User login method, device, computer equipment and storage medium via USB-KEY

By binding the unique identification information of the terminal device through USB-KEY and using the preset mapping table to verify the login request, the problem that the traditional login method is easy to crack is solved, and higher security and user experience are achieved.

CN113987444BActive Publication Date: 2025-09-19BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111333508.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-11
Publication Date
2025-09-19
Estimated Expiration
2041-11-11

AI Technical Summary

Technical Problem

Traditional terminal device login methods are easily cracked, resulting in insufficient security, especially in systems involving confidential information, which poses serious security risks.

Method used

The unique identification information of the terminal device is bound by USB-KEY for identity authentication. The unique identification information of the mobile authentication device is stored and queried using the preset mapping table to verify the login request and detect the integrity of the identification information table in real time to prevent tampering.

Benefits of technology

It improves the security of user login, prevents illegal access, enhances the security of terminal devices, and improves the reliability and user experience of user login.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987444B_ABST
    Figure CN113987444B_ABST
Patent Text Reader

Abstract

The present application provides a method, apparatus, computer device, and storage medium for user login via a USB-KEY, relating to the field of network security technology, and for improving the security of user login. The method primarily comprises: receiving unique identification information of a mobile authentication device and a corresponding terminal device identification input by a management user; storing the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table; and, based on the preset mapping table, sending the corresponding unique identification information of the mobile authentication device to the terminal device corresponding to the terminal device identification; so that the terminal device stores the unique identification information and verifies a USB-KEY login request initiated by the login user based on the unique identification information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, apparatus, computer equipment, and storage medium for user login via a USB-KEY. Background Art

[0002] Traditional secure logins use a system username and password binding to log into terminal devices. Even if a login password is set, it can be cracked to gain access to the terminal device. This is especially true for devices involving confidential information or industrial computers. This can have serious consequences, such as power system attacks. Using UKEY-binding reduces the likelihood of successful brute force cracking and prevents unauthorized access. Summary of the Invention

[0003] The embodiments of the present application provide a user login method, apparatus, computer equipment and storage medium via a USB-KEY, which are used to perform vulnerability detection on software installed in a terminal device.

[0004] An embodiment of the present invention provides a user login method using a USB-KEY, the method comprising:

[0005] Receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user;

[0006] Storing the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence;

[0007] According to the preset mapping table, the unique identification information of the corresponding mobile authentication device is sent to the terminal device corresponding to the terminal device identifier; so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information.

[0008] An embodiment of the present invention provides a user login device using a USB-KEY, the device comprising:

[0009] A receiving module, configured to receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user;

[0010] A storage module, configured to store the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence;

[0011] The sending module is used to send the unique identification information of the corresponding mobile authentication device to the terminal device corresponding to the terminal device identifier according to the preset mapping table; so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information.

[0012] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the user login method via a USB-KEY is implemented.

[0013] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the user login method through a USB-KEY.

[0014] The present invention provides a user login method and device through a USB-KEY, a computer device and a storage medium. After receiving a USB-KEY login request initiated by a login user through a mobile authentication device, the present invention reads unique identification information in the mobile authentication device, and then queries whether the unique identification information exists in an identification information table to verify whether the login request of the login user is passed. That is, when the unique identification information exists in the identification information table, the login request of the login user is allowed, thereby improving the security of user login through the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 A block diagram of a USB-KEY user login system provided by this application;

[0016] Figure 2 A flowchart of a USB-KEY user login method provided by this application;

[0017] Figure 3 Flowchart of another USB-KEY user login method provided by this application;

[0018] Figure 4 A flowchart of another USB-KEY user login method provided by this application;

[0019] Figure 5 A schematic diagram of the structure of the user login device via USB-KEY provided in this application;

[0020] Figure 6 A schematic diagram of a computer device provided for this application. DETAILED DESCRIPTION

[0021] In order to better understand the above technical solution, the technical solution of the embodiment of the present application is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiment of the present application and the specific features in the embodiment are detailed descriptions of the technical solution of the embodiment of the present application, rather than limitations on the technical solution of the present application. In the absence of conflict, the embodiment of the present application and the technical features in the embodiment can be combined with each other.

[0022] The following will be combined with the Figure 1 The implementation of the embodiments of the present application is described in detail.

[0023] The solution provided in the embodiment of the present application can be applied to Figure 1 The user of USB-KEY shown in the figure logs into the system 10. Figure 1 As shown, the USB-KEY user login system 10 may include: a server 11 and at least one terminal device 12.

[0024] Among them, the server 11 is used to receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user; store the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table, and according to the preset mapping table, send the corresponding unique identification information of the mobile authentication device to the terminal device 12 corresponding to the terminal device identification.

[0025] The terminal device 12 is used to receive a USB-KEY login request initiated by a logging-in user through a mobile authentication device; and read the unique identification information in the mobile authentication device;

[0026] The terminal device 12 is configured to determine whether the unique identification information is stored in an identification information table; the identification information table is issued by the server based on the binding relationship between the user's mobile authentication device and the terminal device;

[0027] The terminal device 12 is configured to determine that the identity authentication of the login user is passed if the unique identification information is stored in the identification information table, and to allow the login request of the login user;

[0028] The terminal device 12 is configured to determine that the identity authentication of the login user has failed and reject the login request of the login user if the unique identification information is not stored in the identification information table.

[0029] It should be noted that the identification information table in the terminal device 12 in this embodiment may include multiple unique identification information, and each unique identification information corresponds to a user's mobile authentication device, that is, one terminal device 12 in this embodiment can meet the login needs of multiple users; and a user's mobile authentication device can also be bound to multiple terminal devices 12, that is, the unique identification information of the user's mobile authentication device can be stored in multiple terminal devices 12, so as to realize the login of the same user on different terminal devices 12.

[0030] The terminal device 12 may be run on electronic devices such as a mobile phone, a tablet computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, and a personal digital assistant (PDA).

[0031] See also Figure 2 , a USB-KEY user login method provided by an embodiment of the present invention, which is described from the perspective of execution by a terminal device, includes steps S201 to S204:

[0032] Step S201: receiving a USB-KEY login request initiated by a login user through a mobile authentication device.

[0033] Step S202: Read the unique identification information in the mobile authentication device.

[0034] Among them, the unique identification information is used to uniquely identify the mobile authentication device, and the user can initiate a USB-KEY login request through the mobile authentication device.

[0035] Step S203: Determine whether unique identification information is stored in the identification information table; the identification information table is issued by the server according to the binding relationship between the logged-in user and the terminal device.

[0036] The identification information table stores unique identification information of at least one mobile authentication device, and the mobile terminal can verify the identity of the logged-in user through the content in the identification information table.

[0037] Step S204: If the unique identification information is stored in the identification information table, it is determined that the identity authentication of the login user is passed, and the login request of the login user is allowed.

[0038] In one embodiment provided by the present invention, in order to prevent the data in the identification information table from being tampered with, thereby causing the login of the terminal device to be unsafe. In this embodiment, after the terminal device allows the login request of the logged-in user, the mobile terminal needs to detect in real time whether the data in the identification information table has been modified by the logged-in user; if the data in the identification information table has been modified by the logged-in user, the head portrait information of the logged-in user is obtained through the camera device; an alarm message is sent to the server, and the alarm message includes the head portrait information of the logged-in user, the unique identification information and the terminal device identification of the current terminal device are sent to the server. The server obtains the alarm message and further performs corresponding processing, such as sending the alarm message to the management user so that the management user can discover the user's illegal operation behavior in time, and can also re-obtain the unique identification information corresponding to the terminal device identification, and then send the unique identification information to the terminal device, so that the terminal device updates the local identification information table according to the unique identification information.

[0039] Furthermore, after the terminal device sends the alarm information to the server, the method also includes: the terminal device receives the identification information table corresponding to the terminal device identification of the current terminal device sent by the server; the terminal device updates and encrypts the identification information table stored in the current terminal device according to the identification information table.

[0040] Step S205: If the unique identification information is not stored in the identification information table, it is determined that the identity authentication of the login user has failed, and the login request of the login user is rejected.

[0041] It should be noted that, in order to prevent illegal users from repeatedly attempting to log into the terminal device, this embodiment can obtain the number of unique identification information logins of the user that failed verification after rejecting the login request of the login user, and then determine whether the user is an abnormal user or an illegal user based on the number of logins, and then issue an alarm to the determined abnormal user or illegal user, thereby effectively preventing illegal users from attempting to log into the terminal device, thereby improving the security of the terminal device. Specifically, this embodiment can determine whether the user's multiple login behaviors are abnormal logins through both the terminal device and the server, as shown below:

[0042] 1. The terminal device determines abnormal login behavior: the terminal device detects whether the number of USB-KEY login requests initiated by the mobile authentication device within a first preset time period is greater than a first preset value; if the number of logins is greater than a second preset value, the unique identification information is sent to the server, so that the server sends an alarm message to the user corresponding to the unique identification information.

[0043] Among them, the first preset time and the first preset value can be set according to actual needs. For example, if the first preset time is 3 minutes and the first preset value is 10, then when the mobile authentication device of a login user fails to authenticate, the login user repeatedly tries to use the same mobile authentication device to log in to the same terminal device, and within 3 minutes, repeatedly initiates 11 USB-KEY login requests, then the terminal device can determine that the login behavior of the login user is an abnormal login. At this time, it is necessary to send the unique identification information of the login user's mobile authentication device to the server, so that the server sends an alarm message to the user corresponding to the unique identification information to remind him of the ongoing abnormal login behavior.

[0044] 2. The server determines abnormal login behavior: the terminal device sends user identity authentication failure information of the logged-in user to the server, where the user identity authentication failure information includes the verification failure time and the unique identification information, so that the server counts whether the number of USB-KEY login requests initiated by the mobile authentication device within a second preset time period is greater than a second preset value based on the verification failure time and the unique identification information, and sends an alarm message to the user corresponding to the unique identification information whose number of logins is greater than the second preset value.

[0045] Among them, the second preset time and the second preset value can be set according to actual needs. For example, if the second preset time is 5 minutes and the second preset value is 5, then when the mobile authentication device of a login user fails to authenticate, the login user repeatedly attempts to use the same mobile authentication device to log in to different terminal devices, and within 5 minutes, the login user repeatedly initiates 6 USB-KEY login requests on different terminal devices. That is, after the server receives the user identity authentication failure information sent by different terminal devices, it determines based on the verification failure time and unique identification information in the information whether the mobile authentication device belonging to the same unique identification information has initiated more than 5 login applications within 5 minutes (and the login application is initiated on at least one terminal). If it is determined that the mobile authentication device belonging to the same unique identification information has initiated more than 5 login applications within 5 minutes, the server can determine that the user's login is an abnormal login behavior. At this time, the server needs to send an alarm message to the user corresponding to the unique identification information to remind the user of the abnormal login behavior.

[0046] The present invention provides a USB-KEY user login method. After receiving a USB-KEY login request initiated by a login user through a mobile authentication device, the present invention reads unique identification information in the mobile authentication device, and then queries whether the unique identification information exists in an identification information table to verify whether the login request of the login user is passed. That is, when the unique identification information exists in the identification information table, the login request of the login user is allowed, thereby improving the security of user login through the present invention.

[0047] See also Figure 3 , a USB-KEY user login method provided by an embodiment of the present invention, which is described from the perspective of interactive execution between a terminal device and a server, includes steps S301 to S310:

[0048] Step S301: The server receives the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user; and stores the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence.

[0049] Step S302: The server sends unique identification information of the corresponding mobile authentication device to the terminal device corresponding to the terminal device identification according to the preset mapping table.

[0050] Step S303: The terminal device receives the unique identification information of the mobile authentication device sent by the mobile device, and stores the unique identification information of the mobile authentication device in an identification information table.

[0051] In step S304, the terminal device receives a USB-KEY login request initiated by the login user through the mobile authentication device, reads the unique identification information in the mobile authentication device, and determines whether the unique identification information is stored in the identification information table; the identification information table is issued by the server based on the binding relationship between the login user and the terminal device.

[0052] Step S305: If the unique identification information is stored in the identification information table, the terminal device determines that the identity authentication of the login user is passed, and allows the login request of the login user.

[0053] Step S306: If the unique identification information is not stored in the identification information table, the terminal device determines that the identity authentication of the login user has failed, and rejects the login request of the login user.

[0054] It should be noted that, in this embodiment, steps S305 and S306 are the same as Figure 2 The description of the corresponding steps in is the same, and this embodiment will not be repeated here.

[0055] Step S307: The terminal device sends unique identification information indicating failed identity authentication to the server.

[0056] Step S308: The server queries whether there is a terminal device identification corresponding to the unique identification information of the failed identity authentication.

[0057] It should be noted that the server stores the unique identification information corresponding to the terminal device identification of each terminal device. Therefore, after the terminal device fails to verify the unique identification information, the terminal device can send the unique identification information to the server, and the server will further confirm the terminal device identification corresponding to the unique identification information.

[0058] Step S309: If there is a terminal device identifier corresponding to the unique identifier information of the failed identity authentication, the terminal device identifier corresponding to the unique identifier information of the failed identity authentication is sent to the terminal device.

[0059] In this embodiment, if the server has a terminal device identifier corresponding to the unique table information of the failed authentication, the terminal device identifier corresponding to the unique identification information of the failed authentication can be sent to the terminal device, so that the terminal device displays the terminal device identifier corresponding to the unique identification information on its screen interface to prompt the login user of the terminal device that can be used for login. This embodiment thus solves the problem of users not knowing the terminal devices that can be used for login, and improves the user's login experience.

[0060] Step S310: If there is no terminal device identification corresponding to the unique identification information of the identity authentication failure, a prompt message indicating that the corresponding mobile authentication device has not been registered is sent to the terminal device.

[0061] On the contrary, if the terminal device identification corresponding to the unique identification information of the failed identity authentication does not exist in the server, the server sends the corresponding mobile authentication device not registered prompt information to the terminal device, so that the terminal device outputs the mobile authentication device not registered prompt information corresponding to the unique identification information on its screen interface to prompt the logged-in user to register the mobile authentication device.

[0062] The present invention provides a USB-KEY user login method. After a terminal device determines that the identity authentication of a login user has failed and rejects the login request of the login user, the terminal device sends unique identification information of the identity authentication failure to a server. The server further determines whether to register. If the user is registered, the terminal device identifier corresponding to the unique identification information of the identity authentication failure is sent to the terminal device. If the user is registered, a prompt message indicating that the corresponding mobile authentication device has not been registered is sent to the terminal device. That is, this embodiment prompts the user to perform corresponding operations based on the information returned by the server, thereby improving the user's login experience.

[0063] See also Figure 4, a USB-KEY user login method provided by an embodiment of the present invention, which is described from the perspective of interaction between a terminal device and a server, includes steps S401 to S408:

[0064] Step S401: The server receives the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user; and stores the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence.

[0065] Step S402: The server sends unique identification information of the corresponding mobile authentication device to the terminal device corresponding to the terminal device identification according to the preset mapping table.

[0066] In one embodiment of the present invention, a server sends unique identification information of a corresponding mobile authentication device to a terminal device corresponding to the terminal device identifier according to a preset mapping table, including: obtaining unique identification information corresponding to the same terminal device identifier in the preset mapping table; encrypting the unique identification information corresponding to the same terminal device identifier to obtain an encrypted unique identification information package; and sending the encrypted unique identification information package to the terminal device corresponding to the corresponding terminal device identifier. It should be noted that the encryption method of this embodiment can adopt any encryption method in the prior art to encrypt the unique identification information to obtain an encrypted package, and then send the encrypted package to the corresponding terminal device, which can ensure the security of data transmission and further improve user login security.

[0067] In one embodiment of the present invention, after the server obtains the unique identification information corresponding to the same terminal device identification information from the preset mapping table, the method further includes: the server encrypting the unique identification information corresponding to the same terminal device identification to generate summary information, and storing the correspondence between the summary information and the terminal device identification in the preset mapping table. For example, if terminal device 1 corresponds to five unique identification information, summary information is generated based on these five unique identification information, and the summary information is stored in the preset mapping table in correspondence with terminal device 1. This allows the server to determine, in subsequent steps, whether the unique identification information in the terminal device has been tampered with or whether the unique identification information in the terminal device is the latest information determined by the server, thereby ensuring the accuracy and real-time nature of the unique identification information in the terminal device.

[0068] In one embodiment of the present invention, the server also needs to detect in real time whether the data in the preset mapping table has been updated. If the data in the preset mapping table has been updated, the server obtains updated data, which includes the terminal device identifier and the unique identification information of the corresponding mobile authentication device. The server then sends the unique identification information of the mobile authentication device in the updated data to the terminal device corresponding to the terminal device identifier. This updates the unique identification information in the terminal device, thereby ensuring the validity of the user's login using the mobile authentication device.

[0069] Step S403: The terminal device receives a USB-KEY login request initiated by the login user through the mobile authentication device, and sends the login request to the server. The USB-KEY login request includes summary information generated based on the locally stored unique identification information and the terminal device identification.

[0070] Step S404: The server detects whether the summary information and the terminal device identifier are stored in a preset mapping table.

[0071] Step S405: If the preset mapping table stores the corresponding summary information and the terminal device identifier, the server sends a preliminary verification success message to the mobile terminal.

[0072] On the other hand, if the summary information and the terminal device identifier are not stored in the preset mapping table, it indicates that the unique identification information in the terminal device may have been tampered with or has not been updated in a timely manner. In this case, the server needs to resend the unique identification information of the corresponding mobile authentication device to the mobile terminal corresponding to the terminal device identifier, so that the mobile terminal can update the locally stored unique identification information of the mobile authentication device based on the received unique identification information of the mobile authentication device.

[0073] Step S406: After receiving the preliminary verification success information, the mobile terminal obtains the unique identification information in the mobile authentication device and determines whether the unique identification information is stored in the identification information table.

[0074] The identification information table stores unique identification information of the terminal device that is allowed to log in. The unique identification information in the identification information table is sent by the server.

[0075] Step S407: If the unique identification information is stored in the identification information table, the terminal device determines that the identity authentication of the login user is passed, and allows the login request of the login user.

[0076] Step S408: If the unique identification information is not stored in the identification information table, the terminal device determines that the identity authentication of the login user has failed, and rejects the login request of the login user.

[0077] In one embodiment provided by the present invention, after the terminal device determines that the login user identity authentication has failed and rejects the login user's login request, the server receives user identity authentication failure information of the login user sent by the terminal device, and the user identity authentication failure information includes the verification failure time and the unique identification information of the mobile authentication device; based on the verification failure time and the unique identification information, the server counts whether the number of USB-KEY login requests initiated by the mobile authentication device within a preset time period is greater than a preset value; if the number of logins is greater than the preset value, an alarm message is sent to the user corresponding to the unique identification information.

[0078] It should be understood that the order of execution of the steps in the above embodiments does not necessarily mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0079] In one embodiment, a user login device via USB-KEY is provided, which corresponds to the user login method via USB-KEY in the above embodiment. Figure 5 As shown, the functional modules of the user login device through USB-KEY are described in detail as follows:

[0080] A receiving module 51 is configured to receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user;

[0081] The storage module 52 is used to store the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table;

[0082] The sending module 53 is used to send the unique identification information of the corresponding mobile authentication device to the terminal device corresponding to the terminal device identifier according to the preset mapping table; so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information.

[0083] In an optional embodiment, the sending module 53 is specifically configured to:

[0084] Obtaining unique identification information corresponding to the same terminal device identification in the preset mapping table;

[0085] Encrypting the unique identification information corresponding to the identification information of the same terminal device to obtain a unique identification information encrypted package;

[0086] The unique identification information encrypted package is sent to the terminal device corresponding to the corresponding terminal device identification.

[0087] In an optional embodiment, the storage module 52 is further configured to encrypt the unique identification information corresponding to the same terminal device identification to generate summary information, and store the correspondence between the summary information and the terminal device identification in the preset mapping table.

[0088] In an optional embodiment, the device further includes: a detection module 54

[0089] The receiving module 51 is further configured to receive a USB-KEY login request initiated by a logging user through a mobile terminal, wherein the USB-KEY login request includes summary information generated based on the locally stored unique identification information and a terminal device identification;

[0090] A detection module 54, configured to detect whether the summary information and the terminal device identifier are stored correspondingly in the preset mapping table;

[0091] The sending module 53 is also used to send preliminary verification success information to the mobile terminal if the summary information and the terminal device identification are stored correspondingly in the preset mapping table, so that the mobile terminal can verify the USB-KEY login request initiated by the login user according to the locally stored unique identification information.

[0092] In an optional embodiment, the sending module 53 is also used to re-send the unique identification information of the corresponding mobile authentication device to the mobile terminal corresponding to the terminal device identification if the summary information and the terminal device identification are not stored in the preset mapping table, so that the mobile terminal updates the unique identification information of the locally stored mobile authentication device according to the received unique identification information of the mobile authentication device.

[0093] In an optional embodiment, the receiving module 51 is further configured to receive user identity authentication failure information of a logged-in user sent by a terminal device, wherein the user identity authentication failure information includes the time of the authentication failure and the unique identification information of the mobile authentication device;

[0094] Counting whether the number of USB-KEY login requests initiated by the mobile authentication device within a preset time period is greater than a preset value based on the verification failure time and the unique identification information;

[0095] The sending module 53 is further configured to send an alarm message to the user corresponding to the unique identification information if the number of login times is greater than a preset value.

[0096] In an optional embodiment, the detection module 54 is further configured to detect whether the data in the preset mapping table is updated;

[0097] If the data in the preset mapping table is updated, obtaining updated data, the updated data including the terminal device identification and the unique identification information of the corresponding mobile authentication device;

[0098] The sending module 53 is further configured to send the unique identification information of the mobile authentication device in the update data to the terminal device corresponding to the terminal device identification.

[0099] For the specific definition of the user login device through USB-KEY, please refer to the definition of the user login method through USB-KEY above, which will not be repeated here. Each module in the above-mentioned device can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0100] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a user login method via a USB-KEY is implemented.

[0101] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:

[0102] Receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user;

[0103] Storing the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence;

[0104] According to the preset mapping table, the unique identification information of the corresponding mobile authentication device is sent to the terminal device corresponding to the terminal device identifier; so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information.

[0105] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0106] Receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user;

[0107] Storing the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence;

[0108] According to the preset mapping table, the unique identification information of the corresponding mobile authentication device is sent to the terminal device corresponding to the terminal device identifier; so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information.

[0109] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0110] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0111] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A user login method via USB-KEY, characterized in that: The method applies a server, and the method includes: Receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user; Storing the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence; According to the preset mapping table, the unique identification information of the corresponding mobile authentication device is sent to the terminal device corresponding to the terminal device identifier; so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information; After the terminal device allows the login request of the logged-in user, the mobile terminal detects in real time whether the data in the identification information table has been modified by the logged-in user; If the data in the identification information table is modified by the logged-in user, obtaining the head portrait information of the logged-in user through a camera device; Sending an alarm message to the server, the alarm message including the avatar information, unique identification information and terminal device identification of the current terminal device of the logged-in user; enabling the server to obtain the alarm message and send the alarm message to the management user.

2. The method according to claim 1, characterized in that The step of sending the unique identification information of the corresponding mobile authentication device to the terminal device corresponding to the terminal device identification according to the preset mapping table includes: Obtaining unique identification information corresponding to the same terminal device identification in the preset mapping table; Encrypting the unique identification information corresponding to the identification information of the same terminal device to obtain a unique identification information encrypted package; The unique identification information encrypted package is sent to the terminal device corresponding to the corresponding terminal device identification.

3. The method according to claim 2, characterized in that After obtaining the unique identification information corresponding to the same terminal device identification information in the preset mapping table, the method further includes: The unique identification information corresponding to the same terminal device identification is encrypted to generate summary information, and the corresponding relationship between the summary information and the terminal device identification is stored in the preset mapping table.

4. The method according to claim 3, characterized in that The method further comprises: Receiving a USB-KEY login request initiated by the login user through a mobile terminal, wherein the USB-KEY login request includes summary information generated based on the locally stored unique identification information and a terminal device identification; Detecting whether the summary information and the terminal device identifier are stored correspondingly in the preset mapping table; If the summary information and the terminal device identification are stored correspondingly in the preset mapping table, preliminary verification success information is sent to the mobile terminal, so that the mobile terminal verifies the USB-KEY login request initiated by the login user according to the unique identification information stored locally.

5. The method according to claim 4, characterized in that After detecting whether the summary information and the terminal device identifier are stored in the preset mapping table, the method further includes: If the summary information and the terminal device identifier are not stored in the preset mapping table, the unique identification information of the corresponding mobile authentication device is re-sent to the mobile terminal corresponding to the terminal device identifier, so that the mobile terminal updates the locally stored unique identification information of the mobile authentication device according to the received unique identification information of the mobile authentication device.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Receiving user identity authentication failure information of a logged-in user sent by a terminal device, wherein the user identity authentication failure information includes the time of the authentication failure and the unique identification information of the mobile authentication device; Counting whether the number of USB-KEY login requests initiated by the mobile authentication device within a preset time period is greater than a preset value based on the verification failure time and the unique identification information; If the number of logins is greater than a preset value, an alarm message is sent to the user corresponding to the unique identification information.

7. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Detecting whether the data in the preset mapping table is updated; If the data in the preset mapping table is updated, obtaining updated data, the updated data including the terminal device identification and the unique identification information of the corresponding mobile authentication device; The unique identification information of the mobile authentication device in the update data is sent to the terminal device corresponding to the terminal device identification.

8. A user login device via USB-KEY, characterized in that: The device comprises: A receiving module, configured to receive the unique identification information of the mobile authentication device and the corresponding terminal device identification input by the management user; A storage module, configured to store the unique identification information of the mobile authentication device and the terminal device identification in a preset mapping table in correspondence; a sending module, configured to send, according to the preset mapping table, the unique identification information of the corresponding mobile authentication device to the terminal device corresponding to the terminal device identifier, so that the terminal device stores the unique identification information and verifies the USB-KEY login request initiated by the login user according to the unique identification information; After the terminal device allows the login request of the logged-in user, the mobile terminal detects in real time whether the data in the identification information table has been modified by the logged-in user; If the data in the identification information table is modified by the logged-in user, obtaining the head portrait information of the logged-in user through a camera device; Send an alarm message to the server, the alarm message including the avatar information, unique identification information and terminal device identification of the current terminal device of the logged-in user; enable the server to obtain the alarm message and send the alarm message to the management user.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the user login method through USB-KEY is implemented as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the user login method via USB-KEY as claimed in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Login verification method and terminal device

    CN108183924A

  • Data processing method and system based on USBKey

    CN110690971A