the server so that the server generates the real data requested by the web side corresponding to the data request and redundant data corresponding to the real data, and obtaining the user key of the logged-in user of the web side, and generating verification data including the real data and the redundant data by using the user key; wherein, the web side request is a request obtained based on the web side and the corresponding data request; the redundant data is obfuscated data related to the real data; the user key is a key pre-generated by the web side based on the biological fingerprint of the logged-in user; and returning the verification data to the web side; Receiving the verification data returned by the server, generating a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and processing the received verification data by using the dynamic key to obtain the real data; Wherein, the obtaining the user key of the logged-in user of the web side and generating verification data including the real data and the redundant data by using the user key includes: Obtaining the user public key of the logged-in user of the web side; wherein, the user public key is a public key pre-generated by the web side based on the biological fingerprint of the logged-in user; Performing encryption processing on the real data and the redundant data respectively by using the user public key to obtain encrypted real data and encrypted redundant data; Wherein, the generating a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user and processing the received verification data by using the dynamic key to obtain the real data includes: Generating a corresponding user private key by re-collecting the biological fingerprint of the logged-in user, and performing decryption processing on the received encrypted real data and encrypted redundant data by using the user private key to obtain the real data.
5. The data processing method according to claim 4, characterized in that Before sending the data request to the server, it further includes: Obtaining the registration information of different users so that different users can use the registration information to log in to the web side; Collecting the biological fingerprint of the user logging in to the web side, and generating the user key based on the biological fingerprint through webauthn technology; Establishing a corresponding relationship between the registration information of different users and the user key respectively so that the server can obtain the user key of the logged-in user of the web side according to the corresponding relationship.
6. A data processing device, characterized in that, Applied to the server side, including: A request receiving module, configured to receive a data request from the web side and generate the real data requested by the web side corresponding to the data request and redundant data corresponding to the real data; the web side request is a request obtained based on the web side and the corresponding data request; the redundant data is obfuscated data related to the real data; A data generating module, configured to obtain the user key of the logged-in user of the web side and generate verification data including the real data and the redundant data by using the user key; wherein, the user key is a key pre-generated by the web side based on the biological fingerprint of the logged-in user; A data return module, configured to return the verification data to the web client, so that the web client can generate a corresponding dynamic key by re-collecting the biological fingerprint of the logged-in user, and use the dynamic key to process the received verification data to obtain the real data; Wherein, the data generation module includes: A public key acquisition unit, configured to acquire the user public key of the logged-in user of the web client; wherein, the user public key is a public key pre-generated by the web client based on the biological fingerprint of the logged-in user; A data encryption unit, configured to perform encryption processing on the real data and the redundant data respectively by using the user public key to obtain encrypted real data and encrypted redundant data; Correspondingly, the data return module is specifically configured to return the encrypted real data and the encrypted redundant data to the web client, so that the web client can generate a corresponding user private key by re-collecting the biological fingerprint of the logged-in user, and use the user private key to decrypt the received encrypted real data and encrypted redundant data to obtain the real data.
7. An electronic device, characterized in that, The electronic device includes a processor and a memory; wherein the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the data processing method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, For storing computer-executable instructions, when the computer-executable instructions are loaded and executed by a processor, the data processing method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Method used for network identity authentication, user terminal, website server and system thereof
CN106878017A