Identity authentication method, device and equipment and computer storage medium
By detecting multiple user actions and the motion trajectory features of moving objects within the verification area, and using the number of consecutive hits of irregularly moving objects to identify users, the problem of easy cracking of existing static image click-based verification is solved, achieving higher security and credibility.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MIGU CO LTD
- Filing Date
- 2022-05-06
- Publication Date
- 2026-04-14
AI Technical Summary
Existing click-based authentication methods based on static images cannot guarantee security and effectiveness, and are vulnerable to automated cracking methods.
By determining the user's multiple operations on the verification area and the motion trajectory characteristics of the moving objects displayed in the verification area, at least two consecutive hits are detected. The user's identity verification result is determined based on the consecutive hits. The moving objects do not need to contain identifiers. The user or attacker is identified by the number of consecutive hits of irregular movements.
It improves the security and credibility of identity verification while ensuring user experience, increasing the difficulty of cracking, and preventing bots from cracking it.
Smart Images

Figure CN114896574B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet technology, specifically to an authentication method, apparatus, device, and computer storage medium. Background Technology
[0002] With the further development of the internet and the improvement of public website quality, click-based CAPTCHAs based on static images have emerged. These typically display specified words or letters within a pre-defined static image, requiring users to click to complete the verification. This click-based verification method offers significantly improved usability compared to traditional input-based CAPTCHAs.
[0003] In the process of implementing the embodiments of the present invention, the inventors of the present invention discovered that the security and effectiveness of existing authentication methods based on clicking on static images cannot be effectively guaranteed. Summary of the Invention
[0004] In view of the above problems, embodiments of the present invention provide an authentication method to solve the problem that the security and effectiveness of authentication methods in the prior art cannot be effectively guaranteed.
[0005] According to one aspect of the present invention, an authentication method is provided, the method comprising:
[0006] Determine the user's operation information on the verification area; the operation information corresponds to multiple operations.
[0007] Determine the motion trajectory characteristics of the moving objects displayed within the verification area;
[0008] When at least two consecutive hits are detected against the moving object, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and the movement trajectory characteristics.
[0009] In one alternative approach, the operation information includes the operation time; the method further includes:
[0010] Determine the initial motion characteristics;
[0011] Based on the initial motion characteristics, a motion simulation algorithm is used to simulate the motion trajectory equation.
[0012] The motion trajectory features are determined based on the operation time and the motion trajectory equation.
[0013] In an alternative approach, the operation information further includes the operation position; the motion trajectory features include the motion position; the method further includes:
[0014] The single hit information of the moving body is determined based on the operation position and the movement position;
[0015] The consecutive hit information is determined based on the operation time and the single hit information.
[0016] In an alternative approach, the method further includes:
[0017] When it is determined that the moving object has a single hit, the initial motion characteristics of the moving object are updated.
[0018] In one alternative approach, the consecutive hit information includes the number of consecutive hits; the method further includes: when the number of consecutive hits is greater than a preset threshold, determining that the user authentication is successful.
[0019] In one alternative approach, the continuous hit information includes a continuous hit time interval; the method further includes: determining that the user authentication is successful when the continuous hit time interval is less than a preset interval threshold.
[0020] In an alternative approach, the method further includes:
[0021] Determine the verification scenario information;
[0022] The initial motion features are determined based on the verification scenario information.
[0023] According to another aspect of the present invention, an authentication device is provided, comprising:
[0024] The first determining module is used to determine the user's operation information on the verification area; the operation information corresponds to multiple operations.
[0025] The second determining module is used to determine the motion trajectory characteristics of the moving body displayed within the verification area;
[0026] The verification module is used to determine the user's identity verification result based on the consecutive hit information when at least two consecutive hits are detected against the moving body; the consecutive hit information is determined based on the operation information and the motion trajectory characteristics.
[0027] According to another aspect of the present invention, an authentication device is provided, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other through the communication bus;
[0028] The memory is used to store at least one executable instruction that causes the processor to perform operations as described in any of the authentication method embodiments.
[0029] According to another aspect of the present invention, a computer-readable storage medium is provided, the storage medium storing at least one executable instruction that causes an authentication device to perform the operation of any of the authentication method embodiments described above.
[0030] This invention, through its embodiments, determines user operation information on a verification area. This operation information corresponds to multiple operations and the determination of the motion trajectory characteristics of a moving object displayed within the verification area. When at least two consecutive hits are detected on the moving object, the user's identity verification result is determined based on these consecutive hits. The consecutive hits are determined based on the operation information and motion trajectory characteristics, thus distinguishing it from existing technologies that rely on clicking static images or verifying based on the click order of multiple dynamic images with labels. In this invention, the moving object does not need to contain a label, and at least one is sufficient. By identifying the user or attacker based on the number of consecutive hits on the moving object, this invention increases the difficulty of verification while ensuring a good user experience, thereby improving the security and credibility of identity verification.
[0031] The above description is merely an overview of the technical solutions of the embodiments of the present invention. In order to better understand the technical means of the embodiments of the present invention and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0032] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:
[0033] Figure 1 A flowchart illustrating the authentication method provided in an embodiment of the present invention is shown;
[0034] Figure 2 This diagram illustrates the motion process of a moving body in an authentication method provided in another embodiment of the present invention.
[0035] Figure 3 A flowchart illustrating an authentication method provided in another embodiment of the present invention is shown;
[0036] Figure 4 A schematic diagram of the structure of the authentication device provided in an embodiment of the present invention is shown;
[0037] Figure 5 A schematic diagram of the structure of the authentication device provided in an embodiment of the present invention is shown. Detailed Implementation
[0038] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein.
[0039] Before describing the embodiments of the present invention, the prior art will be introduced first.
[0040] With the widespread use of the internet, the technical principles and form of CAPTCHA mechanisms have not changed significantly. CAPTCHAs distinguish between legitimate users and malicious programs by requiring users to identify a randomly generated combination of letters, numbers, or characters, thus ensuring website security and user information security, which is of great significance.
[0041] Traditional CAPTCHA generation technology involves generating random, complex backgrounds and printing distorted letters, numbers, or characters, which users then have to recognize and input. This method offers a poor user experience, with users frequently encountering situations where the CAPTCHA is difficult to recognize and having no other choice but to adapt. With the advent of the mobile internet era, touchscreen mobile devices have gradually replaced PCs. However, the smaller screen size and complex input method switching on mobile devices mean that traditional CAPTCHAs are no longer suitable for the new era. Furthermore, some websites, in an effort to improve user experience, increase the clarity of CAPTCHA printing, thereby reducing CAPTCHA security.
[0042] With the further development of the internet and the improvement of public website quality, click-based CAPTCHAs based on static images have emerged. These typically display specified words or letters within a pre-set static image, requiring users to click to complete the verification. This click-based verification method offers significantly improved usability compared to traditional input-based CAPTCHAs. Click-based verification methods, with their simplicity, good user experience, and strong security, are widely used in scenarios such as registration and login, preventing the use of fraudulent coupons and red envelopes, preventing "wool-gathering" (exploiting promotional offers), and data anti-scraping. Currently, click-based CAPTCHA implementations primarily combine a preset target location with the user's click location characteristics to determine whether the user's behavior is normal and the correctness of the click.
[0043] Due to the widespread use of click-based CAPTCHAs, automated cracking methods have emerged. Currently, attackers employ various data analysis methods to analyze and model human operational habits and pre-set static target location data, approximating clicks to crack click-based CAPTCHAs with a high success rate. Therefore, the security and effectiveness of existing static image-based click-based CAPTCHAs are facing serious challenges.
[0044] Figure 1A flowchart of an authentication method provided by an embodiment of the present invention is shown. This method is executed by a computer processing device. The computer processing device may include a mobile phone, a laptop computer, etc. Figure 1 As shown, the method includes the following steps:
[0045] Step 10: Determine the user's operation information on the verification area; the operation information corresponds to multiple operations.
[0046] In one embodiment of the present invention, the verification area is displayed on the user terminal and can be used to verify the verification code based on the user's account and password information, thereby raising the threshold for identity verification and preventing verification request attacks from non-real users.
[0047] The operation information includes the operation type, operation time, and corresponding operation position for each operation. The operation type can be click, swipe, or drag, and the operation position refers to the coordinate position of the operation in the verification area.
[0048] Step 20: Determine the motion trajectory characteristics of the moving objects displayed within the verification area.
[0049] In one embodiment of the present invention, the moving body may be a sphere, a cube, or other shape, and the number of moving bodies is at least one. The movement mode of the moving body may be random throughout or change at indeterminate intervals. The motion trajectory features are the characteristics of the moving body's trajectory, which may include the moving body's movement time, coordinates in the verification area, velocity, acceleration, and other features.
[0050] Optionally, unlike existing technologies that contain verification code information that can be converted into text, such as the identifier of the object being operated on and the sequence of components, the moving body in this method embodiment does not include a moving body identifier. Instead, a prompt message can be displayed on the user terminal to prompt the user to perform operations such as clicking on the moving body for verification.
[0051] In an optional embodiment, the movement pattern of the moving object can change after each detected user operation. This change in movement pattern can refer to a change in at least one of the following: initial position, velocity over time, and acceleration over time. Optionally, after detecting a user operation, the moving object can also display a disappearance effect, prompting the user to complete the operation. The disappearance effect could be that the moving object breaks apart and then disappears after being operated on.
[0052] Step 10 also includes: Step 101: Determine the initial motion characteristics.
[0053] In one embodiment of the present invention, initial motion features are used to characterize the motion characteristics of the moving object when it is initially displayed in the verification area, specifically including initial velocity, initial position, and direction of motion. The initial velocity is expressed in pixels per second; the higher the verification difficulty level, the greater the initial velocity. The direction of motion is represented by the angle between the direction of motion and the clockwise direction at 12 o'clock. The initial motion features can be randomly set to prevent attackers from finding the motion pattern of the moving object and thus breaking the verification process.
[0054] In another embodiment of the present invention, considering that different verification scenarios have different security levels, and that the setting of initial motion features affects the overall motion trajectory of the moving body and the complexity of its changes, thereby affecting the difficulty of cracking, step 101 further includes:
[0055] Step 1011: Determine the verification scenario information.
[0056] In one embodiment of the present invention, the verification scenario information includes scenario type information, security requirement level, and verification difficulty setting. For example, scenario type information includes ordinary interaction confirmation, application login, and payment confirmation, with corresponding security requirement levels gradually increasing.
[0057] Step 1012: Determine the initial motion features based on the verification scenario information.
[0058] In one embodiment of the present invention, the initial motion features corresponding to the verification scene information can be determined according to a preset relationship table.
[0059] In another embodiment of the present invention, the machine learning model can be trained based on the motion data of the moving body corresponding to the historical verification process, the corresponding scene information, and the accuracy of the verification results. The verification scene information is then input into the trained model to obtain the initial motion features.
[0060] Step 102: Simulate the motion according to the initial motion characteristics using a motion simulation algorithm to obtain the motion trajectory equation.
[0061] In one embodiment of the present invention, the motion simulation algorithm may be a collision algorithm. The motion trajectory equation is used to characterize the motion characteristics of the moving body at various moments in motion, wherein the motion characteristics include motion position, motion velocity, motion acceleration, and motion direction, etc.
[0062] Specifically, the equation of motion trajectory is calculated as follows:
[0063] Assuming a sphere of radius R, with initial coordinates (X0, Y0) at time T0, and starting with initial velocity Va and direction α, the position coordinates of the sphere at time T1 can be expressed by the following formula:
[0064] P t1 =(x t1 ,y t1 );
[0065] x t1 =x0+v a *(t1-t0)*sinα;
[0066] y t1 =y0+v a *(t1-t0)*cosα;
[0067] Among them, P t1 x represents the position of the moving body. t1 Let y be the x-coordinate of the moving object. t1 Let be the ordinate of the moving object. The x-axis points to the right, and the y-axis points downwards. The origin of the coordinate system is the upper left corner of the verification area. Furthermore, the directions α and x... t1 y t1 The following constraint exists: when x t1 <0 or x t1 When W–R, α=360–α, while when y t1 <0 or y t1 When H–R, α = 180–α.
[0068] The motion characteristics of the moving body at time T0 and time T1 can be referred to respectively. Figure 2 as well as Figure 3 .
[0069] Step 103: Determine the motion trajectory characteristics based on the operation time and the motion trajectory equation.
[0070] In one embodiment of the present invention, the operation time is substituted into the motion trajectory equation to obtain the motion characteristics of the moving body when the user operates, such as the position and direction of the moving body in the verification area during the operation.
[0071] Step 30: When at least two consecutive hits are detected against the moving body, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and the motion trajectory features.
[0072] In one embodiment of the present invention, two consecutive hits correspond to at least two hits on the moving object, and the operation times of the at least two hits are consecutive. Consecutive operation times mean that there are no other operations before the two hits. A hit means that the feature information of the operation in a specific feature dimension matches the feature information of the moving object in the same dimension. The feature dimension can be position, motion trajectory, etc. Matching can be defined as the difference between feature values being less than a preset threshold; for example, a match is considered to occur when the distance between the position of the operation and the position of the moving object is less than a certain distance threshold.
[0073] Based on the operation information, the location and time of multiple user actions are determined. Then, the degree of matching between the motion trajectory characteristics corresponding to that time and the operation location determines whether the user's single action was successful, such as whether a moving object was clicked. To further increase the difficulty of verification and thus the complexity of the verification process, after determining the success of a single user action, the moving object can be made to disappear, then reappear with a different movement and initial position, and the user can be instructed to click on the moving object again. Based on the hit information of multiple actions performed by the user on the constantly changing moving object, it can be determined whether the user is an attacker. The hit information for multiple actions includes hit rate, hit time interval, number of consecutive hits, and consecutive hit rate.
[0074] Therefore, in one embodiment of the present invention, the operation information further includes the operation position; the motion trajectory feature includes the motion position. Step 20 further includes: Step 201: Determine the single hit information of the moving body based on the operation position and the motion position.
[0075] In one embodiment of the present invention, the distance between the operation position and the movement position is calculated. When the distance is less than a certain error value, it is determined that the user's operation has hit the moving object. The operation time and operation position corresponding to the hit operation are obtained as single hit information.
[0076] The process after step 201 further includes: when it is determined that the moving body has a single hit, updating the initial motion characteristics of the moving body.
[0077] As mentioned earlier, in order to improve the security and difficulty of cracking the verification, the trajectory of the moving object is updated after each user operation, making it more difficult for attackers to obtain the movement pattern of the moving object by observation alone, and thus predict the position where the moving object will appear and successfully hit it.
[0078] Specifically, the update method can be to render the effect of the moving object disappearing in the verification area, such as the sphere breaking or the slider fading out, and then re-render the moving object at the updated initial position, and control the moving object to move according to the initial motion characteristics starting from the updated initial position.
[0079] Step 202: Determine the consecutive hit information based on the operation time and the single hit information.
[0080] In one embodiment of the present invention, the time interval and number of consecutive hits can be determined based on the time and location of a single hit. The hit rate, consecutive hit rate, and hit trajectory within a preset time period can also be determined.
[0081] Step 30: Determine the user's authentication result based on the continuous hit information.
[0082] In one embodiment of the present invention, considering that the movement pattern of a moving object is constantly changing, it takes an attacker a certain amount of time to crack the movement pattern compared to a user. Therefore, the probability of an attacker hitting the moving object multiple times consecutively is relatively low, or even if multiple hits are achieved consecutively, the time interval between consecutive hits will be relatively large, or the hit rate of the attacker within a preset time period will be low due to trial and error time. Therefore, the consecutive hit information may include information such as the number of consecutive hits, the time interval between consecutive hits, or the hit rate within a preset time period. The user's authentication result is obtained by filtering the consecutive hit information against preset thresholds for the number of hits, time intervals, or hit rates.
[0083] Therefore, in another embodiment of the present invention, the consecutive hit information includes the number of consecutive hits; step 30 further includes:
[0084] Step 301: When the number of consecutive hits is greater than a preset threshold, the user authentication is confirmed to be successful.
[0085] In one embodiment of the present invention, considering the high difficulty for a hacker to achieve consecutive hits—requiring the hacker to decipher the movement patterns of the moving object to achieve accurate consecutive hits, as guesswork alone makes it difficult to achieve multiple consecutive hits—the preset number of hits threshold can be determined based on the verification scenario information. For example, when the security requirement level is high, the preset number of hits threshold can be relatively increased.
[0086] In one embodiment of the present invention, the continuous hit information includes a continuous hit time interval; step 30 further includes:
[0087] Step 302: When the consecutive hit time interval is less than a preset interval threshold, the user authentication is determined to be successful.
[0088] In one embodiment of the present invention, the consecutive hit time interval can be the time interval between two consecutive hit operations. Considering that existing machine cracking schemes often require a certain amount of time to crack human-machine verification schemes, the verification time when using machine cracking for verification will inevitably be longer than the time consumed by normal users. Therefore, by limiting the consecutive hit time interval provided by this solution, machine recognition technology and robots can be effectively prevented from cracking human-machine verification.
[0089] In another embodiment of the present invention, to further increase the difficulty of cracking the verification process, the number of moving objects can be multiple. The appearance of the multiple moving objects can be the same, while their movement trajectories can be the same or different. When multiple moving objects exist, the consecutive hit information can correspond to an operation that hits at least twice in time for one moving object, or it can correspond to an operation that hits at least two moving objects in time, i.e., at least once for a single moving object among the multiple moving objects.
[0090] Correspondingly, consecutive hit information includes the total hit rate, total number of consecutive hits, and maximum hit interval for multiple moving objects within a preset time period. For example, consider three moving objects, denoted as A, B, and C. Following the steps described above, determine the single hit information for A, B, and C respectively. Based on the single hit information for A, B, and C, determine the total hit rate for these three moving objects within a preset time period (e.g., 30 seconds). If two of A, B, and C are hit, the total hit rate is 66.7%. The total number of consecutive hits refers to the total number of hit operations for all moving objects. The maximum hit interval refers to the maximum time interval between hit operations for all moving objects.
[0091] In another embodiment of the present invention, in order to further increase the difficulty for a cracker to crack the verification method based solely on the information displayed on the client, the operation process can be decoupled and divided, with the client and the backend server interacting to complete the task. This ensures that even if an attacker controls the client and has access to the information on the client, they cannot predict the trajectory of the moving object or the verification logic, thus making it impossible to hit the moving object multiple times in a row and successfully pass the verification.
[0092] Therefore, in another embodiment of the present invention, the authentication process can also refer to Figure 3 .
[0093] like Figure 3 As shown, the client calculates the click verification area information (length W, height H) based on the user terminal information and submits it to the server to request verification information.
[0094] The server generates the initial position P0, initial velocity Va (unit: pixels / second, the higher the verification difficulty level, the greater the initial velocity), and direction α (angle between the direction of movement and the clockwise direction of 12 o'clock) for each click based on the verification area location and verification scene information, according to Table 1. Simultaneously, it returns the verification session Sid to the client. Meanwhile, the backend simulates and calculates the bubble's movement position using a collision algorithm and records the backend bubble's position P(Δt0, Δt1...Δti) at fixed time intervals. That is, the server can obtain the simulated bubble's position (XsΔt, YsΔt) based on the bubble's movement time Δt.
[0095]
[0096] surface
[0097] Table 1. Relationship between Initial Speed, Position, and Difficulty Level
[0098] Based on the position P0 returned by the server, the client renders the verification background and generates a bubble-shaped moving object at position P0. Based on an initial velocity Va, the bubble moves within the click verification area (length W, height H) according to a collision algorithm. The client records the initial time T0 of the bubble's movement, and then refreshes the bubble's position at fixed intervals. It should be noted that the bubble's trajectory can also be calculated by the server and sent to the client.
[0099] When a user clicks the bubble, the client renders a popping effect, indicating that the user has completed a click verification. The client records the time T1 of the user's click and transmits information such as the balloon's movement duration (T1-T0), the user's click location, the bubble's current position, and the verification session ID (Sid) to the server.
[0100] The server performs a secondary check on the validity of the user's click based on the bubble's initial speed and direction, as well as the motion duration uploaded by the client. This confirms the click's validity and accumulates the number of successful verifications (SuccNum) during a single verification session (initially 0, incremented by 1 for each successful click). If SuccNum reaches the pre-set minimum number of verifications (M1) required for a single session, the server returns a successful verification result to the client, allowing for subsequent business processing. Otherwise, it generates the next initial position (Pn) and returns it to the client, which then renders and generates more bubbles for the user to click and verify again.
[0101] The server-side validation logic is as follows:
[0102] First, a check is performed to verify whether the single click was successful. The trajectory of the ball is calculated based on the collision algorithm, and the ball's movement time collected by the client is used to calculate whether the error between the ball's position at the time of the user's click and the specific position of the click is within a reasonable range.
[0103] The server-side simulation of the sphere's trajectory is consistent with the client-side algorithm, so it will not be elaborated further.
[0104] The server queries the position of the simulated sphere in the backend based on the sphere's motion time Δt passed from the frontend.
[0105] Ps(Δt)=P(XsΔt,YsΔt)
[0106] Verify whether the difference between the location information passed by the client and the location on the server is within the allowable error Δx, Δy.
[0107] Pc(Δt)=P(XcΔt,YcΔt)
[0108] That is, if |XsΔt-XcΔt|<=Δx and |YsΔt-YcΔt|<=Δy, then a single click is considered a hit.
[0109] Based on a single click, the success rate of consecutive clicks is verified. The number of consecutive valid clicks on the sphere within a single session is checked against a pre-set service requirement to determine the correctness of the entire verification process. Specifically, multiple consecutive single-click verification results are recorded. When SuccNum = M within a session (without changing Sid), it indicates that the consecutive click verification has passed, and the front-end receives the overall verification result, with the current Sid recorded as successful.
[0110] The authentication method provided in this embodiment of the invention determines user operation information on a verification area; the operation information corresponds to multiple operations and determines the motion trajectory characteristics of the moving objects displayed in the verification area; when at least two consecutive hits are detected on the moving object, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and motion trajectory characteristics, thus distinguishing it from the prior art's verification based on clicking on static images, or verification based on the click order of multiple dynamic images with labels. In this embodiment of the invention, the moving object does not need to contain a label, and at least one is sufficient. This embodiment of the invention identifies users or attackers by the number of consecutive hits on irregularly moving moving objects, thereby increasing the difficulty of verification while ensuring user experience, and improving the security and credibility of authentication.
[0111] Figure 4 A schematic diagram of the structure of the authentication device provided in an embodiment of the present invention is shown. Figure 4 As shown, the device 40 includes: a first determining module 401, a second determining module 402, and a verification module 403.
[0112] The first determining module 401 is used to determine the user's operation information on the verification area; the operation information corresponds to multiple operations.
[0113] The second determining module 402 is used to determine the user's continuous hit information for the moving object based on the operation information and motion trajectory characteristics; the continuous hit information corresponds to the operation of hitting the moving object at least twice in time.
[0114] The verification module 403 is used to determine the user's identity verification result based on the consecutive hit information when at least two consecutive hits are detected against the moving body; the consecutive hit information is determined based on the operation information and the motion trajectory features.
[0115] The operation process of the authentication device provided in this embodiment of the invention is largely the same as that of the aforementioned method embodiment, and will not be described again.
[0116] The authentication device provided in this embodiment of the invention determines user operation information on a verification area; the operation information corresponds to multiple operations and determines the motion trajectory characteristics of a moving object displayed within the verification area; when at least two consecutive hits are detected on the moving object, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and motion trajectory characteristics, thus distinguishing it from the prior art's verification based on clicking on static images or based on the click order of multiple dynamic images with labels. In this embodiment of the invention, the moving object does not need to contain a label, and at least one is sufficient. This embodiment of the invention identifies users or attackers by the number of consecutive hits on a moving object with irregular movement, thereby increasing the difficulty of verification while ensuring user experience, and improving the security and credibility of authentication.
[0117] Figure 5 The diagram shows a structural schematic of an authentication device provided in an embodiment of the present invention. The specific implementation of the authentication device is not limited by the specific embodiments of the present invention.
[0118] like Figure 5 As shown, the authentication device may include: a processor 502, a communications interface 504, a memory 506, and a communications bus 508.
[0119] The processor 502, communication interface 504, and memory 506 communicate with each other via communication bus 508. Communication interface 504 is used to communicate with other network elements such as clients or other servers. The processor 502 executes program 510, specifically performing the relevant steps described above in the authentication method embodiment.
[0120] Specifically, program 510 may include program code, which includes computer-executable instructions.
[0121] Processor 502 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The authentication device may include one or more processors of the same type, such as one or more CPUs; or it may include processors of different types, such as one or more CPUs and one or more ASICs.
[0122] Memory 506 is used to store program 510. Memory 506 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.
[0123] Specifically, program 510 can be called by processor 502 to cause the authentication device to perform the following operations:
[0124] Determine the user's operation information on the verification area; the operation information corresponds to multiple operations; the verification area displays the moving object with irregular movement;
[0125] When at least two consecutive hits are detected against the moving object, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and the movement trajectory characteristics.
[0126] The operation process of the authentication device provided in this embodiment of the invention is largely the same as that of the aforementioned method embodiment, and will not be described again.
[0127] The authentication device provided in this embodiment of the invention determines user operation information on a verification area; the operation information corresponds to multiple operations and determines the motion trajectory characteristics of a moving object displayed within the verification area; when at least two consecutive hits are detected on the moving object, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and motion trajectory characteristics, thus distinguishing it from the prior art's verification based on clicking on static images or based on the click order of multiple dynamic images with labels. In this embodiment of the invention, the moving object does not need to contain a label, and at least one is sufficient. This embodiment of the invention identifies users or attackers by the number of consecutive hits on a moving object with irregular movement, thereby increasing the difficulty of verification while ensuring user experience, and improving the security and credibility of authentication.
[0128] This invention provides a computer-readable storage medium storing at least one executable instruction that, when executed on an authentication device, causes the authentication device to perform the authentication method in any of the above method embodiments.
[0129] Specifically, the executable instructions can be used to cause the authentication device to perform the following operations:
[0130] Determine the user's operation information on the verification area; the operation information corresponds to multiple operations.
[0131] When at least two consecutive hits are detected against the moving object, the user's authentication result is determined based on the consecutive hits; the consecutive hits are determined based on the operation information and the movement trajectory characteristics.
[0132] The operation process of the executable instructions stored in the computer storage medium provided in this embodiment of the invention is largely the same as that in the aforementioned method embodiments, and will not be described again.
[0133] The executable instructions stored in the computer storage medium provided in this embodiment of the invention determine the user's operation information on the verification area; the operation information corresponds to multiple operations; the verification area displays a moving object with irregular movement; the continuous hit information of the user on the moving object is determined according to the operation information and the movement trajectory characteristics; the user's identity verification result is determined according to the continuous hit information, thereby distinguishing it from the verification based on clicking on static images in the prior art, or the verification based on the click order of multiple dynamic images with labels. In this embodiment of the invention, the moving object does not need to contain a label, and at least one is required. This embodiment of the invention identifies the user or attacker by the number of consecutive hits of the irregularly moving moving object, thereby increasing the difficulty of verification while ensuring user experience, and improving the security and credibility of identity verification.
[0134] This invention provides an authentication device for performing the above-described authentication method.
[0135] This invention provides a computer program that can be invoked by a processor to cause an authentication device to execute the authentication method in any of the above method embodiments.
[0136] This invention provides a computer program product, which includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions that, when executed on a computer, cause the computer to perform the authentication method in any of the above method embodiments.
[0137] The algorithms or displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The required structure for constructing such systems is apparent from the above description. Furthermore, the embodiments of the present invention are not directed to any particular programming language. It should be understood that the content of the invention described herein can be implemented using various programming languages, and the above description of specific languages is for the purpose of disclosing the best mode of implementation of the invention.
[0138] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.
[0139] Similarly, it should be understood that, in order to streamline the invention and aid in understanding one or more of the various aspects of the invention, features of the embodiments of the invention are sometimes grouped together in a single embodiment, figure, or description thereof in the above description of exemplary embodiments of the invention. However, this disclosure should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim.
[0140] Those skilled in the art will understand that modules in the device of the embodiments can be adaptively changed and placed in one or more devices different from that embodiment. Modules, units, or components in the embodiments can be combined into a single module, unit, or component, and can be divided into multiple sub-modules, sub-units, or sub-components. Except where at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all processes or units of any method or device so disclosed. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) may be replaced by an alternative feature that serves the same, equivalent, or similar purpose.
[0141] It should be noted that the above embodiments are illustrative of the invention and not restrictive, and that those skilled in the art can devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The invention can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names. The steps in the above embodiments, unless otherwise specified, should not be construed as limiting the order of execution.
Claims
1. An identity verification method, characterized by, The method includes: Determine the user's operation information on the verification area; the operation information includes operation time and operation location, and the operation information corresponds to multiple operations. Determine the initial motion characteristics, simulate the motion according to the motion simulation algorithm based on the initial motion characteristics, and obtain the motion trajectory equation; determine the motion trajectory characteristics of the moving body displayed in the verification area based on the operation time and the motion trajectory equation, and the motion trajectory characteristics include the motion position. The single hit information of the moving body is determined based on the operation position and the movement position; the continuous hit information is determined based on the operation time and the single hit information; wherein, when it is determined that the moving body has a single hit, the initial movement characteristics of the moving body are updated. When at least two consecutive hits are detected against the moving object, the user's authentication result is determined based on the consecutive hits.
2. The method of claim 1, wherein, The consecutive hit information includes the number of consecutive hits; determining the user's authentication result based on the consecutive hit information includes: When the number of consecutive hits exceeds a preset threshold, the user authentication is deemed successful.
3. The method of claim 1, wherein, The consecutive hit information includes the consecutive hit time interval; determining the user's authentication result based on the consecutive hit information includes: When the consecutive hit time interval is less than a preset interval threshold, the user authentication is determined to be successful.
4. The method according to any one of claims 1-3, characterized in that, The determination of initial motion characteristics includes: Determine the verification scenario information; The initial motion features are determined based on the verification scenario information.
5. An identity verification apparatus characterized by comprising: The device includes: The first determining module is used to determine the user's operation information on the verification area; the operation information includes operation time and operation location, and the operation information corresponds to multiple operations. The second determining module is used to determine the initial motion characteristics, simulate the motion according to the motion simulation algorithm based on the initial motion characteristics, and obtain the motion trajectory equation; and determine the motion trajectory characteristics of the moving body displayed in the verification area based on the operation time and the motion trajectory equation, wherein the motion trajectory characteristics include the motion position. The verification module is used to determine single-hit information of a moving object based on the operation position and movement position; and to determine consecutive hit information based on the operation time and single-hit information. Specifically, when a single hit is determined for the moving object, the initial motion characteristics of the moving object are updated; when at least two consecutive hits are detected for the moving object, the user's authentication result is determined based on the consecutive hit information. The consecutive hit information is determined based on the operation information and motion trajectory characteristics.
6. An identity verification device, characterized by include: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable instruction that causes the processor to perform the operation of the authentication method as described in any one of claims 1-4.
7. A computer readable storage medium characterized in that, The storage medium stores at least one executable instruction, which, when executed on the authentication device, causes the authentication device to perform the operation of the authentication method as described in any one of claims 1-4.
Citation Information
Patent Citations
Information verification method and device, electronic equipment and readable medium
CN114398614A