Verification method, terminal device, server and nonvolatile storage medium

By incorporating time information and behavioral analysis into the CAPTCHA generation process, and generating CAPTCHA description information, the problem of insufficient protection and security caused by the simplicity of existing CAPTCHA generation methods is solved, achieving higher cracking difficulty and security.

CN115828211BActive Publication Date: 2026-02-17CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211183234.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-27
Publication Date
2026-02-17
Estimated Expiration
2042-09-27

AI Technical Summary

Technical Problem

The existing methods for generating CAPTCHAs are too simplistic, resulting in inadequate protection and security, and making them easy to crack.

Method used

By incorporating time information, the verification image is displayed on the terminal device, and the verification behavior information of the target object is obtained. Verification description information is then generated and sent to the server to determine the verification result.

Benefits of technology

This increases the difficulty of cracking CAPTCHAs, enhancing their protection and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115828211B_ABST
    Figure CN115828211B_ABST
Patent Text Reader

Abstract

The application discloses a verification method, a terminal device, a server and a nonvolatile storage medium. The method comprises the following steps: a terminal device acquires verification data and verification rule information from a server, wherein the verification data comprises a verification image, and the verification rule information at least comprises display time information of the verification image in the terminal device; the verification data is displayed in the terminal device according to the verification rule information; verification behavior information of a target object is acquired in the process of displaying the verification data; verification description information is generated according to the verification behavior information, and the verification description information is sent to the server, wherein the verification description information is used for determining a verification result. The application solves the technical problem that the protection and safety do not meet the requirements due to the simple verification code generation mode in the related art.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data security, in particular to a verification method, a terminal device, a server and a nonvolatile storage medium. BACKGROUND

[0002] CAPTCHA is an effective technical means for human-computer identification, which can prevent operators from using machine software to register garbage, crack passwords, steal information, fake exchanges, vote, forum water, etc., thereby protecting enterprise fund safety, marketing safety and information safety, and playing a major role in maintaining network community order.

[0003] Currently, the CAPTCHA in the related art usually shows a static verification image to a user and generates a CAPTCHA by obtaining verification behavior information of the user. This CAPTCHA generation manner is too simple, and with the development of artificial intelligence, deep learning and image recognition technology, the protection and security of the traditional CAPTCHA technology cannot meet the requirements.

[0004] In view of the above problems, no effective solution has been proposed so far. SUMMARY

[0005] The embodiments of the present application provide a verification method, a terminal device, a server and a nonvolatile storage medium to at least solve the technical problem that the protection and security do not meet the requirements due to the simple CAPTCHA generation manner in the related art.

[0006] According to an aspect of an embodiment of the present application, a verification method is provided, including: a terminal device obtaining verification data and verification rule information from a server, wherein the verification data includes a verification image, and the verification rule information at least includes display time information of the verification image in the terminal device; displaying the verification data in the terminal device according to the verification rule information; obtaining verification behavior information of a target object in the process of displaying the verification data; generating verification description information according to the verification behavior information, and sending the verification description information to the server, wherein the verification description information is used to determine a verification result.

[0007] Optionally, the verification rule information further includes a preset verification behavior corresponding to the verification image in the process of displaying the verification image, and the step of displaying the verification data in the terminal device according to the verification rule information includes: determining a target verification image from the verification image; generating prompt information according to the verification rule information and the target verification image, wherein the prompt information is used to prompt feature information of the target verification image and a target preset verification behavior when the target verification image is displayed; and displaying the prompt information in the process of displaying the verification image.

[0008] Optionally, the feature information of the target verification image comprises object type information of an object contained in the target verification image.

[0009] Optionally, the step of obtaining the verification data and the verification rule information from the server comprises: obtaining the verification rule information; in a case where there are multiple sets of verification images in the verification data, determining an obtaining order of the multiple sets of verification images according to the verification rule information; and obtaining each set of verification images in the multiple sets of verification images in sequence according to the obtaining order.

[0010] Optionally, the step of obtaining each set of verification images in the multiple sets of verification images in sequence according to the obtaining order comprises: obtaining a first verification image from the server, wherein the first verification image is a verification image corresponding to the first position in the obtaining order; sending verification description information corresponding to the last obtained verification image to the server, and obtaining a second verification image after sending the verification description information, wherein the verification description information is used to instruct the server to send the verification image according to the obtaining order, and the second verification image is a verification image other than the first verification image. Optionally, the step of generating the verification description information according to the verification behavior information comprises: determining verification time information corresponding to the verification behavior information, wherein the verification time information comprises a time point corresponding to the verification behavior of the target object; and generating the verification description information according to the verification time information and the verification behavior information.

[0011] Optionally, the display time information comprises a display start time point of the verification image in the terminal device, and a display duration of the verification image in the terminal device.

[0012] Optionally, the verification behavior information comprises at least one of the following: key action behavior information, touch gesture behavior information.

[0013] According to another aspect of the embodiments of the present application, a verification method is also provided, comprising: sending verification data and verification rule information to a terminal device, wherein the verification data comprises verification images, and the verification rule information at least comprises display time information of the verification images in the terminal device; obtaining verification description information generated by the terminal device according to the verification data and the verification rule information; and determining a verification result according to the verification description information.

[0014] Optionally, the step of determining the verification result based on the verification description information includes: determining the operator behavior model and historical verification behavior data corresponding to the target object, wherein the historical verification behavior data includes at least one of the following: historical verification description information of the target object, verification frequency information of the target object; calculating the target probability information based on the operator behavior model, historical verification behavior data, verification description information, and verification rule information, wherein the target probability information is used to reflect the probability that the target object is an allowed access object; comparing the target probability with a preset probability threshold, and determining the verification result as verification passed if the target probability is not less than the preset probability threshold; and determining the verification result as verification failed if the target probability is less than the preset probability threshold.

[0015] Optionally, if there are multiple target probabilities, the multiple target probabilities are summed, and the result of the summation is used as the target probability.

[0016] According to another aspect of the embodiments of this application, a terminal device is also provided, including a communication module, a display module, and a behavior module. The communication module is used to obtain verification data and verification rule information from a server. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device. The display module is used to display the verification data on the terminal device according to the verification rule information. The behavior module is used to obtain verification behavior information of a target object during the display of the verification data. The communication module is also used to generate verification description information based on the verification behavior information and send the verification description information to the server, wherein the verification description information is used to determine the verification result.

[0017] According to another aspect of the embodiments of this application, a server is also provided, including a generation module, a communication module, and a verification module. The generation module is used to generate verification data and verification rule information, wherein the verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device; the communication module is used to send the verification data and verification rule information to the terminal device; and to obtain verification description information generated by the terminal device based on the verification data and verification rule information; the verification module is used to determine the verification result based on the verification description information.

[0018] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, wherein a program is stored in the non-volatile storage medium, and the program controls the device where the non-volatile storage medium is located to execute a verification method when it runs.

[0019] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, and the program executes a verification method during runtime.

[0020] In this embodiment, a terminal device obtains verification data and verification rule information from a server. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device. Based on the verification rule information, the verification data is displayed on the terminal device. During the display of the verification data, verification behavior information of the target object is obtained. Verification description information is generated based on the verification behavior information and sent to the server. The verification description information is used to determine the verification result. By introducing time information during the generation of the verification description information, the complexity of the verification description information is increased, thereby achieving the technical effect of increasing the difficulty of cracking the verification code. This solves the technical problem that the protection and security requirements are not met due to the simplified verification code generation method in related technologies. Attached Figure Description

[0021] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0022] Figure 1 This is a flowchart illustrating a verification method provided according to an embodiment of this application;

[0023] Figure 2 This is a schematic diagram of a verification image provided according to an embodiment of this application;

[0024] Figure 3 This is a schematic diagram of another verification image provided according to an embodiment of this application;

[0025] Figure 4 This is a flowchart illustrating another verification method provided according to an embodiment of this application;

[0026] Figure 5 This is a flowchart illustrating a verification process provided according to an embodiment of this application;

[0027] Figure 6 This is a flowchart illustrating another verification process provided according to an embodiment of this application;

[0028] Figure 7 This is a schematic diagram of a verification process applicable to a client, provided according to an embodiment of this application;

[0029] Figure 8 This is a schematic diagram of a verification process applicable to a server, provided according to an embodiment of this application;

[0030] Figure 9 This is a schematic diagram of a client structure provided according to an embodiment of this application;

[0031] Figure 10 This is a schematic diagram of the structure of a server according to an embodiment of this application;

[0032] Figure 11 This is a schematic diagram of the structure of an electronic device provided according to an embodiment of this application. Detailed Implementation

[0033] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0035] In related technologies, CAPTCHAs typically involve displaying a static verification image to the user and generating the CAPTCHA by obtaining the user's verification behavior information. This method of generating CAPTCHAs is overly simplistic and therefore vulnerable to cracking, failing to meet practical needs in terms of protection and security. This application addresses these issues by introducing time information during the generation of the verification description information, as detailed below.

[0036] According to an embodiment of this application, a method embodiment for verification is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0037] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, or similar computing devices. Figure 11A hardware structure block diagram of a computer terminal (or mobile device) for implementing a verification method is shown. Figure 11 As shown, the computer terminal 11 (or mobile device 11) may include one or more processors 1102 (shown as 1102a, 1102b, ..., 1102n in the figure) (processor 1102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 1104 for storing data, and a transmission module 1106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, the computer terminal 110 may also include... Figure 11 The more or fewer components shown, or having the same Figure 11 The different configurations shown.

[0038] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 11 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0039] The memory 1104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the verification method in this embodiment. The processor 1102 executes various functional applications and data processing by running the software programs and modules stored in the memory 1104, thereby implementing the above-mentioned vulnerability detection method for the application. The memory 1104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 1104 may further include memory remotely located relative to the processor 1102, and these remote memories can be connected to the computer terminal 11 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0040] The transmission device 116 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 11. In one example, the transmission device 116 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 116 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0041] The display can be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 11 (or mobile device).

[0042] The technical solutions of this application embodiment can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, or 5G system, etc.

[0043] Under the above operating environment, this application provides a verification method applicable to terminal devices, such as... Figure 1 As shown, the method includes the following steps:

[0044] In step S102, the terminal device obtains verification data and verification rule information from the server. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device.

[0045] Specifically, the aforementioned display time information includes the start time of the display of the verification image on the terminal device and the display duration of the verification image on the terminal device.

[0046] In some embodiments of this application, the verification image is divided into several frames of image data. The display timing and duration of different image data are controlled according to the description of the verification rule information. While a certain frame of image data is being displayed, the operator needs to respond. This application digitizes the operator's response according to time slices to form an operator behavior description, that is, generates operator behavior description information or behavior feature code. Furthermore, during the verification process, this application performs calculations on the verification rules and behavior descriptions to determine whether to allow the operation.

[0047] In some embodiments of this application, the steps of the terminal device obtaining verification data and verification rule information from the server include: obtaining verification rule information; in the case that there are multiple sets of verification images in the verification data, determining the acquisition order of the multiple sets of verification images according to the verification rule information; and sequentially acquiring each set of verification images in the multiple sets of verification images according to the acquisition order.

[0048] In some embodiments of this application, the step of sequentially acquiring each set of verification images from multiple sets of verification images according to the acquisition order includes: acquiring a first verification image from the server, wherein the first verification image is the verification image that is first in the acquisition order; sending the verification description information corresponding to the previously acquired verification image to the server, and acquiring a second verification image after sending the verification description information, wherein the verification description information is used to instruct the server to send the verification images according to the acquisition order, and the second verification image is a verification image other than the first verification image.

[0049] Because this application can send the verification image to the terminal device multiple times, instead of sending all the verification images at once, it offers higher security and increases the difficulty of cracking compared to related technologies. Furthermore, in some embodiments of this application, different verification rules can be set for different verification images, further increasing the difficulty of cracking.

[0050] Step S104: Display the verification data on the terminal device according to the verification rule information;

[0051] In a summary of some embodiments of this application, the verification rule information also includes a preset verification behavior corresponding to the verification image during the display of the verification image. The step of displaying verification data in the terminal device according to the verification rule information includes: determining the target verification image from the verification image; generating prompt information according to the verification rule information and the target verification image, wherein the prompt information is used to prompt the feature information of the target verification image and the target preset verification behavior when displaying the target verification image; and displaying the prompt information during the display of the verification image.

[0052] As an optional implementation, the feature information of the target verification image includes object type information of the objects contained in the target verification image. For example, when the target verification image is as follows: Figure 2 When verifying an image as shown, the object type information can be a bicycle in the image. In this case, the prompt message can instruct the target object to click on the image when it sees a verification image containing a bicycle. When the target verification image is as follows... Figure 3 When verifying an image, the object type information can be the color of the numbers in the image. In this case, the prompt information can be an instruction to the target object to click on the image when it sees an image containing numbers of a specific color (such as red).

[0053] Step S106: During the process of displaying verification data, obtain the verification behavior information of the target object;

[0054] Optionally, the operation line information includes at least one of the following: key action behavior information, touch gesture behavior information.

[0055] Step S108: Generate verification description information based on the verification behavior information and send the verification description information to the server, wherein the verification description information is used to determine the verification result.

[0056] Optionally, the step of generating verification description information based on the verification behavior information includes: determining verification time information corresponding to the verification behavior information, wherein the verification time information includes the time point corresponding to the verification behavior of the target object; and generating the verification description information based on the verification time information and the verification behavior information.

[0057] The terminal device obtains verification data and verification rule information from the server. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device. Based on the verification rule information, the verification data is displayed on the terminal device. During the display of the verification data, the verification behavior information of the target object is obtained. Based on the verification behavior information, verification description information is generated and sent to the server. The verification description information is used to determine the verification result. By introducing time information in the process of generating the verification description information, the complexity of the verification description information is increased, thereby achieving the technical effect of increasing the difficulty of cracking the CAPTCHA. This solves the technical problem that the protection and security requirements are not met due to the simple CAPTCHA generation method in related technologies.

[0058] According to an embodiment of this application, another verification method embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0059] Figure 4 This is a flowchart illustrating another verification method provided according to an embodiment of this application, applicable to servers, such as... Figure 4 As shown, the method includes the following steps:

[0060] Step S402: Send verification data and verification rule information to the terminal device, wherein the verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device;

[0061] Step S404: Obtain the verification description information generated by the terminal device based on the verification data and verification rule information;

[0062] Step S406: Determine the verification result based on the verification description information.

[0063] In some embodiments of this application, the step of determining the verification result based on the verification description information includes: determining the operator behavior model and historical verification behavior data corresponding to the target object, wherein the historical verification behavior data includes at least one of the following: historical verification description information of the target object, verification frequency information of the target object; calculating target probability information based on the operator behavior model, the historical verification behavior data, the verification description information, and the verification rule information, wherein the target probability information is used to reflect the probability that the target object is an allowed access object; comparing the target probability with a preset probability threshold, and determining the verification result as verification passed if the target probability is not less than the preset probability threshold; and determining the verification result as verification failed if the target probability is less than the preset probability threshold.

[0064] In some embodiments of this application, when there are multiple target probabilities, the multiple target probabilities are summed, and the result of the summation is used as the target probability.

[0065] According to an embodiment of this application, a method such as... is also provided. Figure 5 The illustrated verification process example is applicable to a verification system consisting of terminal devices and a server. For example... Figure 5 As shown, the verification process includes the following steps:

[0066] In step S502, the server generates verification rules and verification images, and sends them to the terminal device;

[0067] Step S504: The terminal device displays the verification image and the prompt information generated based on the verification rules and the verification image to the target object;

[0068] Step S506: The terminal device collects user behavior information of the target object and sends the user behavior information to the server.

[0069] Step S508: The server calculates the target probability value based on the user behavior information;

[0070] In step S510, the server compares the target probability value with the preset probability threshold. If the target probability value is lower than the preset probability threshold, the process jumps to step S502. If the target probability value is not lower than the preset probability threshold, the process jumps to step S512.

[0071] Step S512: Send a verification code to the terminal device.

[0072] According to an embodiment of this application, another method is also provided. Figure 6 The illustrated verification process example is applicable to verification systems consisting of a server and an electronic device running a browser. For example...Figure 6 As shown, the verification process includes the following steps:

[0073] In step S602, the browser includes a JavaScript file in the page and then writes the CAPTCHA tag.

[0074] In step S604, after the page is initialized, the browser uses WebSocket to request the server to obtain the verification code.

[0075] In step S606, after receiving the request, the server generates a new verification rule, which includes a generation rule and a display rule. The server stores the verification rule in the storage module. Then, based on the generation rule, it generates a set of image data. Finally, it returns the set of image data and the display rule to the page via WebSocket.

[0076] In step S608, the page in the browser displays prompt text according to the returned rules (e.g., when red text is displayed, perform an upward swipe action on the screen), and displays specified image data at a specified time according to the rule description.

[0077] In step S610, the browser page collects the operator's actions, processes them into action feature codes, and uploads them to the server.

[0078] In step S612, the server performs a verification operation based on the action feature code and the stored verification code rules. The verification operation comprehensively utilizes multiple factors such as the operator's behavior model, historical input data, operator input history, and request frequency. The verification operation returns a probability value, which can represent the probability of a normal access operator to a certain extent, and this value is stored. If a stored value already exists, it is accumulated.

[0079] Step S614: Compare the stored probability value with the set threshold. If the probability value is greater than the threshold, the verification is successful. Generate a successful verification marker character and store the character. Return the marker character to the webpage. If the probability value is less than the threshold, jump to S606 and enter the next loop until the probability value is greater than the threshold.

[0080] Step S616: Verify the verification code. The webpage service sends the submitted verification code marker character to the server. If the server recognizes the marker character, the submission is valid; otherwise, it is invalid.

[0081] According to an embodiment of this application, a method such as... is also provided. Figure 7 The verification process shown is for the client. (Example) Figure 7 As shown, the verification process includes the following steps:

[0082] Step S702: Obtain verification data from the server;

[0083] Step S704: Display the verification data to the target object;

[0084] Step S706: Collect the operation behavior of the target object and determine whether there is still verification data to be displayed. If it is determined that there is still verification data to be displayed, proceed to step S704; otherwise, proceed to step S708.

[0085] Step S708: Send operation behavior information to the server and receive the verification result returned by the server. If the verification result is successful, the verification process ends; if the verification result is unsuccessful, proceed to step S702.

[0086] According to an embodiment of this application, a method such as... is also provided. Figure 8 The verification process shown is applicable to the server. For example... Figure 8 As shown, the verification process includes the following steps:

[0087] Step S802: Receive the verification request sent by the client, and generate verification rules and verification image data;

[0088] Step S804: Send the verification rules and verification image data to the client;

[0089] Step S806: Receive behavior description information sent by the client;

[0090] Step S808: Verify the behavior description information;

[0091] Step S810: Return the verification result.

[0092] According to an embodiment of this application, a method is provided as follows: Figure 9 An example of the terminal device shown. (As...) Figure 9 As shown, the terminal device includes a communication module 90, a display module 92, and a behavior module 94. The communication module 90 is used to obtain verification data and verification rule information from the server. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device. The display module 92 is used to display the verification data on the terminal device according to the verification rule information. The behavior module 94 is used to obtain the verification behavior information of the target object during the display of the verification data. The communication module 90 is also used to generate verification description information based on the verification behavior information and send the verification description information to the server. The verification description information is used to determine the verification result.

[0093] According to an embodiment of this application, a method is provided as follows: Figure 10 An example of a server is shown. (As...) Figure 10As shown, the server includes a generation module 100, a communication module 102, and a verification module 104. The generation module 100 is used to generate verification data and verification rule information. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device. The communication module 102 is used to send the verification data and verification rule information to the terminal device and obtain verification description information generated by the terminal device based on the verification data and verification rule information. The verification module 104 is used to determine the verification result based on the verification description information.

[0094] It should be noted that the modules in the aforementioned terminal devices and servers can be program modules (e.g., a set of program instructions that implement a specific function) or hardware modules. For the latter, they can take the following forms, but are not limited to these: each of the aforementioned modules is represented by a processor, or the functions of each of the aforementioned modules are implemented by a processor.

[0095] According to an embodiment of this application, an embodiment of a non-volatile storage medium is also provided. The non-volatile storage medium stores a program, wherein, during program execution, it controls the device where the non-volatile storage medium resides to perform the following verification method: the terminal device obtains verification data and verification rule information from a server, wherein the verification data includes a verification image, and the verification rule information includes at least information about the display time of the verification image on the terminal device; based on the verification rule information, the verification data is displayed on the terminal device; during the display of the verification data, verification behavior information of the target object is obtained; verification description information is generated based on the verification behavior information, and the verification description information is sent to the server, wherein the verification description information is used to determine the verification result.

[0096] In some embodiments of this application, the non-volatile storage medium also controls the device where the non-volatile storage medium is located to perform the following verification method during program execution: sending verification data and verification rule information to the terminal device, wherein the verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device; obtaining verification description information generated by the terminal device based on the verification data and verification rule information; and determining the verification result based on the verification description information.

[0097] According to an embodiment of this application, an embodiment of an electronic device is also provided. The electronic device includes a memory and a processor, the processor being used to run a program stored in the memory, wherein the program executes the following verification method: a terminal device obtains verification data and verification rule information from a server, wherein the verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device; based on the verification rule information, the verification data is displayed on the terminal device; during the display of the verification data, verification behavior information of the target object is obtained; verification description information is generated based on the verification behavior information, and the verification description information is sent to the server, wherein the verification description information is used to determine the verification result.

[0098] In some embodiments of this application, the program may also execute the following verification method during runtime: sending verification data and verification rule information to a terminal device, wherein the verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device; obtaining verification description information generated by the terminal device based on the verification data and verification rule information; and determining the verification result based on the verification description information.

[0099] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0100] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0101] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0102] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0103] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0104] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A verification method, applicable to terminal devices, characterized in that, include: The terminal device obtains verification data and verification rule information from the server. The verification data includes a verification image, which is sent to the terminal device in multiple parts. Different verification images are set with different verification rules. The verification rule information includes at least the display time information of the verification image on the terminal device. Based on the verification rule information, the verification data is displayed on the terminal device, wherein a target verification image is determined from the verification image, and the feature information of the target verification image includes the object type information of the objects contained in the target verification image; during the display of the verification image, prompt information is displayed, the prompt information including clicking the verification image when seeing a verification image that includes the object type information; During the process of displaying the verification data, the verification behavior information of the target object is obtained; Verification description information is generated based on the verification behavior information and sent to the server. The verification time information corresponding to the verification behavior information is determined, including the time point corresponding to the verification behavior of the target object. The verification description information is used to determine the verification result. The server is also used to determine the operator behavior model and historical verification behavior data corresponding to the target object. The historical verification behavior data includes at least one of the following: historical verification description information of the target object, and verification frequency information of the target object. Target probability information is calculated based on the operator behavior model, the historical verification behavior data, the verification description information, and the verification rule information. The target probability information reflects the probability that the target object is an allowed access object. The target probability is compared with a preset probability threshold. If the target probability is not less than the preset probability threshold, the verification result is determined to be verification passed. If the target probability is less than the preset probability threshold, the verification result is determined to be verification failed.

2. The verification method according to claim 1, characterized in that, The verification rule information also includes preset verification behaviors corresponding to the verification image during the display of the verification image, wherein the step of displaying the verification data in the terminal device according to the verification rule information includes: Determine the target verification image from the verification image; Based on the verification rule information and the target verification image, a prompt message is generated, wherein the prompt message is used to prompt the feature information of the target verification image and the target preset verification behavior when displaying the target verification image.

3. The verification method according to claim 1, characterized in that, The steps for the terminal device to obtain verification data and verification rule information from the server include: Obtain the verification rule information; If there are multiple sets of verification images in the verification data, the acquisition order of the multiple sets of verification images is determined according to the verification rule information; Each set of verification images is acquired sequentially according to the acquisition order.

4. The verification method according to claim 3, characterized in that, The step of sequentially acquiring each verification image from the plurality of verification images according to the acquisition order includes: Obtain a first verification image from the server, wherein the first verification image is the verification image that is obtained first in the acquisition order; The server sends the verification description information corresponding to the previously acquired verification image to the server, and acquires a second verification image after sending the verification description information. The verification description information is used to instruct the server to send the verification images according to the acquisition order, and the second verification image is a verification image other than the first verification image.

5. The verification method according to claim 1, characterized in that, The step of generating verification description information based on the verification behavior information includes: The verification description information is generated based on the verification time information and the verification behavior information.

6. The verification method according to claim 1, characterized in that, The display time information includes the start time of the display of the verification image on the terminal device, and the display duration of the verification image on the terminal device.

7. The verification method according to claim 1, characterized in that, The verification behavior information includes at least one of the following: key action behavior information, touch gesture behavior information.

8. A verification method, applicable to a server, characterized in that, include: Verification data and verification rule information are sent to a terminal device. The verification data includes a verification image, and the verification rule information includes at least the display time information of the verification image on the terminal device. The verification image includes a target verification image, and the verification image is sent to the terminal device in multiple parts. Different verification images have different verification rules. The feature information of the target verification image includes the object type information of the objects contained in the target verification image. During the display of the verification image, a prompt message is displayed, which includes clicking the verification image when the verification image containing the object type information is seen. The terminal device generates verification description information based on the verification data and the verification rule information. The verification description information is generated based on the verification behavior information, and the verification behavior information corresponds to verification time information, which includes the time point corresponding to the verification behavior of the target object. Based on the verification description information, a verification result is determined, wherein the operator behavior model and historical verification behavior data corresponding to the target object are determined, wherein the historical verification behavior data includes at least one of the following: historical verification description information of the target object, verification frequency information of the target object; a target probability information is calculated based on the operator behavior model, the historical verification behavior data, the verification description information, and the verification rule information, wherein the target probability information is used to reflect the probability that the target object is an allowed access object; the target probability is compared with a preset probability threshold, and if the target probability is not less than the preset probability threshold, the verification result is determined to be verification passed; and if the target probability is less than the preset probability threshold, the verification result is determined to be verification failed.

9. The verification method according to claim 8, characterized in that, In the case of multiple target probabilities, the multiple target probabilities are summed, and the result of the summation is taken as the target probability.

10. A terminal device, characterized in that, It includes a communication module, a display module, and a behavior module, among which, The communication module is used to obtain verification data and verification rule information from the server. The verification data includes a verification image, which is sent to the terminal device in multiple parts. Different verification images are set with different verification rules. The verification rule information includes at least the display time information of the verification image on the terminal device. The display module is used to display the verification data on the terminal device according to the verification rule information, wherein a target verification image is determined from the verification image, and the feature information of the target verification image includes the object type information of the objects contained in the target verification image; during the display of the verification image, prompt information is displayed, the prompt information including clicking the verification image when seeing a verification image that includes the object type information; The behavior module is used to obtain the verification behavior information of the target object during the process of displaying the verification data; The communication module is further configured to generate verification description information based on the verification behavior information and send the verification description information to the server. Specifically, it determines verification time information corresponding to the verification behavior information, including the time point corresponding to the verification behavior of the target object. The verification description information is used to determine the verification result. The server is further configured to determine the operator behavior model and historical verification behavior data corresponding to the target object. The historical verification behavior data includes at least one of the following: historical verification description information of the target object, and verification frequency information of the target object. Based on the operator behavior model, the historical verification behavior data, the verification description information, and the verification rule information, target probability information is calculated, whereby the target probability information reflects the probability that the target object is an allowed access object. The target probability is compared with a preset probability threshold. If the target probability is not less than the preset probability threshold, the verification result is determined to be verification passed. If the target probability is less than the preset probability threshold, the verification result is determined to be verification failed.

11. A server, characterized in that, It includes a generation module, a communication module, and a verification module, among which, The generation module is used to generate verification data and verification rule information. The verification data includes verification images, which are sent to the terminal device in multiple batches. Different verification images have different verification rules. The verification rule information includes at least the display time information of the verification images on the terminal device. The verification images include target verification images, and the feature information of the target verification images includes object type information of the objects contained in the target verification images. During the display of the verification images, prompt information is displayed, including clicking on the verification image when the verification image containing the object type information is seen. The communication module is used to send verification data and verification rule information to the terminal device; and to obtain verification description information generated by the terminal device based on the verification data and the verification rule information, wherein the verification description information is generated based on verification behavior information, the verification behavior information corresponds to verification time information, and the verification time information includes the time point corresponding to the verification behavior of the target object; The verification module is used to determine a verification result based on the verification description information, wherein it determines the operator behavior model and historical verification behavior data corresponding to the target object, wherein the historical verification behavior data includes at least one of the following: historical verification description information of the target object, verification frequency information of the target object; calculates target probability information based on the operator behavior model, the historical verification behavior data, the verification description information, and the verification rule information, wherein the target probability information is used to reflect the probability that the target object is an allowed access object; compares the target probability with a preset probability threshold, and determines the verification result as verification passed if the target probability is not less than the preset probability threshold; and determines the verification result as verification failed if the target probability is less than the preset probability threshold.

12. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores a program, wherein when the program is executed, it controls the device where the non-volatile storage medium is located to perform the verification method according to any one of claims 1 to 7 or any one of claims 8 to 9.

13. An electronic device, characterized in that, include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when running, performs the verification method according to any one of claims 1 to 7 or any one of claims 8 to 9.

Citation Information

Patent Citations

  • Clicking type dynamic verification code method

    CN114722376A