U-shield-based authentication methods, devices, electronic equipment, and storage media

By using financial institution platforms to detect U-shield permissions and authenticate U-shield customer identities, the problems of low U-shield authentication efficiency and insufficient permission verification are solved, achieving efficient U-shield authentication and permission management.

CN116232736BActive Publication Date: 2025-11-14INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310233864.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2025-11-14
Estimated Expiration
2043-03-03

AI Technical Summary

Technical Problem

Existing technologies for USB token authentication are inefficient and cannot verify permissions, resulting in third-party applications needing cumbersome manual registration and being unable to differentiate between USB tokens with different permission levels when accessing the system.

Method used

By receiving customer authentication requests from the open platform through the financial institution platform, obtaining U-shield information, detecting permissions based on the U-shield type, and authenticating the identity of the U-shield customer after the permissions are approved, the profile registration process is simplified and supports U-shield verification with different permissions.

Benefits of technology

It improves authentication efficiency, meets the permission requirements of different businesses, reduces manual registration costs, and enables effective verification of U-shield permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232736B_ABST
    Figure CN116232736B_ABST
Patent Text Reader

Abstract

This invention discloses an authentication method, apparatus, electronic device, and storage medium based on a USB key (U-shield), relating to the field of information security. The authentication method includes: receiving a client authentication request transmitted from an open platform; upon receiving a USB key detection response, obtaining USB key information associated with the detection response; based on the USB key type, detecting whether the USB key client has the authority to process the target service indicated by the service identifier; if the USB key client has the authority to process the target service, authenticating the USB key client's identity based on identity information and pre-set identity information, and returning the authentication result to the partner platform. This invention solves the technical problems of low authentication efficiency and inability to verify USB key permissions in related technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security, and more specifically, to an authentication method, apparatus, electronic device, and storage medium based on a USB key. Background Technology

[0002] Currently, the number of corporate and individual U-shield customers is constantly increasing, and all U-shield customers are registered with their real names. In the development of internet finance, most customers register and open accounts online via the internet or mobile phones. How to verify customer identity and implement real-name registration requirements has always been a difficult problem for internet companies. Furthermore, U-shield customers also hope to expand the application areas of U-shield services and ensure the security of their information and funds in third-party applications. In the internet context, product innovation has entered a platform innovation model. To create an open platform and support product innovation, third-party institutions have been introduced to collaborate on product development, leading to the launch of the "Real-Name Signature" product.

[0003] To meet the needs of partners for verifying customer identities and providing digital signatures for transactions conducted on their websites, the system leverages the real-name signature service of financial institutions to enable customers to use the financial institution's USB token to conduct related transactions on the partner's website. This real-name signature service also meets the partner's needs for verifying customer identities and expanding the scope of USB token usage for existing customers.

[0004] In this technology, partners need to open merchant profiles at financial institutions and obtain merchant certificates issued by those institutions. This verifies that the partner has already activated the real-name signature service when calling the financial institution's API. The real-name signature service applies to merchants completing signatures or adding signatures to their real names on the financial institution's website. The merchant server connects to the financial institution's server through the financial institution's open platform and completes the customer signature action on the returned financial institution page. Figure 1 This is a diagram illustrating an optional enterprise real-name signature process based on relevant technologies, such as... Figure 1 As shown, the process is as follows, assuming no transaction anomalies:

[0005] (1) When a customer browses a partner's website and plans to open a certain business through real-name authentication, they can request real-name authentication from the financial institution.

[0006] (2) The partner forms and submits data in accordance with the data specifications of the financial institution’s enterprise real-name signature interface, and signs the data using the merchant certificate provided by the financial institution, and forms a form to be returned to the customer’s browser;

[0007] (3) The customer calls the financial institution’s enterprise real-name signature interface, submits the form to the financial institution’s server, and the financial institution’s server verifies the partner’s signature and then shows the partner’s agreement to the customer. The customer reads the agreement and uses the financial institution’s U-shield or other mediums to perform real-name verification (i.e., interactive verification on the real-name signature page).

[0008] (4) After the financial institution verifies the customer's identity and signature, it calls the partner notification interface to notify the partner of the real-name signature transaction result (real-name signature successful, failure, non-real-name signature successful, failure).

[0009] (5) After receiving the verification success notification, the partner returns the success page address to the financial institution;

[0010] (6) If the partner returns a redirect link, the financial institution guides the customer to the partner's page;

[0011] (7) The customer completes the subsequent process on the partner's platform.

[0012] However, in the real-name signature process of related technologies, third-party applications need to register a profile in the financial institution's internal management system before integration. Then, the validity of the profile number is verified during real-name authentication in the corporate online banking system. This process requires manual registration in the internal management system, which is cumbersome and labor-intensive. Furthermore, the real-name signature process in these technologies does not support verification of U-shield permissions, failing to meet the needs of certain business scenarios requiring permission authentication, and cannot differentiate between U-shields with different permission levels.

[0013] There is currently no effective solution to the above problems. Summary of the Invention

[0014] This invention provides an authentication method, apparatus, electronic device, and storage medium based on a USB key, to at least solve the technical problems of low authentication efficiency and inability to verify the permissions of the USB key in related technologies.

[0015] According to one aspect of the present invention, a USB key-based authentication method is provided, applied to a financial institution platform, the financial institution platform communicating with a partner platform through an open platform interface, comprising: receiving a customer authentication request transmitted by the open platform, wherein the customer authentication request includes at least: identity information and a business identifier; upon receiving a USB key detection response, obtaining USB key information associated with the USB key detection response, wherein the USB key information includes at least: USB key type and preset identity information, the USB key being a USB key held by a USB key customer, and the preset identity information being identity information pre-stored in the USB key; based on the USB key type, detecting whether the USB key customer has permission to process the target business indicated by the business identifier; if the USB key customer has permission to process the target business, authenticating the identity of the USB key customer based on the identity information and the preset identity information, and returning the authentication result to the partner platform.

[0016] Optionally, before receiving the customer authentication request transmitted by the open platform, the method further includes: the partner platform receiving a login request sent by the client and verifying the login information carried in the login request; if the verification is successful, the partner platform sending an authentication information entry request to the client, wherein the client obtains authentication information based on the authentication information entry request and returns the authentication information to the partner platform, the authentication information including at least: identity information and business identifier; the partner platform assembling the authentication information into the customer authentication request based on the interface elements of the platform interface; the partner platform encrypting and signing the customer authentication request, and sending the encrypted and signed customer authentication request to the open platform, wherein the open platform decrypts and verifies the signature of the customer authentication request, and transmits the verified and decrypted customer authentication request to the financial institution platform.

[0017] Optionally, after receiving the customer authentication request transmitted by the open platform, the method further includes: parsing the customer authentication request to obtain business element parameters; and sending a U-shield detection request to the client if the validity of the business element parameters passes the verification, wherein the client returns the U-shield detection response if it detects that the U-shield is connected to the client interface.

[0018] Optionally, after obtaining the U-shield information associated with the U-shield detection response, the method further includes: simulating a login environment based on the U-shield information, wherein the login environment is an environment in which the client displays customer information to the U-shield customer; upon receiving a confirmation response for customer information, the client returns the confirmation response for customer information and the contractual agreement response; and upon successful verification of the confirmation response for customer information and the contractual agreement response, detecting the permissions of the U-shield customer.

[0019] Optionally, the step of detecting whether the U-shield customer has the permission to process the target service indicated by the service identifier based on the U-shield type includes: determining a set of U-shields that initiated the U-shield detection response, wherein the U-shield set includes at least one U-shield; determining the U-shield permissions corresponding to the U-shield type of each U-shield, and determining a set of U-shield permissions based on all the U-shield permissions; and determining that the U-shield customer has the permission to process the target service if the service permissions required by the target service belong to the set of U-shield permissions.

[0020] Optionally, the step of authenticating the identity of the U-shield customer based on the identity information and the preset identity information includes: if the identity information includes a customer name and a customer identifier, querying a preset customer information database based on the customer name and the customer identifier to obtain a customer code; or, if the identity information includes an account name and an account identifier, querying a preset account information database based on the account name and the account identifier to obtain a customer code; if the customer code matches the U-shield customer code carried in the preset identity information, determining that the U-shield customer's identity authentication is successful, and recording the successful identity authentication result of the U-shield customer to the authentication result.

[0021] Optionally, after confirming that the U-shield customer's identity authentication is successful, the method further includes: assembling the authentication result into a notification message and sending it to the partner platform, wherein the partner platform forwards the notification message to the partner platform, the partner platform processes the notification message and sends a preset address to the financial institution platform; parsing the preset address to obtain a preset redirect address; and returning the preset redirect address to the client.

[0022] According to another aspect of the present invention, a USB key-based authentication device is also provided, applied to a financial institution platform. The financial institution platform communicates with a partner platform through an open platform interface. The device includes: a receiving unit for receiving a customer authentication request transmitted by the open platform, wherein the customer authentication request includes at least: identity information and a business identifier; an acquisition unit for acquiring USB key information associated with a USB key detection response upon receiving such a response, wherein the USB key information includes at least: USB key type and preset identity information, wherein the USB key is a USB key held by a USB key customer, and the preset identity information is identity information pre-stored in the USB key; a detection unit for detecting, based on the USB key type, whether the USB key customer has permission to process the target business indicated by the business identifier; and an authentication unit for authenticating the identity of the USB key customer based on the identity information and the preset identity information, if the USB key customer has permission to process the target business, and returning the authentication result to the partner platform.

[0023] Optionally, the authentication device further includes: a first receiving module, configured to receive a login request sent by a client and verify the login information carried in the login request before receiving the client authentication request transmitted by the open platform; a first sending module, configured to send an authentication information entry request to the client when the verification is successful, wherein the client obtains authentication information based on the authentication information entry request and returns the authentication information to the partner platform, the authentication information including at least: identity information and business identifier; a first assembly module, configured to assemble the authentication information into the client authentication request based on the interface elements of the platform interface; and a first encryption module, configured to encrypt and sign the client authentication request and send the encrypted and signed client authentication request to the open platform, wherein the open platform decrypts and verifies the client authentication request and transmits the verified and decrypted client authentication request to the financial institution platform.

[0024] Optionally, the authentication device further includes: a first parsing module, configured to parse the customer authentication request after receiving the customer authentication request transmitted by the open platform to obtain business element parameters; and a second sending module, configured to send a U-shield detection request to the client if the legality verification of the business element parameters passes, wherein the client returns the U-shield detection response if it detects that the U-shield is connected to the client interface.

[0025] Optionally, the authentication device further includes: a first simulation module, configured to simulate a login environment based on the U-shield information after obtaining the U-shield information associated with the U-shield detection response, wherein the login environment is an environment in which the client displays customer information to the U-shield customer, and the client returns the confirmed customer information response and the contract agreement response upon receiving the confirmed customer information response; and a first detection module, configured to detect the permissions of the U-shield customer if the confirmed customer information response and the contract agreement response are verified to be valid.

[0026] Optionally, the detection unit includes: a first determining module, configured to determine a set of U-shields that initiated the U-shield detection response, wherein the set of U-shields includes at least one U-shield; a second determining module, configured to determine the U-shield permissions corresponding to the U-shield type of each U-shield, and determine a set of U-shield permissions based on all the U-shield permissions; and a third determining module, configured to determine that the U-shield customer has the permission to process the target service if the service permissions required by the target service belong to the set of U-shield permissions.

[0027] Optionally, the authentication unit includes: a first query module, configured to query a preset customer information database based on the customer name and customer identifier when the identity information includes a customer name and a customer identifier, to obtain a customer code; a second query module, configured to query a preset account information database based on the account name and account identifier when the identity information includes an account name and an account identifier, to obtain a customer code; and a fourth determination module, configured to determine that the U-shield customer's identity authentication is successful when the customer code matches the U-shield customer code carried in the preset identity information, and record the successful identity authentication result of the U-shield customer to the authentication result.

[0028] Optionally, the authentication device further includes: a second assembly module, configured to assemble the authentication result into a notification message after determining that the U-shield customer's identity authentication is successful, and send it to the partner platform, wherein the partner platform forwards the notification message to the partner platform, the partner platform processes the notification message, and sends a preset address to the financial institution platform; a second parsing module, configured to parse the preset address to obtain a preset redirect address; and a first return module, configured to return the preset redirect address to the client.

[0029] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the above-described authentication method based on a U-shield.

[0030] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the above-described U-shield-based authentication method.

[0031] In this disclosure, a customer authentication request transmitted by an open platform is received. Upon receiving a U-shield detection response, the U-shield information associated with the U-shield detection response is obtained. Based on the U-shield type, it is detected whether the U-shield customer has the authority to process the target business indicated by the business identifier. If the U-shield customer has the authority to process the target business, the identity of the U-shield customer is authenticated based on the identity information and the preset identity information, and the authentication result is returned to the partner platform. In this disclosure, upon receiving a customer authentication request, if a U-shield detection response is received, the relevant U-shield information can be obtained. Then, based on the U-shield type carried in the U-shield information, it is detected whether the relevant U-shield customer has the authority to process the target business indicated by the business identifier carried in the customer authentication request. If the customer has the authority, the identity of the U-shield customer can be authenticated based on the identity information carried in the customer authentication request and the preset identity information carried in the U-shield information. The authentication result is then returned to the partner platform to process subsequent business processes after successful authentication. This eliminates the need for pre-authentication registration on the partner platform, improving authentication efficiency. Furthermore, pre-authentication U-shield permission verification can meet the authentication requirements of different businesses for different permissions, thereby solving the technical problems of low authentication efficiency and inability to verify U-shield permissions in related technologies. Attached Figure Description

[0032] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0033] Figure 1 This is a schematic diagram of an optional enterprise real-name signature process based on relevant technologies;

[0034] Figure 2 This is a flowchart of an optional authentication method based on a U-shield according to an embodiment of the present invention;

[0035] Figure 3 This is a schematic diagram of an optional U-shield permission detection process according to an embodiment of the present invention;

[0036] Figure 4 This is a schematic diagram of an optional real-name authentication process based on a U-shield according to an embodiment of the present invention;

[0037] Figure 5 This is a schematic diagram of an optional U-shield-based authentication device according to an embodiment of the present invention;

[0038] Figure 6 This is a hardware structure block diagram of an electronic device (or mobile device) for a U-shield-based authentication method according to an embodiment of the present invention. Detailed Implementation

[0039] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0040] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0041] To facilitate understanding of the present invention by those skilled in the art, some terms or nouns involved in the various embodiments of the present invention are explained below:

[0042] U-Shield: A guardian of online banking security, it is a high-level security tool provided by financial institutions for conducting online banking business. It is a digital certificate used to identify users in the network environment.

[0043] Real-name signature: A service that verifies the identity of customers conducting business on a website and provides digital signatures.

[0044] RSA is an asymmetric encryption method where encryption and decryption use different keys. In general, a public key is used for encryption and a private key for decryption.

[0045] Corporate online banking: This is an electronic bank that provides financial services to enterprises. It serves an organization rather than an individual and provides corporate clients with a full range of services, including account management, settlement services, investment services, international settlement, annuities, and asset custody.

[0046] Open Platform: This is a unified access portal and management platform for financial institutions to provide open service interfaces (APIs) to their branches and partners. It provides services through standardized design, quickly responds to external cooperation needs, and establishes a mutually beneficial ecosystem for branches, partners, and users through interactive service innovation.

[0047] API (Application Programming Interface): An API is a set of definitions, programs, and protocols that enable communication between computer software.

[0048] URL (Uniform Resource Locator): The Uniform Resource Locator is a method used in Internet World Wide Web services to represent the location of information.

[0049] The internal management system is a subsystem of the online banking system of financial institutions. It is designed for internal staff at all levels of the financial institution's online banking system and provides functions such as management and maintenance of corporate and personal customers of the online banking system.

[0050] It should be noted that the authentication method and device based on U-shield in this disclosure can be used in the field of information security for authentication based on U-shield, and can also be used in any field other than information security for authentication based on U-shield. This disclosure does not limit the application field of the authentication method and device based on U-shield.

[0051] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data) disclosed herein are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use, and processing of such data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding access points are provided for users to choose to authorize or refuse. For example, this system has interfaces with relevant users or organizations. Before obtaining relevant information, a request to obtain the information must be sent to the aforementioned user or organization through the interface, and the relevant information will be obtained only after receiving consent from the aforementioned user or organization.

[0052] The following embodiments of the present invention can be applied to various systems / applications / devices based on U-shield authentication. This invention proposes a real-name authentication method based on U-shields. For customers holding U-shields, based on the real-name customer information associated with the U-shield authentication, API interfaces can be called to complete customer authentication and identification. Simultaneously, before authentication, the permissions of the customer holding the U-shield can be verified. If the customer has the necessary permissions, authentication is performed according to the real-name authentication method; otherwise, a message is sent back to the partner. By verifying the permissions of the customer holding the U-shield, the application of the real-name authentication system in different business scenarios is improved, better meeting customer needs and solving the problems of related technologies where real-name signature authentication systems require registration files, involve cumbersome manual steps, and cannot support permission verification.

[0053] The present invention will now be described in detail with reference to various embodiments.

[0054] Example 1

[0055] According to an embodiment of the present invention, an embodiment of an authentication method based on a U-shield is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0056] Figure 2 This is a flowchart of an optional U-shield-based authentication method according to an embodiment of the present invention, such as... Figure 2 As shown, the method includes the following steps:

[0057] Step S201: Receive a customer authentication request transmitted by the open platform, wherein the customer authentication request includes at least: identity information and business identifier.

[0058] Step S202: Upon receiving a U-shield detection response, obtain the U-shield information associated with the U-shield detection response. The U-shield information includes at least: U-shield type and pre-set identity information. The U-shield is a U-shield held by the U-shield customer, and the pre-set identity information is identity information pre-stored in the U-shield.

[0059] Step S203: Based on the U-shield type, detect whether the U-shield customer has the authority to process the target business indicated by the business identifier.

[0060] Step S204: If the U-shield customer has the authority to process the target business, the identity of the U-shield customer is authenticated based on the identity information and the pre-set identity information, and the authentication result is returned to the partner platform.

[0061] Through the above steps, the system can receive customer authentication requests transmitted by the open platform. Upon receiving a U-shield detection response, it can obtain the U-shield information associated with the U-shield detection response. Based on the U-shield type, it can detect whether the U-shield customer has the authority to process the target business indicated by the business identifier. If the U-shield customer has the authority to process the target business, it can authenticate the identity of the U-shield customer based on the identity information and the preset identity information, and return the authentication result to the partner platform. In this embodiment of the invention, after receiving a customer authentication request, if a U-shield detection response is received, the relevant U-shield information can be obtained. Then, based on the U-shield type carried in the U-shield information, it is detected whether the relevant U-shield customer has the authority to process the target business indicated by the business identifier carried in the customer authentication request. If the customer has the authority, the identity of the U-shield customer can be authenticated based on the identity information carried in the customer authentication request and the preset identity information carried in the U-shield information. The authentication result is then returned to the partner platform so that subsequent business processes can be processed after successful authentication. This eliminates the need to register a profile with the partner platform before authentication, improving authentication efficiency. Furthermore, performing U-shield permission verification before authentication can meet the authentication requirements of different businesses for different permissions, thereby solving the technical problems of low authentication efficiency and inability to verify U-shield permissions in related technologies.

[0062] The embodiments of the present invention will be described in detail below with reference to the steps described above. The following steps can be applied to financial institution platforms (such as corporate online banking), which communicate with partner platforms through the platform interface of the open platform.

[0063] Optionally, before receiving the customer authentication request transmitted by the open platform, the process further includes: the partner platform receiving the login request sent by the client and verifying the login information carried in the login request; if the verification is successful, the partner platform sending an authentication information entry request to the client, wherein the client obtains authentication information based on the authentication information entry request and returns the authentication information to the partner platform, the authentication information including at least: identity information and business identifier; the partner platform assembling the authentication information into a customer authentication request based on the interface elements of the platform interface; the partner platform encrypting and signing the customer authentication request, and sending the encrypted and signed customer authentication request to the open platform, wherein the open platform decrypts and verifies the signature of the customer authentication request, and transmits the verified and decrypted customer authentication request to the financial institution platform.

[0064] In this embodiment of the invention, a customer can log in to a third-party partner's website (i.e., the partner platform) through a client and enter the login information displayed on the website page (i.e., the partner platform receives the login request sent by the client). The partner platform then verifies the login information carried in the login request. If the verification is successful, it sends an authentication information entry request to the client. The client obtains the authentication information based on the authentication information entry request (i.e., the customer can enter the authentication information according to the authentication information entry request displayed on the client page) and returns the authentication information to the partner platform. The authentication information may include: identity information (i.e., the customer's identity information, such as the company name and organization code (i.e., unified social credit code), or account name and account number) and business identifier (i.e., the unique identifier of the business that the customer needs to process). Subsequently, the partner platform can assemble the authentication information into a customer authentication request based on the interface elements (i.e., the data specification format pre-set by the interface) of the platform interface (i.e., the API interface of the open platform). The assembled customer authentication request is then encrypted (e.g., RSA encryption) and signed. The encrypted and signed customer authentication request is then sent to the open platform. The open platform can decrypt and verify the customer authentication request, and transmit the verified and decrypted customer authentication request to the financial institution platform (e.g., corporate online banking). The corporate online banking platform provides the service, offering customer identity verification and customer information retrieval functions via API interface.

[0065] Step S201: Receive a customer authentication request transmitted by the open platform, wherein the customer authentication request includes at least: identity information and business identifier.

[0066] In this embodiment of the invention, a decrypted and verified customer authentication request transmitted by the open platform is received. The customer authentication request includes: identity information, business identifier, etc.

[0067] Optionally, after receiving the client authentication request transmitted by the open platform, the method further includes: parsing the client authentication request to obtain business element parameters; and sending a U-shield detection request to the client if the validity of the business element parameters is verified, wherein the client returns a U-shield detection response if it detects that the U-shield is connected to the client interface.

[0068] In this embodiment of the invention, the financial institution platform can first parse the received customer authentication request to obtain business element parameters (i.e., parameters about the business indicated by the business identifier). If the validity of the business element parameters is verified (i.e., these business element parameters conform to the preset parameters), a U-shield detection request can be sent to the client (i.e., the client is notified to remind the customer that they can insert the U-shield; if the customer holds multiple U-shields, they can insert them in sequence).

[0069] Step S202: Upon receiving a U-shield detection response, obtain the U-shield information associated with the U-shield detection response. The U-shield information includes at least: U-shield type and pre-set identity information. The U-shield is a U-shield held by the U-shield customer, and the pre-set identity information is identity information pre-stored in the U-shield.

[0070] In this embodiment of the invention, if the financial institution platform receives a U-shield detection response, it can obtain the U-shield information associated with the U-shield detection response (i.e., if the financial institution platform receives a response from the client indicating that a U-shield has been inserted, it can collect the U-shield information of the U-shield being inserted). The U-shield information includes: U-shield type (e.g., financial shield, management shield, etc.), pre-set identity information (i.e., identity information pre-stored in the U-shield), and the inserted U-shield is the U-shield held by the U-shield customer.

[0071] Optionally, after obtaining the U-shield information associated with the U-shield detection response, the method further includes: simulating a login environment based on the U-shield information, wherein the login environment is the environment in which the client displays customer information to the U-shield customer; upon receiving a confirmation response for customer information, the client returns a confirmation response for customer information and a contractual agreement response; and upon successful verification of the confirmation response for customer information and the contractual agreement response, detecting the U-shield customer's permissions.

[0072] In this embodiment of the invention, after obtaining the U-shield information, the financial institution platform can simulate a login environment (the login environment is the environment in which the client displays customer information to the U-shield customer). After receiving the confirmation of customer information response (i.e., after the customer confirms the customer information displayed on the client page), the client returns the confirmation of customer information response and the contract signing response (i.e., after the customer confirms the customer information, the customer can sign the displayed agreement (i.e., the client can return the contract signing response after the customer signs the agreement)). If the verification of the confirmation of customer information response and the contract signing response is successful, the permissions of the U-shield customer can be detected to determine whether the shield-holding customer has the authority to handle the corresponding business.

[0073] Step S203: Based on the U-shield type, detect whether the U-shield customer has the authority to process the target business indicated by the business identifier.

[0074] Optionally, the step of detecting whether a U-shield customer has the permission to process the target service indicated by the service identifier based on the U-shield type includes: determining the set of U-shields that initiated the U-shield detection response, wherein the U-shield set includes at least one U-shield; determining the U-shield permissions corresponding to the U-shield type of each U-shield, and determining a set of U-shield permissions based on all U-shield permissions; and determining that the U-shield customer has the permission to process the target service if the service permissions required by the target service belong to the set of U-shield permissions.

[0075] In this embodiment of the invention, the U-shield can be a corporate online banking U-shield (such as a financial shield or management shield). The verification of U-shield permissions can include verifying the U-shield's transfer permissions to the group's main account. For example, for single-shield customers and multi-shield customers without authorized shields (i.e., customers with multiple U-shields), the transfer permissions of the U-shield to the group's main account are verified. For multi-shield customers with authorized shields, the U-shield must be an authorized shield and have transfer permissions to the group's main account. If a financial shield is used: it is verified whether the group to which the U-shield belongs has a financial authorized shield; if so, the financial authorized shield must be used; otherwise, the financial submission shield can be used. If a management shield is used: it is verified whether the group to which the U-shield belongs has a management authorized shield; if so, the management authorized shield must be used; otherwise, the management submission shield can be used.

[0076] In this embodiment of the invention, the U-shield customer's permission to process the target business indicated by the business identifier can be detected based on the U-shield type. Specifically, the U-shield set that initiated the U-shield detection response can be determined first (this U-shield set includes at least one U-shield; if it is a single U-shield, it is a single-shield customer; otherwise, it is a multi-shield customer). Then, the U-shield permissions corresponding to the U-shield type of each U-shield can be determined (for example, if it is a financial shield, it has financial permissions; if it is a management shield, it has management permissions). Afterward, the U-shield permission set can be determined based on all U-shield permissions. If the business permissions required by the target business belong to the U-shield permission set (i.e., all U-shield permissions satisfy the permission to process the target business), then it can be determined that the U-shield customer has the permission to process the target business and can process the target business in subsequent processes.

[0077] Figure 3 This is a schematic diagram of an optional U-shield authorization detection process according to an embodiment of the present invention, such as... Figure 3 As shown, it can first determine whether it is a multi-shield customer. If not, it determines the U-shield permissions corresponding to the U-shield type and checks whether the U-shield permissions meet the requirements for processing business. If they do, it performs authentication; otherwise, it directly returns the authentication result. If it is a multi-shield customer, it sequentially determines the U-shield permissions (e.g., U-shield permission 1, U-shield permission 2, etc.) corresponding to the U-shield type. Based on all U-shield permissions, it determines the U-shield permission set and checks whether the U-shield permission set meets the requirements for processing business. If it does, it performs authentication; otherwise, it directly returns the authentication result.

[0078] Step S204: If the U-shield customer has the authority to process the target business, the identity of the U-shield customer is authenticated based on the identity information and the pre-set identity information, and the authentication result is returned to the partner platform.

[0079] Optionally, the step of authenticating the identity of a U-shield customer based on identity information and pre-set identity information includes: if the identity information includes a customer name and a customer identifier, querying a pre-set customer information database based on the customer name and customer identifier to obtain a customer code; or, if the identity information includes an account name and an account identifier, querying a pre-set account information database based on the account name and account identifier to obtain a customer code; if the customer code matches the U-shield customer code carried in the pre-set identity information, determining that the U-shield customer's identity authentication is successful, and recording the successful identity authentication result of the U-shield customer in the authentication result.

[0080] In this embodiment of the invention, if the U-shield customer has the authority to process the target business, the U-shield customer's identity can be authenticated based on the identity information and preset identity information. Specifically: if the identity information includes the customer name (such as the company name) and the customer identifier (such as the organization code), the preset customer information database (i.e., a pre-built database storing customer information, which stores customer codes associated with each customer's customer information) can be queried based on the customer name and the customer identifier to obtain the customer code; if the identity information includes the account name and the account identifier (i.e., the account number), the preset account information database (i.e., a pre-built database storing account information, which stores customer codes associated with each customer's account information) can be queried based on the account name and the account identifier to obtain the customer code. If the customer code matches the U-shield customer code carried in the preset identity information, it can be determined that the U-shield customer's identity authentication is successful, and the successful authentication result of the U-shield customer is recorded in the authentication result (this authentication result may include: authentication successful, authentication failed, no permission, etc.).

[0081] Optionally, after confirming that the U-shield customer's identity authentication is successful, the method further includes: assembling the authentication result into a notification message and sending it to the partner platform, wherein the partner platform forwards the notification message to the partner platform, processes the notification message, and sends a preset address to the financial institution platform; parsing the preset address to obtain a preset redirect address; and returning the preset redirect address to the client.

[0082] In this embodiment of the invention, the authentication result can be assembled into a notification message and sent to the partner platform. The partner platform can forward the notification message to the financial institution platform, process the notification message (e.g., view the authentication result, store the authentication result, etc.), and send a preset address to the financial institution platform (i.e., after the authentication result indicates that the authentication is successful, the partner platform can send the URL that the customer needs to be redirected to to the financial institution platform so that the customer can handle subsequent business processes). The financial institution platform can parse the preset address to obtain the preset redirect address, and then return the preset redirect address to the client so that the customer can be redirected to the corresponding address to handle business.

[0083] The following describes in detail another optional implementation method.

[0084] Figure 4 This is a schematic diagram of an optional real-name authentication process based on a U-shield according to an embodiment of the present invention, such as... Figure 4 As shown, it includes: client, partner platform, open platform, financial institution platform, preset customer information database, and preset account information database. The specific process is as follows:

[0085] (1) The client logs into the partner platform through the client. The partner platform verifies the login and sends an authentication information entry request to the client. The client obtains the authentication information entered by the client and sends the authentication information to the partner platform. The partner platform assembles the client authentication request based on the authentication information and the interface elements of the platform interface, and sends the client authentication request to the open platform after encrypting and signing it.

[0086] (2) After the open platform decrypts and verifies the customer authentication request, it sends the customer authentication request that has passed the verification and decryption to the financial institution platform.

[0087] (3) The financial institution platform parses the customer authentication request and verifies the validity of the parsed parameters. After the verification is successful, it sends a U-shield detection request to the client.

[0088] (4) The client performs U-shield detection, that is, during the process of connecting the open platform to the partner platform, it supports customers with U-shields to call the API interface to complete customer authentication and identification by inserting the U-shield. The obtained U-shield information is then sent to the financial institution platform.

[0089] (5) The financial institution platform queries the U-shield information and performs a simulated login. The shield holder confirms the information through the client and signs the agreement. The client sends the confirmation result to the financial institution platform.

[0090] (6) After the financial institution platform verifies the signature of the confirmation result, it will conduct permission test, that is, before authentication, the U-shield permission will be verified. Users who meet the permission requirements can be judged according to different real-name methods.

[0091] (7) If there is no permission, the permission-less result is directly assembled into a notification message message; if there is permission, the real-name method needs to be determined. If the real-name method is account + account name, the service is called in the preset account information database to query the main account customer number; if the real-name method is organization code + enterprise name, the service is called in the preset customer information database to query the enterprise customer number.

[0092] (8) The financial institution platform compares the customer number with the customer number in the U-shield of the shield-holding customer, queries the customer information in the preset customer information database, completes the customer authentication and connection, assembles the authentication result into a notification message, and sends it to the open platform.

[0093] (9) The open platform receives the notification message and forwards it to the partner platform. After the partner platform processes the data, the financial institution platform parses the URL returned by the partner platform and returns the authentication result and the redirect address to the client.

[0094] In this embodiment of the invention, the need for partners to verify the identity of customers conducting business on their website and to perform digital signatures can be met, reducing the cost and workload of manually registering files in the internal management system. Furthermore, encryption algorithms ensure the confidentiality, integrity, and consistency of the signature data, preventing forgery and tampering of the verification data. In addition, the verification of U-shield permissions can meet the needs of business scenarios requiring authorization authentication, better satisfying customers' needs for authorization verification, and differentiating U-shields with different permission levels.

[0095] The following is a detailed description with reference to another embodiment.

[0096] Example 2

[0097] The authentication device based on a U-shield provided in this embodiment includes multiple implementation units, each of which corresponds to a specific implementation step in Embodiment 1 above.

[0098] Figure 5 This is a schematic diagram of an optional U-shield-based authentication device according to an embodiment of the present invention, such as... Figure 5 As shown, the authentication device may include: a receiving unit 50, an acquiring unit 51, a detecting unit 52, and an authentication unit 53, wherein...

[0099] The receiving unit 50 is used to receive customer authentication requests transmitted by the open platform, wherein the customer authentication request includes at least: identity information and business identifier;

[0100] The acquisition unit 51 is used to acquire the U-shield information associated with the U-shield detection response when a U-shield detection response is received. The U-shield information includes at least: U-shield type and preset identity information. The U-shield is a U-shield held by the U-shield customer, and the preset identity information is identity information pre-stored in the U-shield.

[0101] The detection unit 52 is used to detect whether the U-shield customer has the authority to process the target business indicated by the business identifier, based on the U-shield type.

[0102] The authentication unit 53 is used to authenticate the identity of the U-shield customer based on the customer's identity information and pre-set identity information, when the U-shield customer has the authority to process the target business, and return the authentication result to the partner platform.

[0103] The aforementioned authentication device can receive customer authentication requests transmitted from the open platform via receiving unit 50, obtain U-shield information associated with the U-shield detection response via obtaining unit 51, detect whether the U-shield customer has the authority to process the target business indicated by the business identifier via detection unit 52 based on the U-shield type, and authenticate the identity of the U-shield customer based on identity information and preset identity information via authentication unit 53 if the U-shield customer has the authority to process the target business, and return the authentication result to the partner platform. In this embodiment of the invention, after receiving a customer authentication request, if a U-shield detection response is received, the relevant U-shield information can be obtained. Then, based on the U-shield type carried in the U-shield information, it is detected whether the relevant U-shield customer has the authority to process the target business indicated by the business identifier carried in the customer authentication request. If the customer has the authority, the identity of the U-shield customer can be authenticated based on the identity information carried in the customer authentication request and the preset identity information carried in the U-shield information. The authentication result is then returned to the partner platform so that subsequent business processes can be processed after successful authentication. This eliminates the need to register a profile with the partner platform before authentication, improving authentication efficiency. Furthermore, performing U-shield permission verification before authentication can meet the authentication requirements of different businesses for different permissions, thereby solving the technical problems of low authentication efficiency and inability to verify U-shield permissions in related technologies.

[0104] Optionally, the authentication device further includes: a first receiving module, used for receiving a login request sent by a client before receiving a client authentication request transmitted by the open platform, and verifying the login information carried in the login request; a first sending module, used for the partner platform to send an authentication information entry request to the client after successful verification, wherein the client obtains authentication information based on the authentication information entry request and returns the authentication information to the partner platform, the authentication information including at least: identity information and business identifier; a first assembly module, used for the partner platform to assemble the authentication information into a client authentication request based on the interface elements of the platform interface; and a first encryption module, used for the partner platform to encrypt and sign the client authentication request, and send the encrypted and signed client authentication request to the open platform, wherein the open platform decrypts and verifies the signature of the client authentication request, and transmits the verified and decrypted client authentication request to the financial institution platform.

[0105] Optionally, the authentication device further includes: a first parsing module, used to parse the client authentication request after receiving the client authentication request transmitted by the open platform to obtain business element parameters; and a second sending module, used to send a U-shield detection request to the client if the legality verification of the business element parameters passes, wherein the client returns a U-shield detection response if it detects that the U-shield is connected to the client interface.

[0106] Optionally, the authentication device further includes: a first simulation module, used to simulate a login environment based on the U-shield information after obtaining the U-shield information associated with the U-shield detection response, wherein the login environment is the environment in which the client displays customer information to the U-shield customer, and the client returns a confirmation of customer information response and a contract agreement response upon receiving a confirmation of customer information response; and a first detection module, used to detect the U-shield customer's permissions if the confirmation of customer information response and the contract agreement response are verified to be successful.

[0107] Optionally, the detection unit includes: a first determining module, used to determine the set of U-shields that initiated the U-shield detection response, wherein the set of U-shields includes at least one U-shield; a second determining module, used to determine the U-shield permissions corresponding to the U-shield type of each U-shield, and to determine the U-shield permission set based on all U-shield permissions; and a third determining module, used to determine that the U-shield customer has the permission to process the target business if the business permissions required by the target business belong to the U-shield permission set.

[0108] Optionally, the authentication unit includes: a first query module, used to query a preset customer information database based on the customer name and customer identifier when the identity information includes the customer name and customer identifier, to obtain a customer code; a second query module, used to query a preset account information database based on the account name and account identifier when the identity information includes the account name and account identifier, to obtain a customer code; and a fourth determination module, used to determine that the U-shield customer's identity authentication is successful when the customer code matches the U-shield customer code carried in the preset identity information, and to record the successful identity authentication result of the U-shield customer in the authentication result.

[0109] Optionally, the authentication device further includes: a second assembly module, used to assemble the authentication result into a notification message after confirming that the U-shield customer's identity authentication is successful, and send it to the partner platform, wherein the partner platform forwards the notification message to the partner platform, the partner platform processes the notification message and sends a preset address to the financial institution platform; a second parsing module, used to parse the preset address to obtain a preset redirect address; and a first return module, used to return the preset redirect address to the client.

[0110] The authentication device described above may also include a processor and a memory. The receiving unit 50, the acquiring unit 51, the detecting unit 52, the authentication unit 53, etc., are all stored in the memory as program units, and the processor executes the program units stored in the memory to realize the corresponding functions.

[0111] The aforementioned processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured. By adjusting kernel parameters, the kernel can authenticate the U-shield customer's identity based on their identity information and pre-set identity information, provided the U-shield customer has the authority to handle the target business, and then return the authentication result to the partner platform.

[0112] The aforementioned memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0113] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program with the following method steps: receiving a customer authentication request transmitted by an open platform; upon receiving a U-shield detection response, obtaining the U-shield information associated with the U-shield detection response; based on the U-shield type, detecting whether the U-shield customer has the authority to process the target business indicated by the business identifier; if the U-shield customer has the authority to process the target business, authenticating the identity of the U-shield customer based on identity information and preset identity information, and returning the authentication result to the partner platform.

[0114] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the above-described U-shield-based authentication method.

[0115] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors cause the one or more processors to implement the above-described U-shield-based authentication method.

[0116] Figure 6 This is a hardware structure block diagram of an electronic device (or mobile device) for an authentication method based on a USB key, according to an embodiment of the present invention. Figure 6 As shown, an electronic device may include one or more ( Figure 6The processor 602 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 604 for storing data may also be included. In addition, it may include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 6 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, the electronic device may also include components that are more... Figure 6 The more or fewer components shown, or having the same Figure 6 The different configurations shown.

[0117] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0118] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0119] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0120] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0121] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0122] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0123] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. An authentication method based on a USB key, characterized in that, Applied to financial institution platforms, these platforms communicate with partner platforms through open platform interfaces, including: Receive customer authentication requests transmitted by the open platform, wherein the customer authentication request includes at least: identity information and business identifier; Upon receiving a U-shield detection response, the U-shield information associated with the U-shield detection response is obtained, wherein the U-shield information includes at least: U-shield type and preset identity information, wherein the U-shield is a U-shield held by a U-shield customer, and the preset identity information is identity information pre-stored in the U-shield; Based on the U-shield type, detect whether the U-shield customer has the authority to process the target service indicated by the service identifier; If the U-shield customer has the authority to process the target business, the identity of the U-shield customer is authenticated based on the identity information and the preset identity information, and the authentication result is returned to the partner platform. The step of detecting whether the U-shield customer has the authority to process the target service indicated by the service identifier, based on the U-shield type, includes: Determine the set of U-shields that initiate the U-shield detection response, wherein the set of U-shields includes at least one U-shield; Determine the U-shield permissions corresponding to the U-shield type for each U-shield, and determine the U-shield permission set based on all the U-shield permissions; If the business permissions required for the target service belong to the U-shield permission set, it is determined that the U-shield customer has the permission to process the target service; The method also includes authenticating the customer's identity according to different real-name authentication methods, provided that the U-shield customer has the authority to process the target business.

2. The authentication method according to claim 1, characterized in that, Before receiving the client authentication request transmitted by the open platform, the process also includes: The partner platform receives the login request sent by the client and verifies the login information carried in the login request; Upon successful verification, the partner platform sends an authentication information entry request to the client. The client obtains authentication information based on the authentication information entry request and returns the authentication information to the partner platform. The authentication information includes at least: identity information and business identifier. The partner platform assembles the authentication information into the customer authentication request based on the interface elements of the platform interface; The partner platform encrypts and signs the customer authentication request, and sends the encrypted and signed customer authentication request to the open platform. The open platform decrypts and verifies the customer authentication request, and transmits the verified and decrypted customer authentication request to the financial institution platform.

3. The authentication method according to claim 1, characterized in that, After receiving the client authentication request transmitted by the open platform, the process also includes: Parse the customer authentication request to obtain business element parameters; If the validity of the business element parameters passes the verification, a U-shield detection request is sent to the client. If the client detects that the U-shield is connected to the client interface, it returns the U-shield detection response.

4. The authentication method according to claim 1, characterized in that, After obtaining the U-shield information associated with the U-shield detection response, the method further includes: Based on the U-shield information, a login environment is simulated, wherein the login environment is an environment in which the client displays customer information to the U-shield customer, and the client returns the customer information confirmation response and the contract agreement response upon receiving the customer information confirmation response; If the confirmation of customer information and the signing agreement are verified, the permissions of the U-shield customer are checked.

5. The authentication method according to claim 1, characterized in that, The steps for authenticating the identity of the U-shield customer based on the aforementioned identity information and the pre-set identity information include: If the identity information includes a customer name and a customer identifier, a customer code is obtained by querying a preset customer information database based on the customer name and the customer identifier; or... If the identity information includes an account name and an account identifier, a customer code is obtained by querying a preset account information database based on the account name and the account identifier. If the customer code matches the U-shield customer code carried in the preset identity information, it is determined that the U-shield customer's identity authentication is successful, and the successful identity authentication result of the U-shield customer is recorded in the authentication result.

6. The authentication method according to claim 5, characterized in that, After confirming that the U-shield customer's identity authentication is successful, the process also includes: The authentication results are assembled into a notification message and sent to the partner platform. The partner platform forwards the notification message to the partner platform, processes the notification message, and sends it to a preset address to the financial institution platform. Parse the preset address to obtain the preset jump address; The preset redirect address is returned to the client.

7. An authentication device based on a USB key, characterized in that, Applied to financial institution platforms, these platforms communicate with partner platforms through open platform interfaces, including: The receiving unit is configured to receive a customer authentication request transmitted by the open platform, wherein the customer authentication request includes at least: identity information and business identifier; The acquisition unit is used to acquire U-shield information associated with the U-shield detection response when a U-shield detection response is received. The U-shield information includes at least: U-shield type and preset identity information. The U-shield is a U-shield held by a U-shield customer, and the preset identity information is identity information pre-stored in the U-shield. The detection unit is used to detect, based on the type of the U-shield, whether the U-shield customer has the authority to process the target service indicated by the service identifier; The authentication unit is used to authenticate the identity of the U-shield customer based on the identity information and the preset identity information, when the U-shield customer has the authority to process the target business, and return the authentication result to the partner platform; The detection unit is further configured to determine the set of U-shields that initiated the U-shield detection response, wherein the set of U-shields includes at least one U-shield; determine the U-shield permissions corresponding to the U-shield type of each U-shield, and determine a set of U-shield permissions based on all the U-shield permissions; if the business permissions required by the target business belong to the set of U-shield permissions, determine that the U-shield customer has the permission to process the target business; the authentication device is further configured to authenticate the customer's identity according to different real-name authentication methods if the U-shield customer has the permission to process the target business.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the authentication method based on any one of claims 1 to 6.

9. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the U-shield-based authentication method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Convenient login method and device

    CN110647728A

  • Information processing behavior supervision method

    CN113505358A