A roaming login method and electronic device

By combining roaming identifiers and verification graphic codes, the address of the roaming authentication terminal is determined, solving the problem of poor interoperability between different authentication servers and enabling secure and flexible remote login.

CN116418550BActive Publication Date: 2026-04-07CHANGCHUN JIDA ZHENGYUAN INFORMATION TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-30
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing roaming login methods have poor interoperability between different authentication servers, making them vulnerable to network attacks, resulting in low flexibility and poor security.

Method used

By combining roaming identifiers and verification graphic codes, the roaming address of the roaming authentication terminal is determined, and the authentication terminal is hidden during information transmission. The randomness of the graphic code is used to prevent replay attacks, thus achieving secure roaming login.

Benefits of technology

It improves the flexibility and security of roaming login, ensuring privacy for logins from different locations and preventing external interception attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116418550B_ABST
    Figure CN116418550B_ABST
Patent Text Reader

Abstract

The application discloses a roaming login method and an electronic device. Specifically, the roaming identifier sent by a mobile terminal, the identification information of a verification code and the user information of the mobile terminal are acquired; the roaming address of a roaming authentication end is determined according to the roaming identifier; the identification information and the user information are sent to the roaming authentication end according to the roaming address, so that the roaming authentication end performs roaming login according to the identification information and the user information. The technical scheme of the embodiment of the application can hide and protect the roaming authentication end in the process of information transmission by combining the roaming identifier and the verification code and acting on the verification and roaming login, and can ensure the security of the roaming login in a different place because the verification code has randomness when it is generated, so that the external interception cannot perform a replay attack.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a roaming login method, an electronic device and a storage medium. BACKGROUND

[0002] With the rapid development of society, more and more people start to rely on the convenience of transportation and the Internet to carry out more extensive social activities. Therefore, information sharing in different geographical locations has become a popular research direction. Among them, verification login in different places in the roaming situation is one of the key problems of information sharing technology.

[0003] Currently, the mainstream authentication method is to perform roaming login through verification between a mobile terminal and an authentication server. Different authentication servers may not be interoperable, or the interconnection link is weak, and is vulnerable to network attacks. This results in low flexibility and poor security of the roaming login method. SUMMARY

[0004] The present application provides a roaming login method, an electronic device and a storage medium to improve the flexibility and security of roaming login.

[0005] According to a first aspect of the present application, a roaming login method is provided, applied to a local authentication end, and the method comprises:

[0006] obtaining a roaming identifier, identification information of a verification graphic code and user information of a mobile terminal sent by the mobile terminal;

[0007] determining a roaming address of a roaming authentication end according to the roaming identifier;

[0008] sending the identification information and the user information to the roaming authentication end according to the roaming address, so that the roaming authentication end performs roaming login according to the identification information and the user information.

[0009] According to a second aspect of the present application, a roaming login method is provided, applied to a roaming authentication end, and the method comprises:

[0010] obtaining identification information of a verification graphic code and user information of a mobile terminal sent by a local authentication end; wherein the roaming authentication end is selected by the local authentication end according to a roaming address determined by a roaming identifier;

[0011] verifying the mobile terminal according to the identification information and the user information, and performing roaming login if the verification is passed.

[0012] According to a third aspect of the present application, a roaming login method is provided, applied to a mobile terminal, and the method comprises:

[0013] obtaining a roaming identifier of a roaming authentication end and identification information of a verification graphic code.

[0014] The roaming identifier and identification information are sent to the local authentication terminal, so that the local authentication terminal sends the identification information and user information in the mobile terminal to the roaming authentication terminal corresponding to the roaming address determined based on the roaming identifier, and performs roaming login through the roaming authentication terminal based on the identification information and user information.

[0015] According to a fourth aspect of this application, a roaming login device is provided for use at a local authentication terminal, the device comprising:

[0016] The terminal information acquisition module is used to acquire the roaming identifier, the identification information of the verification graphic code, and the user information of the mobile terminal sent by the mobile terminal.

[0017] The roaming address determination module is used to determine the roaming address of the roaming authentication terminal based on the roaming identifier;

[0018] The information sending module is used to send identification information and user information to the roaming authentication terminal based on the roaming address, so that the roaming authentication terminal can perform roaming login based on the identification information and user information.

[0019] According to a fifth aspect of this application, a roaming login device is provided for use in a roaming authentication terminal, the device comprising:

[0020] The local information acquisition module is used to acquire the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal; wherein, the roaming authentication terminal is selected by the local authentication terminal based on the roaming address determined by the roaming identifier;

[0021] The roaming login module is used to verify the mobile terminal based on identification information and user information. If the verification is successful, roaming login is performed.

[0022] According to a sixth aspect of this application, a roaming login device is provided for use on a mobile terminal, the device comprising:

[0023] The roaming information acquisition module is used to acquire the identification information of the roaming identifier and verification graphic code from the roaming authentication terminal;

[0024] The local sending module is used to send the roaming identifier and identification information to the local authentication terminal, so that the local authentication terminal sends the identification information and user information in the mobile terminal to the roaming authentication terminal corresponding to the roaming address determined based on the roaming identifier, and performs roaming login through the roaming authentication terminal based on the identification information and user information.

[0025] According to a seventh aspect of this application, an electronic device is provided, the electronic device comprising:

[0026] At least one processor; and

[0027] A memory communicatively connected to the at least one processor; wherein,

[0028] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the roaming login method described in any embodiment of this application.

[0029] According to an eighth aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the roaming login method described in any embodiment of this application.

[0030] The technical solution of this application embodiment, through the combination of roaming identifier and verification graphic code, in scope verification and roaming login, determines the roaming address of the roaming authentication terminal locally through the roaming identifier, which can play a role in hiding and protecting the roaming authentication terminal during information transmission. At the same time, since the verification graphic code has randomness when it is generated, external interception cannot carry out replay attacks, thus ensuring the security of roaming login in different locations.

[0031] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0032] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 This is a flowchart of a roaming login method provided according to Embodiment 1 of this application;

[0034] Figure 2 This is a flowchart of a roaming login method according to Embodiment 2 of this application;

[0035] Figure 3A This is a flowchart of a roaming login method according to Embodiment 3 of this application;

[0036] Figure 3B This is a schematic diagram of a roaming login according to an embodiment of this application;

[0037] Figure 4 This is a schematic diagram of the structure of a roaming login device according to Embodiment 4 of this application;

[0038] Figure 5 This is a schematic diagram of the structure of a roaming login device according to Embodiment 5 of this application;

[0039] Figure 6 This is a schematic diagram of the structure of a roaming login device according to Embodiment Six of this application;

[0040] Figure 7 This is a schematic diagram of the structure of an electronic device that implements the roaming login method of the embodiments of this application. Detailed Implementation

[0041] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0042] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0043] Example 1

[0044] Figure 1 The flowchart of a roaming login method is provided in Embodiment 1 of this application. This embodiment is applicable to the login of a mobile terminal to a remote authentication terminal when roaming. The method is applied to the local authentication terminal and can be executed by a roaming login device. The roaming login device can be implemented in hardware and / or software and can be configured in an electronic device.

[0045] It is worth noting that the roaming authentication terminal described in this application embodiment can be a system composed of a roaming authentication server and roaming login terminals (e.g., computers). The roaming authentication server connects to multiple roaming login terminals via a network. Each roaming login terminal displays a verification graphic code generated by the roaming authentication server, which the user can scan to complete authentication and login.Figure 1 As shown, the method includes:

[0046] S110. Obtain the roaming identifier, verification graphic code identification information, and user information of the mobile terminal sent by the mobile terminal.

[0047] The mobile terminal can be a user's mobile device such as a smartphone or tablet. As a device carried by the user, it facilitates roaming login and verification in different locations. The local authentication terminal can be a server or a computer, or even a combination of both. It should be noted that there is a pre-defined association between the local authentication terminal and the mobile terminal. This means that when the user is not roaming, they log in through the local authentication terminal (which could be for a specific system or service). When roaming, the user is in a different location and logs in through the roaming authentication terminal. Similar to the local authentication terminal, the roaming authentication terminal can also be a server and / or a computer, or a combination of both. The actual distance between the roaming authentication terminal and the local authentication terminal is not limited, but they do not share the same physical or network address. The number of roaming authentication terminals is also not limited; the embodiments in this application only describe the verification and login process using a local authentication terminal and a roaming authentication terminal.

[0048] The roaming identifier can be used to mark different roaming authentication terminals, especially to mark verification graphic codes, indicating which roaming authentication terminal generated the verification graphic code. Optionally, the roaming identifier can be the identification information of the roaming authentication terminal stored in the verification graphic code; and the identification information can be composed of a preset string. The verification graphic code can be a graphic QR code or a barcode, etc., and can be generated by the roaming authentication terminal. The identification information of the verification graphic code can be used to mark the verification graphic code. Since the verification graphic code can be randomly generated by the roaming authentication terminal (i.e., the same roaming authentication terminal can generate different verification graphic codes to be displayed in different roaming authentication devices connected to it, providing users with QR code scanning authentication login), in order to distinguish the verification graphic codes, this identification information needs to be added to the verification graphic code. For example, this identification information can be a QR code ID (Identity Document). User information can be the identity information pre-set by the user of the mobile terminal in the mobile terminal, so as to facilitate the identification and / or verification of the user terminal, etc.

[0049] Specifically, before a user logs in while roaming, the local authentication terminal needs to obtain the roaming identifier, the identification information from the graphic verification code, and the user information from the user's mobile terminal. Of course, the roaming identifier and the identification information from the graphic verification code can be integrated into the graphic verification code simultaneously, or they can be combined into the graphic verification code separately or separated from it. This application embodiment does not limit this.

[0050] S120. Determine the roaming address of the roaming authentication terminal based on the roaming identifier.

[0051] The roaming address of the roaming authentication terminal can be a specific physical address and / or network address, which is not limited in this embodiment.

[0052] Optionally, determining the roaming address of the roaming authentication terminal based on the roaming identifier may include: obtaining a local token of the mobile terminal; verifying the mobile terminal based on the local token; and if the verification is successful, determining the roaming address of the roaming authentication terminal based on the roaming identifier and a preset address mapping table.

[0053] The local token (login token) helps users log in at the local authentication terminal. The address mapping table can be a pre-set association table in the local authentication terminal between each roaming identifier and its corresponding roaming address. The local authentication terminal obtains the user's mobile terminal's local token to verify local login; the login verification method can be any existing verification method. After successful verification, the local authentication terminal obtains the roaming identifier from the mobile terminal and queries the pre-set address mapping table for the roaming address of the roaming authentication terminal, thereby determining which roaming authentication terminal the roaming identifier originates from, i.e., determining which roaming authentication terminal the current user needs to log in at. Optionally, one roaming address corresponds to one roaming authentication terminal.

[0054] S130. Based on the roaming address, send identification information and user information to the roaming authentication terminal so that the roaming authentication terminal can perform roaming login based on the identification information and user information.

[0055] Based on the roaming address determined in the preceding steps, identification information (e.g., QR code ID) and user information are sent to the roaming authentication terminal corresponding to that address. The roaming authentication terminal then verifies the user's eligibility to log in remotely using this identification information. If the identification information is indeed generated by this roaming authentication terminal, sent to the local authentication terminal via the mobile terminal, and ultimately returned to the roaming authentication terminal for verification, then the user is allowed to log in while roaming. The specific login method can employ existing technologies, such as generating a roaming token based on the user's information and binding this token to the aforementioned identification information to enable login via the roaming authentication terminal.

[0056] In one optional implementation, sending identification information and user information to the roaming authentication terminal based on the roaming address may include: sending a roaming verification file to the roaming authentication terminal based on the roaming address; wherein the roaming verification file includes a preset roaming key corresponding to the roaming identifier, identification information, and user information; so that the roaming authentication terminal verifies the local authentication terminal based on the roaming key; if the verification is successful, the identification information and user information are obtained.

[0057] The roaming verification file can be a pre-defined intermediate file used to store or integrate roaming keys, identification information, and user information. The roaming verification file can be a table, a folder, or similar format. The roaming key can be a pre-defined key used for login verification, bound to a roaming identifier and stored together in an address mapping table. This key can be pre-defined at any authentication endpoint (including local authentication endpoints and each roaming authentication endpoint), and one authentication endpoint can pre-store the roaming keys of all other authentication endpoints for information verification. Once the roaming address is determined, the local authentication endpoint sends the roaming verification file, containing the roaming key, identification information, and user information, to the roaming authentication endpoint at that address via a pre-defined data interface. The information is verified using the pre-stored roaming key to determine the legitimacy of the local authentication endpoint. Upon successful verification, the identification information and user information can be obtained.

[0058] For example, the local authentication terminal transmits user information (such as employee name or ID number), identification information, and roaming identifier along with relevant signature information to the roaming authentication terminal. The signature information is composed of the data to be authenticated (such as various information in the aforementioned roaming verification file) combined with the authentication data combination rules preset by each roaming authentication terminal, and can be signed using a signature algorithm (such as SHA256). The data to be authenticated may include, but is not limited to, the roaming identifier, the roaming key corresponding to the roaming identifier obtained by the local authentication terminal through an address mapping table, and identification information.

[0059] After receiving user information, identification information, and the roaming identifier along with relevant signature information, the roaming authentication terminal looks up the roaming key corresponding to the roaming identifier in a locally pre-stored address mapping table. Based on the roaming key, it verifies the legitimacy of the local authentication terminal. Specifically, it performs a signature operation on the data to be authenticated—the roaming identifier, the queried roaming key corresponding to the roaming identifier, and the identification information—using the same authentication data combination rules and signature algorithm as the local authentication terminal. The resulting signature is then compared with the received signature to complete the verification of the local authentication terminal. The core principle is that not just any local authentication terminal can pass the verification of the roaming authentication terminal. Only local authentication terminals with the same pre-stored address mapping table can allow their corresponding mobile terminal users to log in on roaming terminals. This ensures the security of roaming login.

[0060] The technical solution of this application embodiment combines roaming identifiers and verification graphic codes to perform verification and roaming login. The roaming identifier determines the roaming address of the roaming authentication terminal locally, which can hide and protect the roaming authentication terminal during information transmission. At the same time, since the verification graphic code is random when it is generated, external interception cannot carry out attacks, thus ensuring the security of roaming login in different locations.

[0061] Example 2

[0062] Figure 2 This application provides a flowchart of a roaming login method according to Embodiment 2. This embodiment is applicable to the login of a mobile terminal to a remote authentication terminal while roaming. The method is applied to the roaming authentication terminal and can be executed by a roaming login device. This roaming login device can be implemented in hardware and / or software and can be configured in an electronic device. Figure 2 As shown, the method includes:

[0063] S210. Obtain the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal; wherein, the roaming authentication terminal is selected by the local authentication terminal based on the roaming address determined by the roaming identifier.

[0064] The methods for determining the roaming address based on the roaming identifier have been described in the preceding embodiments, and will not be repeated in this embodiment. Since the local authentication terminal determines the roaming authentication terminal based on the roaming address, the roaming authentication terminal receives the identification information of the verification graphic code and user information sent by the local authentication terminal. The receiving method can be through a preset data interface, which is not limited in this embodiment.

[0065] In one optional implementation, obtaining the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal may include: obtaining the roaming key corresponding to the roaming identifier sent by the local authentication terminal; and obtaining the identification information and user information sent by the local authentication terminal based on the roaming key.

[0066] Before receiving the identification and user information sent by the local authentication terminal, the roaming key sent by the local authentication terminal is first verified. Since the roaming authentication terminal also pre-stores the roaming key of the local authentication terminal, a comparison can be made to determine whether the key belongs to the local authentication terminal. After successful verification, the identification and user information can be received.

[0067] Furthermore, obtaining the roaming key sent by the local authentication terminal may include: obtaining a roaming verification file sent by the local authentication terminal; wherein the roaming verification file includes the roaming key, identification information, and user information; correspondingly, obtaining the identification information and user information sent by the local authentication terminal based on the roaming key may include: verifying the local authentication terminal based on the roaming key; if the verification is successful, then obtaining the identification information and user information.

[0068] One way to obtain a roaming key is to first obtain the roaming verification file sent by the local authentication terminal. This file includes the roaming key, identification information, and user information. The identification information and user information can then be obtained after verifying the roaming key. In essence, the roaming key acts as a protection mechanism for obtaining identification and user information. Even if the roaming verification file is obtained, if the roaming key fails verification, the identification and user information cannot be obtained, thus restricting the user's roaming login.

[0069] S220. Verify the mobile terminal based on the identification information and user information. If the verification is successful, proceed with roaming login.

[0070] After obtaining the identification information and user information, the data is verified. If the verification passes and the user information is indeed from a mobile terminal bound to the local authentication terminal, a roaming token corresponding to the user information is generated. The roaming token is then associated with the identification information, thereby enabling roaming login.

[0071] In the technical solution of this application embodiment, roaming login for users in different locations is achieved through information verification between the roaming authentication terminal and the local authentication terminal, providing users with a practical and effective roaming login method, improving the usability of roaming login and enhancing the user experience.

[0072] Example 3

[0073] Figure 3AThis application provides a flowchart of a roaming login method in Embodiment 3. This embodiment is applicable to the login of a mobile terminal to a remote authentication terminal while roaming. The method is applied to the mobile terminal and can be executed by a roaming login device. This roaming login device can be implemented in hardware and / or software and can be configured in an electronic device. Figure 3A As shown, the method includes:

[0074] S310. Obtain the identification information of the roaming identifier and verification graphic code from the roaming authentication terminal.

[0075] The mobile terminal can obtain roaming identification and recognition information on the login interface of the roaming login terminal to which the roaming authentication terminal belongs. Optionally, obtaining the roaming identification and verification graphic code recognition information of the roaming authentication terminal may include: scanning the verification graphic code of the roaming login terminal; and determining the roaming identification and verification graphic code recognition information of the roaming authentication terminal and the verification graphic code on the roaming login terminal based on the scanning result. It is understood that when a user performs roaming login, they need to log in through the login interface (e.g., human-computer interaction interface) of the roaming authentication terminal. Before verifying the login, the roaming login terminal can display a verification graphic code for roaming login, such as a QR code or barcode, for the user to scan using the mobile terminal. The scanned verification graphic code is then decoded to obtain the scanning result, which may include the roaming identification and verification graphic code recognition information (e.g., QR code ID) of the roaming authentication terminal.

[0076] S320. Send the roaming identifier and identification information to the local authentication terminal, so that the local authentication terminal sends the identification information and user information in the mobile terminal to the roaming authentication terminal corresponding to the roaming address determined based on the roaming identifier, and performs roaming login through the roaming authentication terminal based on the identification information and user information.

[0077] The roaming identifier and identification information obtained from scanning the QR code in the aforementioned steps, along with the user information pre-stored in the mobile terminal, are sent to the local authentication terminal. This allows the local authentication terminal to determine the roaming address using the roaming identifier, and further determine the roaming authentication terminal corresponding to the roaming address (i.e., the roaming authentication terminal that the user needs to use for roaming login). The local authentication terminal then forwards the user information and identification information to the roaming authentication terminal for roaming login verification.

[0078] In one optional implementation, the method may further include: sending a local token to a local authentication terminal, so that after the local authentication terminal verifies the mobile terminal based on the local token, it determines the roaming address of the roaming authentication terminal based on the roaming identifier and a preset address mapping table.

[0079] Since there is a pre-set association between the mobile terminal and the local authentication terminal, it can be understood that the user holding the mobile terminal always logs in at the local authentication terminal. Therefore, the mobile terminal can send a pre-set local token (login token) to the local authentication terminal, and the local authentication terminal can verify that the mobile terminal has login permissions locally. After successful verification, the local authentication terminal uses a pre-saved address mapping table to query the roaming identifier to determine the roaming address of the roaming authentication terminal. This address can be a physical address or a network IP address, etc., and this embodiment does not limit this.

[0080] The technical solution of this application embodiment determines that the user has the permission to log in from a different location through login verification between the mobile terminal and the local authentication terminal, thereby helping the user to build a bridge for login verification between the local authentication terminal and the roaming authentication terminal, which helps to improve the security and reliability of roaming login.

[0081] Based on the foregoing embodiments, this application also provides a preferred embodiment, such as... Figure 3B As shown, roaming login is achieved through the collaboration of a mobile phone (mobile terminal), authentication center A (local authentication terminal), and authentication center B (roaming authentication terminal), specifically including:

[0082] For example, if a mobile phone belongs to Company A, and the mobile phone authentication APP is issued by authentication center A, and the user travels to Company B on a business trip to access Company B's office system, they need to scan a QR code to roam and log in.

[0083] When a user operates a mobile application, they must first authenticate with a certificate or other factors through the authentication center A to successfully log in and obtain token A (i.e., user information, which may include a local token).

[0084] Certification Center B displays QR code B (i.e. verification graphic code) through the human-computer interaction interface of its roaming login terminal. QR code B contains the roaming identifier of Certification Center B (identifying which certification center generated the QR code, which can be composed of strings such as letters and numbers), which is then scanned and recognized by the mobile application.

[0085] After the mobile application successfully scans and parses QR code B, it obtains the ID of QR code B (equivalent to the identification information of the verification image code, used to identify the source of the QR code's authentication center and associated with the roaming login terminal), the roaming identifier of authentication center B, and token A, etc., and sends them to authentication center A. Authentication center A parses the roaming identifier of authentication center B and looks up the address of authentication center B according to the address mapping table.

[0086] Authentication center A pushes the ID and user information of QR code B to authentication center B; authentication center B verifies this information, and if the verification is successful, it generates a user token (i.e., a roaming token) and associates the user token with the ID of QR code B, thereby confirming that the user can roam and log in to authentication center B through the mobile terminal; after confirming the successful QR code verification, authentication center B logs in to the application.

[0087] It's worth noting that, for mobile applications to scan QR codes generated by different authentication centers, the identifiers and addresses of each authentication center must be pre-configured. The QR code can also include the server identifier of the authentication center. After the mobile phone scans the QR code, it can use the identifier in the QR code to navigate to the authentication center (or server) that generated the QR code. Then, it notifies the roaming authentication center that generated the QR code of the currently logged-in user information through the local authentication center where the mobile terminal is registered, thus enabling login via scanning while roaming.

[0088] Example 4

[0089] Figure 4 This is a schematic diagram of a roaming login device provided in Embodiment 4 of this application. This device is applied to a local authentication terminal, such as… Figure 4 As shown, the device 400 includes:

[0090] The terminal information acquisition module 410 is used to acquire the roaming identifier, the identification information of the verification graphic code, and the user information of the mobile terminal sent by the mobile terminal.

[0091] The roaming address determination module 420 is used to determine the roaming address of the roaming authentication terminal based on the roaming identifier;

[0092] The information sending module 430 is used to send identification information and user information to the roaming authentication terminal based on the roaming address, so that the roaming authentication terminal can perform roaming login based on the identification information and user information.

[0093] The technical solution of this application embodiment, through the combination of roaming identifier and verification graphic code, in scope verification and roaming login, determines the roaming address of the roaming authentication terminal locally through the roaming identifier, which can play a role in hiding and protecting the roaming authentication terminal during information transmission. At the same time, since the verification graphic code has randomness when it is generated, external interception cannot carry out replay attacks, thus ensuring the security of roaming login in different locations.

[0094] In one optional implementation, the roaming identifier is the identification information of the roaming authentication terminal stored in the verification graphic code; and the identification information is composed of a preset string.

[0095] In one alternative implementation, the roaming address determination module 420 may include:

[0096] The local token acquisition unit is used to acquire the local token of the mobile terminal.

[0097] The mobile terminal verification unit is used to verify the mobile terminal based on the local token.

[0098] The roaming address determination unit is used to determine the roaming address of the roaming authentication terminal based on the roaming identifier and a preset address mapping table if the verification is successful.

[0099] In one optional implementation, the information sending module 430 may be specifically used for:

[0100] Based on the roaming address, a roaming verification file is sent to the roaming authentication terminal. The roaming verification file includes a preset roaming key, identification information, and user information corresponding to the roaming identifier. This enables the roaming authentication terminal to verify the local authentication terminal based on the roaming key. If the verification is successful, the identification information and user information are obtained.

[0101] The roaming login device provided in this application embodiment can execute the roaming login method provided in the first aspect embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the roaming login method.

[0102] Example 5

[0103] Figure 5 This is a schematic diagram of a roaming login device provided in Embodiment 5 of this application. This device is applied to a roaming authentication terminal, such as... Figure 5 As shown, the device 500 includes:

[0104] The local information acquisition module 510 is used to acquire the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal; wherein, the roaming authentication terminal is selected by the local authentication terminal based on the roaming address determined by the roaming identifier.

[0105] The roaming login module 520 is used to verify the mobile terminal based on the identification information and user information. If the verification is successful, roaming login is performed.

[0106] In the technical solution of this application embodiment, roaming login for users in different locations is achieved through information verification between the roaming authentication terminal and the local authentication terminal, providing users with a practical and effective roaming login method, improving the usability of roaming login and enhancing the user experience.

[0107] In one optional embodiment, the local information acquisition module 510 may include:

[0108] The roaming key acquisition unit is used to acquire the roaming key corresponding to the roaming identifier sent by the local authentication terminal;

[0109] The local information acquisition unit is used to acquire the identification information and user information sent by the local authentication terminal based on the roaming key.

[0110] Furthermore, the roaming key acquisition unit can be specifically used to: acquire the roaming verification file sent by the local authentication terminal; wherein the roaming verification file includes the roaming key, identification information, and user information;

[0111] Accordingly, the local information acquisition unit can be specifically used to: verify the local authentication terminal based on the roaming key; if the verification is successful, then acquire the identification information and user information.

[0112] The roaming login device provided in this application embodiment can execute the roaming login method provided in the second aspect embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the roaming login method.

[0113] Example 6

[0114] Figure 6 This is a schematic diagram of a roaming login device provided in Embodiment Six of this application. This device is applied to a mobile terminal, such as… Figure 6 As shown, the device 600 includes:

[0115] The roaming information acquisition module 610 is used to acquire the identification information of the roaming identifier and verification graphic code of the roaming authentication terminal;

[0116] The local sending module 620 is used to send the roaming identifier and identification information to the local authentication terminal, so that the local authentication terminal sends the identification information and user information in the mobile terminal to the roaming authentication terminal corresponding to the roaming address determined based on the roaming identifier, and performs roaming login through the roaming authentication terminal based on the identification information and user information.

[0117] The technical solution of this application embodiment determines that the user has the permission to log in from a different location through login verification between the mobile terminal and the local authentication terminal, thereby helping the user to build a bridge for login verification between the local authentication terminal and the roaming authentication terminal, which helps to improve the security and reliability of roaming login.

[0118] In one alternative embodiment, the roaming login device 600 may further include:

[0119] The local token sending module is used to send a local token to the local authentication terminal so that after the local authentication terminal verifies the mobile terminal based on the local token, it determines the roaming address of the roaming authentication terminal according to the roaming identifier and the preset address mapping table.

[0120] In another alternative embodiment, the roaming information acquisition module 610 may include:

[0121] The scanning unit is used to scan the verification graphic code of the roaming authentication terminal;

[0122] The roaming information determination unit is used to determine the identification information of the roaming identifier and verification graphic code of the roaming authentication terminal based on the scanning results.

[0123] The roaming login device provided in this application embodiment can execute the roaming login method provided in the third aspect embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the roaming login method.

[0124] Example 7

[0125] Figure 7 A schematic diagram of an electronic device 10, which can be used to implement embodiments of this application, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.

[0126] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0127] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0128] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as the roaming login method.

[0129] In some embodiments, the roaming login method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the roaming login method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the roaming login method by any other suitable means (e.g., by means of firmware).

[0130] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0131] Computer programs used to implement the methods of this application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0132] In the context of this application, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0133] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0134] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0135] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0136] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.

[0137] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A roaming login method, characterized in that, Applied to a local authentication endpoint, the method includes: Obtain the roaming identifier, the identification information of the verification graphic code, and the user information of the mobile terminal sent by the mobile terminal; The roaming address of the roaming authentication terminal is determined based on the roaming identifier; Based on the roaming address, the identification information and the user information are sent to the roaming authentication terminal so that the roaming authentication terminal can perform roaming login based on the identification information and the user information; The step of sending the identification information and the user information to the roaming authentication terminal based on the roaming address includes: Based on the roaming address, a roaming verification file is sent to the roaming authentication terminal; wherein, the roaming verification file includes a preset roaming key corresponding to the roaming identifier, the identification information, and the user information; so that the roaming authentication terminal can verify the local authentication terminal based on the roaming key; if the verification is successful, the identification information and the user information are obtained; The roaming verification file is a pre-set intermediate file used to store or integrate the roaming key, the identification information, and the user information. The roaming key is a preset key used to verify login. The roaming key is bound to the roaming identifier and stored together in the address mapping table. The roaming key is preset in both the local authentication terminal and the roaming authentication terminal, and each authentication terminal pre-stores the roaming keys corresponding to all other authentication terminals for verification.

2. The method according to claim 1, characterized in that, The roaming identifier is the identification information of the roaming authentication terminal stored in the verification graphic code; and the identification information is composed of a preset string.

3. The method according to claim 1, characterized in that, Determining the roaming address of the roaming authentication terminal based on the roaming identifier includes: Obtain the local token from the mobile device; The mobile terminal is verified based on the local token. If the verification is successful, the roaming address of the roaming authentication terminal is determined according to the roaming identifier and the preset address mapping table.

4. A roaming login method, characterized in that, The method, applied to roaming authentication, includes: The system obtains the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal; wherein the roaming authentication terminal is selected by the local authentication terminal based on the roaming address determined by the roaming identifier. The mobile terminal is verified based on the identification information and the user information. If the verification is successful, roaming login is performed. The process of obtaining the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal includes: Obtain the roaming key corresponding to the roaming identifier sent by the local authentication terminal; Based on the roaming key, obtain the identification information and user information sent by the local authentication terminal; The step of obtaining the roaming key corresponding to the roaming identifier sent by the local authentication terminal includes: Obtain the roaming verification file sent by the local authentication terminal; wherein the roaming verification file includes the roaming key, the identification information, and the user information; Accordingly, obtaining the identification information and user information sent by the local authentication terminal based on the roaming key includes: The local authentication terminal is verified using the roaming key; if the verification is successful, the identification information and the user information are obtained. The roaming verification file is a pre-set intermediate file used to store or integrate the roaming key, the identification information, and the user information. The roaming key is a preset key used to verify login. The roaming key is bound to the roaming identifier and stored together in the address mapping table. The roaming key is preset in both the local authentication terminal and the roaming authentication terminal, and each authentication terminal pre-stores the roaming keys corresponding to all other authentication terminals for verification.

5. A roaming login method, characterized in that, Applied to a mobile terminal, the method includes: Obtain the identification information of the roaming identifier and verification graphic code from the roaming authentication terminal; The roaming identifier and the identification information are sent to the local authentication terminal, so that the local authentication terminal sends the identification information and the user information in the mobile terminal to the roaming authentication terminal corresponding to the roaming address determined based on the roaming identifier, and performs roaming login through the roaming authentication terminal based on the identification information and the user information; Before the roaming authentication terminal performs roaming login based on the identification information and the user information, the roaming authentication terminal obtains the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal. The roaming authentication terminal obtains the identification information of the verification graphic code sent by the local authentication terminal and the user information of the mobile terminal, including: The roaming authentication terminal obtains the roaming key corresponding to the roaming identifier sent by the local authentication terminal; The roaming authentication terminal obtains the identification information and user information sent by the local authentication terminal based on the roaming key; The roaming authentication terminal obtains the roaming key corresponding to the roaming identifier sent by the local authentication terminal, including: The roaming authentication terminal obtains the roaming verification file sent by the local authentication terminal; wherein, the roaming verification file includes the roaming key, the identification information, and the user information; Accordingly, the roaming authentication terminal obtains the identification information and user information sent by the local authentication terminal based on the roaming key, including: The roaming authentication terminal verifies the local authentication terminal based on the roaming key; if the verification is successful, the identification information and the user information are obtained. The roaming verification file is a pre-set intermediate file used to store or integrate the roaming key, the identification information, and the user information. The roaming key is a preset key used to verify login. The roaming key is bound to the roaming identifier and stored together in the address mapping table. The roaming key is preset in both the local authentication terminal and the roaming authentication terminal, and each authentication terminal pre-stores the roaming keys corresponding to all other authentication terminals for verification.

6. The method according to claim 5, characterized in that, The method includes: A local token is sent to the local authentication terminal so that after the local authentication terminal verifies the mobile terminal based on the local token, it determines the roaming address of the roaming authentication terminal based on the roaming identifier and a preset address mapping table.

7. The method according to claim 5, characterized in that, The step of obtaining the roaming identifier of the roaming authentication terminal and the identification information of the verification graphic code includes: Scan the verification graphic code on the roaming authentication terminal; Based on the scanning results, the roaming identifier of the roaming authentication terminal and the identification information of the verification graphic code are determined.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the roaming login method according to any one of claims 1-3, or to perform the roaming login method according to any one of claims 4, or to perform the roaming login method according to any one of claims 5-7.

Citation Information

Patent Citations

  • Method and system for realizing secure login

    CN105933353A

  • Identity authentication method and authentication device

    CN108134787A