A method, apparatus, device, and medium for triggering a login process.
By establishing a trust relationship between the terminal device and the application to generate a second login credential, the operational costs and time consumption issues when users switch login accounts between different devices are solved, and convenient login without entering a password or verification code is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-17
- Publication Date
- 2026-04-03
AI Technical Summary
In existing technologies, users need to frequently enter passwords or verification codes when switching login accounts between different terminal devices, resulting in high operating costs and time consumption.
After establishing a trust relationship between the first device and the target application, a second login credential is generated. The login request then checks the consistency between the first and second login credentials. If they are consistent, the process of the user account logging into the target application on the first device is triggered, without requiring the user to enter a password or verification code.
It simplifies user operations, reduces login time, and improves login convenience.
Smart Images

Figure CN116405270B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, device and medium for triggering a login process. Background Technology
[0002] With the development of computer technology and the needs of people's lives, users may have multiple terminal devices and may need to switch between logging in to the same account on different terminal devices. For users who need to frequently switch login accounts on their frequently used devices, they will need to perform login verification each time, such as by entering a password or verifying via SMS, which is both costly and time-consuming.
[0003] Therefore, there is a need to provide a more convenient way to log in to an account. Summary of the Invention
[0004] This specification provides a method, apparatus, device, and medium for triggering a login process, in order to solve the problems of high operating costs and time consumption in existing login methods.
[0005] To solve the above-mentioned technical problems, the embodiments in this specification are implemented as follows:
[0006] This specification provides an embodiment of a login process triggering method, including:
[0007] Obtain a login request sent by a first device for logging into a target application; the login request includes a first login credential and a first device identifier of the first device;
[0008] Determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account;
[0009] Determine whether the first login credential and the second login credential are consistent to obtain the first determination result;
[0010] If the first determination result indicates that the first login credential is consistent with the second login credential, then the process of logging into the target application on the first device with the user account is triggered.
[0011] This specification provides an embodiment of a login process triggering method, including:
[0012] The first device acquires the user's first action of opening the target application;
[0013] Based on the first operation, a login page is displayed; the login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account;
[0014] Obtain the user's second operation on the login control;
[0015] Based on the second operation, a login request is generated for requesting to log in to the target application using the user account; the login request includes the first login credential and the first device identifier of the first device;
[0016] The login request is sent to the server so that, after the first login credential is verified, the server triggers a process to log in to the target application on the first device with the user account.
[0017] This specification provides an embodiment of a method for setting up a trusted device, comprising:
[0018] The second device obtains a trusted device settings page sent by the server, which contains device information of historically logged-in devices; the historically logged-in devices are devices that have logged into the target application using a user account;
[0019] The trusted device settings page is displayed; the trusted device settings page includes a first confirmation control.
[0020] Obtain the user's first confirmation operation on the first confirmation control;
[0021] Based on the first confirmation operation, a trusted device setting request is generated; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device.
[0022] The trusted device setting request is sent to the server so that the server generates login credentials corresponding to the trusted device; the login credentials are used to log in to the target application using the user account.
[0023] This specification provides an embodiment of a login process triggering device, comprising:
[0024] The information acquisition module is used to acquire a login request sent by the first device for logging into the target application; the login request includes a first login credential and a first device identifier of the first device;
[0025] The credential determination module is used to determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account;
[0026] The judgment module is used to determine whether the first login credential and the second login credential are consistent, and to obtain a first judgment result;
[0027] The login process triggering module is used to trigger a process of logging into the target application on the first device with the user account if the first judgment result indicates that the first login credential is consistent with the second login credential.
[0028] This specification provides an embodiment of a login process triggering device, comprising:
[0029] The first operation acquisition module is used to acquire the user's first operation when launching the target application.
[0030] A page display module is used to display a login page based on the first operation; the login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account;
[0031] The second operation acquisition module is used to acquire the user's second operation on the login operation control;
[0032] The request generation module is configured to generate a login request for requesting to log in to the target application using the user account, based on the second operation; the login request includes the first login credential and the first device identifier of the first device;
[0033] The request sending module is used to send the login request to the server so that after the first login credential is verified, the server triggers the process of logging into the target application on the first device with the user account.
[0034] This specification provides an embodiment of an apparatus for setting up trusted devices, comprising:
[0035] The settings page acquisition module is used to acquire the trusted device settings page sent by the server, which contains device information of historical login devices; the historical login devices are devices that have logged into the target application using a user account;
[0036] The settings page display module is used to display the trusted device settings page; the trusted device settings page includes a first confirmation control;
[0037] The confirmation operation acquisition module is used to acquire the user's first confirmation operation on the first confirmation control;
[0038] The configuration request generation module is used to generate a trusted device configuration request based on the first confirmation operation; the trusted device configuration request includes the device identifier of the historical login device that has been determined by the user to be a trusted device;
[0039] The configuration request sending module is used to send the trusted device configuration request to the server so that the server can generate a second identification corresponding to the login credential; the login credential is a credential used to log in to the target application using the user account.
[0040] This specification provides an embodiment of a login process triggering device, comprising:
[0041] At least one processor; and,
[0042] A memory communicatively connected to the at least one processor; wherein,
[0043] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:
[0044] Obtain a login request sent by a first device for logging into a target application; the login request includes a first login credential and a first device identifier of the first device;
[0045] Determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account;
[0046] Determine whether the first login credential and the second login credential are consistent to obtain the first determination result;
[0047] If the first determination result indicates that the first login credential is consistent with the second login credential, then the process of logging into the target application on the first device with the user account is triggered.
[0048] This specification provides an embodiment of a login process triggering device, comprising:
[0049] At least one processor; and,
[0050] A memory communicatively connected to the at least one processor; wherein,
[0051] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:
[0052] Obtain the user's first action when opening the target application;
[0053] Based on the first operation, a login page is displayed; the login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account;
[0054] Obtain the user's second operation on the login control;
[0055] Based on the second operation, a login request is generated for requesting to log in to the target application using the user account; the login request includes the first login credential and the first device identifier of the first device;
[0056] The login request is sent to the server so that, after the first login credential is verified, the server triggers a process to log in to the target application on the first device with the user account.
[0057] This specification provides an embodiment of a device for setting up trusted devices, comprising:
[0058] At least one processor; and,
[0059] A memory communicatively connected to the at least one processor; wherein,
[0060] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:
[0061] Obtain a trusted device settings page sent by the server, which contains device information of historically logged-in devices; the historically logged-in devices are devices that have logged into the target application using a user account;
[0062] The trusted device settings page is displayed; the trusted device settings page includes a first confirmation control.
[0063] Obtain the user's first confirmation operation on the first confirmation control;
[0064] Based on the first confirmation operation, a trusted device setting request is generated; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device.
[0065] The trusted device setting request is sent to the server so that the server generates login credentials corresponding to the trusted device; the login credentials are used to log in to the target application using the user account.
[0066] This specification provides an embodiment of a computer-readable medium storing computer-readable instructions that can be executed by a processor to implement a method for triggering the login process described above or a method for setting up a trusted device.
[0067] One embodiment of this specification achieves the following beneficial effects:
[0068] In the embodiments of this specification, the login request sent by the first device for logging into the target application includes a first login credential. If it is determined that the first login credential is consistent with the second login credential used for logging into the user account on the first device, the process of logging into the target application on the first device with the user account can be triggered. Thus, when the user logs into the target application on the first device, there is no need for the user to enter account verification information such as password and verification code, which can reduce user operations and login time, and improve the convenience of login. Attached Figure Description
[0069] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0070] Figure 1 This is a schematic diagram of the overall scheme of a login process triggering method in an embodiment of this specification;
[0071] Figure 2 A flowchart illustrating a method for triggering a login process provided in an embodiment of this specification;
[0072] Figure 3 A schematic diagram of a trusted device settings page provided in an embodiment of this specification;
[0073] Figure 4 This is a flowchart illustrating a method for triggering a login process provided in an embodiment of this specification.
[0074] Figure 5 This is a schematic diagram of a login page provided in an embodiment of this specification;
[0075] Figure 6 This is a flowchart illustrating a method for setting up a trusted device as provided in the embodiments of this specification;
[0076] Figure 7 Swimlane diagram of a login process triggering method provided in the embodiments of this specification;
[0077] Figure 8 The embodiments provided in this specification correspond to Figure 2 A schematic diagram of the structure of a login process triggering device;
[0078] Figure 9 The embodiments provided in this specification correspond to Figure 4 A schematic diagram of the structure of a login process triggering device;
[0079] Figure 10 The embodiments provided in this specification correspond to Figure 6 A schematic diagram of a device for setting up trusted devices;
[0080] Figure 11 The embodiments provided in this specification correspond to Figure 2 or Figure 4 A device that triggers a login process or corresponds to Figure 6 A schematic diagram of the structure of a device for setting up trusted devices. Detailed Implementation
[0081] To make the objectives, technical solutions, and advantages of one or more embodiments of this specification clearer, the technical solutions of one or more embodiments of this specification will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of one or more embodiments of this specification.
[0082] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.
[0083] In the existing technology, after a user logs out of the terminal application on a terminal device, if they need to log in again, they need to log in again by entering a password, verification code, or other verification methods. When logging in on different devices, they need to enter a password, verification code, or other operations each time.
[0084] To address the shortcomings of existing technologies, this solution provides the following embodiments:
[0085] Figure 1 This is a schematic diagram illustrating the overall scheme of a login process triggering method in one embodiment of this specification. For example... Figure 1As shown, the scheme may include a first device 1 and a server 2, wherein the first device may be a device used to log in to the target application. After the user opens the target application on the first device 1, the terminal page may display a login page for logging into the target application with a user account. This page may also contain a login control. When the user clicks or triggers the first device to log in to the target application through other means, the first device 1 may send a first login credential to the server 2 in the login request. The first login credential may be a credential for logging into the target application stored on the first device. The server 2 may obtain the first login credential contained in the login request, verify the credential, and allow the first device to log in to the target application with the user account after successful verification. The server may determine the second login credential generated after the first device establishes a trust relationship with the user account of the target application, and determine whether the first login credential and the second login credential are consistent. If they are consistent, it can be determined that the login request sent by the first device can be verified and the first device can be allowed to log in to the target application with the user account. In the embodiments of this specification, login credentials can replace the password, verification code, and other verification information entered by the user in the prior art. The login method using login credentials eliminates the need for the user to enter verification information, simplifies user operations, and improves login efficiency.
[0086] Next, a method for triggering a login process provided in the embodiments of the specification will be described in detail with reference to the accompanying drawings:
[0087] Figure 2 This is a flowchart illustrating a login process triggering method provided in an embodiment of this specification. From a programming perspective, the execution entity of the process can be a program hosted on an application server or an application client.
[0088] like Figure 2 As shown, the process may include the following steps:
[0089] Step 202: Obtain the login request sent by the first device for logging into the target application; the login request includes the first login credential and the first device identifier of the first device.
[0090] Step 204: Determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account.
[0091] The first login credential can be a login credential stored locally on the first device for logging into the target application; the second login credential can be a login credential corresponding to the first device stored on a server or in the cloud. The second login credential can be a credential generated for the first device after a trust relationship is established between the first device and the user account of the target application, or in other words, after the first device is set as a trusted device for the user account. The second login credential corresponds to the first device; different devices correspond to different login credentials. The second login credential can only be used to log into the target application on the first device using the user account. In the embodiments of this specification, after generating a login credential for the first device, the credential can be stored on a server or in the cloud, or it can be sent to the first device. In practical applications, if the first device is not attacked or encounters other security issues, the first login credential stored on the first device should be consistent with the second login credential determined by the server.
[0092] Considering that in practical applications, the login credentials stored in the first device may change due to some insecurity factors, the first login credential is used here to represent the login credentials stored in the first device that may change, and the second login credential is used to represent the login credentials corresponding to the first device that have not changed and are stored on the server or in the cloud. The first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual order between these entities or operations.
[0093] From a computer perspective, a login credential can be a string containing specific characters. After receiving a login request from the first device, the server can extract the first login credential contained in the login request based on the specific characters.
[0094] The first device identifier of the first device can be a unique identifier for the first device. For example, this identifier can be used by the server to distinguish different devices.
[0095] Step 206: Determine whether the first login credential and the second login credential are consistent, and obtain the first determination result.
[0096] Step 208: If the first judgment result indicates that the first login credential is consistent with the second login credential, then the process of logging into the target application on the first device with the user account is triggered.
[0097] If the first login credential matches the second login credential, it indicates that the login request sent by the first device has been successfully verified, allowing the first device to log in to the target application using a user account. The server can access the process of the user account logging into the target application on the first device. Specifically, it can send a login success message to the first device, or it can send a page from the target application after logging in with a user account, such as the homepage or the page the user last viewed. The first device can then display the corresponding page content. In practical applications, if the first login credential and the second login credential do not match, it indicates that the login method of the first device using the login credential cannot be verified. The server can send a login failure message to the first device, or it can send a verification login page requiring the user to enter a password, verification code, or other verification information to the first device, so that the first device can log in to the target application based on the verification information provided by the user.
[0098] The target application can be understood as the terminal application that the first device can log in to. The user account can be the login account determined when the user registers as a user of the target application. It can be an email address, mobile phone number, user ID number, etc., or it can be custom characters that meet the login requirements of the target application. There are no specific restrictions on the specific form here.
[0099] It should be understood that the order of some steps in the methods described in one or more embodiments of this specification may be interchanged according to actual needs, or some steps may be omitted or deleted.
[0100] Figure 2 In the method described above, the login request sent by the first device for logging into the target application contains a first login credential. If it is determined that the first login credential is consistent with the second login credential used for logging into the user account on the first device, the process of logging into the target application on the first device with the user account can be triggered. Thus, when the user logs into the target application on the first device, there is no need for the user to enter account verification information such as password and verification code, which can reduce user operations and login time, and improve the convenience of login.
[0101] based on Figure 2 In addition to the methods described herein, this specification also provides some specific implementation schemes, which are described below.
[0102] To further ensure user account security, optionally, before triggering the process of logging into the target application on the first device with the user account in the embodiments of this specification, the following may also be included:
[0103] Determine whether the first login credential is within its validity period to obtain a second determination result.
[0104] Specifically, the process of triggering the login of the target application on the first device with the user account can include: if the second determination result indicates that the first login credential is within the validity period of the first login credential, then the process of logging into the target application on the first device with the user account is triggered.
[0105] In practical applications, the first login credential sent by the first device may include the generation time of the first login credential. The aforementioned determination of whether the first login credential is within its validity period may include: determining whether the time difference between the generation time of the first login credential and the time when the login request is obtained is less than or equal to a preset threshold. Specifically, if the time difference between the generation time of the first login credential and the time when the login request is obtained is less than or equal to the preset threshold, it indicates that the first login credential is within its validity period.
[0106] In practical applications, the determination of login credential validity can also be performed by the first device. In practice, the login request sent by the first device can be generated based on the login operation performed by the user on the first device. After obtaining the user's login operation, the first device can determine whether the time difference between the generation time of the first login credential and the time of obtaining the user's operation is less than or equal to a preset threshold. If the time difference is less than or equal to the preset threshold, the first login credential is considered valid, and a login request can be sent to the server. If the first login credential is not valid, the first device can display a page for the user to input verification information, so as to send a verification login request to the server based on the verification information provided by the user. After successful verification, the first device can log in to the target application using the user's account.
[0107] In this embodiment of the specification, the validity period of the second login credential can also be used to determine whether the login request sent by the first device has been verified. As one implementation, after determining the second login credential, it can also be determined whether the time difference between the generation time of the second login credential and the time of obtaining the login request is equal to or less than a preset threshold. If the time difference is less than or equal to the preset threshold, it can be determined that the second login credential is within its validity period. If the second login credential is within its validity period, it can be used to verify the login request sent by the first device. The preset threshold can be set according to actual needs, for example, 10 days, 20 days, 30 days, etc. No specific limit is specified here.
[0108] In practical applications, login credentials may also include time information indicating the validity period of the login credentials, such as the start and end times of the validity period. In the embodiments of this specification, the validity of the login credentials can also be determined based on the time information of the validity period. For example, the first device can determine whether the time when the user login is obtained is within the validity period between the start and end times of the first login credentials' validity period, and the server can also determine whether the time when the login request is obtained is within the validity period between the start and end times of the second login credentials' validity period. In practical applications, specific determination methods can be set according to actual needs; no specific limitations are made here.
[0109] In the embodiments of this specification, the login credentials generated by the server for the device may also include the device identifier. Optionally, before determining the second login credentials corresponding to the first device identifier, the following may also be included:
[0110] Parse the first login credential to obtain the second device identifier contained in the first login credential;
[0111] Determine whether the second device identifier is consistent with the first device identifier to obtain a third determination result.
[0112] Specifically, determining the second login credential corresponding to the first device identifier may include: if the third determination result indicates that the second device identifier is consistent with the first device identifier, then searching for the second login credential corresponding to the first device identifier.
[0113] In practical applications, if the third judgment result indicates that the second device identifier is inconsistent with the first device identifier, it means that the login credentials sent by the first device are not for that device and are invalid. The server can terminate the request sent to the first device to log in to the target application through the login credentials, send a message indicating that the login failed to trust the first device, or send a login verification page to the first device.
[0114] In practical applications, users typically do not frequently log in to the same account on different devices. To ensure security, a limit can be set on the number of trusted login attempts. For example, a user account can be allowed to log in to the target application via trusted login up to 10 times per day, or up to 20 times per week. If this limit is exceeded, the user will need to log in by entering a password, verification code, or other verification information. The method in the embodiments of this specification may also include:
[0115] Based on the user account, determine whether the number of times the target application logs into the user account using login credentials within a preset time period before receiving the login request sent by the first device is greater than or equal to a preset number.
[0116] If the number of login attempts is less than the preset number, the verification process for the first login credential can be executed, as described in steps 204 to 208 above. If the number of times the target application logs into the user account using login credentials within a preset time period is greater than or equal to the preset number, the processing of the login request can be terminated, the current trusted login can be determined to have failed, and a reminder message or a login verification page can be sent to the first device. The specific value of the preset number of attempts can be set according to actual needs. The preset number of attempts can represent the total number of times different devices are allowed to log into the user account using login credentials; it can also represent the number of times the same device is allowed to log into the user account using login credentials, taking a single device as the dimension.
[0117] In practical applications, the process for determining whether a preset number of attempts has been exceeded can also be executed on the first device. The first device can count the number of times it has logged into the target application using login credentials within a preset time period. It can determine whether the number of times the first device has logged into the target application using login credentials within the preset time period is greater than or equal to the preset number. If it is greater than or equal to the preset number, the first device can no longer be allowed to log into the user account through trusted login, and a login verification page can be displayed. If the number of times the first device has logged into the target application using login credentials within the preset time period is less than the preset number, a trusted login page can be displayed.
[0118] In the embodiments of this specification, the user can set trusted devices in the device according to actual needs. Devices designated as trusted devices can quickly log in to the target application using login credentials. Optionally, before obtaining the login request sent by the first device for logging into the target application as described above in the embodiments of this specification, the following may also be included:
[0119] Obtain device information of historical login devices that have logged into the target application using the user account; the historical login devices include the first device;
[0120] Generate a trusted device settings page containing device information of the historically logged-in devices; the device information includes at least one of device model and device custom name;
[0121] The trusted device settings page is sent to the second device; the second device is a device that was logged into the target application using the user account before the first device sent the login request;
[0122] Obtain the trust device setting request sent by the second device based on the trust device setting page; the trust device setting request includes the device identifier of the first device;
[0123] Based on the device identifier of the first device, the first device is identified as a trusted device; the trusted device is used to represent a device that has the permission to log in to the user account in the target application using login credentials.
[0124] The historical login devices can include devices that have logged into the target application using a user account within a preset time period, such as devices that have logged into the target application using a user account within the last month, three months, or one year. Devices that are still logged in after logging into the target application using a user account can also be considered historical login devices.
[0125] Figure 3 This is a schematic diagram of a trusted device settings page provided in an embodiment of this specification. Figure 3 As shown, assuming the second device is a device that was logged into the target application using the user account before the first device sent the login request, this page can be a settings page displayed on the second device. The page may contain device information for each historically logged-in device, such as the device model, code, etc., or a user-defined name, etc. Figure 3 The "Device A of [Name]", "Device B of [Name]", and "Device C of [Name]" shown can be user-defined device names. In practical applications, the device name settings can be included in the terminal application's settings function, and the server can obtain the user-defined device names.
[0126] like Figure 3 As shown, this page may include a first confirmation control 301 for verifying the trusted device, such as a "Confirm Enable" control. When the user clicks this control, the second device can send a trusted device setting request to the server. This trusted device setting request may include the device identifier of the first device that the user has confirmed as a trusted device. Figure 3As shown, the page may also include a selection control 302 for selecting devices. When this control is selected, it indicates that the user has confirmed setting the selected device as a trusted device. The second device can generate a trusted device setting request based on the state of the selection control. This request may include the device identifiers of each selected device. The user can select one or more devices as trusted devices. After the server receives the trusted device setting request sent by the second device, it can determine the corresponding device as a trusted device with the permission to log in to the user account in the target application using login credentials based on the device identifiers contained in the request. For example, a corresponding list of trusted devices can be generated for the user account and the target application.
[0127] In the embodiments of this specification, the trusted device determination page may further include device information of the second device, such as "Device A of [Name]" as shown in Figure 3. This page may include the status identifier of the device that is logged in, such as... Figure 3 The "Current" option can refer to "Device A of [username]" as the device currently logged into the target application using a user account. Other unmarked options can be devices that have logged into a user account before Device A.
[0128] The method in the embodiments of this specification may further include: determining the second device as the trusted device. Specifically, the device identifier of the second device may be saved to the trusted device list.
[0129] In practical applications, historical login devices can be sorted based on factors such as login frequency, duration of consecutive logins, and login time, prioritizing frequently used devices. For example, weights can be assigned to each factor: higher login frequency receives a higher weight, longer consecutive logins receive a higher weight, and login times closer to the current time receive a higher weight. These weights can be weighted and summed to determine a comprehensive score for each device, which is then displayed in descending order of score. In practical applications, if a user has many historical login devices, the top-ranked devices can be selected and displayed in the settings page.
[0130] In practical applications, the first device and the second device can be the same device or different devices.
[0131] In the embodiments of this specification, the server can generate login credentials for each trusted device. The login credentials are device-specific, with different devices corresponding to different login credentials. Optionally, after determining the first device as a trusted device, the embodiments of this specification may further include:
[0132] Based on the device identifier of the first device, generate the second login credential corresponding to the first device;
[0133] Send the second login credential to the first device;
[0134] Save the correspondence between the second login credential and the first device.
[0135] The server can store the second login credential and its corresponding mapping to the first device. In practice, the second login credential, the first device, and the user account have a corresponding relationship. For example, a list of trusted devices and their corresponding login credentials can be maintained. In practice, this information can be stored on the server, in the cloud, or in a blockchain system. The server can also send the generated second login credential to the first device so that the first device can log in based on the credential.
[0136] Similarly, in the embodiments of this specification, after determining the second device as the trusted device as described above, it may also include:
[0137] Based on the device identifier of the second device, the third login credential corresponding to the second device is generated;
[0138] Send the third login credential to the second device;
[0139] Save the correspondence between the third login credential and the second device.
[0140] Similar to the methods described above, the server can store the third login credential and the mapping between the third login credential and the second device. In practical applications, the third login credential, the second device, and the user account have a corresponding relationship, which can be stored in a trusted device list. Alternatively, it can be stored in storage spaces such as servers, the cloud, or blockchain systems. The server can also send the generated third login credential to the second device so that the second device can log in based on the credential.
[0141] In practical applications, after a user logs into their user account on a second device and is in a logged-in state on the second device, the user can set up a trusted device on the second device. This can be understood as the second device being in a logged-in state when setting up a trusted device. After the trusted device is set up, the server can send the generated login credentials for the second device to the second device.
[0142] To ensure user account security, in this embodiment of the specification, when a user sets a trusted device, the user's verification information can also be collected. Only after successful verification can the device selected by the user be designated as a trusted device. Optionally, before designating the first device as a trusted device in this embodiment of the specification, the following steps may also be included:
[0143] Obtain the first verification information sent by the second device;
[0144] A fourth determination result is obtained by determining whether the first information to be verified is consistent with the first preset verification information; the first preset verification information includes at least one of registration verification information and identity authentication information; the registration verification information is the verification information provided by the user when registering the target application with the user account; the identity authentication information is the identity information provided by the user during the user authentication process based on the user account;
[0145] The step of identifying the first device as a trusted device may specifically include:
[0146] If the fourth judgment result indicates that the first information to be verified is consistent with the first preset verification information, then the first device is determined to be a trusted device.
[0147] In the embodiments of this specification, during the setup of the trusted device, the second device may also display a page for obtaining the first verification information provided by the user. For example, the second device may display a page prompting the user to enter their account password and verification code, or it may display a user identity information collection page, such as a page for collecting the user's face, fingerprint, iris, etc. The first verification information may include information representing the user's identity, such as face, fingerprint, iris, etc., and may also include information that can verify the account, such as account password, verification code, etc. The specific verification information is not specifically limited here and can be set according to actual needs.
[0148] In practical applications, after receiving the trusted device setting request from the second device, the server can send a verification information retrieval request to the second device, so that the second device can display an information collection page to obtain the verification information provided by the user. Alternatively, the second device can proactively display a page for obtaining verification information. For example, after receiving confirmation from the user regarding the trusted device, it can display a page for obtaining the first verification information provided by the user. The second device can generate a trusted device setting request based on the obtained first verification information and the device identifier of the trusted device selected by the user, and send it to the server. In practical applications, the first verification information and the trusted device setting request can also be sent to the server separately; the specific sending method is not limited here.
[0149] After the server obtains the first verification information provided by the user, it can compare the first verification information with the first preset verification information of the user account that has been stored in advance to determine their consistency. If the first verification information matches the first preset verification information, it indicates that the setting of the trusted device has been agreed upon by the user, and the server can determine the device targeted by the setting request as a trusted device.
[0150] In the embodiments of this specification, the first preset verification information may include registration verification information provided by the user when registering the target application with the user account, such as a login password; it may also include identity information provided by the user during user authentication based on the user account, such as biometric information that can identify the user's identity, such as facial, iris, and fingerprint features, determined during real-name authentication, or information from the user's identification document. The specific information to be verified and the corresponding preset verification information can be set according to actual needs, and are not specifically limited here.
[0151] In practical applications, the settings page can also include terms for users to understand the trusted devices and trusted login services. After understanding the terms, users can check the corresponding terms, which indicates that the user has authorized the server to obtain the user information required to perform the trusted login process.
[0152] For image-based information, determining whether two pieces of information are consistent can be understood as whether the similarity between the two pieces of information is greater than or equal to a preset threshold. If the similarity is greater than or equal to the preset threshold, the two pieces of information can be considered similar.
[0153] To ensure the security of user account information, in this embodiment of the specification, after the first device is identified as a trusted device, the first device needs to log in to the target application through verification. It can then obtain a second login credential sent by the server, so that the first device can use the login credential to log in during subsequent login processes. Optionally, before sending the second login credential to the first device, this embodiment of the specification may further include:
[0154] Obtain the verification login request sent by the first device, wherein the verification login request includes the account information of the user account and the second verification information provided by the user in the first device;
[0155] The system determines whether the second information to be verified is consistent with the second preset verification information to obtain a fifth determination result; the second preset verification information includes at least one of registration verification information and identity authentication information; the registration verification information is the verification information provided by the user when registering the target application with the user account; the identity authentication information is the identity information provided by the user during the user authentication process based on the user account;
[0156] If the fifth judgment result indicates that the second information to be verified is consistent with the second preset verification information, then the first device is allowed to log in to the target application using the user account;
[0157] Sending the second login credential to the first device specifically includes:
[0158] When the first device is in a logged-in state using the target account to log in to the target application, the second login credential is sent to the first device.
[0159] Account information may include account name, email address, mobile phone number, and other information representing the account. Similar to the first type of information to be verified mentioned above, the second type of information to be verified may be account information such as account password and verification code, or user biometric information such as facial features and fingerprints. The specific verification process is similar to that described above and will not be repeated here.
[0160] The number of times the same login credential can be used in the embodiments of this specification may be limited. After the number of times it is used reaches a preset number, the login credential may be determined to be invalid. When the login credential is used again in the future, it will not be verified and will not be able to perform the trusted login process that does not require the input of password, verification code and other information.
[0161] As one implementation method, the login credential in the embodiments of this specification can be a credential that can be used only once. After the server triggers the process of logging into the target application on the first device with the user account, the correspondence between the second login credential and the first device can be deleted, and the second login credential can be determined as an invalid credential.
[0162] After the second login credential expires, the server can generate a new credential so that the device can subsequently log in to the user account using the new credential through trusted login. Optionally, the method in the embodiments of this specification may further include:
[0163] A fourth login credential is generated based on the device identifier of the first device;
[0164] Save the correspondence between the fourth login credential and the first device;
[0165] Send the fourth login credential to the first device.
[0166] In practical applications, after the first device logs into the user account using the first login credential, the server can delete the second login credential used for this login or mark it as invalid. It can also generate a fourth login credential for the first device and send the fourth login credential to the first device when the first device is logged in.
[0167] The first login credential, second login credential, third login credential, and fourth login credential in the embodiments of this specification are different names used to clearly illustrate the method provided in the embodiments of this specification. The composition, generation, and usage of each login credential can be similar, and the above description can be referred to accordingly. The embodiments of this specification, by cyclically issuing copy-resistant one-time login credentials on trusted devices, can greatly improve the login experience for users on multiple devices.
[0168] In the embodiments of this specification, the same user account can be used simultaneously on one device. After logging in on the first device, the user account will be logged out on other devices. Optionally, after triggering the above-mentioned process of logging into the target application on the first device with the user account in the embodiments of this specification, it may further include: deregistering the user account from its login status on other devices.
[0169] To enable users to conveniently use the trusted login function, this embodiment of the specification may also send a reminder message to the user's device to prompt them to set up trusted devices. Optionally, the method in this embodiment of the specification may further include:
[0170] Determine whether the user account has logged into multiple devices within a preset time period to obtain the fifth determination result;
[0171] If the fifth determination result indicates that the user account has logged into multiple devices within a preset time period, a reminder message prompting the user to set a trusted device is sent to at least one of the multiple devices; the trusted device refers to a device that has the permission to log into the user account in the target application using login credentials. The reminder message may include a control pointing to the settings page for setting a trusted device in the target application.
[0172] In practical applications, the reminder message can be sent to the logged-in device where the user's account is logged in. The logged-in device can display the reminder message, and the user can perform preset operations on the reminder message, or be redirected to a settings page for setting trusted devices, as described above. Figure 3 The prompt message shown is the Trusted Device Settings page. This prompt may also include a path description to access the Trusted Device Settings page, allowing users to navigate to it step-by-step.
[0173] In practical applications, the prompt message can be sent to the user's device through information overlay, system message, etc. The server can also count the number of times the user closes, does not read, or ignores the prompt message. If the number exceeds the preset number, it can be determined that the user does not want to use trusted login. In order to reduce the disturbance to the user, the prompt message can be stopped from being sent to the user's account within a preset time period, such as one month or three months.
[0174] Based on the same idea, this specification also provides a method for triggering a login process with the first device as the execution subject, corresponding to the above method. Figure 4 This is a flowchart illustrating a login process triggering method provided in an embodiment of this specification. Figure 4 As shown, the method may include:
[0175] Step 402: The first device acquires the user's first operation of opening the target application.
[0176] In the embodiments of this specification, the target application can be a terminal application, mini-program, or other application installed on the first device. The display page of the first device may include an identifier for the target application, such as an icon or name, which the user can click to open the target application. The target application can be an application that the user has pre-registered by entering a username or user account, password, or other information. In practical applications, the username and user account can be the same or different. The target application can be a payment application, a chat application, an entertainment application, a lifestyle service application, or other types of applications; no specific limitations are made here.
[0177] Step 404: Based on the first operation, display the login page; the login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account.
[0178] Figure 5 This is a schematic diagram of a login page provided in an embodiment of this specification. Figure 5 As shown, the login page may include user account information 501 and login operation control 502 for logging into the user account. In actual applications, the page content, layout, control descriptions, and other page information can be set according to actual needs, and no specific limitations are made here.
[0179] Step 406: Obtain the user's second operation on the login operation control.
[0180] Step 408: Based on the second operation, generate a login request for requesting to log in to the target application using the user account; the login request includes the first login credential and the first device identifier of the first device.
[0181] Continuing from the above Figure 5 As described, users can click the login operation control 502, and the first device can generate a login request based on the user's second operation and send it to the server. The login request may include the user's account information, as well as the first login credentials stored on the first device and the device identifier of the first device.
[0182] Step 410: Send the login request to the server so that after the first login credential is verified, the server triggers the process of logging into the target application on the first device with the user account.
[0183] The server can verify the login request sent by the first device. The specific verification method can be found in the login process triggering method described above with the server as the execution entity; it will not be repeated here. After successful verification, the first device can log in to the target application using its user account. In the embodiments of this specification, the user account can be logged in using login credentials stored in the device, eliminating the need for the user to enter a password, verification code, or other verification information, thus simplifying user operations and improving login efficiency.
[0184] Login credentials can have an expiration date, such as 10 days or 30 days. The first login credential stored in the first device can contain the validity period information of the credential, and before displaying the login page, it can also include:
[0185] Based on the first operation, obtain the first login credential stored in the first device;
[0186] Determine whether the first login credential is within its validity period;
[0187] The display of the login page may specifically include:
[0188] If the first login credential is within the validity period, the login page will be displayed.
[0189] If the first login credential is not within its validity period, a verification information login page will be displayed. Users can enter their account password, verification code, identity information, and other verification information on this page. After successful verification, the first device can also log in to the target application using the user account. The method of logging into the target application through the verification information login page can be the same as or similar to existing login methods.
[0190] To ensure user account security in this embodiment, a maximum number of trusted login attempts using login credentials can be set for each user account, such as 10 times per day. Before displaying the login page, the first device can also determine whether the cumulative number of times the user account has logged in using trusted login within a preset time period exceeds a preset number. If it does not exceed the preset number, the login page can be displayed; otherwise, a login page requiring verification can be displayed.
[0191] In practical applications, users typically do not frequently log in to the same user account on the same device or different devices within a short period of time. In this embodiment, the frequency of user account logins on the same or different devices can also be used to determine whether a user-defined trusted device or user account poses a security risk. For example, if a user account is logged in more than or equal to a preset number of times using trusted login within a preset time period, the user account or the user-defined trusted device can be considered to be at risk. A security alert can be sent to the user, the user account's trusted login can be revoked, or the trusted login permission for the risky trusted device can be revoked.
[0192] In the embodiments of this specification, the login credential can be a credential generated by the server for the device after determining that the device is a trusted device, which can be used to log in to the target application using a user account. Before generating the login request for requesting to log in to the target application using the user account, the embodiments of this specification may further include:
[0193] Obtain the second login credential sent by the server; the second login credential is a login credential generated by the server after the first device is determined to be a trusted device, corresponding to the first device, for logging into the target application using the user account; the trusted device is used to represent a device with the permission to log into the user account in the target application using the login credential.
[0194] In practical applications, if the first device accurately receives the second login credential sent by the server, and the credential is securely stored during this period (i.e., after the first device obtains the second login credential, the credential remains unchanged), the first login credential included in the login request generated by the first device can be the same as the second login credential sent by the server. However, if the first device experiences a security issue or the login credential stored in the first device is maliciously manipulated, the first login credential stored in the first device may change, becoming inconsistent with the second login credential sent by the server.
[0195] Based on the same idea, this specification also provides a method for setting a trusted device with a second device as the execution subject, corresponding to the above method. Figure 6 This is a flowchart illustrating a method for setting up a trusted device as provided in an embodiment of this specification. Figure 6 As shown, the method may include:
[0196] Step 602: The second device obtains a trusted device settings page sent by the server, which contains device information of historically logged-in devices; the historically logged-in devices are devices that have logged into the target application using a user account.
[0197] The second device can be a device that is logged into the target application using a user account. After the second device logs into the target application using a user account, it can enter the trusted device settings page, which can contain device information of historically logged-in devices, such as device name, model and other information.
[0198] In practical applications, users can access the trusted device settings page via a preset path. For example, the target application may contain settings for configuring the target application, and setting the trusted device can be one of the application's settings. The specific path can be set according to the actual needs of the application.
[0199] Step 604: Display the Trusted Device Settings page; the Trusted Device Settings page contains a first confirmation control.
[0200] Step 606: Obtain the user's first confirmation operation on the first confirmation control.
[0201] Step 608: Based on the first confirmation operation, generate a trusted device setting request; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device;
[0202] Step 610: Send a trusted device setting request to the server so that the server generates login credentials for the target application using the user account for the device that the user has determined to be a trusted device.
[0203] As described above Figure 3 This diagram illustrates a trusted device settings page provided in an embodiment of this specification. The page may include a first confirmation control 301. When a user clicks this control, a second device receives the user's confirmation of the first confirmation and generates a trusted device settings request, which is then sent to the server. On this page, the user can select one or more devices to be designated as trusted devices. The trusted device settings request may include the device identifiers of each selected device, enabling the server to determine the trusted device and generate login credentials for that device.
[0204] To ensure user account security, this embodiment of the specification may also collect user verification information during the process of setting up a trusted device. After successful verification, the device selected by the user can be designated as a trusted device. After sending the trusted device setting request to the server, the process may further include:
[0205] Display the information retrieval page;
[0206] Based on the information acquisition page, obtain the first information to be verified provided by the user;
[0207] The first verification information is sent to the server so that the server can determine the device that the user has set as a trusted device as a trusted device after the first verification information has been verified.
[0208] The information acquisition page can be a page for users to input verification information or a page for collecting users' biometric information. It can be set according to actual needs, and no specific limitation is made here.
[0209] The second device used for setting up a trusted device in the embodiments of this specification can also be a trusted device, and the server can also generate login credentials for the second device. The device determined by the user to be set as a trusted device in the embodiments of this specification can include the second device, and the above method can further include:
[0210] Obtain the third login credential sent by the server; the third login credential is a login credential corresponding to the second device generated by the server based on the device identifier of the second device after the second device is identified as a trusted device.
[0211] In the embodiments of this specification, after setting the trusted device in the second device, the trusted device can also be deactivated. The path to deactivate the setting can be the same as the path to confirm the setting. After entering the trusted device settings page, select the device that has been set as a trusted device. This settings page can display controls for deactivating the setting, such as... Figure 3 The "Confirm Enable" control shown can be changed to "Confirm Cancel". After the user clicks this control, the second device can send a cancellation request to the server for the selected device to cancel the trust settings. The server can then remove the device from the trusted device list based on the request. After cancellation, the device will need to log in to the target application by entering verification information.
[0212] In the embodiments of this specification, the server can obtain a request sent by the second device to remove the trust relationship of the device. The request may contain the device identifier of the trusted device to be removed from the trust relationship. Based on the request, the server can delete the correspondence between the device and the user account, remove the device from the list of trusted devices, or delete the login credentials corresponding to the device.
[0213] In practical applications, information about associated trusted devices can be displayed on any device within the trusted devices list corresponding to a user account. For example, if a user completes the settings for a trusted device on a second device, after logging into their user account on the first device, the trusted device information can also be displayed on the settings page of the target application on the first device. Subsequently, the user can edit the settings for trusted devices, such as adding, deleting, or removing them, both on the first and second devices. During the editing process, the user can be verified before editing can be performed, or the edited information can be saved.
[0214] To more clearly illustrate the login process triggering method provided in the embodiments of this specification, Figure 7 This is a swimlane diagram of a login process triggering method provided in the embodiments of this specification. For example... Figure 7 As shown, the solution may include a device setup phase and a login phase, specifically including:
[0215] Step 702: After the second device logs into the target application with a user account, the user can enter the settings page for setting trusted devices by following the preset path. The trusted device settings page can be displayed on the second device.
[0216] Step 704: On this page, the user can select a trusted device and perform a confirmation operation. The second device can generate a trusted device setting request based on the user's operation on this page and send the request to the server.
[0217] Step 706: The server receives the trusted device setting request sent by the second device. Based on the device identifier contained in the request, the server determines the trusted devices and can generate corresponding login credentials for each trusted device. Assuming that the trusted devices include the first device and the second device, the server can generate a second login credential for the first device and send it to the first device, and can also generate a third login credential for the second device and send it to the second device.
[0218] Step 708: The second device can obtain the third login credential sent by the server so that after the second device logs out of the user account, it can log in to the user account based on the login credential.
[0219] Step 710: The first device can also obtain the second login credential sent by the server. Specifically, after the first device is designated as a trusted device, it needs to log in to the target application using a user account through verification before it can obtain the second login credential sent by the server.
[0220] Step 712: Assuming the first device obtains the second login credential and logs out of the user account, then logs into the target application again using the same user account, the first device can obtain the user's action of opening the target application and determine whether the local first login credential is valid. The first login credential can be understood as the login credential stored locally on the device after obtaining the second login credential sent by the server.
[0221] Step 714: If the first login credential is valid, the trusted login page can be displayed. This page may include a login control; based on the user's interaction with this control, a login request containing the first login credential can be generated and sent to the server.
[0222] Step 716: If the first login credential is invalid, the login verification process can be executed, and the login verification page will be displayed. On this page, the user can enter verification information such as password, verification code, and biometric information.
[0223] Step 718: After the server receives the login request sent by the first device, it can determine whether the first login credentials and the second login credentials contained in the request are consistent.
[0224] Step 720: If the first login credential is consistent with the second login credential, the process of logging into the target application on the first device with the user account can be triggered, and the state of the first device can be determined as the login state.
[0225] Step 722: The server can also determine that the second login credential is invalid. For example, it can delete the second login credential, or it can generate a new login credential for the first device and send it to the first device.
[0226] Step 724: The first device can display the application page corresponding to the target application after logging into the user account, such as the application's homepage, the page most recently viewed by the user using that account, etc. It can also receive new login credentials sent by the server and invalidate previously saved login credentials, for example, by deleting the first login credential.
[0227] Step 726: If the first login credential and the second login credential are inconsistent, the trusted login process can be terminated, a prompt message indicating that the trusted login has failed can be generated, and feedback can be sent to the first device.
[0228] Step 728: The first device can receive prompts from the server. The first device can also display a login verification page, allowing users to log in to their accounts by providing verification information.
[0229] Assume that the second device is logged into the same user account before the first device logs in. After the first device logs in, the second device will be logged out. A user account is allowed to be logged in and used on one device simultaneously. If the user wants to log in again using the second device, since the second device has already obtained the third login credential, it can log in using the login credential stored on the second device in a similar manner as described above. Furthermore, after initiating a login request using a stored login credential, the second device can also invalidate the used login credential and obtain a new login credential generated and sent by the server. The specific process will not be detailed here.
[0230] In the embodiments of this specification, when a user needs to switch between logging into the same user account on different devices, they can use login credentials for trusted login, eliminating the need for the user to enter account passwords, verification codes, and other verification information each time, thus improving convenience. On the other hand, since logging into the user account using login credentials eliminates the need for the user to provide verification information each time, devices without verification information acquisition capabilities can also log into the user account. For example, assuming that logging into a target application using a user account via verification requires collecting the user's facial or other biometric information, the currently used device needs to have biometric collection capabilities, such as a camera. If the device does not have a camera, login will not be possible on that device. However, the method in the embodiments of this specification, because it does not require the user to provide verification information, allows login to the user account on the device even if it does not have a camera.
[0231] Based on the same idea, embodiments of this specification also provide apparatus corresponding to the above methods. Figure 8 The embodiments provided in this specification correspond to Figure 2 A schematic diagram of the structure of a login process triggering device. (See diagram below.) Figure 8 As shown, the device may include:
[0232] The request acquisition module 802 is used to acquire a login request sent by the first device for logging into the target application; the login request includes a first login credential and a first device identifier of the first device;
[0233] The credential determination module 804 is used to determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account;
[0234] The judgment module 806 is used to determine whether the first login credential and the second login credential are consistent, and to obtain a first judgment result;
[0235] The login process triggering module 808 is used to trigger a process of logging into the target application on the first device with the user account if the first judgment result indicates that the first login credential is consistent with the second login credential.
[0236] Based on the same idea, embodiments of this specification also provide apparatus corresponding to the above methods. Figure 9 The embodiments provided in this specification correspond to Figure 4 A schematic diagram of the structure of a login process triggering device. (See diagram below.) Figure 9 As shown, the device may include:
[0237] The first operation acquisition module 902 is used to acquire the first operation of the user opening the target application;
[0238] The page display module 904 is used to display a login page based on the first operation; the login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account;
[0239] The second operation acquisition module 906 is used to acquire the user's second operation on the login operation control;
[0240] The request generation module 908 is configured to generate a login request for requesting to log in to the target application using the user account based on the second operation; the login request includes the first login credential and the first device identifier of the first device;
[0241] The request sending module 910 is used to send the login request to the server so that after the first login credential is verified, the server triggers the process of logging into the target application on the first device with the user account.
[0242] Based on the same idea, embodiments of this specification also provide apparatus corresponding to the above methods. Figure 10 The embodiments provided in this specification correspond to Figure 6 A schematic diagram of a device for setting up trusted devices. (For example...) Figure 10 As shown, the device may include:
[0243] The settings page acquisition module 1002 is used to acquire a trusted device settings page sent by the server, which contains device information of historical login devices; the historical login devices are devices that have logged into the target application using a user account.
[0244] The setting page display module 1004 is used to display the trusted device settings page; the trusted device settings page includes a first confirmation control.
[0245] The confirmation operation acquisition module 1006 is used to acquire the user's first confirmation operation on the first confirmation control;
[0246] The setting request generation module 1008 is used to generate a trusted device setting request based on the first confirmation operation; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device;
[0247] The setting request sending module 1010 is used to send the trusted device setting request to the server so that the server can generate login credentials corresponding to the trusted device; the login credentials are credentials used to log in to the target application using the user account.
[0248] Based on the same idea, this specification also provides devices corresponding to the above methods in its embodiments.
[0249] Figure 11 The embodiments provided in this specification correspond to Figure 2 or Figure 4 A device that triggers a login process or corresponds to Figure 6 A schematic diagram of the structure of a device for setting up trusted devices. For example... Figure 11 As shown, device 1100 may include:
[0250] At least one processor 1110; and,
[0251] Memory 1130 communicatively connected to the at least one processor;
[0252] Among them, corresponding to Figure 2 The method for triggering a login process is shown, wherein the memory 1130 stores instructions 1120 that can be executed by the at least one processor 1110, the instructions being executed by the at least one processor 1110 to enable the at least one processor 1110 to:
[0253] Obtain a login request sent by a first device for logging into a target application; the login request includes a first login credential and a first device identifier of the first device;
[0254] Determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account;
[0255] Determine whether the first login credential and the second login credential are consistent to obtain the first determination result;
[0256] If the first determination result indicates that the first login credential is consistent with the second login credential, then the process of logging into the target application on the first device with the user account is triggered.
[0257] Among them, corresponding to Figure 4 The method for triggering a login process is shown, wherein the memory 1130 stores instructions 1120 that can be executed by the at least one processor 1110, the instructions being executed by the at least one processor 1110 to enable the at least one processor 1110 to:
[0258] Obtain the user's first action when opening the target application;
[0259] Based on the first operation, a login page is displayed; the login page includes the user's account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user's account;
[0260] Obtain the user's second operation on the login control;
[0261] Based on the second operation, a login request is generated for requesting to log in to the target application using the user account; the login request includes the first login credential and the first device identifier of the first device;
[0262] The login request is sent to the server so that, after the first login credential is verified, the server triggers a process to log in to the target application on the first device with the user account.
[0263] Among them, corresponding to Figure 6 The method for setting up a trusted device is shown, wherein the memory 1130 stores instructions 1120 that can be executed by the at least one processor 1110, the instructions being executed by the at least one processor 1110 to enable the at least one processor 1110 to:
[0264] The second device obtains a trusted device settings page sent by the server, which contains device information of historically logged-in devices; the historically logged-in devices are devices that have logged into the target application using a user account;
[0265] The trusted device settings page is displayed; the trusted device settings page includes a first confirmation control.
[0266] Obtain the user's first confirmation operation on the first confirmation control;
[0267] Based on the first confirmation operation, a trusted device setting request is generated; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device.
[0268] The trusted device setting request is sent to the server so that the server generates login credentials corresponding to the trust information; the login credentials are credentials used to log in to the target application using the user account.
[0269] Based on the same approach, embodiments of this specification also provide a computer-readable medium corresponding to the above-described method. The computer-readable medium stores computer-readable instructions that can be executed by a processor to implement the above-described login process triggering method or the method for setting trusted devices.
[0270] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on its differences from other embodiments. In particular, for... Figure 11 As the device shown is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0271] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Moreover, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used when writing program development code. The original code before compilation must also be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using the aforementioned hardware description languages and programming it into an integrated circuit, the hardware circuit that implements the logic method flow can be easily obtained.
[0272] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, ASICs, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0273] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0274] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0275] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0276] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0277] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0278] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0279] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0280] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0281] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0282] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. This application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0283] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0284] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.
Claims
1. A method for triggering a login process, comprising: Obtain the trusted device setting request sent by the second device; The trusted device setting request includes the device identifier of the first device; The second device is a device that was logged into the target application using a user account before the first device sent the login request; Based on the device identifier of the first device, the first device is identified as a trusted device; The trusted device is used to represent a device that has the permission to log in to the user account in the target application using login credentials; Obtain the login request sent by the first device for logging into the target application; The login request includes a first login credential and a first device identifier of the first device; Determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account; Determine whether the first login credential and the second login credential are consistent to obtain the first determination result; If the first determination result indicates that the first login credential is consistent with the second login credential, then the process of logging into the target application on the first device with the user account is triggered.
2. The method according to claim 1, further comprising, before triggering the process of logging into the target application on the first device with the user account: Determine whether the first login credential is within its validity period to obtain a second determination result; The process of triggering the login of the target application on the first device with the user account specifically includes: If the second determination result indicates that the first login credential is within the validity period of the first login credential, then the process of logging into the target application on the first device with the user account is triggered.
3. The method according to claim 1, further comprising, before determining the second login credential corresponding to the first device identifier: Parse the first login credential to obtain the second device identifier contained in the first login credential; Determine whether the second device identifier is consistent with the first device identifier to obtain a third determination result; The step of determining the second login credential corresponding to the first device identifier specifically includes: If the third determination result indicates that the second device identifier is consistent with the first device identifier, then the second login credential corresponding to the first device identifier is searched.
4. The method according to claim 1, further comprising, before obtaining the login request sent by the first device for logging into the target application: Obtain device information of historical login devices that have used the user account to log in to the target application; The historical login device includes the first device; Generate a trusted device settings page containing device information of the historically logged-in devices; the device information includes at least one of device model and device custom name; Send the trusted device settings page to the second device; Obtain the trusted device setting request sent by the second device based on the trusted device setting page; Based on the device identifier of the first device, the first device is identified as a trusted device.
5. The method according to claim 4, further comprising, after determining the first device as a trusted device: Based on the device identifier of the first device, generate the second login credential corresponding to the first device; Send the second login credential to the first device; Save the correspondence between the second login credential and the first device.
6. The method according to claim 4, further comprising, before determining the first device as a trusted device: Obtain the first verification information sent by the second device; Determine whether the first information to be verified is consistent with the first preset verification information to obtain a fourth determination result; The first preset verification information includes at least one of registration verification information and identity authentication information; the registration verification information is the verification information provided by the user when registering the target application with the user account; the identity authentication information is the identity information provided by the user during the user authentication process based on the user account. The step of identifying the first device as a trusted device specifically includes: If the fourth judgment result indicates that the first information to be verified is consistent with the first preset verification information, then the first device is determined to be a trusted device.
7. The method according to claim 5, further comprising, before sending the second login credential to the first device: Obtain the verification login request sent by the first device, wherein the verification login request includes the account information of the user account and the second verification information provided by the user in the first device; Determine whether the second information to be verified is consistent with the second preset information to be verified, and obtain the fifth judgment result; The second preset verification information includes at least one of registration verification information and identity authentication information; the registration verification information is the verification information provided by the user when registering the target application with the user account; the identity authentication information is the identity information provided by the user during the user authentication process based on the user account. If the fifth judgment result indicates that the second information to be verified is consistent with the second preset verification information, then the first device is allowed to log in to the target application using the user account; Sending the second login credential to the first device specifically includes: When the first device is in a logged-in state using the user account to log in to the target application, the second login credential is sent to the first device.
8. The method according to claim 4, wherein the trusted device determination page further includes device information of the second device; the method further includes: The second device is identified as the trusted device.
9. The method of claim 8, wherein after determining the second device as the trusted device, it further comprises: Based on the device identifier of the second device, a third login credential corresponding to the second device is generated; Send the third login credential to the second device; Save the correspondence between the third login credential and the second device.
10. The method according to claim 1, further comprising: After the process of logging into the target application on the first device with the user account is triggered, the correspondence between the second login credential and the first device is deleted.
11. The method according to claim 10, further comprising: A fourth login credential is generated based on the device identifier of the first device; Save the correspondence between the fourth login credential and the first device; Send the fourth login credential to the first device.
12. The method according to claim 1, further comprising, after triggering the process of logging into the target application on the first device with the user account: Log out the user account from the login status on other devices.
13. The method according to claim 1, further comprising: Determine whether the user account has logged into multiple devices within a preset time period to obtain the fifth determination result; If the fifth determination result indicates that the user account has logged into multiple devices within a preset time period, a reminder message is sent to at least one of the multiple devices to prompt the user to set a trusted device; the trusted device is used to represent a device that has the permission to log into the user account in the target application using login credentials.
14. A method for triggering a login process, comprising: The first device acquires the user's first action of opening the target application; The first device is a trusted device established through the second device; The setup process specifically includes: the second device sending a trusted device setup request to the server, so that the server generates login credentials corresponding to the trusted device; the trusted device setup request includes the device identifier of the first device; the login credentials are credentials used to log in to the target application using a user account; the second device is a device that was in a login state using the user account to log in to the target application before the first device sent the login request; Based on the first operation, a login page is displayed; the login page includes the user account's account information and a login operation control for indicating that the first device is used as a trusted device to log in to the target application using the user account; Obtain the user's second operation on the login control; Based on the second operation, a login request is generated for requesting to log in to the target application using the user account; the login request includes a first login credential and a first device identifier of the first device; The login request is sent to the server so that, after the first login credential is verified, the server triggers a process to log in to the target application on the first device with the user account.
15. A method for setting up a trusted device, comprising: The second device obtains a trusted device settings page sent by the server, which contains device information of historically logged-in devices; the historically logged-in devices are devices that have logged into the target application using a user account; The second device is a device that is logged into the target application using a user account; The trusted device settings page is displayed; the trusted device settings page includes a first confirmation control. Obtain the user's first confirmation operation on the first confirmation control; Based on the first confirmation operation, a trusted device setting request is generated; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device. The trusted device setting request is sent to the server so that the server can generate login credentials corresponding to the trusted device; The login credentials are credentials used to log in to the target application using the user account.
16. A device for triggering a login process, comprising: The information acquisition module is used to acquire the trusted device setting request sent by the second device; The trusted device setting request includes the device identifier of the first device; The second device is a device that was logged into the target application using a user account before the first device sent the login request; Based on the device identifier of the first device, the first device is identified as a trusted device; The trusted device is used to represent a device that has the permission to log in to the user account in the target application using login credentials; Obtain the login request sent by the first device for logging into the target application; The login request includes a first login credential and a first device identifier of the first device; The credential determination module is used to determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account; The judgment module is used to determine whether the first login credential and the second login credential are consistent, and to obtain a first judgment result; The login process triggering module is used to trigger a process of logging into the target application on the first device with the user account if the first judgment result indicates that the first login credential is consistent with the second login credential.
17. A device for triggering a login process, comprising: The first operation acquisition module is used to acquire the user's first operation when launching the target application. A page display module is used to display the login page based on the first operation; The login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account; The second operation acquisition module is used to acquire the user's second operation on the login operation control; The request generation module is used to generate a login request for requesting to log in to the target application using the user account, based on the second operation. The login request includes a first login credential and a first device identifier of the first device; The first device is a trusted device established through the second device; The setup process specifically includes: the second device sending a trusted device setup request to the server so that the server generates login credentials corresponding to the trusted device; the trusted device setup request includes the device identifier of the first device; the login credentials are credentials used to log in to the target application using the user account; the second device is a device that was in a login state using the user account to log in to the target application before the first device sent the login request; The request sending module is used to send the login request to the server so that after the first login credential is verified, the server triggers the process of logging into the target application on the first device with the user account.
18. An apparatus for setting up a trusted device, comprising: The settings page acquisition module is used to acquire the trusted device settings page sent by the server, which contains device information of historical login devices; the historical login devices are devices that have logged into the target application using a user account; The device for setting the trust device is a device that is in a login state when logging into the target application using a user account; The settings page display module is used to display the trusted device settings page; the trusted device settings page includes a first confirmation control; The confirmation operation acquisition module is used to acquire the user's first confirmation operation on the first confirmation control; The configuration request generation module is used to generate a trusted device configuration request based on the first confirmation operation; the trusted device configuration request includes the device identifier of the historical login device that has been determined by the user to be a trusted device; The module is configured to send a trust device setting request to the server so that the server can generate login credentials corresponding to the trust device. The login credentials are used to log in to the target application using the user account.
19. A device for triggering a login process, comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to: Obtain a Trust Device Setting Request sent by a second device; the Trust Device Setting Request includes the device identifier of the first device; the second device is a device that was logged into the target application using a user account before the first device sent the login request; Based on the device identifier of the first device, the first device is identified as a trusted device; the trusted device is used to represent a device that has the permission to log in to the user account in the target application using login credentials; Obtain the login request sent by the first device for logging into the target application; the login request includes a first login credential and a first device identifier of the first device; Determine the second login credential corresponding to the first device identifier; the second login credential is a credential generated after the first device establishes a trust relationship with the user account of the target application, which is used by the first device to log in to the user account; Determine whether the first login credential and the second login credential are consistent to obtain the first determination result; If the first determination result indicates that the first login credential is consistent with the second login credential, then the process of logging into the target application on the first device with the user account is triggered.
20. A device for triggering a login process, comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to: Obtain the user's first action when opening the target application; Based on the first operation, a login page is displayed; the login page includes user account information and login operation controls for indicating that the first device is used as a trusted device to log in to the target application using the user account; Obtain the user's second operation on the login control; Based on the second operation, a login request is generated for requesting to log in to the target application using the user account; the login request includes a first login credential and a first device identifier of the first device; the first device is a trusted device set up by the second device; the setting process specifically includes: the second device sending a trusted device setting request to the server, so that the server generates a login credential corresponding to the trusted device; the trusted device setting request includes the device identifier of the first device; the login credential is a credential used to log in to the target application using the user account; the second device is a device that was in a login state using the user account to log in to the target application before the first device sent the login request; The login request is sent to the server so that, after the first login credential is verified, the server triggers a process to log in to the target application on the first device with the user account.
21. A device for setting up trusted devices, comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to: The system retrieves a trusted device settings page sent by the server, which contains device information of historically logged-in devices. The historically logged-in devices are devices that have logged into the target application using a user account. The device for which the trusted device is set is a device that is currently logged into the target application using a user account. The trusted device settings page is displayed; the trusted device settings page includes a first confirmation control. Obtain the user's first confirmation operation on the first confirmation control; Based on the first confirmation operation, a trusted device setting request is generated; the trusted device setting request includes the device identifier of the historical login device that has been determined by the user to be a trusted device. The trusted device setting request is sent to the server so that the server generates login credentials corresponding to the trusted device; the login credentials are used to log in to the target application using the user account.
22. A computer-readable medium having stored thereon computer-readable instructions that can be executed by a processor to implement the method for triggering a login process according to any one of claims 1 to 13, or the method for triggering a login process according to claim 14, or the method for setting a trusted device according to claim 15.
Citation Information
Patent Citations
Method and device for multi-terminal-equipment exclusion on same application
CN107404488A
A method and a system of mobile terminal secret-free login
CN109089264A
Shared login method and device, computer readable storage medium and electronic equipment
CN113612756A