A website interaction verification method, device, electronic device and storage medium
By introducing verification applet code and two parameter verification steps in website interactive verification, the problem of high cost and low security of SMS verification code is solved, achieving higher security and convenience, and reducing latency and cost.
Patent Information
- Application Number
- CN202310099787.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-10
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2043-02-10
AI Technical Summary
There are problems in existing website interactive verification with high costs, high latency and low security, especially when SMS verification codes are easily leaked during the sending process and cannot be received, affecting user data verification and information security.
Two verification steps are adopted, first obtaining the applet verification parameters through the verification applet code, and then sending the website verification code after the parameter verification is passed, combining the user's unique identity and interactive business identity for parameter verification, and comparing it on the client and server side.
It improves the security of website interactive verification and reduces costs, avoids the risk of loss and leakage of verification codes, and reduces the latency of verification code reception and improves user experience.
Smart Images

Figure CN116132164B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of website verification, and particularly relates to a website interaction verification method, device, electronic device and storage medium. Background Art
[0002] During the website interaction verification process (such as website registration, file download, etc.), the SMS verification code is a relatively commonly used verification and identification method at present. Its working process is as follows: The website or APP sends a verification message to the target user through the SMS interface. The user needs to correctly fill in the verification content within the specified time. If the user times out or fills in incorrectly, then other operations cannot be continued. However, using the SMS verification code for interactive verification has the following problems: high usage cost (SMS needs to be charged), and in special cases, it cannot be received (i.e., there is high latency). For example, factors such as the customer's mobile phone running out of credit or the mobile phone being blacklisted by the operator will cause the user not to receive the verification code. At the same time, the SMS verification code is prone to leakage during the sending process and is also relatively easy to be brute-forced during use, thus affecting the user's data verification and information security. Therefore, how to provide a website verification method with low cost, low latency and high security has become an urgent problem to be solved. Summary of the Invention
[0003] The purpose of the present invention is to provide a website interaction verification method, device, electronic device and storage medium to solve the problems of high cost, high latency and low security existing in the prior art.
[0004] To achieve the above purpose, the present invention adopts the following technical solutions:
[0005] In a first aspect, a website interaction verification method is provided, including:
[0006] The server responds to the verification request sent by the Web end, generates a verification mini-program code and a website verification code;
[0007] The server sends the verification mini-program code to the Web end;
[0008] The Web end receives the verification mini-program code sent by the server and performs visual display after receiving the verification mini-program code, so that the client can scan the visually displayed verification mini-program code to generate mini-program verification parameters;
[0009] When the client responds to the scanning of the verification mini-program code on the Web end, based on the verification mini-program code, mini-program verification parameters are obtained;
[0010] The client sends the mini-program verification parameters to the server;
[0011] The server receives the applet verification parameters sent by the client and verifies the parameters of the applet verification parameters;
[0012] If the parameter verification passes, the server sends the website verification code to the client;
[0013] The client receives the website verification code sent by the server and uses the website verification code as the website re-verification code;
[0014] The client performs website interaction verification with the Web side based on the website re-verification code;
[0015] When the Web side performs website interaction verification with the client, it obtains the website re-verification code and sends the website re-verification code to the server;
[0016] The server receives the website re-verification code sent by the Web side and determines whether the website verification code is consistent with the website re-verification code;
[0017] If so, the server determines that the website interaction verification passes; otherwise, it determines that the website interaction verification fails.
[0018] Based on the above-disclosed content, when the present invention performs website interaction verification, it first generates a verification applet code and a website verification code; then, it sends the verification applet code to the Web side for visual display. At this time, the user can use the client to scan the verification applet code to obtain the applet verification parameters; further, the client sends the obtained applet verification parameters to the server for parameter verification; then, after the server determines that the applet verification parameters pass the verification, it sends the website verification code to the client. At this time, the user can enter the website verification code on the Web side so that the Web side sends it to the server; finally, the server can achieve website interaction verification by comparing whether the verification code input by the user is consistent with the initially generated verification code.
[0019] Through the above design, when the present invention performs website interaction verification, it first sends a verification applet code to the user to obtain applet parameters, and then, after the applet verification parameters pass the verification, it sends a website verification code to the user. In this way, the present invention is equivalent to having two verification steps, and its security in use has been greatly improved compared to the traditional single SMS verification; at the same time, during the verification process, the verification applet code is introduced as a way to obtain verification parameters, which realizes the concealment processing of the parameters. Compared with the traditional plaintext SMS acquisition method, it is not easily cracked, and the security in use has been further improved; in addition, the present invention uses an applet to implement parameter acquisition and verification. Compared with the SMS verification method, it not only does not require a fee, reduces costs, but also is not prone to the problem of not receiving the verification code. Therefore, compared with the traditional verification method, the present invention increases the security in use while reducing costs and delays, and is suitable for large-scale application and promotion.
[0020] In a possible design, the applet verification parameters include: a user unique identifier and an interaction service identifier. Among them, performing parameter verification on the applet verification parameters includes:
[0021] Determine whether the user unique identifier is a legal identifier;
[0022] If so, obtain the interaction service corresponding to the verification request, and determine a service unique identifier based on the interaction service;
[0023] Determine whether the interaction service identifier is consistent with the service unique identifier;
[0024] If so, determine that the applet verification parameters pass the parameter verification.
[0025] Based on the above disclosed content, the present invention uses the user unique identifier and the interaction service identifier as applet verification parameters. In this way, it can be ensured that for each user when performing interaction verification of the same or different services, the applet verification parameters are different. Based on this, the security of the verification can be further improved.
[0026] In a possible design, before determining whether the website verification code is consistent with the website re-verification code, the method further includes:
[0027] Obtain the generation time of the website verification code and the sending time of the website re-verification code;
[0028] Determine whether the time difference between the generation time and the sending time is greater than a preset threshold;
[0029] If so, determine that the website interaction verification fails; otherwise, determine whether the website verification code is consistent with the website re-verification code.
[0030] In a possible design, in response to a verification request sent by the Web side to generate a website verification code, it includes:
[0031] Obtain a globally unique identifier;
[0032] Generate a pseudo-random number using a random number generation function, and use the globally unique identifier as the seed of the random number generation function, so as to generate the website verification code by using the pseudo-random number, the seed, and the random number generation function, where the random number generation function includes the System.Random class function.
[0033] In a possible design, the verification mini-program code contains a registered user identifier, an unregistered user identifier, and an interactive service identifier;
[0034] Among them, based on the verification mini-program code, obtaining mini-program verification parameters includes:
[0035] Parse the verification mini-program code to obtain a registered user identifier, an unregistered user identifier, and an interactive service identifier;
[0036] Obtain the user information of the target user, and determine whether the target user is a registered user based on the user information, where the target user is the user corresponding to the client, and the user information is obtained when the client responds to the scanning process of the verification mini-program code on the Web side;
[0037] If so, use the registered user identifier as the user unique identifier, otherwise, use the unregistered user identifier as the user unique identifier;
[0038] Use the user unique identifier and the interactive service identifier to form the mini-program verification parameters.
[0039] In a second aspect, a website interaction verification device is provided. Taking the device as a server as an example, it includes:
[0040] A verification code generation unit, configured to generate a verification mini-program code and a website verification code in response to a verification request sent by the Web side;
[0041] A first sending unit, configured to send the verification mini-program code to the Web side, so that the Web side performs visual display after receiving the verification mini-program code, so that the client can scan the visually displayed verification mini-program code to generate mini-program verification parameters;
[0042] A verification unit, configured to receive the mini-program verification parameters sent by the client and perform parameter verification on the mini-program verification parameters;
[0043] A first sending unit, configured to send the website verification code to the client when parameter verification is passed, so that after receiving the website verification code, the client uses the website verification code as a website re-verification code, and performs website interaction verification with the Web side based on the website re-verification code, so that when the Web side performs website interaction verification with the client, the website re-verification code is obtained;
[0044] The verification unit is further configured to receive the website re-verification code sent by the Web side, and determine whether the website verification code is consistent with the website re-verification code;
[0045] The verification unit is configured to determine that the website interaction verification is passed when the website verification code is consistent with the website re-verification code, otherwise, determine that the website interaction verification fails.
[0046] In a third aspect, a second website interaction verification device is provided. Taking the device as the client as an example, it includes:
[0047] A verification parameter acquisition unit, configured to, in response to a scanning process of a verification applet code on the Web side, obtain applet verification parameters based on the verification applet code;
[0048] A second sending unit, configured to send the applet verification parameters to the server, so that after receiving the applet verification parameters, the server performs parameter verification on the applet verification parameters, and after the parameter verification is passed, sends a website verification code to the client;
[0049] A receiving unit, configured to receive the website verification code sent by the server, and use the website verification code as a website re-verification code;
[0050] An interaction unit, configured to perform website interaction verification with the Web side based on the website re-verification code, so that when the Web side performs website interaction verification with the client, the website re-verification code is obtained, and the website re-verification code is sent to the server, so that when the server determines that the website re-verification code is consistent with the website verification code, it determines that the website interaction verification is passed.
[0051] In a fourth aspect, a third website interaction verification device is provided. Taking the device as an electronic device as an example, it includes a memory, a processor, and a transceiver that are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the website interaction verification method as described in the first aspect or any possible design in the first aspect.
[0052] Fifth aspect, a storage medium is provided, on which instructions are stored. When the instructions are run on a computer, the website interaction verification method as described in the first aspect or any possible design in the first aspect is executed.
[0053] Sixth aspect, a computer program product containing instructions is provided. When the instructions are run on a computer, the computer is made to execute the website interaction verification method as described in the first aspect or any possible design in the first aspect.
[0054] Beneficial effects:
[0055] (1) The website interaction verification method provided by the present invention enables users to obtain verification codes more conveniently and quickly. At the same time, it avoids the security risk problems caused by factors such as the loss and leakage of verification codes during the verification code acquisition process, reduces the reception delay of verification codes, and reduces the cost expenditure during the use of verification codes. Therefore, the present invention not only improves the convenience and security of verification code acquisition, but also improves the user experience. Description of the drawings
[0056] Figure 1 It is a schematic diagram of the architecture of the website interaction verification system provided by an embodiment of the present invention;
[0057] Figure 2 It is a schematic diagram of the step flow of the website interaction verification method provided by an embodiment of the present invention;
[0058] Figure 3 It is an example diagram of the verification mini-program code provided by an embodiment of the present invention;
[0059] Figure 4 It is a display schematic diagram of the website verification code provided by an embodiment of the present invention;
[0060] Figure 5 It is a schematic diagram of verification failure provided by an embodiment of the present invention;
[0061] Figure 6 It is a schematic diagram of user registration provided by an embodiment of the present invention;
[0062] Figure 7 It is a schematic diagram of the structure of the server provided by an embodiment of the present invention;
[0063] Figure 8 It is a schematic diagram of the structure of the client provided by an embodiment of the present invention;
[0064] Figure 9 It is a schematic diagram of the structure of the electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0065] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the accompanying drawings and the description of the embodiments or the prior art. Obviously, the following description of the structures of the drawings is only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. It should be noted here that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation on the present invention.
[0066] It should be understood that although terms such as first, second, etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, the first unit may be called the second unit, and similarly, the second unit may be called the first unit, without departing from the scope of the exemplary embodiments of the present invention.
[0067] It should be understood that for the term "and / or" that may appear in this article, it is merely a description of the associated relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, B exists alone, and A and B exist simultaneously; for the term " / and" that may appear in this article, it is a description of another associated object relationship, indicating that two relationships may exist. For example, A / and B may represent: A exists alone, and A and B exist alone; in addition, for the character " / " that may appear in this article, generally it means that the associated objects before and after are in an "or" relationship.
[0068] Embodiment:
[0069] See Figure 1As shown in the figure, this application provides a system architecture, which may but is not limited to including: a server, a client (such as intelligent terminals like smart phones and tablets), and a Web (World Wide Web) end. Among them, the Web end is used to provide a website interaction interface. When a user interacts with the Web end, a verification request is generated and sent to the server. After receiving the verification request sent by the Web end, the server first generates a verification mini-program code and a website verification code, and sends the verification mini-program code to the Web end for visual display. In this way, the user can scan the verification mini-program code based on the client to enter the mini-program to obtain the mini-program verification parameters. At the same time, the client also sends the mini-program verification parameters to the server, and the server verifies the mini-program verification parameters. After the verification passes, the server sends the website verification code to the client. Then, the user can input the received website verification code into the Web end, and the Web end sends it to the server. Finally, the server can complete the website interaction verification by comparing whether the verification code input by the user is the same as the generated verification code. Therefore, by setting two parameter verifications and using the verification mini-program code to obtain verification parameters, the security of this system is greatly improved compared with the traditional plain text SMS verification method. In addition, this invention uses a mini-program to implement parameter acquisition and verification. Compared with the SMS verification method, it not only does not require a fee, reduces costs, but also is not prone to the problem of not receiving the verification code. Therefore, this system can improve the convenience and security of obtaining the verification code while reducing the usage cost and improving the user experience.
[0070] See Figure 2 As shown in the figure, the website interaction verification method provided in this embodiment may but is not limited to run on the server, the client, and the Web end side. It can be understood that the foregoing execution subject does not constitute a limitation on the embodiments of this application. Correspondingly, the running steps of this method may but are not limited to the following steps S1 to S12 shown.
[0071] S1. The server generates a verification mini-program code and a website verification code in response to a verification request sent by the Web side. Specifically, in practical applications, the verification request can be, but is not limited to, generated when the Web side interacts with the user. For example, when registering an account, after the user clicks the verification button on the Web side, the Web side can generate a verification request and send it to the server. Optionally, for example, the verification request can include, but is not limited to, the business types of the user's website interaction, such as account registration, report download, login verification, etc., which can be changed according to the business used, and is not limited to the foregoing examples. Further, in this embodiment, for example, the server can encapsulate the registered user identifier (such as the user account or a string of random numbers), the unregistered user identifier (such as a string of pseudo-random numbers), and the interaction service identifier (which can be, but is not limited to, a unique identifier corresponding to each service, and the unique identifier can be a number, a letter, a symbol, or a combination of the three) into the verification mini-program code, so as to obtain the foregoing information by scanning the verification mini-program code subsequently, thereby being used for website interaction verification. In addition, for example, after generating the verification mini-program code, the server uses the encapsulated Dapper (an object mapper) to interact and save it in the database to achieve data retention.
[0072] In specific implementation, for example, the server can, but is not limited to, first obtain a globally unique identifier (which can be pre-set in the server), and then use a random number generation function to generate a pseudo-random number, and use the globally unique identifier as the seed of the random number generation function, so as to generate the website verification code by using the pseudo-random number, the seed, and the random number generation function. Further, for example, the random number generation function can include, but is not limited to, the System.Random class function. In addition, for example, the website verification code can be, but is not limited to, a combination of numbers, letters, symbols, or the three, and in this embodiment, it is preferably a six-digit numerical verification code.
[0073] After generating the verification mini-program code and the website verification code, website interaction verification can be performed. Among them, this embodiment sets two verification processes. The first is the parameter verification of the verification mini-program code; the second is the parameter verification of the website verification code after the first verification passes. In this way, by using the two verification methods and the mini-program verification method, its security is greatly improved compared with the traditional SMS verification method. In specific applications, the first verification process is shown in the following steps S2 to S7.
[0074] S2. The server sends the verification mini-program code to the Web side.
[0075] The Web end receives the verification mini-program code sent by the server and visually displays it after receiving the verification mini-program code, so that the client can scan the visually displayed verification mini-program code to generate mini-program verification parameters. Specifically, in application, the Web end can directly display the foregoing verification mini-program code on the website interaction interface. In this way, the user can use the client to scan the verification mini-program code, such as using WeChat to perform the scanning process, so as to enter the mini-program and obtain the verification parameters included in the verification mini-program code by parsing the verification mini-program code. Specifically, the process of obtaining the verification parameters is as shown in step S4 below.
[0076] S4. When the client responds to the scanning process of the verification mini-program code on the Web end, based on the verification mini-program code, obtain the mini-program verification parameters. Specifically, in application, the process of obtaining the mini-program verification parameters can, for example but not limited to, be as shown in steps S41 to S44 below.
[0077] S41. Parse the verification mini-program code to obtain the registered user identifier, unregistered user identifier, and interaction service identifier. In this embodiment, by scanning the verification mini-program code, the parsing of the verification mini-program code can be realized, so as to obtain the foregoing identifiers for representing the user and service type. Then, when scanning the code, the client can determine different mini-program verification parameters according to whether the user is registered, and the determination process is as shown in steps S42 to S44 below.
[0078] S42. Obtain the user information of the target user, and based on the user information, determine whether the target user is a registered user, where the target user is the user corresponding to the client, and the user information is obtained when the client responds to the scanning process of the verification mini-program code on the Web end.
[0079] S43. If so, use the registered user identifier as the user's unique identifier; otherwise, use the unregistered user identifier as the user's unique identifier. In specific applications, when the client scans the code to verify the mini-program code, if the user is a registered user, directly log in to the mini-program and use the parsed registered user identifier as the user's unique identifier. If the user is an unregistered user, at this time, use the parsed unregistered user identifier as the user's unique identifier. At the same time, a registration service can also be provided for the user, such as providing a registration button, and after the user clicks the registration button, providing a corresponding account registration form. After the user fills it out, the account registration can be completed and the account information can be transmitted to the server for storage. In this way, regardless of whether the user is registered or not, a corresponding user unique identifier can be generated, thus ensuring the smooth verification service for different users. In addition, in this embodiment, if the target user is an unregistered user, for example, this embodiment can, but is not limited to, adopt the method of registering first and then obtaining the mini-program verification parameters for the first verification. Of course, the principle of its verification method is the same as the foregoing example and will not be elaborated here.
[0080] After obtaining the user's unique identifier, the mini-program verification parameters corresponding to the user can be formed by combining the interactive service identifier, as shown in step S44 below.
[0081] S44. Use the user's unique identifier and the interactive service identifier to form the mini-program verification parameters. In this embodiment, for registered users, for example, it can also be, but is not limited to, based on the registered user's account, to match the registered user identifier from the registration database of the server (this database stores a large number of registered users and the user identifiers corresponding to each registered user). Of course, the registered user identifier is not limited to the two foregoing examples and can be specifically set according to usage.
[0082] Thus, through the foregoing steps S41 to S44, this embodiment can obtain the mini-program verification parameters based on the verified mini-program code, and thus complete the first interactive verification based on this parameter. Specifically, the process of the first interactive verification can be, but is not limited to, as shown in steps S5 and S6 below.
[0083] S5. The client sends the mini-program verification parameters to the server.
[0084] The S6 server receives the applet verification parameters sent by the client and verifies the applet verification parameters; specifically, in practical applications, for example, a user identification database and a service identification database are set up in the server. Among them, a large number of user identifications are stored in the user identification database, and the service identification corresponding to each interactive service is stored in the service identification database; thus, when the server verifies the applet verification parameters, it can but is not limited to first determining whether the user unique identification is a legal identification, that is, determining whether the user unique identification exists in the user identification database; if so, it is determined as a legal identification, otherwise, it is determined that the website interaction verification fails; at the same time, after the user unique identification verification passes, the verification of the interactive service identification can be carried out, that is, obtaining the interactive service corresponding to the verification request and determining the service unique identification based on the interactive service; finally, by determining whether the interactive service identification is consistent with the service unique identification, the parameter verification of the applet verification parameters can be completed; that is, in the service identification database, determining the service identification that matches the interactive service corresponding to the verification request; then, determining whether the matched service identification (that is, the service unique identification) is consistent with the interactive service identification, if so, the verification passes, otherwise, the verification fails.
[0085] After completing the verification process of the applet parameter verification, the second parameter verification can be carried out, that is, the verification of the website verification code, as shown in the following steps S7 to S12.
[0086] S7. If the parameter verification passes, the server sends the website verification code to the client.
[0087] S8. The client receives the website verification code sent by the server and uses the website verification code as the website re-verification code.
[0088] S9. The client conducts website interaction verification with the Web side based on the website re-verification code.
[0089] S10. When the Web side conducts website interaction verification with the client, it obtains the website re-verification code and sends the website re-verification code to the server; specifically, in practical applications, for example, the client can but is not limited to, after receiving the website verification code, using it as the website re-verification code for visual display. Of course, this display is also in the applet corresponding to the verified applet code, as shown in Figure 4 shown; thus, the user can input the website re-verification code displayed in the applet on the website interaction interface of the Web side, and then the Web side can send the website re-verification code input by the user to the server for the second parameter verification; further, the verification process of the server for the website re-verification code is as shown in the following steps S11 and step S12.
[0090] S11. The server receives the website re-verification code sent by the Web end and determines whether the website verification code is consistent with the website re-verification code; in this embodiment, an example also sets a step for judging the timeliness of the website re-verification code, that is, before judging the consistency between the website verification code and the website re-verification code, the generation time of the website verification code and the sending time of the website re-verification code can be obtained first; then, by judging whether the time difference between the generation time and the sending time is greater than a preset threshold (such as 1 minute, two minutes, 3 minutes, etc.), the timeliness judgment can be completed, that is, if the time difference is greater than the preset threshold, it is determined that the timeliness of the verification code has expired, and at the same time, it is determined that the website interaction verification fails; otherwise, the next step of verifying the consistency between the website verification code and the website re-verification code is performed, and after the consistency verification passes, the website interaction verification is completed, as shown in the following step S12.
[0091] S12. If so, the server determines that the website interaction verification passes; otherwise, it determines that the website interaction verification fails; in this embodiment, after determining that the website interaction verification fails, for example, the server can but is not limited to send a verification code error prompt message to the client, so that after the client receives the verification code error prompt message, it can re-perform website interaction verification based on the website verification code and the Web end, so that when the Web re-performs website interaction verification with the client, it can obtain the website verification code again and send it to the server; in this way, the website interaction verification can be re-implemented.
[0092] Thus, through the website interaction verification method detailed in the foregoing steps S1 to S12, the present invention greatly improves the use security compared with the traditional plain text SMS verification by setting two parameter verifications and using the verification mini-program code to obtain verification parameters; in addition, the present invention uses a mini-program to implement parameter acquisition and verification. Compared with the SMS verification method, it not only does not require a fee, reduces costs, but also is not prone to the problem of not receiving the verification code. Therefore, the system can improve the convenience and security of obtaining the verification code while reducing the use cost and improving the user experience.
[0093] In a possible design, as shown in Figures 3 to 6 shown, the second aspect of this embodiment provides an example processing process based on the website interaction verification method described in the first aspect of the embodiment, as follows:
[0094] For example, the website interaction verification can be but is not limited to: the identity verification when a user downloads a research report on a website. The traditional verification method is to input a mobile phone number to obtain an SMS verification code for identity verification, and the report can be downloaded only after the identity verification passes; the following changes the SMS verification method to the method described in the first aspect of the embodiment for identity verification, and its operation process is:
[0095] After the user clicks the "Report Download" button on the web side, a pop-up window containing a verification mini-program code will appear. For a schematic diagram, please refer to Figure 3 as shown. Among them, the verification mini-program code displayed in the pop-up window is generated by the server when it receives the verification request generated by the user clicking the "Report Download" button, and the verification mini-program code contains mini-program verification parameters (i.e., the user's unique identifier and the interactive service identifier); at the same time, the web page will guide the user to use the client to scan the code. Specifically, it can be but is not limited to using WeChat to scan the code. That is, the user uses the "Scan" function of WeChat. After scanning the code, the "HR Intelligent Address Book" mini-program will be opened, and corresponding information will be displayed inside the mini-program according to the different account registration statuses of the user.
[0096] For registered users, after scanning the code with WeChat and entering the mini-program, they obtain the mini-program verification parameters contained in the verification mini-program code and transmit them to the server. The server compares and verifies the mini-program verification parameters uploaded by the client. If the verification fails, relevant information will be prompted on the mini-program side to remind the user to scan the code again; if the verification passes, the website verification code generated when the verification request is received will be sent to the client for visual display (of course, it will also be displayed in the mini-program, as Figure 4 shown); then the user fills in the displayed verification code in the input box on the web side that requires the download code to be entered, and after clicking the "Confirm and Download" button, the web side can send the verification code entered by the user to the server; finally, the server performs a numerical comparison. If the comparison is correct, the report download can be completed. If the comparison is incorrect, relevant information will be prompted (such as displaying that the verification code is incorrect on the mini-program, see Figure 5 shown), to remind the user to enter the verification code again.
[0097] For unregistered users, the unregistered user identifier and the interactive service identifier in the verification mini-program code are used to generate the mini-program verification parameters. Similarly, the client will also send the verification parameters to the server, and the subsequent interactive verification process of the server based on the verification parameters is the same as that of the aforementioned registered users, which will not be elaborated here.
[0098] In addition, the registration process for unregistered users is as follows:
[0099] After the user scans the mini-program code with WeChat and enters the mini-program, first click the "Authorize to Obtain the Report Download Code" button. After clicking, an information filling form will pop up (see Figure 6As shown, the user fills in basic information (such as mobile phone number, name, etc.). After filling is completed, user registration can be completed. Of course, for the verification method of registering first and then obtaining the applet verification parameters, on the basis of the aforementioned successful registration, directly scan the code for website interaction verification. In this way, the applet transmits the applet verification parameters included in the applet code to the server, and then determines whether to send the website verification code to the applet according to the transmitted parameters. The verification process can refer to the verification process of the aforementioned registered users and will not be elaborated here.
[0100] In addition, in this embodiment, if it is detected that the user scans the code repeatedly within a preset time period (such as 10 s), that is, the interval time between two scans is less than the preset time period, then a prompt message indicating that the code scanning is too frequent will be generated to prompt the user that the code scanning is too frequent. Of course, this message also includes the time when the next code scanning is allowed, such as "Please scan the code after 60 s", etc. In specific implementation, the aforementioned prompt message can be specifically set according to actual use and is not limited to the aforementioned examples here.
[0101] Of course, in this embodiment, the aforementioned examples are only illustrative. The principle of the website verification process of different interactive services is the same as that of the aforementioned examples and is within the protection scope of the present invention.
[0102] As Figure 7 shown, in the third aspect of this embodiment, a hardware device for implementing the website interaction verification method described in the first aspect of the embodiment is provided. Taking the device as the server as an example, it includes:
[0103] A verification code generation unit, configured to generate a verification applet code and a website verification code in response to a verification request sent by the Web side.
[0104] A first sending unit, configured to send the verification applet code to the Web side, so that the Web side performs visual display after receiving the verification applet code, so that the client scans the visually displayed verification applet code to generate applet verification parameters.
[0105] A verification unit, configured to receive the applet verification parameters sent by the client and perform parameter verification on the applet verification parameters.
[0106] A first sending unit, configured to send the website verification code to the client when the parameter verification is passed, so that the client uses the website verification code as the website re-verification code after receiving the website verification code, and performs website interaction verification with the Web side based on the website re-verification code, so that the Web side obtains the website re-verification code when performing website interaction verification with the client.
[0107] The verification unit is further configured to receive the website re-verification code sent by the Web end, and determine whether the website verification code is consistent with the website re-verification code.
[0108] The verification unit is configured to determine that the website interaction verification passes when the website verification code is consistent with the website re-verification code; otherwise, it determines that the website interaction verification fails.
[0109] For the working process, working details and technical effects of the device provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated herein.
[0110] As Figure 8 shown, the fourth aspect of this embodiment provides a second website interaction verification device. Taking the device as the client as an example, it includes:
[0111] The verification parameter acquisition unit is configured to, in response to the scanning process of the verification mini-program code on the Web end, obtain the mini-program verification parameter based on the verification mini-program code.
[0112] The second sending unit is configured to send the mini-program verification parameter to the server, so that after receiving the mini-program verification parameter, the server performs parameter verification on the mini-program verification parameter, and after the parameter verification passes, sends the website verification code to the client.
[0113] The receiving unit is configured to receive the website verification code sent by the server and use the website verification code as the website re-verification code.
[0114] The interaction unit is configured to perform website interaction verification with the Web end based on the website re-verification code, so that when the Web end performs website interaction verification with the client, it obtains the website re-verification code and sends the website re-verification code to the server, so that the server determines that the website interaction verification passes when it determines that the website re-verification code is consistent with the website verification code.
[0115] As Figure 9 shown, the fifth aspect of this embodiment provides a third website interaction verification device. Taking the device as an electronic device as an example, it includes a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the website interaction verification method described in the first aspect of the embodiment.
[0116] Specifically, the memory may include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO) and / or first in last out (FILO), etc.; specifically, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). At the same time, the processor may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state.
[0117] In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. For example, the processor may not be limited to using a microprocessor of the STM32F105 series, a reduced instruction set computer (RISC) microprocessor, an X86 architecture processor, or a processor integrated with an embedded neural network processor (NNPs); the transceiver may include, but is not limited to, a Wi-Fi wireless transceiver, a Bluetooth wireless transceiver, a General Packet Radio Service (GPRS) wireless transceiver, a ZigBee (low-power local area network protocol based on the IEEE 802.15.4 standard) wireless transceiver, a 3G transceiver, a 4G transceiver, and / or a 5G transceiver, etc. In addition, the device may also include, but is not limited to, a power module, a display screen, and other necessary components.
[0118] For the working process, working details and technical effects of the electronic device provided in this embodiment, reference can be made to the first aspect of the embodiment, which will not be elaborated here.
[0119] In the sixth aspect of this embodiment, a storage medium storing instructions for the website interaction verification method described in the first aspect of the embodiment is provided, that is, instructions are stored on the storage medium, and when the instructions run on a computer, the website interaction verification method described in the first aspect of the embodiment is executed.
[0120] Among them, the storage medium refers to a carrier for storing data, and can include, but is not limited to, floppy disks, optical discs, hard disks, flash memories, USB flash drives, and / or memory sticks, etc. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0121] For the working process, working details and technical effects of the storage medium provided in this embodiment, reference can be made to the first aspect of the embodiment, which will not be elaborated here.
[0122] In the seventh aspect of this embodiment, a computer program product containing instructions is provided. When the instructions run on a computer, the computer is made to execute the website interaction verification method described in the first aspect of the embodiment, where the computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0123] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A website interaction verification method, characterized in that, Applied to a server, wherein the method includes: Responding to a verification request sent by the Web side to generate a verification mini-program code and a website verification code; Sending the verification mini-program code to the Web side so that the Web side can perform visual display after receiving the verification mini-program code, so that the client can scan the visually displayed verification mini-program code to generate mini-program verification parameters; Receiving the mini-program verification parameters sent by the client and performing parameter verification on the mini-program verification parameters; If the parameter verification passes, send the website verification code to the client so that the client, after receiving the website verification code, uses the website verification code as a website re-verification code and performs website interaction verification with the Web side based on the website re-verification code, so that the Web side can obtain the website re-verification code when performing website interaction verification with the client; Receiving the website re-verification code sent by the Web side and determining whether the website verification code is consistent with the website re-verification code; If so, determine that the website interaction verification passes; otherwise, determine that the website interaction verification fails; The mini-program verification parameters include: a user unique identifier and an interaction service identifier. Among them, performing parameter verification on the mini-program verification parameters includes: Judging whether the user unique identifier is a legal identifier; If so, obtain the interaction service corresponding to the verification request and determine a service unique identifier based on the interaction service; Judging whether the interaction service identifier is consistent with the service unique identifier; If so, determine that the mini-program verification parameters pass the parameter verification.
2. The method according to claim 1, wherein Before determining whether the website verification code is consistent with the website re-verification code, the method further includes: Obtaining the generation time of the website verification code and the sending time of the website re-verification code; Judging whether the time difference between the generation time and the sending time is greater than a preset threshold; If so, determine that the website interaction verification fails; otherwise, determine whether the website verification code is consistent with the website re-verification code.
3. The method according to claim 1, wherein Responding to a verification request sent by the Web side to generate a website verification code, including: Obtaining a globally unique identifier; Generating a pseudo-random number using a random number generation function, and using the globally unique identifier as the seed of the random number generation function, so as to generate the website verification code using the pseudo-random number, the seed, and the random number generation function, where the random number generation function includes a System.Random class function.
4. A website interaction verification method, characterized in that, Applied to a client, wherein the method includes: When responding to the scanning of the verification mini-program code on the Web side, obtaining mini-program verification parameters based on the verification mini-program code; Sending the mini-program verification parameters to the server so that the server, after receiving the mini-program verification parameters, performs parameter verification on the mini-program verification parameters and, after the parameter verification passes, sends a website verification code to the client; Receiving the website verification code sent by the server and using the website verification code as a website re-verification code; Based on the website re-verification code, perform website interaction verification with the Web end, so that when the Web end performs website interaction verification with the client, obtain the website re-verification code and send the website re-verification code to the server, so that when the server determines that the website re-verification code is consistent with the website verification code, it determines that the website interaction verification passes; The verification mini-program code contains a registered user identifier, an unregistered user identifier, and an interaction service identifier; Among them, based on the verification mini-program code, obtain mini-program verification parameters, including: Parse the verification mini-program code to obtain a registered user identifier, an unregistered user identifier, and an interaction service identifier; Obtain the user information of the target user, and based on the user information, determine whether the target user is a registered user. Among them, the target user is the user corresponding to the client, and the user information is obtained when the client responds to the scanning process of the verification mini-program code on the Web end; If so, use the registered user identifier as the user unique identifier, otherwise, use the unregistered user identifier as the user unique identifier; Use the user unique identifier and the interaction service identifier to form the mini-program verification parameters; Among them, after the server determines that the user unique identifier is a legal identifier, obtain the interaction service corresponding to the verification request, and based on the interaction service, determine the service unique identifier. When it determines that the interaction service identifier is consistent with the service unique identifier, it determines that the mini-program verification parameters pass the parameter verification.
5. A website interaction verification device, characterized in that, Include: A verification code generation unit, which is used to generate a verification mini-program code and a website verification code in response to a verification request sent by the Web end; A first sending unit, which is used to send the verification mini-program code to the Web end, so that the Web end performs visual display after receiving the verification mini-program code, so that the client can scan the visually displayed verification mini-program code to generate mini-program verification parameters; A verification unit, which is used to receive the mini-program verification parameters sent by the client and perform parameter verification on the mini-program verification parameters; The first sending unit is used to send the website verification code to the client when the parameter verification passes, so that the client uses the website verification code as the website re-verification code after receiving the website verification code, and performs website interaction verification with the Web end based on the website re-verification code, so that the Web end obtains the website re-verification code when performing website interaction verification with the client; The verification unit is also used to receive the website re-verification code sent by the Web end and determine whether the website verification code is consistent with the website re-verification code; The verification unit is used to determine that the website interaction verification passes when the website verification code is consistent with the website re-verification code, otherwise, it determines that the website interaction verification fails; The mini-program verification parameters include: a user unique identifier and an interaction service identifier. Among them, performing parameter verification on the mini-program verification parameters includes: Determine whether the user unique identifier is a legal identifier; If so, obtain the interactive service corresponding to the verification request, and determine a unique service identifier based on the interactive service; Determine whether the interactive service identifier is consistent with the unique service identifier; If so, determine that the applet verification parameter passes the parameter verification.
6. A website interaction verification device, characterized in that It includes: A verification parameter acquisition unit, configured to, in response to a scanning process of a verification applet code on the Web side, obtain an applet verification parameter based on the verification applet code; A second sending unit, configured to send the applet verification parameter to a server, so that after receiving the applet verification parameter, the server performs parameter verification on the applet verification parameter, and after the parameter verification passes, sends a website verification code to the client; A receiving unit, configured to receive the website verification code sent by the server, and use the website verification code as a website re-verification code; An interaction unit, configured to perform website interaction verification with the Web side based on the website re-verification code, so that when the Web side performs website interaction verification with the client, obtain the website re-verification code and send the website re-verification code to the server, so that the server determines that the website interaction verification passes when it determines that the website re-verification code is consistent with the website verification code; The verification applet code contains a registered user identifier, an unregistered user identifier, and an interactive service identifier; Among them, obtaining an applet verification parameter based on the verification applet code includes: Analyze the verification applet code to obtain a registered user identifier, an unregistered user identifier, and an interactive service identifier; Obtain the user information of the target user, and determine whether the target user is a registered user based on the user information, where the target user is the user corresponding to the client, and the user information is obtained by the client in response to a scanning process of a verification applet code on the Web side; If so, use the registered user identifier as the unique user identifier, otherwise, use the unregistered user identifier as the unique user identifier; Use the unique user identifier and the interactive service identifier to form the applet verification parameter; Among them, after the server determines that the unique user identifier is a legal identifier, it obtains the interactive service corresponding to the verification request, determines a unique service identifier based on the interactive service, and determines that the applet verification parameter passes the parameter verification when it determines that the interactive service identifier is consistent with the unique service identifier.
7. An electronic device, characterized in that, It includes: A memory, a processor, and a transceiver that are communicatively connected in sequence, where the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the website interaction verification method according to any one of claims 1 to 3 or 4.
8. A storage medium, characterized in that, Instructions are stored on the storage medium, and when the instructions are run on a computer, the website interaction verification method according to any one of claims 1 to 3 or 4 is executed.