Secure Browser with Identity Authentication Lock Screen Interface and Terminal Permission Control

Through the identity authentication lock screen interface and terminal permission management secure browser, the problem of insufficient browser security in shared terminal scenarios is solved, and mutual non-interference and terminal security protection is achieved for multiple logins, enhancing the security and usage record management of browsers.

CN114462011BActive Publication Date: 2025-07-25DALIAN NINELOCK NETWORKS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210055896.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-18
Publication Date
2025-07-25
Estimated Expiration
2042-01-18

AI Technical Summary

Technical Problem

In the shared terminal scenario, the existing browsers have insufficient security protection, and they have failed to effectively realize that multiple people log in without interfering with each other and are invisible to each other, and the browser protection is ignored.

Method used

It provides a secure browser with an identity authentication lock screen interface. It receives and authenticates user identity information through the lock screen interface, combines the QR code, personal account and PIN code login method to realize the identity authentication of end users, and controls the use of USB flash drives and applications through permission whitelists, and combines the background server for unified management.

Benefits of technology

It realizes that multiple people log in on the shared terminal does not interfere with each other and is invisible to ensure terminal security, protect the security status during browser use, and protect the shared terminal and browser at the same time through personalized permission configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114462011B_ABST
    Figure CN114462011B_ABST
Patent Text Reader

Abstract

The present invention provides a secure browser with an identity authentication lock screen interface and terminal permission management, which relates to the field of information security technology. Functions such as login lock screen, permission control, and shared login are added to the browser. The login lock screen part includes three login methods: one-key login, QR code login, and PIN code login; the permission control includes two parts: application program running control and USB flash drive reading control. The browser in the present invention is applicable to the shared scenario. When the user first uses the browser, a unified default policy will be configured, and all usage records generated during the login of the personal account will be uploaded to the server for backup. After the user logs in to the browsers of different hosts through the personal account, only their own usage records and personalized settings can be seen. By binding with the identity of the user logging in to the operating system and then performing user-specific permission configuration, the present invention achieves the purpose of protecting both the shared terminal and the browser at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and particularly to a secure browser with an identity authentication lock screen interface and terminal permission management. Background Art

[0002] A browser is an application software that displays files within a website server or a file system and enables users to interact with these files. Generally, a browser has functions such as web page browsing, bookmarks, favorites, downloads, searches, etc. In scenarios such as enterprises, schools, Internet cafes, etc., where office work, study, entertainment, and multiple people need to share a terminal, the browser also has the function of realizing shared terminals.

[0003] However, when realizing shared terminals through a browser, only the security of the terminal is often considered, but the protection of the browser is ignored. Summary of the Invention

[0004] In view of this, the present invention provides a secure browser with an identity authentication lock screen interface and terminal permission control. Through this secure browser, a controlled terminal can be controlled to achieve shared terminals where multiple people can log in to the same terminal without interfering with each other and being invisible to each other, and ensure that the terminal is in a secure state during the use of the browser; more importantly, the present invention performs user - personalized permission configuration after binding with the identity of the user logging in to the operating system, so as to achieve the purpose of protecting both the shared terminal and the shared browser.

[0005] For this purpose, the present invention provides the following technical solutions:

[0006] The present invention provides a secure browser with an identity authentication lock screen interface and terminal permission control. The secure browser is installed on a controlled terminal and starts automatically after the controlled terminal is powered on. The secure browser includes a lock screen interface; the lock screen interface pops up after the secure browser starts automatically. The secure browser controls the controlled terminal in the following manner:

[0007] The secure browser receives the login identity information of the terminal user through the lock screen interface; and authenticates the login identity information of the terminal user.

[0008] If the authentication is successful, the terminal user is allowed to log in to the secure browser and use the controlled terminal through the secure browser; if the authentication is unsuccessful, the terminal user is prohibited from logging in to the secure browser.

[0009] Further, the secure browser receives the login identity information of the terminal user through the lock screen interface, including:

[0010] The secure browser starts the browser secondary login process while popping up the lock screen interface and submits browser information to the server side;

[0011] The browser secondary login process receives the QR code generated by the background server and displays the QR code on the lock screen interface so that the end user can scan the QR code through the mobile device;

[0012] The background server receives the QR code scan success notification and the login identity information of the end user from the user's mobile device;

[0013] Correspondingly, authenticating the login identity information of the end user includes:

[0014] The background server verifies the received login identity information. If the verification fails, it sends a verification failure notification to the user's mobile device; if the verification is successful, it sends a QR code scan success notification, login identity information, and the historical record corresponding to the login identity information to the browser secondary login process.

[0015] Further, the secure browser receives the login identity information of the end user through the lock screen interface, including:

[0016] The secure browser starts the browser secondary login process while popping up the lock screen interface;

[0017] The browser secondary login process receives the personal account information input by the end user on the lock screen interface;

[0018] The browser secondary login process submits the browser information and the received personal account information to the background server;

[0019] The background server of the browser verifies whether the personal account information exists. If it exists, it sends a one - key login request to the mobile device of the end user so that the one - key login request interface pops up after the mobile device of the end user receives the one - key login request;

[0020] The background server receives the login feedback information and login identity information sent by the mobile device of the end user through the one - key login request interface;

[0021] Correspondingly, authenticating the login identity information of the end user includes:

[0022] The background server verifies the received login identity information. If the verification fails, it sends a verification failure notification to the user's mobile device; if the verification is successful, it sends a QR code scan success notification, login identity information, and the historical record corresponding to the login identity information to the browser secondary login process.

[0023] Furthermore, the secure browser receives the login identity information of the end user through the lock screen interface, including:

[0024] The secure browser starts the browser secondary login process while popping up the lock screen interface;

[0025] The browser secondary login process receives the personal account information input by the end user on the lock screen interface, and retrieves the calculation formula corresponding to the personal account in the local background;

[0026] The browser secondary login process randomly generates a string of numbers and displays them on the lock screen interface;

[0027] The browser secondary login process calculates the numbers according to the calculation formula to obtain a calculation result;

[0028] The browser secondary login process receives the PIN code input by the end user through the lock screen interface, and the PIN code is calculated by the mobile terminal of the end user according to the calculation formula corresponding to the personal account for the numbers;

[0029] Correspondingly, the authentication of the login identity information of the end user is performed, including:

[0030] The browser secondary login process compares the calculation result and the PIN code. If they are the same, the verification is successful; if not, the verification fails.

[0031] Furthermore, the background server of the secure browser is provided with a permission whitelist for controlling the permissions of USB flash drives and application programs.

[0032] Furthermore, the secure browser controls the permissions of USB flash drives, including:

[0033] The secure browser starts the browser secondary login process while popping up the lock screen interface;

[0034] The browser secondary login process receives the USB flash drive access notification sent by the controlled terminal;

[0035] The browser secondary login process reads the access USB flash drive feature value;

[0036] The browser secondary login process determines whether the access USB flash drive feature value is in the USB flash drive permission whitelist. If it is not in the USB flash drive permission whitelist, it sends an instruction not to allow reading the USB flash drive to the controlled terminal; if it is in the USB flash drive permission whitelist, it sends an instruction to allow reading the USB flash drive to the controlled terminal.

[0037] Furthermore, the secure browser controls the permissions of application programs, including:

[0038] The secure browser starts the secondary login process of the browser while popping up the lock screen interface;

[0039] The secondary login process of the browser receives the application startup notification sent by the controlled terminal;

[0040] The secondary login process of the browser reads the application feature value;

[0041] The secondary login process of the browser determines whether the application feature value is in the application permission whitelist. If it is not in the application permission whitelist, it sends an instruction not to allow the application to start to the controlled terminal; if it is in the application permission whitelist, it sends an instruction to allow the application to start to the controlled terminal.

[0042] Furthermore, it also includes: binding the personal account of the user's mobile terminal with the enterprise account through the background server of the browser.

[0043] Advantages and positive effects of the present invention:

[0044] The present invention realizes the control of terminal login through a secure browser. When the controlled terminal is powered on, the browser is automatically popped up, and the lock screen interface is also popped up, which can completely replace the lock screen interfaces of operating systems such as Windows and Linux. All usage records are associated with the personal account, and the personal account usage records are uploaded to the cloud through the network. When the account logs out on the shared terminal, all the memory and usage records related to this account in this shared terminal will be cleared, so that multiple people can log in to this terminal (not simultaneously logged in) without interfering with each other and without seeing each other's records. It is mainly applied to scenarios such as enterprises, schools, Internet cafes, etc., where office work, learning, entertainment, and multiple people need to share terminals. Description of the Drawings

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0046] Figure 1 It is a schematic diagram of the binding process in an embodiment of the present invention;

[0047] Figure 2 It is a schematic diagram of a lock screen login process in an embodiment of the present invention;

[0048] Figure 3 It is another schematic diagram of a lock screen login process in an embodiment of the present invention;

[0049] Figure 4 It is a schematic diagram of another lock screen login process in an embodiment of the present invention;

[0050] Figure 5 It is a schematic diagram of a permission setting process in an embodiment of the present invention;

[0051] Figure 6 It is a schematic diagram of a USB flash drive control process in an embodiment of the present invention;

[0052] Figure 7 It is a schematic diagram of an application program control process in an embodiment of the present invention. Detailed implementation manners

[0053] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0054] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0055] The present invention provides a secure browser with an identity authentication lock screen interface and terminal permission management. On the basis of the functions of a general browser such as web page browsing, bookmarks, favorites, downloads, and searches, functions such as login lock screen, permission control, and shared login are added. Among them, the login lock screen part includes three login methods: one-key login, QR code login, and PIN code login; the permission control includes two parts: application program running control and USB flash drive reading control. The browser in the present invention is applicable to the shared terminal scenario. When the user first uses the browser, a unified default policy will be configured, and all usage records generated during the personal account login will be uploaded to the server for backup. After the user logs in to the browsers of different hosts through the personal account, only his own usage records and personalized settings can be seen.

[0056] The following are the binding process, login process (login by scanning QR code, one-key login, PIN code login), permission setting process, and permission control process (USB drive read control, application program running control) mainly involved in the secure browser of the present invention:

[0057] I. Binding Process

[0058] After the enterprise registers the enterprise account, the personal account is bound to the enterprise account, so that the personal accounts bound to the enterprise account can all use the controlled terminal, and the personalized settings and personal records are saved. As Figure 1 shown, the binding process specifically includes:

[0059] S101. Register the enterprise-exclusive enterprise account on the server side, and import the personal accounts subordinate to the enterprise account to the server side to generate a personal account list;

[0060] Among them, the server side refers to the server corresponding to the browser. Registering the enterprise-exclusive enterprise account on the server side means that the administrator of the enterprise directly imports the enterprise account to the server side, which is equivalent to registering the account.

[0061] S102. Perform enterprise initialization configuration in the host;

[0062] Among them, the enterprise initialization configuration includes but is not limited to opening some host permissions, closing the host Windows lock screen interface, closing the Windows lock screen password, logging out of the Windows account, etc. Here, the host refers to the host selected by the enterprise where the installation browser is to be installed.

[0063] S103. The user registers a personal account on the mobile phone side;

[0064] S104. Enter the enterprise account on the mobile phone side, and bind the personal account to the enterprise account;

[0065] After the personal account is sent to the server side, the personal account is compared with the imported personal account list. If the personal account exists in the personal account list, it is regarded as a successful binding.

[0066] S105. The server side verifies whether the personal account is successfully bound and whether it belongs to the personnel of this enterprise. If the personal account is successfully bound or the personal account does not belong to this enterprise, the approval is not given; if the personal account is successfully bound and the personal account belongs to this enterprise, the approval is passed;

[0067] S106. Send the verification result to the mobile phone side;

[0068] S107. The user logs in to the lock screen interface of the browser through the personal account, enters and uses the browser.

[0069] II. Lock Screen Login Process - Login by Scanning QR Code

[0070] This login method is the QR code scanning login method. This method can minimize user operations. Without the need to enter complex passwords, it replaces the traditional password login through three-terminal (mobile terminal, server terminal, browser terminal) authentication, realizing a passwordless login mode. As Figure 2 shown, the specific process of scanning the QR code for login includes:

[0071] S201. The controlled terminal executes the power-on instruction;

[0072] S202. After the controlled terminal is powered on, it automatically starts the browser main process;

[0073] S203. After the browser main process is started, it starts the browser secondary login process and pops up the lock screen interface;

[0074] Since the browser main process cannot directly cover the Windows or Linux lock screen interface unless the user manually closes it, it is necessary to start the secondary login process after the operating system login part. Here, it is called the secondary login process.

[0075] S204. The browser secondary login process submits browser information to the server terminal;

[0076] Among them, the browser information is the initialization information submitted by the browser secondary login process to the server terminal, including information such as the terminal ID, browser model, and browser ID;

[0077] S205. The server terminal sends the generated QR code to the browser secondary login process and displays it on the lock screen interface;

[0078] S206. The mobile terminal scans the QR code on the lock screen interface;

[0079] S207. After the mobile terminal successfully scans the QR code, it sends a QR code scan success notification to the server terminal and sends the mobile terminal login identity information to the server terminal;

[0080] S208. The server terminal verifies the login identity information. If the verification of the login identity information fails, it sends a login identity information verification failure notification to the mobile terminal;

[0081] Among them, the login identity information refers to the personal account. The mobile terminal sends the login identity information to the server terminal, and the server terminal compares whether this login identity information is a personal account that has been bound before to complete the verification of the login identity information.

[0082] S209. If the server terminal successfully verifies the login identity information, it sends a QR code scan success notification, the login identity information, and the historical record corresponding to the login identity information to the browser secondary login process;

[0083] S210. The browser secondary login process is unlocked and the login is successful. After successful login, the browser will pop up directly, that is, the browser main process. The browser cannot be exited during user use. Exiting the browser means exiting the current login.

[0084] S211. The browser secondary login process feeds back the unlock and login success notifications to the browser main process and synchronizes the historical records corresponding to the login identity information.

[0085] S212. The browser main process synchronizes the operation records to the server side in real time.

[0086] III. Lock screen login process - One - key login

[0087] This login method is a one - key login method, which reduces the possibility of password leakage. There is no need to enter a complex password. It replaces the traditional password login through three - end (mobile phone end, server end, browser end) authentication to achieve a password - free login mode. As Figure 3 shown, the specific process of one - key login includes:

[0088] S301. The controlled terminal executes the power - on instruction.

[0089] S302. After the controlled terminal is powered on, it automatically starts the browser main process.

[0090] S303. After the browser main process is started, it starts the browser secondary login process and pops up the lock screen interface.

[0091] S304. The user enters the personal account on the lock screen interface.

[0092] S305. The browser secondary login process submits the browser information and personal account information to the server side.

[0093] S306. The server side verifies the received browser information and personal account information to verify whether the personal account exists.

[0094] S307. If the personal account exists, a one - key login request is sent to the mobile phone of this account.

[0095] S308. A one - key login request interface pops up on the user's mobile phone, and the user selects whether to log in. If the login is refused, the process terminates; if the login is agreed, feedback information is sent.

[0096] S309. The mobile phone side feeds back the one - key login notification to the server side and sends the login identity information.

[0097] S310. The server side verifies the login identity information. If the verification of the login identity information fails, a login identity information verification failure notification is fed back to the mobile phone side.

[0098] S311. If the server successfully verifies the login identity information, it feeds back a one-key login success notification, the login identity information, and the historical record of synchronizing the corresponding login identity information to the browser's secondary login process.

[0099] Among them, the login identity information refers to the personal account. The mobile device sends the login identity information to the server, and the server compares whether this login identity information is a personal account that has been bound before to complete the verification of the login identity information.

[0100] S312. The browser's secondary login process is unlocked and logged in successfully. After successful login, the browser will be directly popped up, that is, the browser main process. The browser cannot be exited when the user is using it. Exiting the browser means exiting this login.

[0101] S313. The browser's secondary login process feeds back the unlock and login success notification to the browser main process and synchronizes the historical record corresponding to the login identity information.

[0102] S314. The browser main process synchronizes the operation record to the server in real time.

[0103] IV. Lock Screen Login Process - PIN Code Login (Offline)

[0104] This login method is the PIN code login method. This method can ensure normal use of the login in the offline state, and after the controlled terminal is connected to the network, the operation record of this time can be synchronized to the server to ensure that the information will not be lost. It replaces the traditional password login through three-end (mobile device (mobile), server, browser) authentication, and the numbers required for each login are random, so the security of the account is guaranteed to the greatest extent. After logging in through this method, the controlled terminal will maintain the initialized default configuration and cannot synchronize the historical record. As Figure 4 shown, the specific process of one-key login includes:

[0105] S401. The controlled terminal executes the power-on instruction.

[0106] S402. After the controlled terminal is powered on, it automatically starts the browser main process.

[0107] S403. After the browser main process is started, it starts the browser secondary login process and pops up the lock screen interface.

[0108] S404. Enter the personal account in the login interface of the browser secondary login process, and call out the calculation formula corresponding to the personal account in the local background. And each account has and only has one corresponding calculation formula.

[0109] Among them, the calculation formula is randomly generated when the user initially registers the personal account, and the calculation formula of each personal account is unique and unchanged.

[0110] S405. The browser secondary login process displays a string of randomly generated numbers on the login interface, and calculates the result obtained by calculating this random number through the calculation formula corresponding to the personal account;

[0111] S406. The mobile device inputs the random numbers displayed on the browser secondary login process login interface;

[0112] S407. The mobile device substitutes the input random numbers into the calculation formula corresponding to the personal account for calculation and outputs the calculation result, which is the login PIN code;

[0113] S408. Input the PIN code generated by the mobile device into the browser secondary login process login interface, and compare the PIN code with the result calculated by the browser secondary login process. If the results are inconsistent, the unlocking fails;

[0114] S409. If the results are consistent, the browser secondary login process unlocks successfully;

[0115] S410. Notify and feedback the successful unlocking of the browser secondary login process to the browser main process;

[0116] S411. The browser main process saves the record of this operation to the local controlled terminal;

[0117] S412. After connecting to the network, the browser main process synchronizes the operation records saved locally to the server side.

[0118] V. Permission Setting Process

[0119] The secure browser in the present invention can control the permissions of USB flash drives and application programs. By setting a whitelist, it controls the USB flash drives that can be connected and the application programs that can run, strengthening the security of the controlled terminal, greatly reducing malicious viruses and hacker attacks on the controlled terminal, and greatly reducing the possibility of information leakage. As Figure 5 shown, the specific process of permission setting includes:

[0120] S501. The controlled terminal executes the boot command;

[0121] S502. After the controlled terminal boots up, it automatically starts the browser main process;

[0122] S503. After the browser main process starts, it starts the browser secondary login process and pops up the lock screen interface;

[0123] S504. The browser secondary login process partially logs in successfully;

[0124] S505. After the browser secondary login process partially logs in successfully, it enables permission control for USB flash drives, application programs, etc.;

[0125] S506. The server sets up a permission whitelist.

[0126] S507. Synchronize the content of the permission whitelist set by the server to the browser.

[0127] VI. U Disk Control Process

[0128] As Figure 6 shown, the U disk control process specifically includes:

[0129] S601. The controlled terminal executes the power-on instruction.

[0130] S602. After the controlled terminal is powered on, automatically start the browser main process.

[0131] S603. After the browser main process is started, start the browser secondary login process and pop up the lock screen interface.

[0132] S604. The browser secondary login process partially logs in successfully and enables U disk permission control.

[0133] S605. An unknown U disk is connected to the controlled terminal.

[0134] S606. The controlled terminal sends a U disk connection notification to the browser secondary login process.

[0135] S607. The browser secondary login process reads the connected U disk feature value.

[0136] S608. After the browser secondary login process reads the connected U disk feature value, compare it with the preset U disk permission whitelist. If the U disk is not in the preset U disk permission whitelist, the controlled terminal is not allowed to read the U disk; if the U disk is in the preset U disk permission whitelist, the controlled terminal is allowed to read the U disk.

[0137] S609. The controlled terminal executes the instruction sent by the browser secondary login process.

[0138] S610. The browser secondary login process sends the execution result to the server for recording.

[0139] VII. Application Program Control Process

[0140] As Figure 7 shown, the application program control process specifically includes:

[0141] S701. The controlled terminal executes the power-on instruction.

[0142] S702. After the controlled terminal is powered on, automatically start the browser main process.

[0143] After the browser main process is started, start the browser secondary login process and pop up the lock screen interface;

[0144] The browser secondary login process partially logs in successfully and enables application permission control;

[0145] The controlled terminal starts an unknown application;

[0146] The controlled terminal sends a notification of the start of an unknown application to the browser secondary login process;

[0147] The browser secondary login process reads the feature values of the started application;

[0148] After the browser secondary login process reads the feature values of the application, compare them with the preset application permission whitelist. If the application is not in the preset application permission whitelist, the controlled terminal is not allowed to run the application; if the application is in the preset application permission whitelist, the controlled terminal is allowed to run the application;

[0149] The controlled terminal executes the instructions sent by the browser secondary login process.

[0150] The browser secondary login process sends the execution result to the server side for recording.

[0151] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: it is still possible to modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A secure browser with an identity authentication lock screen interface and terminal permission control, characterized in that, The secure browser is installed on the controlled terminal and starts automatically after the controlled terminal is powered on. The secure browser includes a lock screen interface. The lock screen interface pops up after the secure browser starts automatically and completely replaces the native lock screen interface of the operating system. The secure browser controls the controlled terminal in the following manner: The secure browser receives the login identity information of the terminal user through the lock screen interface and authenticates the login identity information of the terminal user. If the authentication is successful, the terminal user is allowed to log in to the secure browser and use the controlled terminal through the secure browser. If the authentication fails, the terminal user is prohibited from logging in to the secure browser.

2. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 1, wherein The secure browser receives the login identity information of the terminal user through the lock screen interface, including: The secure browser starts a secondary browser login process while popping up the lock screen interface and submits browser information to the server side. The secondary browser login process receives the QR code generated by the background server and displays the QR code on the lock screen interface so that the terminal user can scan the QR code through the mobile device. The background server receives the QR code scan success notification and the login identity information feedback from the user's mobile device. Accordingly, authenticating the login identity information of the terminal user includes: The background server verifies the received login identity information. If the verification fails, it sends a verification failure notification to the user's mobile device. If the verification is successful, it sends a QR code scan success notification, login identity information, and the historical record corresponding to the login identity information to the secondary browser login process.

3. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 1, characterized in that The secure browser receives the login identity information of the terminal user through the lock screen interface, including: The secure browser starts a secondary browser login process while popping up the lock screen interface. The secondary browser login process receives the personal account information entered by the terminal user on the lock screen interface. The secondary browser login process submits the browser information and the received personal account information to the background server. The background server of the browser verifies whether the personal account information exists. If it exists, it sends a one-key login request to the mobile device of the terminal user so that a one-key login request interface pops up after the mobile device of the terminal user receives the one-key login request. The background server receives the login feedback information and login identity information sent by the mobile device of the terminal user through the one-key login request interface. Accordingly, authenticating the login identity information of the terminal user includes: The background server verifies the received login identity information. If the verification fails, it sends a verification failure notification to the user's mobile device. If the verification is successful, it sends a QR code scan success notification, login identity information, and the historical record corresponding to the login identity information to the secondary browser login process.

4. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 1, wherein The secure browser receives the login identity information of the terminal user through the lock screen interface, including: The secure browser starts a secondary browser login process while popping up the lock screen interface. The secondary login process of the browser receives the personal account information input by the end user on the lock screen interface and retrieves the calculation formula corresponding to the personal account in the local background; The secondary login process of the browser randomly generates a string of numbers and displays them on the lock screen interface; The secondary login process of the browser calculates the numbers according to the calculation formula to obtain a calculation result; The secondary login process of the browser receives the PIN code input by the end user through the lock screen interface, and the PIN code is calculated by the mobile device of the end user according to the calculation formula corresponding to the personal account for the numbers; Correspondingly, authenticating the login identity information of the end user includes: The secondary login process of the browser compares the calculation result and the PIN code. If they are consistent, the verification is successful; if they are inconsistent, the verification fails.

5. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 1, wherein The background server of the secure browser is provided with a permission whitelist for controlling the permissions of USB drives and application programs.

6. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 5, wherein The secure browser controls the permissions of USB drives, including: The secure browser starts the secondary login process of the browser while popping up the lock screen interface; The secondary login process of the browser receives the USB drive access notification sent by the controlled terminal; The secondary login process of the browser reads the access USB drive characteristic value; The secondary login process of the browser determines whether the access USB drive characteristic value is in the USB drive permission whitelist. If it is not in the USB drive permission whitelist, it sends an instruction not allowing the USB drive to be read to the controlled terminal; if it is in the USB drive permission whitelist, it sends an instruction allowing the USB drive to be read to the controlled terminal.

7. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 5, wherein The secure browser controls the permissions of application programs, including: The secure browser starts the secondary login process of the browser while popping up the lock screen interface; The secondary login process of the browser receives the application program start notification sent by the controlled terminal; The secondary login process of the browser reads the application program characteristic value; The secondary login process of the browser determines whether the application program characteristic value is in the application program permission whitelist. If it is not in the application program permission whitelist, it sends an instruction not allowing the application program to be started to the controlled terminal; if it is in the application program permission whitelist, it sends an instruction allowing the application program to be started to the controlled terminal.

8. The secure browser with an identity authentication lock screen interface and terminal permission control according to claim 1, wherein It further includes: Binding the personal account of the user's mobile device with the enterprise account through the background server of the browser.

Citation Information

Patent Citations

  • An intelligent terminal safety protection system for login verification of an operating system

    CN109831463A

  • Multi-application login method and device based on browser

    CN111193710A

  • Method for controlling multi-terminal authentication based on dynamic two-dimensional code

    CN112118234A