A login authentication method and device
Through the communication connection between the authentication system and the OMS system, the mobile key device is used to generate random verification codes and perform signature verification, and generate authentication-free identification, which solves the account security problems caused by multiple logins in the OMS system, realizes multi-factor verification and unified login, and improves security and convenience.
Patent Information
- Application Number
- CN202111468942.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-03
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-12-03
AI Technical Summary
In the existing OMS system, users need to log in to each system, resulting in the leakage of accounts and passwords, reducing account security.
Through the authentication system, the communication and connection is made with multiple OMS systems, the mobile key device generates a random verification code, reads the verification information for signature verification, generates authentication-free identification, realizes multi-factor verification, and unified login.
It improves the security of login accounts, realizes unified login of multiple OMS systems, reduces user management burden, and enhances system security.
Smart Images

Figure CN114238922B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of login verification, and particularly to a login identity verification method and device. Background Art
[0002] With the rapid development of the national economy, the scale of the power grid has been continuously expanding. The OMS (Order Management System) belongs to the category of power monitoring systems. As an important support system for the daily work of dispatching operations, it is necessary to protect the security of power monitoring systems and dispatching data networks, resist the destruction and attacks of hackers, viruses, malicious codes, etc., prevent the collapse or paralysis of power monitoring systems, and the resulting power system accidents or large-scale power outages.
[0003] In the current OMS system, the user information stored in each system is independent of each other. When using multiple systems in work, it is necessary to log in to each system separately, and usually, it depends on the user's personal password for account login. In the above account login method, since it is necessary to continuously log in to each system separately, it is easy to cause the leakage of accounts and passwords, resulting in a reduction in account security. Summary of the Invention
[0004] The present invention provides a login identity verification method and device, which solves the technical problem that in the existing account login method of the OMS system, since it is necessary to continuously log in to each system separately, it is easy to cause the leakage of accounts and passwords, resulting in a reduction in account security.
[0005] A login identity verification method provided by the present invention is applied to an authentication system, and the authentication system is communicatively connected to a plurality of preset OMS systems. The method includes:
[0006] When it is detected that a mobile key device is inserted into any one of the OMS systems and the forwarded user login information is received, return a random verification code corresponding to the user login information;
[0007] When the input information in response to the random verification code is received, read the verification information from the mobile key device;
[0008] Sign the input information with the verification information to obtain signature data and verify it;
[0009] If the verification passes, generate a login success prompt and an authentication-free identifier corresponding to the user login information;
[0010] When the updated user login information forwarded by any one of the OMS systems is received again, based on the verification result of the authentication-free identifier carried in the updated user login information, determine whether to generate the login success prompt.
[0011] Optionally, the method further includes:
[0012] If the verification fails, a rejection login prompt is generated.
[0013] Optionally, the step of, when detecting that any one of the OMS systems inserts a mobile key device and receives the forwarded user login information, returning a random verification code corresponding to the user login information includes:
[0014] When detecting that any one of the OMS systems inserts a mobile key device and receives the user account, a password input prompt is generated;
[0015] After the OMS system receives the login password input in response to the password input prompt, it determines whether the login password is correct;
[0016] If so, the OMS system determines the user account as the user login information and forwards it to the authentication system, and the authentication system returns a random verification code corresponding to the user login information;
[0017] If not, a login failure prompt is generated.
[0018] Optionally, the authentication system includes a certificate database; the step of using the verification information to sign the input information to obtain signature data and verifying includes:
[0019] Using the verification information to sign the random verification code to generate signature data;
[0020] Searching for the corresponding user signature certificate from the certificate database according to the user login information;
[0021] Comparing the user signature certificate with the signature data;
[0022] If the signature of the user signature certificate is consistent with the signature corresponding to the signature data, the verification is determined to pass;
[0023] If the signature of the user signature certificate is inconsistent with the signature corresponding to the signature data, the verification is determined to fail.
[0024] Optionally, the step of, when receiving the updated user login information forwarded by any one of the OMS systems again, determining whether to generate the login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information includes:
[0025] When receiving the updated user login information forwarded by any one of the OMS systems again, it determines whether the updated user login information carries the authentication-free identifier;
[0026] If so, verify the authentication-free identifier, and determine whether the user login information to which the authentication-free identifier belongs has been logged in;
[0027] If it is determined that the user has logged in, generate the login success prompt;
[0028] If it is determined that the user has not logged in, jump to execute the step of returning the random verification code corresponding to the user login information.
[0029] The present invention further provides a login identity authentication device, which is applied to an authentication system. The authentication system is communicatively connected to a plurality of preset OMS systems. The device includes:
[0030] A random verification code return module, configured to return a random verification code corresponding to the user login information when it is detected that any one of the OMS systems inserts a mobile key device and receives the forwarded user login information;
[0031] A verification information reading module, configured to read verification information from the mobile key device when receiving the input information in response to the random verification code;
[0032] A signature verification module, configured to sign the input information with the verification information to obtain signature data and verify it;
[0033] A login success determination module, configured to generate a login success prompt and an authentication-free identifier corresponding to the user login information if the verification is passed;
[0034] A single sign-on verification module, configured to determine whether to generate the login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information when receiving the updated user login information forwarded by any one of the OMS systems again.
[0035] Optionally, the device further includes:
[0036] A login failure determination module, configured to generate a login rejection prompt if the verification fails.
[0037] Optionally, the random verification code return module is specifically configured to:
[0038] Generate a password input prompt when it is detected that any one of the OMS systems inserts a mobile key device and receives the user account;
[0039] When the OMS system receives the login password entered in response to the password input prompt, determine whether the login password is correct;
[0040] If so, determine the user account as user login information through the OMS system and forward it to the authentication system, and return a random verification code corresponding to the user login information through the authentication system;
[0041] If not, generate a login failure prompt.
[0042] Optionally, the authentication system includes a certificate database; the signature verification module is specifically used for:
[0043] Sign the random verification code with the verification information to generate signature data;
[0044] Search for the corresponding user signature certificate from the certificate database according to the user login information;
[0045] Compare the user signature certificate with the signature data;
[0046] If the signature of the user signature certificate is consistent with the signature corresponding to the signature data, it is determined that the verification is passed;
[0047] If the signature of the user signature certificate is inconsistent with the signature corresponding to the signature data, it is determined that the verification fails.
[0048] Optionally, the single sign-on verification module is specifically used for:
[0049] When receiving the updated user login information forwarded by any of the OMS systems again, determine whether the updated user login information carries the authentication-free identifier;
[0050] If so, verify the authentication-free identifier and determine whether the user login information to which the authentication-free identifier belongs has been logged in;
[0051] If it is determined that the user has logged in, generate the login success prompt;
[0052] If it is determined that the user has not logged in, jump to execute the step of returning the random verification code corresponding to the user login information.
[0053] From the above technical solutions, it can be seen that the present invention has the following advantages:
[0054] When the authentication system detects that any OMS system inserts a mobile key device and receives the forwarded user login information, it returns a random verification code corresponding to the user login information; when it receives the input information in response to the random verification code, it reads the verification information from the mobile key device; it signs the input information with the verification information to obtain signature data and verifies it; if the verification passes, it generates a login success prompt and an authentication-free identifier corresponding to the user login information; when it receives the updated user login information forwarded by any OMS system again, it determines whether to generate a login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information. Thus, unified login of multiple OMS systems is realized, and at the same time, the security of the login account is improved through the method of multi-factor verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0056] Figure 1 It is a flowchart of the steps of a login identity authentication method provided in Embodiment 1 of the present invention;
[0057] Figure 2 It is a flowchart of the steps of a login identity authentication method provided in Embodiment 2 of the present invention;
[0058] Figure 3 It is a single sign-on flowchart provided in the embodiments of the present invention;
[0059] Figure 4 It is a structural block diagram of a login identity authentication device provided in Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0060] The embodiments of the present invention provide a login identity authentication method and device, which are used to solve the technical problem that the account login method of the existing OMS system is prone to account and password leakage due to the need for continuous login in each system, resulting in reduced account security.
[0061] In order to make the object, features, and advantages of the present invention more obvious and understandable, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the embodiments described below are only some embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0062] Please refer to Figure 1 , Figure 1 which is the flowchart of the steps of a login authentication method provided in the first embodiment of the present invention.
[0063] A login authentication method provided by the present invention is applied to an authentication system, which is communicatively connected to a plurality of preset OMS systems. The method includes:
[0064] Step 101, when it is detected that a mobile key device is inserted into any OMS system and the forwarded user login information is received, return a random verification code corresponding to the user login information;
[0065] The mobile key device refers to a small storage device that is directly connected to a computer through USB (Universal Serial Bus Interface), has a password verification function, and is reliable and fast, such as a Ukey. The digital certificate is written into the UKey through the API provided by the UKey device manufacturer, and the corresponding driver is installed, so that the system can recognize the UKey mobile device, provide corresponding encryption and decryption signature interfaces, such as reading the UKey serial number, reading the encrypted signature certificate, signing, etc., prohibit directly reading the private key, and have corresponding security policies for protection.
[0066] In the embodiment of the present invention, the authentication system can be communicatively connected to a plurality of OMS systems respectively. If it is detected that a mobile key device is inserted into a certain OMS system, the user login information input by the user at this time, such as the user account, etc., is received through this OMS system. When the authentication system receives the user login information forwarded by the OMS system, it can generate a random verification code corresponding to the user login information locally in the authentication system and return it.
[0067] Step 102, when the input information in response to the random verification code is received, read the verification information from the mobile key device;
[0068] The verification information refers to information such as the user signature certificate pre-stored in the mobile key device.
[0069] After returning the random verification code, the user can respond to the received random verification code and type in the input information on the OMS system. At this time, the authentication system can read the verification information from the mobile key device.
[0070] Step 103, use the verification information to sign the input information to obtain signature data and verify it;
[0071] After receiving the input information and extracting the verification information, the verification information can be used to sign the input information to obtain signature data, and the verification code and signature in the signature data are verified in combination with the signature certificate in the authentication system.
[0072] Step 104, if the verification is passed, generate a login success prompt and an authentication-free identifier corresponding to the user login information.
[0073] In the embodiment of the present invention, if the verification is passed, it indicates that the user login information can be allowed to log in to the OMS system at this time, and a login success prompt can be generated and the user can be redirected to the initial operation page of the OMS system.
[0074] Meanwhile, since there are multiple OMS systems, in order to facilitate the subsequent login of the same user, an authentication-free identifier corresponding to the user login information can be generated while allowing the user to log in.
[0075] Step 105, when receiving the updated user login information forwarded by any OMS system again, based on the verification result of the authentication-free identifier carried in the updated user login information, determine whether to generate a login success prompt.
[0076] The updated user login information refers to the user login information received by the remaining OMS systems except the logged-in one, and the user login information carries an authentication-free identifier.
[0077] When receiving the updated user login information forwarded by any OMS system again, the authentication-free identifier carried in the updated user login information can be verified, and based on the verification result, it can be determined whether to allow the updated user login information to log in to the OMS system, that is, to determine whether to generate a login success prompt.
[0078] In the embodiment of the present invention, when the authentication system detects that any OMS system inserts a mobile key device and receives the forwarded user login information, it returns a random verification code corresponding to the user login information; when receiving the input information in response to the random verification code, it reads the verification information from the mobile key device; uses the verification information to sign the input information to obtain signature data and verifies it; if the verification is passed, it generates a login success prompt and an authentication-free identifier corresponding to the user login information; when receiving the updated user login information forwarded by any OMS system again, based on the verification result of the authentication-free identifier carried in the updated user login information, determine whether to generate a login success prompt. Thus, unified login of multiple OMS systems is realized, and at the same time, the security of the login account is improved through the multi-factor verification method.
[0079] Please refer to Figure 2 , Figure 2 which is the step flowchart of a login identity verification method provided in the second embodiment of the present invention.
[0080] A login identity verification method provided by the present invention is applied to an authentication system, and the authentication system is communicatively connected to multiple preset OMS systems. The method includes:
[0081] Step 201: When it is detected that any OMS system inserts a mobile key device and receives a user account, generate a password input prompt.
[0082] In an embodiment of the present invention, when it is detected that any OMS system inserts a mobile key device and the user enters a user account, at this time, a corresponding password input prompt can be generated on the OMS system to inform the user that they can further enter a password.
[0083] Step 202: When the OMS system receives the login password entered in response to the password input prompt, determine whether the login password is correct.
[0084] After generating a password input prompt on the OMS system, if the OMS system receives the login password entered by the user in response to the password input prompt, further determine whether the login password is correct.
[0085] There are various ways to determine whether the login password is correct. For example, through the authentication database built in the authentication system, retrieve the corresponding correct login password according to the user account, and compare the correct login password with the entered login password. If they are the same, it is determined that the login password is correct; if they are different, it is determined that the login password is incorrect.
[0086] Step 203: If so, forward the user account as the user login information to the authentication system through the OMS system, and the authentication system returns a random verification code corresponding to the user login information.
[0087] When the login password is determined to be correct, the user account can be forwarded as the user login information to the authentication system through the OMS system. After receiving the user login information, the authentication system can return a corresponding random verification code to the OMS system, waiting for the user to enter the input information corresponding to the random verification code for secondary verification.
[0088] Step 204: If not, generate a login failure prompt.
[0089] If the login password is determined to be incorrect, generate a login failure prompt.
[0090] Step 205: When receiving the input information in response to the random verification code, read the verification information from the mobile key device.
[0091] The verification information refers to information such as the user signature certificate pre-stored in the mobile key device.
[0092] After returning the random verification code, the user can respond to the received random verification code, enter the input information on the OMS system, and the authentication system can read the verification information from the mobile key device at this time.
[0093] Step 206: Sign the input information with the verification information to obtain signature data and verify it.
[0094] Optionally, the authentication system includes a certificate database; Step 206 may include the following sub-steps:
[0095] Sign the random verification code with the verification information to generate signature data;
[0096] Search for the corresponding user signature certificate from the certificate database according to the user login information;
[0097] Compare the user signature certificate with the signature data;
[0098] If the signature corresponding to the user signature certificate is consistent with the signature data, it is determined that the verification is passed;
[0099] If the signature corresponding to the user signature certificate is inconsistent with the signature data, it is determined that the verification fails.
[0100] In the embodiment of the present invention, after obtaining the verification information, the random verification code can be signed with the verification information to obtain signature data; retrieve from the certificate database built in the authentication system according to the user login information. If a user signature certificate corresponding to the user login information is found, the signature in the user signature certificate is compared with the signature in the signature data. If the comparison result is consistent, it can be determined that the signature verification of the random verification code is passed. If it is inconsistent, it is determined that the verification fails.
[0101] Step 207: If the verification is passed, generate a login success prompt and an authentication-free identifier corresponding to the user login information;
[0102] Optionally, the method further includes:
[0103] If the verification fails, generate a login rejection prompt.
[0104] Step 208: When receiving the updated user login information forwarded by any OMS system again, determine whether to generate a login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information.
[0105] Optionally, Step 208 may include the following sub-steps:
[0106] When receiving the updated user login information forwarded by any OMS system again, determine whether the updated user login information carries an authentication-free identifier;
[0107] If so, verify the authentication-free identifier and determine whether the user login information to which the authentication-free identifier belongs has logged in;
[0108] If it is determined that the user has logged in, generate a login success prompt;
[0109] If it is determined that the user is not logged in, then jump to execute the step of returning a random verification code corresponding to the user login information.
[0110] In an example of the present invention, when receiving the updated user login information forwarded by any OMS system again, first determine whether the user login information carries an authentication-free identifier. If it carries an authentication-free identifier, to improve the security of the account, the authentication-free identifier can be further verified to determine whether the user with the authentication-free identifier has logged in.
[0111] In a specific implementation, the authentication system should also verify the authentication-free identifier ticket to determine its validity. All OMS systems need to be able to identify and extract ticket information. To implement the SSO function and allow the user to log in only once, it is necessary to enable the OMS system to identify the users who have already logged in. The OMS system should be able to identify and extract the ticket, and through communication with the authentication system, automatically determine whether the current user has logged in, so as to complete the single sign-on function.
[0112] If it is determined that the user login information has been logged in, it indicates that the current updated user login information belongs to the logged-in user. At this time, a login success prompt can be generated to implement the single sign-on function of the user login information; if it is determined that the user login information has not been logged in, then jump to step 203, return the random verification code again, and use the updated user login information as the new user login information to perform the login verification again. Thus, the user will no longer be troubled by being logged in to the OMS system multiple times from other systems, nor will they need to remember the account of the OMS system anymore, reducing the management burden of the user account and ensuring the security of the system.
[0113] Please refer to Figure 3 , Figure 3 which shows a single sign-on flow chart of the present invention.
[0114] When the user first accesses the OMS system, since the user has not logged in yet, the user will be guided to the authentication system for login; according to the login information provided by the user, the authentication system performs identity verification. If the verification is passed, an authentication credential ticket should be returned to the user; when the user accesses other applications, this ticket will be carried as the user's own authentication credential. After the OMS system receives the request, it will send the ticket to the authentication system for verification to check the legitimacy of the ticket. If the verification is passed, the user can access the OMS system 2 and the OMS system 3 without logging in again. The main function of the authentication system is to compare the user's login information with the user information database to authenticate the user; after successful authentication, the authentication system should generate a unified authentication mark (ticket) and return it to the user.
[0115] In an embodiment of the present invention, when the authentication system detects that any OMS system inserts a mobile key device and receives the forwarded user login information, it returns a random verification code corresponding to the user login information; when receiving the input information in response to the random verification code, it reads the verification information from the mobile key device; it signs the input information with the verification information to obtain signature data and verifies it; if the verification passes, it generates a login success prompt and an authentication-free identifier corresponding to the user login information; when receiving the updated user login information forwarded by any OMS system again, it determines whether to generate a login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information. Thus, unified login for multiple OMS systems is realized, and at the same time, the security of the login account is improved through the multi-factor verification method.
[0116] Please refer to Figure 4 , Figure 4 which is a structural block diagram of a login identity authentication device provided in Embodiment 3 of the present invention.
[0117] An embodiment of the present invention provides a login identity authentication device, which is applied to an authentication system. The authentication system is communicatively connected to multiple preset OMS systems. The device includes:
[0118] A random verification code return module 401, configured to return a random verification code corresponding to the user login information when detecting that any OMS system inserts a mobile key device and receiving the forwarded user login information;
[0119] A verification information reading module 402, configured to read the verification information from the mobile key device when receiving the input information in response to the random verification code;
[0120] A signature verification module 403, configured to sign the input information with the verification information to obtain signature data and verify it;
[0121] A login success determination module 404, configured to generate a login success prompt and an authentication-free identifier corresponding to the user login information if the verification passes;
[0122] A single sign-on verification module 405, configured to determine whether to generate a login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information when receiving the updated user login information forwarded by any OMS system again.
[0123] Optionally, the device further includes:
[0124] A login failure determination module, configured to generate a login rejection prompt if the verification fails.
[0125] Optionally, the random verification code return module 401 is specifically configured to:
[0126] When any OMS system detects the insertion of a mobile key device and receives a user account, a password input prompt is generated;
[0127] After the OMS system receives the login password entered in response to the password input prompt, it determines whether the login password is correct;
[0128] If so, the OMS system determines the user account as the user login information and forwards it to the authentication system, and the authentication system returns a random verification code corresponding to the user login information;
[0129] If not, a login failure prompt is generated.
[0130] Optionally, the authentication system includes a certificate database; the signature verification module 403 is specifically configured to:
[0131] Sign the random verification code using the verification information to generate signature data;
[0132] Search the certificate database for the corresponding user signature certificate according to the user login information;
[0133] Compare the user signature certificate with the signature data;
[0134] If the signature of the user signature certificate is consistent with the signature corresponding to the signature data, it is determined that the verification is passed;
[0135] If the signature of the user signature certificate is inconsistent with the signature corresponding to the signature data, it is determined that the verification fails.
[0136] Optionally, the single sign-on verification module 405 is specifically configured to:
[0137] When receiving the updated user login information forwarded by any OMS system again, it determines whether the updated user login information carries an authentication-free identifier;
[0138] If so, verify the authentication-free identifier and determine whether the user login information to which the authentication-free identifier belongs has been logged in;
[0139] If it is determined that the user has logged in, a login success prompt is generated;
[0140] If it is determined that the user has not logged in, it jumps to the step of returning the random verification code corresponding to the user login information.
[0141] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described devices and modules can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0142] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0143] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0144] In addition, each functional unit in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0145] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0146] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of various embodiments of the present invention.
Claims
1. A login authentication method, characterized in that, Applied to an authentication system, the authentication system is communicatively connected to a plurality of preset OMS systems, and the method includes: When it is detected that a mobile key device is inserted into any one of the OMS systems and the forwarded user login information is received, return a random verification code corresponding to the user login information; When the input information in response to the random verification code is received, read the verification information from the mobile key device; Sign the input information with the verification information to obtain signature data and verify it; If the verification passes, generate a login success prompt and an authentication-free identifier corresponding to the user login information; When the updated user login information forwarded by any one of the OMS systems is received again, based on the verification result of the authentication-free identifier carried in the updated user login information, determine whether to generate the login success prompt; The step of, when the updated user login information forwarded by any one of the OMS systems is received again, based on the verification result of the authentication-free identifier carried in the updated user login information, determining whether to generate the login success prompt, includes: When the updated user login information forwarded by any one of the OMS systems is received again, determine whether the updated user login information carries the authentication-free identifier; If so, verify the authentication-free identifier and determine whether the user login information to which the authentication-free identifier belongs has been logged in; If it is determined that the user has logged in, generate the login success prompt; If it is determined that the user has not logged in, jump to execute the step of returning a random verification code corresponding to the user login information.
2. The method according to claim 1, wherein The method further includes: If the verification fails, generate a login rejection prompt.
3. The method according to claim 1, characterized in that, The step of, when it is detected that a mobile key device is inserted into any one of the OMS systems and the forwarded user login information is received, returning a random verification code corresponding to the user login information, includes: When it is detected that a mobile key device is inserted into any one of the OMS systems and the user account is received, generate a password input prompt; When the OMS system receives the login password entered in response to the password input prompt, determine whether the login password is correct; If so, determine the user account as the user login information through the OMS system and forward it to the authentication system, and the authentication system returns a random verification code corresponding to the user login information; If not, generate a login failure prompt.
4. The method according to any one of claims 1-3, characterized in that, The authentication system includes a certificate database; the step of signing the input information with the verification information to obtain signature data and verifying it includes: Sign the random verification code with the verification information to generate signature data; Search for the corresponding user signature certificate from the certificate database according to the user login information; Compare the user signature certificate with the signature data; If the signature of the user signature certificate is consistent with the signature corresponding to the signature data, determine that the verification passes; If the signature of the user signature certificate is inconsistent with the signature corresponding to the signature data, determine that the verification fails.
5. A login authentication device, characterized in that, Applied to an authentication system, the authentication system is communicatively connected to a plurality of preset OMS systems, and the device includes: A random verification code return module, configured to return a random verification code corresponding to the user login information when it is detected that any one of the OMS systems inserts a mobile key device and the forwarded user login information is received; A verification information reading module, configured to read verification information from the mobile key device when the input information in response to the random verification code is received; A signature verification module, configured to sign the input information with the verification information, obtain signature data and verify it; A login success determination module, configured to generate a login success prompt and an authentication-free identifier corresponding to the user login information if the verification passes; A single sign-on verification module, configured to determine whether to generate the login success prompt based on the verification result of the authentication-free identifier carried in the updated user login information when the updated user login information forwarded by any one of the OMS systems is received again; Specifically, the single sign-on verification module is configured to: When the updated user login information forwarded by any one of the OMS systems is received again, determine whether the updated user login information carries the authentication-free identifier; If so, verify the authentication-free identifier and determine whether the user login information to which the authentication-free identifier belongs has been logged in; If it is determined that the user has logged in, generate the login success prompt; If it is determined that the user has not logged in, jump to execute the step of returning the random verification code corresponding to the user login information.
6. The device according to claim 5, characterized in that, The device further includes: A login failure determination module, configured to generate a login rejection prompt if the verification fails.
7. The device according to claim 5, characterized in that, Specifically, the random verification code return module is configured to: Generate a password input prompt when it is detected that any one of the OMS systems inserts a mobile key device and the user account is received; After the OMS system receives the login password input in response to the password input prompt, determine whether the login password is correct; If so, determine the user account as the user login information through the OMS system and forward it to the authentication system, and the authentication system returns a random verification code corresponding to the user login information; If not, generate a login failure prompt.
8. The device according to any one of claims 5-7, characterized in that, The authentication system includes a certificate database; specifically, the signature verification module is configured to: Sign the random verification code with the verification information to generate signature data; Search for the corresponding user signature certificate from the certificate database according to the user login information; Compare the user signature certificate with the signature data; If the signature of the user signature certificate is consistent with the signature corresponding to the signature data, it is determined that the verification passes; If the signature of the user signature certificate is inconsistent with the signature corresponding to the signature data, it is determined that the verification fails.
Citation Information
Patent Citations
Authentication device and system and method using same for on-line identity authentication and transaction
CN101848090A
Power grid core business system access method and system based on trusted identity authentication
CN112257042A
Transformer substation trusted management system, method and device and computer equipment
CN112667996A