Authentication method, system and terminal device

By automatically obtaining domain name system information matching the region or establishing a virtual private network connection in the terminal device, the problem of connection failure between the terminal device and the authentication server is solved, and the authentication success rate and efficiency are improved.

CN115333855BActive Publication Date: 2026-02-24FORMOVIE (CHONGQING) INNOVATIVE TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211121577.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-15
Publication Date
2026-02-24
Estimated Expiration
2042-09-15

AI Technical Summary

Technical Problem

The terminal device fails to connect to the authentication server after startup, resulting in authentication failure and inability to be used normally, especially in remote areas where it is not fully covered.

Method used

When authentication fails, the terminal device automatically retrieves the domain name system information matching its location from the pre-set domain name system information, modifies the configuration, and resends the authentication request, or establishes a private network connection through a virtual private network server for authentication.

Benefits of technology

It improves the authentication success rate, reduces the need for users to manually modify configurations, and increases the efficiency and success rate of resolving authentication failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333855B_ABST
    Figure CN115333855B_ABST
Patent Text Reader

Abstract

The application relates to an authentication method, system and terminal device. The method comprises the following steps: a terminal device sends a first authentication request and monitors an authentication result of the first authentication request; if the authentication result of the first authentication request is authentication failure, the terminal device acquires domain name system information matched with a region where the terminal device is located from domain name system information respectively set in advance for different regions; the terminal device modifies domain name system configuration information of the terminal device according to the domain name system information; and the terminal device triggers sending of a second authentication request according to the modified domain name system configuration information and starts normal service provision after authentication success. The method can solve the problem of authentication failure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to an authentication method, system, and terminal device. Background Technology

[0002] With the development of science and technology, various terminal devices are becoming more and more popular. Some terminal devices need to be authenticated after startup to confirm whether they have the necessary permissions. They can only be used normally after successful authentication. For example, Internet TV needs to connect to the authentication server of the Internet TV license holder for authentication after startup. Internet TV can only be used normally after successful authentication.

[0003] However, in some situations, the terminal device may fail to connect to the authentication server. For example, in some remote areas, the authentication service may not be fully covered, which may cause the terminal device to fail to connect to the authentication server and thus fail to authenticate, making it impossible to use the terminal device normally. Summary of the Invention

[0004] Therefore, it is necessary to provide an authentication method, system, terminal device, computer-readable storage medium, and computer program product that can solve the authentication failure problem, in order to address the above-mentioned technical issues.

[0005] Firstly, this application provides an authentication method. The method includes:

[0006] The terminal device sends a first authentication request and monitors the authentication result of the first authentication request;

[0007] If the authentication result of the first authentication request is detected as authentication failure, then obtain the domain name system information that matches the region where the terminal device is located from the domain name system information that is set up in advance for different regions.

[0008] Modify the domain name system configuration information of the terminal device according to the domain name system information;

[0009] Based on the modified Domain Name System configuration information, a second authentication request is triggered, and normal service begins after successful authentication.

[0010] Secondly, this application also provides an authentication system. The system includes: a terminal device; wherein:

[0011] The terminal device is used to send a first authentication request and monitor the authentication result of the first authentication request; if the authentication result of the first authentication request is detected as authentication failure, it obtains the domain name system information matching the region where the terminal device is located from the domain name system information that is set in advance for different regions; modifies the domain name system configuration information of the terminal device according to the domain name system information; triggers the sending of a second authentication request according to the modified domain name system configuration information, and starts to provide normal services after successful authentication.

[0012] In one embodiment, the system further includes: a domain name scheme server; wherein:

[0013] The terminal device is further configured to, if it detects that the authentication result of the first authentication request is authentication failure, obtain the region-related information of the region where the terminal device is located, generate a domain name system information acquisition request based on the region-related information, and send the domain name system information acquisition request to the domain name scheme server.

[0014] The domain name scheme server is used to respond to the domain name system information acquisition request, and match the corresponding target region information from the preset domain name scheme according to the region information information in the domain name system information acquisition request; the preset domain name scheme stores region information information and domain name system information respectively; determine the domain name system information stored corresponding to the target region information from the preset domain name scheme, and send the domain name system information to the terminal device.

[0015] In one embodiment, the region-related information includes region information; the target region-related information includes target region information; the domain name scheme server is further configured to respond to the domain name system information acquisition request, determine the region information of the region where the terminal device is located according to the domain name system information acquisition request, and match the corresponding target region information from the preset domain name scheme according to the region information.

[0016] In one embodiment, the domain name scheme server is further configured to determine, based on the region information, the next-level region information corresponding to the region information from a preset domain name scheme, as the target region information.

[0017] In one embodiment, the domain name scheme server is further configured to determine, based on the region information, the region information of adjacent regions from a preset domain name scheme, as the target region information.

[0018] In one embodiment, the region-related information includes a public IP address; the target region-related information includes a target public IP address; the domain name scheme server is further configured to respond to the domain name system information acquisition request, determine the public IP address to which the terminal device is connected based on the domain name system information acquisition request; and perform similarity matching between the public IP address and the IP address in the preset domain name scheme to determine the target public IP address.

[0019] In one embodiment, the system further includes: a virtual private network server; wherein:

[0020] The terminal device is also used to monitor the authentication result in response to the sent second authentication request; if the authentication result of the second authentication request is detected as authentication failure, a connection request is sent to the virtual private network server.

[0021] The virtual private network server is used to establish a private network connection between the terminal device and the authentication server.

[0022] The terminal device is also used to send a third authentication request to the authentication server via the dedicated network connection.

[0023] In one embodiment, the virtual private network server is located in a region with the lowest authentication failure rate.

[0024] Thirdly, this application also provides a terminal device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it causes the processor to perform the steps in the authentication methods described in the embodiments of this application.

[0025] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, causes the processor to perform the steps of the authentication methods described in the embodiments of this application.

[0026] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, causes the processor to perform the steps of the authentication methods described in the embodiments of this application.

[0027] The aforementioned authentication method, system, terminal device, storage medium, and computer program product involve the terminal device sending a first authentication request and monitoring its authentication result. If the first authentication request fails, it retrieves the Domain Name System (DNS) information matching the terminal device's location from pre-configured DNS information for different regions. Based on this DNS information, it modifies the terminal device's DNS configuration information and triggers a second authentication request. Upon successful authentication, it begins providing normal service. This approach automatically retrieves DNS information matching the terminal device's location when authentication fails, and triggers a resend of the authentication request based on the more suitable DNS information, thus resolving the authentication failure issue. Attached Figure Description

[0028] Figure 1 This is a diagram illustrating the application environment of the authentication method in one embodiment;

[0029] Figure 2 This is a diagram illustrating the application environment of the authentication method in another embodiment;

[0030] Figure 3 This is a flowchart illustrating the authentication method in one embodiment;

[0031] Figure 4 This is a schematic diagram of the overall process of the authentication method in one embodiment;

[0032] Figure 5 This is an architecture diagram of an authentication system in one embodiment;

[0033] Figure 6 Here is an architecture diagram of the authentication system in another embodiment;

[0034] Figure 7 This is an architecture diagram of the authentication system in other embodiments;

[0035] Figure 8 This is an internal structure diagram of a terminal device in one embodiment. Detailed Implementation

[0036] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0037] In one embodiment, the authentication method provided in this application can be applied to, for example... Figure 1In the application environment shown, terminal device 102 communicates with the first Domain Name System (DNS) server 104, the second DNS server 106, the authentication server 108, and the DNS scheme server 110 via a network. After terminal device 102 starts up, it can communicate with the first DNS server 104 corresponding to the preset DNS configuration information to obtain the IP address of the authentication server. Then, it sends a first authentication request to the authentication server 108 based on the authentication server's IP address and monitors the authentication result of the first authentication request. If the authentication result of the first authentication request is detected as authentication failure, terminal device 102 can obtain the DNS information matching the region where the terminal device is located from the DNS information preset for different regions by the DNS scheme server 110. Terminal device 102 can modify its domain name system (DNS) configuration information according to the DNS information. Then, based on the modified DNS configuration information, it communicates with the corresponding second DNS server 106 to obtain the IP address of the authentication server. It then triggers a second authentication request to the authentication server 108 and begins providing normal service after successful authentication. Terminal device 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart projectors, smart speakers, smart TVs, smart air conditioners, and smart in-vehicle devices. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted devices. The first DNS server 104, the second DNS server 106, the authentication server 108, and the DNS server 110 can each be implemented using independent servers or a server cluster consisting of multiple servers.

[0038] In another embodiment, the authentication method provided in this application can be applied to, for example, Figure 2In the application environment shown, terminal device 102 communicates with the first domain name system server 104, the second domain name system server 106, the authentication server 108, the domain name scheme server 110, and the virtual private network server 112 via a network. Authentication server 108 communicates with virtual private network server 112 via a network. After triggering the sending of a second authentication request, terminal device 102 can monitor the authentication result in response to the sent second authentication request. If the authentication result of the second authentication request is detected as authentication failure, terminal device 102 sends a connection request to virtual private network server 112, so that virtual private network server 112 establishes a private network connection between terminal device and authentication server. Terminal device 102 can then send a third authentication request to authentication server 108 through the private network connection. Virtual private network server 112 can be implemented using a standalone server or a server cluster consisting of multiple servers. In other embodiments, domain name scheme server 110 and virtual private network server 112 can also be implemented using the same server.

[0039] In one embodiment, such as Figure 3 As shown, an authentication method is provided, which can be applied to... Figure 1 Taking terminal device 102 as an example, the following steps are included:

[0040] Step 302: The terminal device sends a first authentication request and monitors the authentication result of the first authentication request.

[0041] An authentication request is a request sent by the terminal device to determine whether the terminal device is authorized to provide services. An authentication result is the authentication outcome obtained in response to the authentication request.

[0042] In one embodiment, the terminal device may be an Internet TV (i.e., a smart TV), or any other Internet of Things device, personal computer, laptop, smart projector, smartphone, tablet, or portable wearable device.

[0043] Specifically, after startup, the terminal device can send a first authentication request to the authentication server. If the authentication server receives the first authentication request, it can perform authentication processing and return the authentication result to the terminal device. The terminal device can monitor the authentication result.

[0044] In one embodiment, an authentication monitoring service can be set up in the terminal device to monitor the authentication results.

[0045] In one embodiment, the authentication request may include the MAC address (Media Access Control Address) of the terminal device, and the authentication server may perform authentication processing based on the MAC address in the authentication request. The MAC address is used to confirm the location of the network device.

[0046] In one embodiment, the authentication result can include authentication success and authentication failure. Authentication success indicates that the terminal device can begin providing services normally. Authentication failure indicates that the terminal device cannot connect to the authentication server.

[0047] In one embodiment, the terminal device can determine the corresponding first domain name system server based on the preset domain name system configuration information in the terminal device, and obtain the IP address of the authentication server from the first domain name system server. The terminal device can then send a first authentication request to the authentication server based on the IP address of the authentication server.

[0048] In one embodiment, the first Domain Name System (DNS) server can determine the IP address of the authentication server based on the domain name of the authentication server sent by the terminal device.

[0049] The Domain Name System (DNS) configuration information refers to the DNS information configured in the terminal device. DNS information is used to identify the DNS server. The primary DNS server is the server corresponding to the preset DNS configuration information in the terminal device and is used to provide DNS services. The Domain Name System (DNS) is an Internet service used to record the mapping relationship between domain names and IP addresses.

[0050] In one embodiment, the Domain Name System (DNS) information may be the IP address of the DNS server.

[0051] Step 304: If the authentication result of the first authentication request is detected as authentication failure, then obtain the domain name system information that matches the region where the terminal device is located from the domain name system information that is set up separately for different regions in advance.

[0052] In one embodiment, domain name system (DNS) information configured separately for different regions can be pre-stored in a DNS server. Specifically, DNS information from different regions can be collected and aggregated, and then the aggregated DNS information configured separately for different regions can be stored in the DNS server.

[0053] In one embodiment, if the authentication result is detected as authentication failure, the terminal device can obtain the domain name system information that matches the region where the terminal device is located from the domain name system information that is pre-set for different regions stored in the domain name scheme server.

[0054] In one embodiment, if the authentication result is detected as authentication failure, the terminal device can send a Domain Name System (DNS) information retrieval request to the DNS server. The DNS server can respond to the DNS information retrieval request by determining the DNS information that matches the region where the terminal device is located from the DNS information that is pre-set for different regions and sending it to the terminal device.

[0055] In one embodiment, if the authentication result is detected as authentication failure, the terminal device can obtain region-related information about its location, generate a Domain Name System (DNS) information retrieval request based on the region-related information, and send the DNS information retrieval request to the DNS server. The DNS server can respond to the DNS information retrieval request by determining, based on the region-related information in the request, the DNS information matching the terminal device's location from the DNS information pre-set for different regions and sending it to the terminal device.

[0056] Step 306: Modify the domain name system configuration information of the terminal device according to the domain name system information.

[0057] Specifically, the terminal device can replace the domain name system information in the preset domain name system configuration information with the matching domain name system information.

[0058] Step 308: Based on the modified Domain Name System configuration information, trigger the sending of a second authentication request, and start providing normal services after successful authentication.

[0059] In one embodiment, the terminal device can determine the corresponding second DNS server based on the modified DNS configuration information, and obtain the IP address of the authentication server from the second DNS server. The terminal device can then trigger a second authentication request to the authentication server based on the authentication server's IP address, and begin providing normal service after successful authentication.

[0060] In one embodiment, the second Domain Name System (DNS) server can determine the IP address of the authentication server based on the domain name of the authentication server sent by the terminal device.

[0061] The aforementioned authentication method involves the terminal device sending a first authentication request and monitoring its result. If the first authentication request fails, it retrieves the DNS information matching the terminal device's region from pre-configured DNS information for different regions. Based on this DNS information, it modifies the terminal device's DNS configuration and triggers a second authentication request. Upon successful authentication, normal service begins. This method automatically retrieves the DNS information matching the terminal device's region when authentication fails, triggering a resend of the authentication request based on the more suitable DNS information, thus resolving authentication failure issues and improving the success rate. Furthermore, compared to the method where users need to manually modify their DNS configuration information through customer service guidance when authentication fails, this method quickly and automatically matches and modifies the appropriate DNS information, significantly improving the efficiency of resolving authentication failures.

[0062] In one embodiment, if the authentication result of the first authentication request is detected as authentication failure, obtaining the domain name system information matching the region where the terminal device is located from the domain name system information pre-set for different regions includes: if the authentication result of the first authentication request is detected as authentication failure, obtaining the region-related information of the region where the terminal device is located, generating a domain name system information retrieval request based on the region-related information, and sending the domain name system information retrieval request to the domain name scheme server; the domain name scheme server responds to the domain name system information retrieval request, and matches the corresponding target region-related information from the preset domain name scheme according to the region-related information in the domain name system information retrieval request; the preset domain name scheme stores the region-related information and domain name system information respectively; from the preset domain name scheme, determining the domain name system information stored corresponding to the target region-related information, and sending the domain name system information to the terminal device.

[0063] Among them, "region-related information" refers to information related to a specific region. "Target region-related information" refers to region-related information matched from the preset domain name scheme.

[0064] Specifically, if the authentication result of the first authentication request is detected as authentication failure, the terminal device can obtain the region-related information of the region where the terminal device is located, generate a Domain Name System (DNS) information retrieval request based on the region-related information, and send the DNS information retrieval request to the DNS scheme server. The DNS scheme server can respond to the DNS information retrieval request, match the corresponding target region-related information from the preset DNS scheme according to the region-related information in the DNS information retrieval request, then determine the DNS information stored corresponding to the target region-related information from the preset DNS scheme, and send the DNS information to the terminal device.

[0065] In one embodiment, the region-related information may include at least one of region information and a public IP address. The region information refers to the region where the terminal device is located. The public IP address is the IP address of the public network to which the terminal device is connected.

[0066] In one embodiment, a preset domain name scheme can be stored in a domain name scheme server in advance.

[0067] In one embodiment, the matched target region information can be the same as or similar to the region information of the terminal device.

[0068] In one embodiment, the domain name scheme server can perform similarity matching between the region-related information of the terminal device's location and the region-related information in the preset domain name scheme to determine the matched target region-related information.

[0069] In the above embodiments, if the authentication result of the first authentication request is detected as authentication failure, the terminal device sends a Domain Name System (DNS) information retrieval request to the DNS scheme server. The DNS scheme server responds to the DNS information retrieval request by matching the corresponding target region information from the preset DNS scheme based on the region information of the terminal device's location. Then, it determines the DNS information stored corresponding to the target region information from the preset DNS scheme and sends the DNS information to the terminal device. This allows for the matching of more suitable DNS information to trigger a resend of the authentication request, thus solving the authentication failure problem and improving the authentication success rate.

[0070] In one embodiment, the region-related information includes region information; the target region-related information includes target region information; the domain name scheme server responds to the domain name system information retrieval request and matches the corresponding target region-related information from the preset domain name scheme based on the region-related information in the domain name system information retrieval request, including: the domain name scheme server responds to the domain name system information retrieval request and determines the region information of the region where the terminal device is located based on the domain name system information retrieval request; and matches the corresponding target region information from the preset domain name scheme based on the region information.

[0071] In one embodiment, the region information may be the administrative division to which the terminal device is located, such as a city, district, or county. In another embodiment, the region information may be the location information of the region where the terminal device is located, such as latitude and longitude.

[0072] In one embodiment, when the regional information is an administrative division, the domain name scheme server can match the administrative division of the region where the terminal device is located with the administrative division in the preset domain name scheme according to the relationship between administrative divisions, and obtain the corresponding target administrative division.

[0073] In one embodiment, when the regional information is location information, the domain name scheme server can perform similarity matching between the location information of the terminal device's location and the location information in the preset domain name scheme to obtain the corresponding target location information.

[0074] In the above embodiments, the domain name scheme server responds to the domain name system information acquisition request, determines the regional information of the terminal device based on the domain name system information acquisition request, and matches the corresponding target regional information from the preset domain name scheme based on the regional information. This enables the matching of more suitable domain name system information based on the regional information to trigger the resending of the authentication request, thus solving the authentication failure problem and improving the authentication success rate.

[0075] In one embodiment, matching the corresponding target region information from the preset domain name scheme based on the region information includes: determining the parent region information corresponding to the region information from the preset domain name scheme based on the region information, and using it as the target region information.

[0076] In one embodiment, when the regional information is an administrative division, the domain name scheme server can determine the next-level administrative division corresponding to that administrative division from the preset domain name scheme, and use it as the target regional information.

[0077] For example, if the region information of the terminal device is Area A, then the parent region information, City B, can be matched from the preset domain name scheme, and City B can be used as the target region information. Here, Area A is a district within City B.

[0078] In the above embodiments, the domain name scheme server can determine the upper-level regional information corresponding to the regional information from the preset domain name scheme based on the regional information, and use it as the target regional information. This enables the server to accurately match the upper-level regional information based on the regional information, obtain appropriate domain name system information to trigger the resending of the authentication request, solve the authentication failure problem, and improve the authentication success rate.

[0079] In one embodiment, matching the corresponding target region information from the preset domain name scheme based on the region information includes: determining the region information of the neighboring regions of the region information from the preset domain name scheme based on the region information, and using them as the target region information.

[0080] In one embodiment, when the regional information is an administrative division, the domain name scheme server can determine the administrative division adjacent to the administrative division from the preset domain name scheme as the target regional information.

[0081] For example, if the location of the terminal device is County C, then County D, which is adjacent to County C, can be matched from the preset domain name scheme as the target location information.

[0082] In the above embodiments, the domain name scheme server can determine the regional information adjacent to the regional information from the preset domain name scheme based on the regional information, and use it as the target regional information. This enables the server to accurately match the adjacent regional information based on the regional information, obtain the appropriate domain name system information to trigger the resending of the authentication request, solve the authentication failure problem, and improve the authentication success rate.

[0083] In one embodiment, the region-related information includes a public IP address; the target region-related information includes a target public IP address; the domain name scheme server responds to the domain name system information retrieval request and matches the corresponding target region-related information from the preset domain name scheme based on the region-related information in the domain name system information retrieval request, including: the domain name scheme server responds to the domain name system information retrieval request and determines the public IP address to which the terminal device is connected; and performs similarity matching between the public IP address and the IP addresses in the preset domain name scheme to determine the target public IP address.

[0084] In one embodiment, the Domain Name System (DNS) information retrieval request may include the public IP address of the terminal device, and the DNS server can determine the public IP address to which the terminal device is connected based on the DNS information retrieval request.

[0085] In one embodiment, the domain name scheme server can perform similarity matching between the public IP address connected to the terminal device and the IP address in the preset domain name scheme, and determine the IP address with the highest similarity as the target public IP address.

[0086] In one embodiment, the domain name scheme server can determine the region information of the terminal device based on the public IP address, and then match the corresponding target region information from the preset domain name scheme based on the region information.

[0087] In the above embodiments, the domain name scheme server responds to the domain name system information acquisition request, determines the public IP address connected to the terminal device, performs similarity matching between the public IP address and the IP address in the preset domain name scheme, determines the target public IP address, and thus can trigger a resend of the authentication request based on the matching of more suitable domain name system information according to the public IP address, thereby solving the authentication failure problem and improving the authentication success rate.

[0088] In one embodiment, after triggering the sending of a second authentication request based on the modified Domain Name System configuration information, the method further includes: the terminal device monitoring the authentication result in response to the sent second authentication request; if the authentication result of the second authentication request is detected as authentication failure, sending a connection request to the virtual private network server to enable the virtual private network server to establish a private network connection between the terminal device and the authentication server; and sending a third authentication request to the authentication server through the private network connection.

[0089] A Virtual Private Network (VPN) server is a server that provides Virtual Private Network (VPN) services.

[0090] Specifically, after triggering the sending of a second authentication request based on the modified Domain Name System (DNS) configuration information, the terminal device can monitor the authentication result of the second authentication request. If the authentication result of the second authentication request is authentication failure, the terminal device can send a connection request to the Virtual Private Network (VPN) server. The VPN server can respond to the connection request and establish a private network connection between the terminal device and the authentication server. The terminal device can then send a third authentication request to the authentication server through the private network connection and begin providing normal service after successful authentication.

[0091] In one embodiment, the virtual private network server can be located in a region with a low authentication failure rate. In another embodiment, an authentication failure rate less than a preset threshold is considered a low authentication failure rate.

[0092] In one embodiment, the virtual private network server and the domain name scheme server can be the same server. In another embodiment, the virtual private network server and the domain name scheme server can be different servers.

[0093] In one embodiment, after sending a third authentication request to the authentication server via a dedicated network connection, the terminal device can monitor the authentication result of the third authentication request. If the authentication result of the third authentication request is still authentication failure, the terminal device can display a prompt message to prompt the user to contact customer service to resolve the authentication failure issue.

[0094] In the above embodiments, if the authentication result of the second authentication request is detected as authentication failure, the terminal device can send a connection request to the virtual private network server, so that the virtual private network server can establish a private network connection between the terminal device and the authentication server, and send a third authentication request to the authentication server through the private network connection. This allows the terminal device to send an authentication request to the authentication server again if authentication still fails after modifying the domain name system configuration information, so as to further solve the authentication failure problem and improve the authentication success rate.

[0095] In one embodiment, the virtual private network server is located in the region with the lowest authentication failure rate.

[0096] In the above embodiments, the authentication results of terminal devices in different regions can be statistically analyzed to obtain the region with the lowest authentication failure rate. By setting the virtual private network server in the region with the lowest authentication failure rate, it is possible to ensure that a private network connection is successfully established between the terminal device and the authentication server through the virtual private network server, thereby further improving the authentication success rate.

[0097] like Figure 4 The diagram shows the overall flow of the authentication method in various embodiments of this application. The terminal device sends a first authentication request and monitors the authentication result. If the first authentication request is successful, normal service begins. If the first authentication request fails, the terminal device sends a Domain Name System (DNS) information retrieval request to the DNS server. The DNS server determines the DNS information matching the terminal device's location from the DNS information pre-set for different regions and sends it to the terminal device. The terminal device modifies its DNS configuration information according to the DNS information, triggers a second authentication request based on the modified DNS configuration information, and monitors the authentication result of the second authentication request. If the second authentication request is successful, normal service begins. If the second authentication request fails, the terminal device sends a connection request to a Virtual Private Network (VPN) server. The VPN server establishes a private network connection between the terminal device and the authentication server. The terminal device sends a third authentication request through the private network connection and monitors the authentication result of the third authentication request. If the third authentication request is successful, normal service will begin. If the third authentication request fails, the terminal device will display a prompt message.

[0098] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0099] Based on the same inventive concept, this application also provides an authentication system for implementing the authentication method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more authentication system embodiments provided below can be found in the limitations of the authentication method described above, and will not be repeated here.

[0100] In one embodiment, such as Figure 5 As shown, an authentication system 500 is provided, which includes: a terminal device 502, wherein:

[0101] The terminal device is used to send a first authentication request and monitor the authentication result of the first authentication request; if the authentication result of the first authentication request is detected as authentication failure, it obtains the domain name system information matching the region where the terminal device is located from the domain name system information that is set separately for different regions in advance; according to the domain name system information, it modifies the domain name system configuration information of the terminal device; according to the modified domain name system configuration information, it triggers the sending of a second authentication request, and starts to provide normal services after successful authentication.

[0102] In one embodiment, such as Figure 6 As shown, the system also includes: a Domain Name System (DNS) server 504; wherein:

[0103] The terminal device 502 is further configured to, if the authentication result of the first authentication request is detected as authentication failure, obtain the region-related information of the region where the terminal device is located, generate a Domain Name System (DNS) information retrieval request based on the region-related information, and send the DNS information retrieval request to the DNS scheme server. The DNS scheme server 504 is configured to respond to the DNS information retrieval request, match the corresponding target region-related information from a preset DNS scheme according to the region-related information in the DNS information retrieval request; the preset DNS scheme stores region-related information and DNS information accordingly; determine the DNS information stored corresponding to the target region-related information from the preset DNS scheme, and send the DNS information to the terminal device.

[0104] In one embodiment, region-related information includes region information; target region-related information includes target region information. Domain name scheme server 504 is further configured to respond to a Domain Name System (DNS) information retrieval request, determine the region information of the terminal device's location based on the DNS information retrieval request, and match the corresponding target region information from a preset domain name scheme based on the region information.

[0105] In one embodiment, the domain name scheme server 504 is further configured to determine, based on the regional information, the upper-level regional information corresponding to the regional information from a preset domain name scheme, and use it as the target regional information.

[0106] In one embodiment, the domain name scheme server 504 is further configured to determine, based on the regional information, the regional information of adjacent regions of the regional information from a preset domain name scheme, as the target regional information.

[0107] In one embodiment, the region-related information includes a public IP address; the target region-related information includes a target public IP address. The domain name scheme server 504 is further configured to respond to a domain name system information retrieval request, determine the public IP address to which the terminal device is connected based on the domain name system information retrieval request, and perform similarity matching between the public IP address and IP addresses in a preset domain name scheme to determine the target public IP address.

[0108] In one embodiment, such as Figure 7 As shown, the system also includes: a virtual private network server 506, wherein:

[0109] Terminal device 502 is also used to monitor the authentication result in response to the sent second authentication request; if the authentication result of the second authentication request is detected as authentication failure, a connection request is sent to the virtual private network server. Virtual private network server 506 is used to establish a private network connection between the terminal device and the authentication server. Terminal device 502 is also used to send a third authentication request to the authentication server through the private network connection.

[0110] In one embodiment, the virtual private network server is located in the region with the lowest authentication failure rate.

[0111] The aforementioned authentication system involves the terminal device sending a first authentication request and monitoring its result. If the first authentication request fails, it retrieves the DNS information matching the terminal device's region from pre-configured DNS information for different regions. Based on this DNS information, it modifies the terminal device's DNS configuration and triggers a second authentication request. Upon successful authentication, normal service begins. This system automatically retrieves the DNS information matching the terminal device's region when authentication fails, triggering a resend of the authentication request based on the more suitable DNS information, thus resolving authentication failure issues and improving the success rate. Furthermore, compared to the previous method where users needed to manually modify their DNS configuration information through customer service guidance when authentication failed, this system quickly and automatically matches and modifies the appropriate DNS information, significantly improving the efficiency of resolving authentication failures.

[0112] In one embodiment, a terminal device is provided, the internal structure of which can be shown as follows: Figure 8As shown, the terminal device includes a processor, memory, communication interface, and display screen connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements an authentication method. The display screen can be an LCD screen or an e-ink screen.

[0113] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0114] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0115] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.

[0116] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0117] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0118] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0119] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0120] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. An authentication method, characterized in that, The method includes: The terminal device determines the first domain name system server according to the preset domain name system configuration information, sends a first authentication request to the authentication server according to the IP address of the authentication server obtained from the first domain name system server, and monitors the authentication result of the first authentication request; the first authentication request is used to determine whether the terminal device has the authority to provide services. If the authentication result of the first authentication request is detected as an inability to connect to the authentication server, then the region-related information of the terminal device's location is obtained, a Domain Name System (DNS) information retrieval request is generated based on the region-related information, and the DNS information retrieval request is sent to the DNS server; the region-related information includes the public IP address and region information; The domain name scheme server responds to the domain name system information acquisition request and determines the public IP address to which the terminal device is connected based on the domain name system information acquisition request; The public IP address is matched with IP addresses in a preset domain name scheme based on similarity, and the IP address with the highest similarity is determined as the target public IP address. Alternatively, the corresponding target region information is matched from the preset domain name scheme based on the region information of the terminal device. The preset domain name scheme stores region-related information and domain name system information. The target region-related information includes the target public IP address and the target region information. From the preset domain name scheme, determine the domain name system information stored corresponding to the target region information, and send the domain name system information to the terminal device; The terminal device modifies its domain name system configuration information according to the domain name system information. Based on the modified Domain Name System (DNS) configuration information, the second DNS server is determined. Based on the IP address of the authentication server obtained from the second DNS server, a second authentication request is sent to the authentication server, and normal service is provided after successful authentication. If the authentication result of the second authentication request is detected as an inability to connect to the authentication server, a third authentication request is sent to the authentication server through a private network connection established between the terminal device and the authentication server via a virtual private network server, and normal service is started after successful authentication; the virtual private network server is set up in the region with the lowest authentication failure rate.

2. The method according to claim 1, characterized in that, Based on the region information of the terminal device's location, the corresponding target region information is matched from a preset domain name scheme, including: Based on the region information, determine the next-level region information corresponding to the region information from the preset domain name scheme, and use it as the target region information.

3. The method according to claim 1, characterized in that, Based on the region information of the terminal device's location, the corresponding target region information is matched from a preset domain name scheme, including: Based on the region information, the region information of neighboring regions of the region information is determined from the preset domain name scheme and used as the target region information.

4. The method according to any one of claims 1 to 3, characterized in that, After triggering the sending of a second authentication request based on the modified Domain Name System configuration information, the method further includes: The terminal device monitors the authentication result in response to the second authentication request; The process of sending a third authentication request to the authentication server via the private network connection established between the terminal device and the authentication server through the virtual private network server includes: Send a connection request to the virtual private network server so that the virtual private network server establishes a private network connection between the terminal device and the authentication server; A third authentication request is sent to the authentication server via the dedicated network connection.

5. An authentication system, characterized in that, The system includes: terminal equipment, a domain name scheme server, and a virtual private network server; wherein: The terminal device is configured to determine a first domain name system server based on preset domain name system configuration information, send a first authentication request to the authentication server based on the IP address of the authentication server obtained from the first domain name system server, and monitor the authentication result of the first authentication request; the first authentication request is used to determine whether the terminal device has the authority to provide services; if the authentication result of the first authentication request is that it cannot connect to the authentication server, then the device obtains the region-related information of the region where the terminal device is located, generates a domain name system information acquisition request based on the region-related information, and sends the domain name system information acquisition request to the domain name scheme server; the region-related information includes a public IP address and region information; The domain name scheme server responds to the domain name system information acquisition request, and determines the public IP address to which the terminal device is connected based on the request; it performs similarity matching between the public IP address and IP addresses in a preset domain name scheme, and determines the IP address with the highest similarity as the target public IP address; or, it matches the corresponding target region information from the preset domain name scheme based on the region information of the terminal device's location; the preset domain name scheme stores region-related information and domain name system information; wherein, the target region-related information includes the target public IP address and the target region information; it determines the domain name system information stored corresponding to the target region-related information from the preset domain name scheme, and sends the domain name system information to the terminal device; The terminal device is further configured to: modify the domain name system configuration information of the terminal device according to the domain name system information; determine the second domain name system server according to the modified domain name system configuration information; trigger the sending of a second authentication request to the authentication server according to the IP address of the authentication server obtained from the second domain name system server; and start providing normal services after successful authentication; if the authentication result of the second authentication request is detected as an inability to connect to the authentication server, send a third authentication request to the authentication server through the private network connection established between the terminal device and the authentication server via a virtual private network server; and start providing normal services after successful authentication. The virtual private network server is used to establish a private network connection between the terminal device and the authentication server; the virtual private network server is located in the region with the lowest authentication failure rate.

6. The system according to claim 5, characterized in that, The domain name scheme server is also used to determine, based on the region information, the next-level region information corresponding to the region information from a preset domain name scheme, and use it as the target region information.

7. The system according to claim 5, characterized in that, The domain name scheme server is also used to determine the regional information of adjacent regions of the regional information from a preset domain name scheme based on the regional information, and use them as target regional information.

8. The system according to any one of claims 5 to 7, characterized in that, The terminal device is also used to monitor the authentication result in response to the sent second authentication request; if the authentication result of the second authentication request is detected as authentication failure, a connection request is sent to the virtual private network server. The virtual private network server is also used to establish a private network connection between the terminal device and the authentication server. The terminal device is also used to send a third authentication request to the authentication server via the dedicated network connection.

9. A terminal device, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Network access method and device for mobile terminal

    CN105897947A

  • Method, device and system for intercepting malicious website, processor and memorizer

    CN108737327A

  • Domain name resolution method and device for household appliance, electronic equipment and storage medium

    CN110290229A

  • Network request method and device, terminal equipment and storage medium

    CN113206785A