A data processing method, device, apparatus, and storage medium
Patent Information
- Application Number
- CN202210289490.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-23
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-03-23
AI Technical Summary
该服务器在生成当前验证码之后,可以通过手机短信等方式,将当前验证码传输至目标用户,这种数据传输方式存在验证码泄露的风险,即非法用户可以通过截获或欺骗等非正常手段来获取到完整的验证码,进而降低了验证信息的安全性
[0077]在本申请实施例中,客户端在响应针对验证信息生成功能的触发操作时,可以生成具有M个字符的第一验证子信息,进而可以基于验证字符总数量N、第一验证子信息以及客户端对应的对象信息,生成用于向服务器发送的验证信息生成请求,以使服务器生成具有(N-M)个字符的第二验证子信息。其中,N为大于M的正整数。进一步地,客户端可以接收由服务器发送的第二验证子信息,并基于第一验证子信息和第二验证子信息,组成具有N个字符的验证信息。由此可见,本申请实施例中的验证信息并非是由客户端或者服务器独立生成的,而是由客户端和服务器所共同生成的,即该验证信息可以包括为由客户端生成的第一验证子信息以及由服务器生成的第二验证子信息,这样将导致验证信息在客户端与服务器之间传输时的泄露风险降低,即其他终端难以获取完整的验证信息,以至于提高了验证信息的安全性。
Smart Images

Figure CN116846567B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a data processing method, apparatus, device, and storage medium. Background Technology
[0002] In recent years, verification information (e.g., CAPTCHAs) has become a common method for verifying user identity or behavior, besides passwords, playing a crucial role in personal data protection and account security. Common CAPTCHAs are plaintext codes independently generated by a computer device (e.g., a server) with verification information generation capabilities. After generating the CAPTCHA, the server can transmit it to the target user via SMS or other means. This data transmission method carries the risk of CAPTCHA leakage; unauthorized users can obtain the complete CAPTCHA through interception or deception, thus reducing the security of the verification information. Summary of the Invention
[0003] This application provides a data processing method, apparatus, device, and storage medium that can improve the security of verification information.
[0004] One embodiment of this application provides a data processing method, which is executed by a client and includes:
[0005] In response to a trigger operation for the verification information generation function, the system displays a first verification sub-information with M characters and an input character area with (NM) display positions in the verification information display area; where N is a positive integer and M is a positive integer less than N.
[0006] When the second verification sub-information with (NM) characters is obtained from the server, the second verification sub-information is displayed in the input character area in response to the information input operation for the input character area.
[0007] The first and second verification sub-information in the verification information display area are identified as the verification information used for data security verification.
[0008] One embodiment of this application provides a data processing method, which is executed by a server and includes:
[0009] The client sends a verification information generation request. The verification information generation request is generated by the client based on the total number of verification characters N, the first verification sub-information, and the client's corresponding object information. The first verification sub-information is used to constitute the verification information, and the first verification sub-information consists of M characters displayed in the verification information display area when the client responds to the trigger operation for the verification information generation function. M is a positive integer, and N is a positive integer greater than M.
[0010] Based on N, the first verification sub-information, and the object information, generate a second verification sub-information with (NM) characters;
[0011] The second verification sub-information is sent to the client so that the client responds to the information input operation for the input character area in the verification information display area, displays the second verification sub-information in the input character area, and determines the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification.
[0012] One embodiment of this application provides a data processing apparatus, including:
[0013] The first sub-information display module is used to respond to the trigger operation of the verification information generation function, and to display the first verification sub-information with M characters and the input character area with (NM) display positions in the verification information display area; N is a positive integer and M is a positive integer less than N;
[0014] The second sub-information display module is used to respond to the information input operation for the input character area when it obtains the second verification sub-information with (NM) characters from the server, and display the second verification sub-information in the input character area.
[0015] The verification information determination module is used to determine the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification.
[0016] The first sub-information display module includes:
[0017] The page switching unit is used to respond to the trigger operation of the verification information generation function on the client's client service page, and switch the client's display page from the client service page to the verification information filling page; the verification information filling page includes a verification information display area; the verification information display area includes N display positions;
[0018] The first sub-information determination unit is used to display M characters in M display positions in the verification information display area, determine the M characters and their corresponding position information as the first verification sub-information, and determine the (NM) display positions other than the M display positions as the input character area.
[0019] The second sub-information display module includes:
[0020] The summary display unit is used to display a summary of the notification information when the notification information returned by the server is obtained; the notification information includes a second verification sub-information with (NM) characters;
[0021] The notification information display unit is used to display notification information in response to a trigger operation on the notification summary;
[0022] The first display unit is used to respond to information input operations for the input character area and display (NM) characters in the second verification sub-information in the input character area according to the position information corresponding to the notification information.
[0023] The first sub-information generation module further includes:
[0024] The first sub-information generation unit is used to respond to the trigger operation for the verification information generation function in the client's client service page and generate the first verification sub-information with M characters.
[0025] The first sub-information display unit is used to display a first verification sub-information with M characters and an input character area with (NM) display positions in the verification information display area.
[0026] The first sub-information generation unit includes:
[0027] The character count determination subunit is used in the client service page of the client to respond to the trigger operation for the verification information generation function, obtain the total number of verification characters N, and determine the number of fixed characters M based on N;
[0028] The character determination subunit is used to acquire the information character area associated with the verification information and determine M characters from the information character area.
[0029] The first determining subunit is used to determine the position information of M characters in the verification information, and based on the M characters and their respective position information, to determine the first verification sub-information used to constitute the verification information.
[0030] The first sub-information generation unit further includes:
[0031] The object information acquisition subunit is used to respond to the trigger operation of the verification information generation function and acquire the object information associated with the client;
[0032] The string conversion subunit is used to perform string conversion processing on object information based on a hash conversion strategy to obtain object conversion information;
[0033] The second determining sub-unit is used to determine the first verification sub-information used to constitute the verification information based on the object transformation information.
[0034] Both the client and the server are blockchain nodes in the blockchain network;
[0035] The device includes:
[0036] The module for determining information to be signed is used to determine the information to be signed based on the total number of verification characters N, the first verification sub-information, and the object information corresponding to the client.
[0037] The signature processing module is used to obtain the object private key associated with the client, and to process the information to be signed based on the object private key to obtain the client signature information;
[0038] The request generation module is used to generate a verification information generation request to be sent to the server based on the client's signature information and the information to be signed; the client's signature information is used to instruct the server to verify the information to be signed.
[0039] Both the client and the server are blockchain nodes in the blockchain network;
[0040] The second sub-information display module also includes:
[0041] The encrypted information receiving unit is used to receive encrypted data information sent by the server; the encrypted data information is obtained by the server encrypting the second verification sub-information using the public key of the object corresponding to the client.
[0042] The decryption processing unit is used to decrypt the encrypted data information using the object's private key corresponding to the object's public key, and obtain the second verification sub-information;
[0043] The second display unit is used to respond to information input operations for the input character area and display (NM) characters in the second verification sub-information in the input character area.
[0044] The device also includes:
[0045] The verification information sending module is used to send verification information to the server, so that the server can generate an information verification result based on the received verification information and the verification information associated with the client stored on the server; the verification information is the complete information recorded by the server based on the first verification sub-information and the second verification sub-information sent by the client;
[0046] The information verification result receiving module is used to receive the information verification result returned by the server.
[0047] The success notification display module is used to determine the information verification result as a successful verification result if the information verification result indicates that the verification information is consistent with the validation information, and to display a verification success notification that matches the successful verification result.
[0048] The failure notification display module is used to determine the information verification result as a verification failure result if the information verification result indicates that the verification information and the validation information are inconsistent, and to display a verification failure notification that matches the verification failure result.
[0049] One embodiment of this application provides a data processing apparatus, including:
[0050] The request acquisition module is used to acquire the verification information generation request sent by the client. The verification information generation request is generated by the client based on the total number of verification characters N, the first verification sub-information, and the corresponding object information of the client. The first verification sub-information is used to constitute the verification information, and the first verification sub-information consists of M characters displayed in the verification information display area when the client responds to the trigger operation for the verification information generation function; M is a positive integer; N is a positive integer greater than M.
[0051] The second sub-information generation module is used to generate a second verification sub-information with (NM) characters based on N, the first verification sub-information, and the object information.
[0052] The second sub-information sending module is used to send the second verification sub-information to the client so that the client responds to the information input operation for the input character area in the verification information display area, displays the second verification sub-information in the input character area, and determines the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification.
[0053] In this context, both the server and the client are blockchain nodes in the blockchain network; the verification information generation request includes information to be signed and client signature information; the client signature information is obtained by the client signing the information to be signed using the object's private key; the information to be signed is determined by the first verification sub-information and the object information corresponding to the client;
[0054] The device also includes:
[0055] The public key acquisition module is used to obtain the object's public key corresponding to the object's private key when a verification information generation request is received from the client.
[0056] The signature verification result determination module is used to verify the client's signature information based on the object's public key and obtain the signature verification result.
[0057] The successful verification module is used to determine that the client is a legitimate node if the signature verification result indicates successful verification, and to determine that the verification information generation request is a legitimate request.
[0058] The verification failure module is used to determine that the client is an illegal node and to classify the verification information generation request as an illegal request if the signature verification result indicates that the verification has failed.
[0059] The server is a blockchain node in the blockchain network;
[0060] The device also includes:
[0061] The verification information determination module is used to determine the verification information for data security verification of the client based on the first verification sub-information and the second verification sub-information sent by the client when generating the second verification sub-information;
[0062] The packaging module is used to package the verification information to obtain the unverified block of the blockchain to be written into the blockchain network.
[0063] The block broadcasting module is used to broadcast the block to be verified to the consensus nodes in the blockchain network, so that the consensus nodes can reach a consensus on the block to be verified and obtain a consensus result to be returned to the server; the consensus nodes are blockchain nodes in the blockchain network.
[0064] The block writing module is used to determine that the blockchain nodes in the blockchain network have reached a consensus if there is a consensus result in the consensus result that exceeds the consensus threshold, indicating that the consensus is successful, and then write the block to be verified as the target block into the blockchain.
[0065] The device also includes:
[0066] The verification information acquisition module is used to acquire verification information for data security verification of the verification information when it receives the verification information returned by the client; the verification information includes first verification sub-information and second verification sub-information.
[0067] The verification information splitting module is used to split the verification information to obtain the first splitting sub-information and the second splitting sub-information;
[0068] The first comparison module is used to compare the first split sub-information with the first verification sub-information to obtain the first comparison result;
[0069] The second comparison module is used to compare the second sub-information with the second verification sub-information if the first comparison result indicates that the first sub-information is consistent with the first verification sub-information, and to obtain the second comparison result.
[0070] The first result generation module is used to generate a verification result indicating successful verification if the second comparison result indicates that the second split sub-information is consistent with the second verification sub-information.
[0071] The device also includes:
[0072] The second result generation module is used to generate an information verification result indicating verification failure if the first comparison result indicates that the first split sub-information and the first verification sub-information are inconsistent.
[0073] One embodiment of this application provides a computer device, including: a processor and a memory;
[0074] The processor is connected to a memory, which stores a computer program. When the computer program is executed by the processor, it causes the computer device to perform the method provided in the embodiments of this application.
[0075] One aspect of this application provides a computer-readable storage medium storing a computer program adapted to be loaded and executed by a processor, so that a computer device having the processor performs the method provided in this application.
[0076] One aspect of this application provides a computer program product, including a computer program / instructions, which, when executed by a processor, cause the computer device to perform the method provided in this application.
[0077] In this embodiment, when the client responds to a trigger operation for the verification information generation function, it can generate a first verification sub-information with M characters. Then, based on the total number of verification characters N, the first verification sub-information, and the client's corresponding object information, it can generate a verification information generation request to send to the server, causing the server to generate a second verification sub-information with (NM) characters. Here, N is a positive integer greater than M. Further, the client can receive the second verification sub-information sent by the server and, based on the first and second verification sub-information, assemble verification information with N characters. Therefore, the verification information in this embodiment is not generated independently by the client or the server, but jointly by both. That is, the verification information can include the first verification sub-information generated by the client and the second verification sub-information generated by the server. This reduces the risk of leakage when the verification information is transmitted between the client and the server, making it difficult for other terminals to obtain the complete verification information, thus improving the security of the verification information. Attached Figure Description
[0078] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0079] Figure 1 This is a schematic diagram of a network architecture provided in an embodiment of this application;
[0080] Figure 2 This is a schematic diagram of a data interaction scenario provided in an embodiment of this application;
[0081] Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application;
[0082] Figure 4 This is a flowchart illustrating a data processing method provided in an embodiment of this application;
[0083] Figure 5 This is a schematic diagram of a process for performing data security verification on verification information, provided in an embodiment of this application.
[0084] Figure 6 This is a schematic diagram illustrating a data transmission scenario in a blockchain context, as provided in an embodiment of this application.
[0085] Figure 7 This is a schematic diagram illustrating a scenario where verification information is uploaded to the blockchain, as provided in an embodiment of this application.
[0086] Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;
[0087] Figure 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;
[0088] Figure 10 This is a schematic diagram of a computer device provided in an embodiment of this application;
[0089] Figure 11 This is a schematic diagram of the structure of a data processing system provided in an embodiment of this application. Detailed Implementation
[0090] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0091] Please see Figure 1 , Figure 1 This is a schematic diagram of a network architecture provided in an embodiment of this application. Figure 1As shown, this network architecture may include a server 10F and a cluster of terminal devices. The terminal device cluster may include one or more terminal devices; the number of terminal devices is not limited here. Figure 1 As shown, it may specifically include terminal device 100a, terminal device 100b, terminal device 100c, ..., terminal device 100n. For example... Figure 1 As shown, terminal devices 100a, 100b, 100c, ..., 100n can each connect to the server 10F via a network, so that each terminal device can interact with the server 10F through the network connection.
[0092] Each terminal device in this terminal device cluster can include: smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, in-vehicle terminals, smart TVs, and other smart terminals with verification information generation capabilities. It should be understood that, for example... Figure 1 Each terminal device in the terminal device cluster shown can have the target application (i.e., client) installed. When the client runs on each terminal device, it can interact with the aforementioned applications. Figure 1 Data interaction occurs between the servers 10F shown. The client can include social clients, multimedia clients (e.g., video clients), entertainment clients (e.g., game clients), educational clients, live streaming clients, and other clients with verification information generation capabilities. This client can be a standalone client or an embedded sub-client integrated into another client (e.g., social clients, educational clients, and multimedia clients); this is not limited here.
[0093] like Figure 1 As shown, in this embodiment, server 10F can be the server corresponding to the client. Server 10F can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0094] For ease of understanding, the embodiments of this application may be described in detail below. Figure 1 From the multiple terminal devices shown, one terminal device is selected as the target terminal device. For example, in the embodiments of this application, a terminal device can be selected as the target terminal device. Figure 1 The terminal device 100a shown serves as the target terminal device, which may integrate a target application (i.e., a client). In this case, the target terminal device can interact with the server 10F through the business data platform corresponding to the client.
[0095] It should be understood that the client running on the target terminal device, upon responding to a trigger operation for the verification information generation function, can display a first verification sub-information of M characters and an input character area with (NM) display positions in the verification information display area; here, N is a positive integer, and M is a positive integer less than N. It is understood that the first verification sub-information here refers to a fixed verification code bit randomly generated by the client, where the fixed verification code bit refers to the verification code portion of the verification information that has a fixed number of digits, a fixed position, a fixed value, and is uneditable.
[0096] Furthermore, when the client obtains the second verification sub-information with (NM) characters from the server 10F, it responds to the information input operation for the input character area and displays the second verification sub-information in the input character area. Here, the second verification sub-information refers to the remaining code bits generated by the server 10F excluding the first verification sub-information. At this time, the client can determine the first and second verification sub-information in the verification information display area as verification information used for data security verification. Here, the verification information refers to the complete text verification code formed after the interaction between the target terminal device and the server 10F, which is a credential code used to confirm user operations (e.g., registering a client, accessing a client, and changing a password). The information type of this verification information can include numeric characters, English characters, Chinese characters, punctuation characters, etc., and will not be limited here.
[0097] Therefore, the verification information in this embodiment is not generated independently by the client or the server 10F, but is jointly generated by the client and the server 10F. That is, the verification information may include a first verification sub-information generated by the client and a second verification sub-information generated by the server 10F. This will reduce the risk of leakage of verification information when it is transmitted between the client and the server 10F, that is, other terminals will find it difficult to obtain complete verification information, thereby improving the security of verification information.
[0098] For better understanding, please refer to [link / reference]. Figure 2 , Figure 2 This is a schematic diagram illustrating a data interaction scenario provided in an embodiment of this application. For example... Figure 2 As shown, pages 210J, 220J, and 230J in this embodiment are all verification information entry pages displayed by the client at different times. The client here can be a client with verification information generation capabilities, and this client can be running on the aforementioned... Figure 1 Any terminal device in the terminal device cluster, for example, terminal device 100a.
[0099] Page 210J can be the terminal display page displayed by the client after responding to the trigger operation for the verification information generation function. Area 21Q (i.e., the verification information display area) in page 210J can be used to display the verification information jointly generated by the client and the server (taking 8 characters as an example). Area 21Q can include 8 display positions, specifically including the verification code formed by the display positions corresponding to characters Z1, Z2, Z3, Z5, Z6, Z7, and Z8. In this embodiment, the verification information is of numeric character type.
[0100] It should be understood that when the target object corresponding to the client (e.g., the target user accessing the client) modifies the password associated with the client, a trigger operation can be executed based on the client's verification information generation function. This trigger operation can include contact-based operations such as clicking and long-pressing, as well as contactless operations such as voice and gestures, and even trigger operations such as "shake," without limitation here. Furthermore, the client can respond to this trigger operation... Figure 2 The page 210J shown displays a first verification sub-information with M characters and an input character area in area 21Q (i.e., the verification information display area). The first verification sub-information refers to the verification sub-information 2X1 composed of characters Z3 (e.g., "5") and Z6 (e.g., "3"). The input character area refers to all display positions other than those corresponding to characters Z3 and Z6. The subscript 3 in character Z3 indicates that the character "5" is in the third display position within the verification information. The verification sub-information 2X1 generated by the client in each response to the verification information generation function is different; that is, the client's fixed character position information, number of characters, and character values are different each time.
[0101] Furthermore, the client can receive notification information sent by the server (e.g., notification information 2T), and in Figure 2The notification information 2T is displayed on page 220J. This notification information 2T can be "...Your verification code is 184722,...". This notification information 2T can include a second verification sub-information (e.g., verification sub-information 2X2) with 6 characters, generated by the server based on the first verification sub-information, the client's corresponding object information, and the total number of verification characters N (e.g., 8). These 6 characters can specifically include character Z1 (e.g., "1"), character Z2 (e.g., "8"), character Z4 (e.g., "4"), character Z5 (e.g., "7"), character Z7 (e.g., "2"), and character Z8 (e.g., "2").
[0102] Furthermore, the target object can perform an information input operation on region 22Q of page 220J, sequentially filling each character of the verification sub-information 2X2 into the input character area. At this time, the client can respond to the information input operation and display each character of the verification sub-information 2X2 in the input character area of region 23Q of page 230J. At this time, region 23Q can include 8 characters composed of the first verification sub-information and the second verification sub-information. Furthermore, the client can determine the 8 characters displayed in region 23Q (i.e., the string composed of "18547322") as the verification information provided by the verification information generation function.
[0103] Among them, due to Figure 2 The "5" and "3" in positions 3 and 6 of the page 210J shown are fixed and uneditable. The target cannot change the values in these two positions, thus preventing the forgery of a complete verification code and ensuring the security of the verification information. Furthermore, the verification sub-information 2X2 returned by the server is the unfilled portion of the verification code in page 210J. Therefore, even if verification sub-information 2X2 is leaked, the complete verification code cannot be deduced, further ensuring the security of the verification information. Thus, in this embodiment, the client can be used to randomly generate the fixed portion of the verification information (e.g., verification sub-information 2X1), and the server can be used to generate the remaining portion of the verification information (e.g., verification sub-information 2X2). Verification sub-information 2X1 and verification sub-information 2X2 can then be combined to form a complete verification information for data security verification. This means that the verification information is not generated solely by a computer device with verification information generation capabilities, but jointly by the client and server. This makes it difficult for other terminals to obtain the complete verification information, thereby reducing the risk of verification information leakage and improving the security of the verification information.
[0104] The specific implementation method of the client and server jointly generating verification information in this embodiment can be found in the following. Figures 3-7 The corresponding implementation examples.
[0105] Further, please see Figure 3 , Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 3 As shown, this method can be executed by a computer device with data security verification capabilities, which can be a terminal device (e.g., the one described above). Figure 1 The terminal device 100a shown can also be a server (e.g., the one described above). Figure 1 The server shown (10F) is not limited here. For ease of understanding, this application embodiment describes the method as being executed by a terminal device running a client, and the method may include at least the following steps S101-S103:
[0106] Step S101: In response to the trigger operation for the verification information generation function, display the first verification sub-information with M characters and the input character area with (NM) display positions in the verification information display area.
[0107] Here, N is a positive integer, and M is a positive integer less than N. Specifically, the target object (e.g., the target user accessing the client) can perform a trigger operation on the terminal display page of the client running on the terminal device, targeting the verification information generation function. In this embodiment, the terminal display page with the trigger verification information generation function can be referred to as the client service page. The trigger operation can include contact operations such as clicking and long-pressing, non-contact operations such as voice and gestures, and trigger operations such as "shake," which are not limited here. When the client responds to the trigger operation, the client can switch the client's display page from the client service page to the verification information filling page. The verification information filling page can include a verification information display area, and the verification information display area includes N display positions. Further, the client can display M characters in each of the M display positions in the verification information display area, and determine the M characters and their corresponding position information as the first verification sub-information, and determine the (NM) display positions other than the M display positions as the input character area.
[0108] When responding to a trigger operation for the verification information generation function, the client can generate a first verification sub-information with M characters. For example, when responding to this trigger operation, the client can obtain the total number of verification characters N. This total number of verification characters N can be determined by the client itself or requested by the client from the server; this is not limited here. For example, the client can send the object information of the target object to the server, so that the server can obtain the object security level of the target object based on this object information, and then determine the total number of verification characters N of the verification information to be generated based on the object security level. For example, if the object security level of the target object is low, the server can determine to increase the total number of verification characters to increase the complexity of the verification information, thereby improving the security of the subsequent verification information. Further, the client can determine the number of fixed characters M based on the total number of verification characters N, where N is a positive integer greater than M. Further, the client can obtain the information character area associated with the verification information, and then determine M characters from this information character area. At the same time, the client can also determine the position information of M characters in the verification information, and then determine the first verification sub-information used to constitute the verification information based on the M characters and their respective position information.
[0109] The verification information can be of a single type. For example, if the verification information is of numeric character type, the information character area (e.g., the first information character area) can include 10 numeric characters consisting of the characters "0" to "9". Alternatively, if the verification information is of English character type, the information character area (e.g., the second information character area) can include 26 English characters consisting of the characters "a" to "z". The characters in the second information character area can be uppercase or lowercase letters; this is not limited here. Or, if the verification information is of Chinese character type, the information character area (e.g., the third information character area) can include commonly used Chinese characters selected based on a Chinese dictionary. Optionally, the verification information can also be of a non-single type, i.e., more than one type of information. For example, if the verification information is composed of both numeric and English character types, then the information character area can include both the first and second information character areas mentioned above.
[0110] It is understood that the first verification sub-information in this application embodiment may refer to information randomly generated by the client, or generated by the client based on the object information of the target object, or generated by the client based on the object security level of the target object, or generated by the client based on the historical verification information of the target object. It will not be limited here.
[0111] If the first verification sub-information is randomly generated by the client, then when the client responds to the trigger operation for the verification information generation function, it can directly obtain the total number of verification characters N without relying on the external environment or external information, and then randomly determine a fixed number of characters M that is less than N. Furthermore, the client can obtain the information character area associated with the verification information, and then determine M characters from this information character area. At this point, the client can determine the position information of these M characters in the verification information, and then, based on these M characters and their corresponding position information, determine the first verification sub-information used to constitute the verification information.
[0112] For example, when the total number of verification characters N is 8, the number of fixed characters M randomly determined by the client can be 3. Further, the client can obtain the information character area associated with the verification information. When the information character area is the first information character area (e.g., numbers between 0 and 9), the client can randomly obtain 3 characters, specifically including character 1 (e.g., "2"), character 2 (e.g., "5"), and character 3 (e.g., "2"). Each character obtained by the client can be the same or different; this is not limited here. At this point, the client can randomly determine the position information of each of these 3 characters in the verification information. For example, the client can determine that the position information of character 1 is the second character in the verification information, the position information of character 2 is the fifth character in the verification information, and the position information of character 3 is the sixth character in the verification information. This means that character Z2 in the verification information is "2", character Z5 is "5", and Z6 is "2". Furthermore, the client can determine the first verification sub-information used to construct the verification information based on these three characters and their corresponding position information, for example, a string composed of "252". It can be understood that the M characters in the first verification sub-information are randomly selected from the information character area during generation, and the position of each character in the verification information is also randomly determined. That is, the number of fixed characters, each character, and the position of each character in the first verification sub-information generated by the client are different each time it responds to the verification process triggered by the target object. This means that other terminals will find it difficult to replicate the generation method of this first verification sub-information, thus effectively ensuring the flexibility and security of the first verification sub-information.
[0113] Optionally, if the first verification sub-information is generated by the client based on the object information of the target object, then when the client responds to the trigger operation for the verification information generation function, it can choose to use the external environment or external information. For example, the client can obtain object information associated with the client (i.e., the object information of the target object). Here, the object information of the target object may include the target object's contact information (e.g., mobile phone number, email address, social media account, etc.), its identification information in the client (e.g., account ID, etc.), user nickname, device identifier, etc. It is understood that in the specific embodiments of this application, data related to object information is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of related data comply with the relevant laws, regulations, and standards of the relevant countries and regions. Further, the client can obtain a hash conversion strategy for string conversion processing, and then perform string conversion processing on the object information based on the hash conversion strategy to obtain object conversion information. Based on this object conversion information, the first verification sub-information used to constitute the verification information can be determined.
[0114] For example, the hash transformation strategy obtained by client 'a' could be a hash function, also known as a hash algorithm, which is a method to create a small digital "fingerprint" from any kind of data. A hash function compresses a message or data into a digest, reducing the data size and fixing the data format. This function scrambles and mixes the data, recreating a fingerprint called a hash value. Understandably, the client can determine the information to be transformed from the object information. This information could be the contact information or account ID of the target object. At this point, the client can convert the information to be transformed into object transformation information with a transformation bit threshold (e.g., 2 bits) based on the transformation bit threshold in the hash transformation strategy, and then determine the first verification sub-information based on the object transformation information. For example, when the object transformation information is "13", this means that the number of fixed characters M determined by the client can be 2 bits, and the position information of these two characters is the first character and the third character in the verification information, respectively. Of course, the way the object transformation information determines the first verification sub-information can also include other forms, which will not be limited here. Furthermore, the client can randomly select two characters from the information character area associated with the verification information to form the first verification sub-information.
[0115] Optionally, if the first verification sub-information is generated by the client based on the object security level of the target object, then when the client responds to a trigger operation for the verification information generation function to trigger the verification process, the client can obtain the object security level of the target object, and then determine the number of fixed characters M based on the object security level of the target object. Further, the client can obtain the information character area associated with the verification information and determine M characters from the information character area. Simultaneously, the client can also determine the position information of the M characters in the verification information, and based on the M characters and their respective position information, determine the first verification sub-information used to constitute the verification information.
[0116] For ease of understanding, please further refer to Table 1, which is a mapping table related to object security levels provided in an embodiment of this application. As shown in Table 1:
[0117] Table 1
[0118] First level N-1 Second level N-2 … … Level (N-1) 1
[0119] Here, the first level is higher than the second level, the second level is higher than the third level, and so on. It should be understood that the client can determine the number of characters M to be fixed based on Table 1 and the object's security level. For example, when the total number of verification characters is 8 and the object's security level is the highest (i.e., the first level), the client can determine the number of characters M to be fixed according to Table 1 as 7, meaning the first verification sub-information can include 7 characters. Alternatively, when the total number of verification characters is 8 and the object's security level is the lowest (i.e., the seventh level), the client can determine the number of characters M to be fixed according to Table 1 as 1, meaning the first verification sub-information can include 1 character.
[0120] Understandably, a higher object security level implies higher trustworthiness. In this case, the client can increase the number of characters in its generated first verification sub-information. This reduces the number of characters the client needs to request in the second verification sub-information from the server, meaning the user needs to fill in fewer characters, greatly improving user convenience. However, as the object security level decreases, the client can reduce the number of characters in its generated first verification sub-information and request a second verification sub-information with more characters from the server. This dynamic adjustment of the character counts in the first and second verification sub-information effectively ensures the security of the verification information.
[0121] Optionally, if the first verification sub-information is generated by the client based on the historical verification information of the target object, then when the client responds to the trigger operation for the verification information generation function to trigger the verification process, the client can determine the number of fixed characters M based on the total number of verification characters N, and then obtain the information character area associated with the verification information, and determine M characters from the information character area. It can be understood that when determining the position information of each character in the verification information, the client can obtain the historical verification information of the target object, and then, based on the historical verification information of the target object, obtain the position information of each character in the historical first verification sub-information generated by the client. Furthermore, the client can count the number of times each position information is selected by the client, and further, based on the number of times each position information is selected by the client, filter the position information with more selections and determine the position information corresponding to each character from the filtered position information. Therefore, the client can determine the first verification sub-information based on each character and its corresponding position information.
[0122] For example, if the client finds that the first and third positions of the verification information have been used a lot in the past, the client can filter the first and third positions and determine the position information corresponding to each character from the other filtered position information. This means that the first verification sub-information generated by the client this time will not contain characters in the first position or characters in the third position.
[0123] It is understood that, in the process of generating the first verification sub-information in this embodiment, the client can first determine M characters from the information character area, and then determine the position information of each of the M characters in the verification information. Optionally, the client can also first determine the position information of each character in the verification information, and then determine the M characters from the information character area; the order is not limited here. It is understood that the first verification sub-information with M characters can be randomly generated by the client, or determined by the client based on object information and hash conversion strategy, or determined by the client based on the historical verification information or security level of the target object. This means that the first verification sub-information can be independent of the external environment and external information, or it can choose to use the external environment or external information, thus improving the flexibility of generating the first verification sub-information.
[0124] Furthermore, the client can display verification information in the designated area (e.g., the area mentioned above). Figure 2 The area shown (21Q) displays the first verification sub-information with M characters and the input character area with (NM) display positions.
[0125] In step S102, when the second verification sub-information with (NM) characters is obtained from the server, the second verification sub-information is displayed in the input character area in response to the information input operation for the input character area.
[0126] Specifically, upon receiving notification information from the server, the client can display a notification summary corresponding to the notification information on the verification information entry page. For example, the client can overlay the notification summary on the verification information entry page to remind the target object to obtain the second verification sub-information. Here, the notification information may include a second verification sub-information with (NM) characters. Furthermore, the client can respond to the target object's trigger operation on the notification summary, thereby displaying the complete notification information on the terminal display page of the terminal device. It should be understood that when the target object performs an information input operation on the input character area, the client can display (NM) characters from the second verification sub-information in the input character area according to the position information corresponding to the notification information.
[0127] It should be understood that the client can obtain the total number of verification characters N and the object information corresponding to the client. It can then use N, the first verification sub-information, and the client's corresponding object information as request parameters, and based on these parameters, generate a verification information generation request to be sent to the server. When the server receives this verification information generation request, it can parse the request and obtain and record the total number of verification characters N, the first verification sub-information, and the object information included in the request parameters. Furthermore, based on the total number of verification characters N and the number of characters M in the first verification sub-information, the server can determine the number of characters it needs to generate, i.e., (NM). Further, the server can obtain (NM) characters from the information character area associated with the verification information and determine the position information of each character in the verification information. Based on these (NM) characters and the position information corresponding to each character, the server can determine the second verification sub-information used to constitute the verification information. At this point, the server can generate notification information to be returned to the client based on the second verification sub-information, and then return the notification information to the terminal device associated with the target object based on the contact information in the object information.
[0128] For example, the server can concatenate each character in the second verification sub-information, generate a notification message based on the concatenated string, and send this notification message to the terminal device associated with the target object in any form, such as SMS, email, telephone broadcast, or public account notification. Furthermore, the client can obtain the second verification sub-information with (NM) characters sent by the server based on the notification message. The client's verification information entry page can include a verification information display area, which may include the already fixed first verification sub-information and an area for characters to be entered. When the target object learns of the second verification sub-information sent by the server, it can perform an information input operation in the verification information display area to fill in the second verification sub-information. For example, the target object can sequentially fill in each character of the second verification sub-information in the verification information display area. The client can respond to the information input operation and display the second verification sub-information in the area for characters to be entered.
[0129] Step S103: The first verification sub-information and the second verification sub-information in the verification information display area are determined as verification information for data security verification.
[0130] Specifically, such as Figure 2 As shown, the client can determine the first verification sub-information (e.g., "53") fixedly displayed in area 23Q of page 230J and the second verification sub-information (e.g., "184722") displayed in the input character area as the verification information provided by the verification information generation function, that is, the 8 characters consisting of "18547322".
[0131] In this embodiment, the verification information is not generated independently by the client or the server, but jointly by the client and the server. That is, the verification information may include a first verification sub-information generated by the client and a second verification sub-information generated by the server. This reduces the risk of leakage of the verification information during transmission between the client and the server, making it difficult for other terminals to obtain the complete verification information, thereby improving the security of the verification information.
[0132] Further, please see Figure 4 , Figure 4 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 4 As shown, this method can be executed interactively by a terminal device running a client and a server. The terminal device can be one of the aforementioned... Figure 1 Any terminal device in the terminal device cluster shown, for example, terminal device 100a. The server can be any of the aforementioned terminal devices. Figure 1The server 10F is shown. This method may include at least the following steps S201-S206:
[0133] Step S201: The client responds to the trigger operation of the verification information generation function and generates the first verification sub-information with M characters.
[0134] The first verification sub-information may include M characters, where M is a positive integer. Specifically, the target object (e.g., the target user accessing the client) can perform a trigger operation (e.g., registering a client or changing a password) on the client service page in response to the verification information generation function. When responding to this trigger operation, the client can obtain the total number of verification characters N. This total number of verification characters N can be determined by the client itself or requested by the client from the server; this is not limited here. Further, the client can determine the number of fixed characters M based on the total number of verification characters N, where N is a positive integer greater than M. Further, the client can obtain the information character area associated with the verification information, and then determine M characters from this information character area. Simultaneously, the client can also determine the position information of each of the M characters in the verification information, and then determine the first verification sub-information used to constitute the verification information based on the M characters and their respective position information. This first verification sub-information can be permanently displayed on the client's verification information entry page.
[0135] In step S202, the client generates a verification information generation request to be sent to the server based on the total number of verification characters N, the first verification sub-information, and the object information corresponding to the client.
[0136] Specifically, the verification information generation request instructs the server to generate a second verification sub-information with (NM) characters. The client can use the total number of verification characters N, the first verification sub-information, and the client's corresponding object information as request parameters, and then generate a verification information generation request to send to the server based on these parameters.
[0137] Step S203: The client sends a verification information generation request to the server.
[0138] The verification information generation request here can carry the first verification sub-information, the total number of verification characters N, and the object information of the target object.
[0139] In step S204, the server generates a second verification sub-information with (NM) characters based on N, the first verification sub-information, and the object information.
[0140] Specifically, when the server receives the verification information generation request, it can parse the request to obtain and record the total number of verification characters N, the first verification sub-information, and the object information included in the request parameters. Further, based on the total number of verification characters N and the number of characters M in the first verification sub-information, the server can determine the number of characters to be generated, i.e., (NM). Further, the server can obtain (NM) characters from the information character area associated with the verification information and determine the position information of each character in the verification information. Based on the (NM) characters and the position information corresponding to each of the (NM) characters, the server can determine the second verification sub-information used to constitute the verification information.
[0141] When generating the second verification sub-information, the server can rely on the target object's object information. Specifically, when the server determines that the required number of characters to be generated is (NM), it can obtain the target object's contact information (e.g., phone number, account ID, etc.) from the target object's object information. Then, it can randomly select (NM) characters from this contact information and determine the position of each character in the verification information to obtain the second verification sub-information. For example, if the server determines that the required number of characters to be generated is 3, and the target object's account ID is "123a53a6c32", the server can randomly select 3 characters (e.g., 136) from the target object's account ID as characters to constitute the second verification sub-information. Alternatively, it can select the three most frequently occurring characters from the target object's account ID (e.g., 3a2) as characters to constitute the second verification sub-information; this is not a limitation.
[0142] Optionally, when generating the second verification sub-information, the server may not rely on the object information of the target object. That is, when the server determines that the required number of characters to be generated is (NM), the server can determine the information character region associated with the verification information. For example, the information character region may include an information character region associated with numeric character types (e.g., the first information character region) and an information character region associated with English character types (e.g., the second information character region). The server can randomly select (NM) characters from these two information character regions as characters to constitute the second verification sub-information.
[0143] Therefore, it can be seen that when generating the second verification sub-information, the server can rely on the object information of the target object or not. This improves the flexibility of the second verification sub-information generation and can effectively reduce the possibility of other unauthorized users forging the second verification sub-information by knowing the generation strategy, thereby improving the security of the verification information.
[0144] In step S205, the server returns the second verification sub-information to the client.
[0145] Specifically, the server can generate notification information to be returned to the client based on the second verification sub-information, and then return the notification information to the terminal device associated with the target object based on the contact information in the object information. For example, the server can concatenate each character in the second verification sub-information, generate notification information based on the concatenated string, and send the notification information to the terminal device associated with the target object in any form, such as SMS, email, telephone broadcast, or public account notification.
[0146] In step S206, when the client receives the second verification sub-information, it assembles verification information with N characters based on the second verification sub-information and the first verification sub-information.
[0147] Here, the verification information is used for data security verification; the number of characters in the verification information is N. Specifically, the client can receive a second verification sub-information with (NM) characters sent by the server. The client's verification information filling page can include a verification information display area, which can include the already fixed first verification sub-information and a character input area. When the target object receives the second verification sub-information sent by the server, it can perform an information input operation on the verification information display area to fill in the second verification sub-information. For example, the target object can sequentially fill in each character of the second verification sub-information in the verification information display area. The client can respond to the information input operation and display the second verification sub-information in the character input area. At this time, the verification display area can include N characters composed of the first and second verification sub-information. Further, the client can determine the N characters displayed in the verification information display area as the verification information provided by the verification information generation function.
[0148] For specific implementation methods of steps S201-S206, please refer to the above. Figure 3 The descriptions of steps S101-S103 in the corresponding embodiments will not be repeated here.
[0149] For better understanding, please refer to [link / reference]. Figure 5 , Figure 5 This is a schematic diagram illustrating a process for performing data security verification on verification information, as provided in an embodiment of this application. For example... Figure 5 As shown, the embodiments of this application can be executed interactively by a client with verification information generation function and a server with data security verification function. The client can run on the aforementioned... Figure 1Any terminal device in the terminal device cluster in the corresponding embodiment, for example, terminal device 100a. The server can be one of the aforementioned... Figure 1 The corresponding embodiment is server 10F.
[0150] like Figure 5 As shown, in this embodiment, the target object can be a target user used to trigger a verification process associated with a client. The target object can execute step S51, inputting its object information. This object information may include the target object's contact information (e.g., mobile phone number, email address, social media account, etc.), its identification information in client a (e.g., account ID, etc.), user nickname, device identifier, etc. Further, when the target object triggers the verification process on the client-server page, the client can execute step S52, responding to the target object's trigger operation for the verification information generation function, generating first verification sub-information with M characters, where M is a positive integer. Each character occupies one position. Further, the client can display this first verification sub-information fixedly on the client's verification information entry page (e.g., ...). Figure 2 (See page 210J). Simultaneously, the client can generate a verification information generation request to be sent to the server based on the total number of verification characters N, the first verification sub-information, and the client's corresponding object information. The client's generation process for the first verification sub-information can be found above. Figure 3 Step S101 in the corresponding embodiment will not be described again here.
[0151] Furthermore, the client can send a verification information generation request to Figure 5 The server shown is configured to execute step S53, parse the verification information generation request, record the request information in the verification information generation request, and then generate a second verification sub-information with (NM) characters (e.g., Figure 2 (See "184722"). The request information here can include the first verification sub-information carried in the verification information generation request, the total number of verification characters N, and the object information of the target object. At this point, the server can determine the verification information used to perform data security verification on the client based on the first verification sub-information sent by the client and the second verification sub-information it generates itself. For example, the server can keep the position and value of the original first verification sub-information unchanged, and sequentially fill each character of the second verification sub-information into all positions except the first verification sub-information. Then, the N filled strings can be concatenated to form complete verification information, which can then be saved.
[0152] Furthermore, the server can generate notification information to be returned to the target object based on the verification information or the second verification sub-information. It is understood that if the notification information returned by the server is determined based on the verification information, the server can encrypt the verification information to effectively ensure the security of the verification information during data transmission. If the notification information returned by the server is determined based on the second verification sub-information, since the second verification sub-information is not a complete verification code, the server does not need to encrypt the second verification sub-information, thus effectively improving the efficiency of the second verification sub-information during data transmission. Of course, to effectively ensure the security of the second verification sub-information during data transmission, the server can also encrypt the second verification sub-information.
[0153] Therefore, from the perspective of information dependence, the client exhibits a high degree of independence. The specific characters, number of fixed characters, and location information of the first verification sub-information can be generated completely randomly, without relying on any external information. This ensures that the system is unaffected by any real or fake external environment or information, making it difficult to reverse engineer or simulate. Secondly, since the first verification sub-information is randomly generated each time the process is triggered, even if the second verification sub-information is leaked, other terminals cannot reverse engineer the complete verification code information. Furthermore, even if the complete verification information is leaked, it is impossible to construct the verification information by inputting it on the verification information filling page provided by the client on other terminal devices. This makes it impossible to intercept or fraudulently obtain verification information. As described in the above steps and flowchart, from the user's perspective, there is no additional operational cost and no impact on user experience. From the system's perspective, the verification process is completely consistent with the verification process of ordinary verification codes, without increasing the number of additional communications. This means that the embodiments of this application improve the security of the verification information sending and verification system at zero cost.
[0154] It should be understood that when the client receives the notification information, the target object can obtain the second verification sub-information from the notification information. Then, when the target object sequentially fills in each character of the second verification sub-information on the verification information entry page, the client can display the second verification sub-information in the input character area of the verification information entry page. Further, the client can execute step S54 to assemble verification information with N characters based on the first and second verification sub-information. For example... Figure 2 As shown, the eight characters displayed in area 23Q of page 230J are used as the verification information determined by the client.
[0155] The client can send verification information to the server, causing the server to execute step S55 to verify the verification information and generate a verification result. It can be understood that when the server receives the verification information returned by the client, it can obtain verification information used for data security verification of the verification information. This verification information is the complete information recorded by the server based on the first verification sub-information sent by the client and the second verification sub-information generated by the server itself (e.g., the aforementioned...). Figure 2 The complete verification code "18547322" displayed in area 23Q indicates that the verification information may include a first verification sub-information and a second verification sub-information. Furthermore, the server can directly compare the verification information and the validation information to obtain a comparison result. For example, if the comparison result indicates that the validation information matches the verification information, the server can generate a verification result indicating successful verification. If the comparison result indicates that the validation information does not match the verification information, the server can generate a verification result indicating failed verification. Therefore, this embodiment does not require additional verification steps and does not increase the operational burden on users and the server, achieving a higher security index for the verification system with zero-cost modification investment.
[0156] Optionally, to improve the server's verification efficiency, the server can further split the verification information into first and second sub-information. For example, based on the position information of each character in the first verification sub-information sent by the client, the server can identify characters with the same position information as the first sub-information and identify characters with the remaining position information as the second sub-information. The comparison priority of the first sub-information is higher than that of the second sub-information. Based on this, the server can first compare the first sub-information with the first verification sub-information to obtain a first comparison result. If the first comparison result indicates that the first sub-information and the first verification sub-information are inconsistent, the server does not need to compare the first sub-information and the second verification sub-information and can directly generate an information verification result indicating verification failure. Optionally, if the first comparison result indicates that the first sub-information and the first verification sub-information are consistent, the server needs to continue comparing the second sub-information with the second verification sub-information to obtain a second comparison result, and then generate an information verification result based on the second comparison result. If the second comparison result indicates that the second sub-information and the second verification sub-information are consistent, the server can generate a verification result indicating successful verification. If the second comparison result indicates that the second sub-information and the second verification sub-information are inconsistent, the server can generate a verification result indicating failed verification.
[0157] Furthermore, the server can return the information verification result to the client, causing the client to execute step S56 and respond to the information verification result. It can be understood that if the information verification result indicates that the verification information matches the validation information, the client can determine that the information verification result is a successful verification result and display a verification success notification matching the successful verification result; alternatively, if the information verification result indicates that the verification information does not match the validation information, the client can determine that the information verification result is a verification failure result and display a verification failure notification matching the verification failure result.
[0158] Therefore, the M characters randomly generated by the client can be randomly filled into M positions in the verification information display area. The first verification sub-information generated each time the verification process is triggered is different, and the remaining part of the verification information, excluding the first verification sub-information, is generated by the server. Thus, even if the communication information (e.g., a verification code returned via SMS) is leaked, other terminals cannot obtain the complete verification code. Furthermore, even if the complete verification information is leaked, because the specific characters generated by the client based on the verification information generation function, the number of fixed characters M, and the position information of each character are different each time, and are uneditable, even if other terminals obtain the complete verification information, they cannot input it on their running clients, thus preventing the server's verification process from being triggered.
[0159] Optionally, in this embodiment, both the client and the server can be blockchain nodes in a blockchain network to execute steps S201-S206. The blockchain network is a peer-to-peer (P2P) network, a distributed application architecture that distributes tasks and workloads among users; it is a network or grouping of peer-to-peer computing models at the application layer. The blockchain system corresponding to this blockchain network can be a distributed system formed by multiple blockchain nodes connected through network communication. This blockchain system can include multiple blockchain nodes, and these blockchain nodes can be any form of computer device accessing the blockchain network. For example, the computer device can be a client or a server accessing the blockchain network; the specific form of the blockchain node is not limited here.
[0160] Understandably, when the client executes step S202 above to generate a verification information generation request based on the total number of verification characters N, the first verification sub-information, and the object information of the target object, it can determine the information to be signed based on the total number of verification characters N, the first verification sub-information, and the object information corresponding to the client. Further, the client can obtain the object private key of the target object associated with the client, and then perform signature processing on the information to be signed based on this object private key, thereby obtaining the client-signed information. At this point, the client can generate a verification information generation request to be sent to the server based on the client-signed information and the information to be signed. Here, the client-signed information is used to instruct the server to verify the information to be signed.
[0161] Furthermore, before executing step S204 upon receiving the verification information generation request, the server can pre-determine whether the client sending the verification information generation request is legitimate. For example, upon receiving the verification information generation request from the client, the server can obtain the object public key corresponding to the object private key. Further, the server can verify the client's signature information based on the object public key to obtain the verification result. If the verification result indicates verification failure, the server can determine that the client is an illegitimate node and classify the verification information generation request as an illegitimate request. In this case, the server does not need to execute step S204 and can directly return notification information indicating that the client is an illegitimate node to the client. Optionally, if the verification result indicates verification success, the client is determined to be a legitimate node and the verification information generation request is classified as a legitimate request. In this case, the server can continue executing step S204 to generate second verification sub-information with (NM) characters based on N, the first verification sub-information, and the object information. Further, the server can execute step S205 to return the second verification sub-information. To ensure the security of the second verification sub-information during data transmission, the server can encrypt the second verification sub-information to obtain encrypted data information. Then, step S205 can be executed to return the encrypted data information to the client. At this point, the client can decrypt the encrypted data information using the object's private key corresponding to the object's public key, thereby obtaining the second verification sub-information. Then, step S206 can be executed to assemble the verification information provided by the verification information generation function based on the second verification sub-information and the first verification sub-information.
[0162] For better understanding, please refer to [link / reference]. Figure 6 , Figure 6 This is a schematic diagram illustrating a data transmission scenario in a blockchain context, as provided in an embodiment of this application. Figure 6As shown, in this embodiment of the application, both the client a and the server 6F in the terminal device 6A can be blockchain nodes in a blockchain network. For example, the terminal device 6A can be the aforementioned Figure 1 Any terminal device in the terminal device cluster in the corresponding embodiment, for example, terminal device 100a. The server 6F in this embodiment can be any of the aforementioned... Figure 1 The corresponding embodiment is server 10F.
[0163] like Figure 6 As shown, the verification sub-information 60X1 can be the verification information of M characters generated by client a when responding to the target object's trigger operation for generating verification information, where M is a positive integer. It should be understood that client a can concatenate the total number of verification characters N, the verification sub-information 60X1, and the object information 60D corresponding to the target object to obtain... Figure 6 The information to be signed is shown as 61k. At this time, client a can sign the information to be signed 61k based on the object private key of the target object, obtaining client signature information 62k corresponding to the information to be signed 61k. It can be understood that client a can obtain the hash calculation rule for the information to be signed 61k, which can be a digest algorithm pre-agreed between client a and other blockchain nodes in the blockchain network (e.g., server 6F). Therefore, client a can perform hash calculation on the information to be signed 61k based on the hash calculation rule to obtain digest information (e.g., digest information h) of the information to be signed 61k. In this embodiment, the digest information h of the information to be signed 61k determined by client a can be referred to as the first digest information. Further, client a can sign the first digest information based on the object private key of the target object, thereby obtaining... Figure 6 The client signature information shown is 62k.
[0164] Furthermore, the terminal device 6A can generate, based on the information to be signed 61k and the client signature information 62k, Figure 6The verification information generation request 60q shown can be sent to server 6F, so that server 6F can verify the client signature information 62k based on the object public key corresponding to the object private key (i.e., the target object's object public key) and obtain the verification result. It can be understood that server 6F can obtain the target object's object public key, and then verify the client signature information 62k based on that object public key to obtain the first digest information of the information to be signed 61k. Simultaneously, server 6F can also obtain the same hash calculation rule as client a, and perform hash calculation on the information to be signed 61k to obtain the digest information (e.g., digest information H) of the information to be signed 61k determined by server 6F. In this embodiment, the digest information H of the information to be signed 61k determined by server 6F can be referred to as the second digest information.
[0165] At this point, server 6F can compare the first digest information with the second digest information to obtain the signature verification result, thereby determining whether the information to be signed 61k has been tampered with. It is understood that if the first digest information and the second digest information are different, server 6F can determine that the signature verification result indicates verification failure. In this case, server 6F can determine that client a is an illegitimate node and classify the received verification information generation request 60q as an illegitimate request. Optionally, if the first digest information and the second digest information are the same, server 6F can determine that the signature verification result indicates verification success. This means that the information to be signed 61k has not been tampered with, and the information to be signed 61k was indeed sent by client a. In this case, server 6F can determine that client a is a legitimate node and classify the received verification information generation request 60q as a legitimate request.
[0166] Understandably, when the signature verification result determined by server 6F indicates successful verification, server 6F can generate a second verification sub-information with (NM) characters based on N, verification sub-information 60X1, and object information 60D (e.g., Figure 6 The verification sub-information 60X2 is shown. To ensure the security of verification sub-information 60X2 during data transmission, server 6F can encrypt verification sub-information 60X2 to obtain encrypted data information, which can then be returned to client a. At this time, client a can decrypt the encrypted data information using the object private key corresponding to the object public key, thereby obtaining verification sub-information 60X2. Based on verification sub-information 60X2 and verification sub-information 60X1, verification information provided by the verification information generation function can then be constructed.
[0167] Furthermore, it can be understood that after executing step S204 above, the server can also determine the verification information used to verify the data security of the client based on the first verification sub-information sent by the client and the second verification sub-information generated by itself. Due to the immutability of the blockchain, in order to improve the data security of the stored verification information, the server can package the verification information to obtain the unverified block to be written into the blockchain network, and broadcast the unverified block to the consensus nodes in the blockchain network, so that the consensus nodes can reach a consensus on the obtained unverified block, thereby obtaining a consensus result to be returned to the server; where the consensus nodes and the server are both blockchain nodes in the blockchain network. If there is a consensus result in the consensus result that exceeds the consensus threshold, indicating successful consensus, the server can determine that the blockchain nodes in the blockchain network have reached a consensus and write the unverified block as the target block into the blockchain.
[0168] For easier understanding, please refer to Figure 7 , Figure 7 This is a schematic diagram illustrating a scenario where verification information is uploaded to the blockchain, as provided in an embodiment of this application. Figure 7 As shown, in this embodiment, server 7F can be a blockchain node in a blockchain network, and server 7F can be the aforementioned... Figure 1 The corresponding embodiment is server 10F. Figure 7 Each consensus node 710g and server 7F in the consensus node network shown belong to the same blockchain network.
[0169] in, Figure 7 The blockchain 7L shown can be a shared blockchain among all nodes in the blockchain network to which server 7F belongs. Each node can access the information stored in blockchain 7L. Blockchain 7L includes blocks 70a, 70b, ..., 70n, and a target block. Block 70a can be considered the genesis block of blockchain 7L. The target block in blockchain 7L contains the verification information determined by server 7F based on the first verification sub-information and the second verification sub-information.
[0170] It is understandable that server 7F, in this context, refers to... Figure 7When the verification information shown is written to blockchain 7L, the block 70n with the largest generation timestamp can be obtained from blockchain 7L. Further, server 7F can package this verification information to obtain the block to be verified to be written to blockchain 7L. At this time, server 7F can broadcast the block to be verified to consensus node 710g on the blockchain, so that consensus node 710g can reach a consensus on the obtained block to be verified and obtain a consensus result. If the consensus result returned by consensus node 710g contains more than the consensus threshold (e.g., 1 / 2), indicating successful consensus, then server 7F can determine that the blockchain nodes in the blockchain network have reached a consensus, and can then write the block to be verified as the target block into the aforementioned blockchain 7L, that is, make the block to be verified the next block after block 70n. The verification information in the target block is used to perform data security verification on the verification information when server 7F receives the verification information sent by the client.
[0171] In this embodiment, the verification information is not generated independently by the client or the server, but jointly by both. Randomization and fixation techniques render forgery and brute-force attacks ineffective. Furthermore, this embodiment does not require additional verification steps and does not increase the operational burden on users or the server, achieving a higher security index for the verification system with zero-cost modification investment. It is understood that the first verification sub-information with M characters can be randomly generated by the client or determined by the client based on object information and hash conversion strategies. This means that the first verification sub-information can be independent of external environment and information, or it can choose to use external environment or information; that is, the generation of the first verification sub-information has a certain degree of flexibility. In addition, when generating the second verification sub-information with (NM) characters, the server can send only the second verification sub-information (i.e., a portion of the verification information) or send the complete information including the second verification sub-information. Since the first verification information is fixedly displayed on the client, this greatly improves the security of the verification information. Moreover, when both the server and the client are blockchain nodes in the blockchain network, the immutability of the blockchain and the encryption and signing processes during data transmission further ensure the security of the verification information.
[0172] Further, please see Figure 8 , Figure 8 This is a schematic diagram of the structure of a data processing apparatus provided in an embodiment of this application. The data processing apparatus 1 can be a computer program (including program code) running on a computer device; for example, the data processing apparatus 1 is an application software. The data processing apparatus 1 can be used to execute corresponding steps in the method provided in the embodiments of this application. Figure 8As shown, the data processing device 1 can run on a client with verification information generation capabilities, and this client can be used in the aforementioned... Figure 1 The corresponding embodiment refers to any terminal device in the terminal device cluster, for example, terminal device 100a. The data processing device 1 may include: a first sub-information display module 10, a second sub-information display module 20, a verification information determination module 30, a signature-to-be-signed information determination module 40, a signature processing module 50, a request generation module 60, a verification information sending module 70, an information verification result receiving module 80, a success notification display module 90, and a failure notification display module 91.
[0173] The first sub-information display module 10 is used to respond to the trigger operation for the verification information generation function, and to display the first verification sub-information with M characters and the input character area with (NM) display positions in the verification information display area; N is a positive integer and M is a positive integer less than N.
[0174] The first sub-information display module 10 includes: a page switching unit 101, a first sub-information determination unit 102, a first sub-information generation unit 103, and a first sub-information display unit 104.
[0175] The page switching unit 101 is used to respond to the trigger operation for the verification information generation function on the client's client service page, and switch the client's display page from the client service page to the verification information filling page; the verification information filling page includes a verification information display area; the verification information display area includes N display positions.
[0176] The first sub-information determination unit 102 is used to display M characters in M display positions in the verification information display area, determine the M characters and their corresponding position information as the first verification sub-information, and determine the (NM) display positions other than the M display positions as the input character area.
[0177] The first sub-information generation unit 103 is used to generate a first verification sub-information with M characters in response to a trigger operation for the verification information generation function on the client's client service page.
[0178] The first sub-information generation unit 103 includes: a character quantity determination sub-unit 1031, a character determination sub-unit 1032, a first determination sub-unit 1033, an object information acquisition sub-unit 1034, a string conversion sub-unit 1035, and a second determination sub-unit 1036.
[0179] The character quantity determination subunit 1031 is used to respond to the trigger operation for the verification information generation function in the client service page of the client, obtain the total number of verification characters N, and determine the number of solidified characters M based on N;
[0180] The character determination subunit 1032 is used to obtain the information character area associated with the verification information and determine M characters from the information character area;
[0181] The first determining subunit 1033 is used to determine the position information of M characters in the verification information, and based on the M characters and their respective position information, to determine the first verification sub-information used to constitute the verification information; the first verification sub-information is used to be fixedly displayed on the verification information filling page of the client.
[0182] The object information acquisition subunit 1034 is used to respond to the trigger operation for the verification information generation function and acquire object information associated with the client.
[0183] The string conversion subunit 1035 is used to perform string conversion processing on object information based on a hash conversion strategy to obtain object conversion information;
[0184] The second determining subunit 1036 is used to determine, based on object conversion information, the first verification sub-information used to constitute the verification information.
[0185] The specific implementation methods of the character quantity determination subunit 1031, character determination subunit 1032, first determination subunit 1033, object information acquisition subunit 1034, string conversion subunit 1035, and second determination subunit 1036 can be found above. Figure 3 The description of the first verification sub-information in the corresponding embodiments will not be repeated here.
[0186] The first sub-information display unit 104 is used to display a first verification sub-information with M characters and an input character area with (NM) display positions in the verification information display area.
[0187] The specific implementation methods of the page switching unit 101, the first sub-information determination unit 102, the first sub-information generation unit 103, and the first sub-information display unit 104 can be found in the above description. Figure 3 The description of step S101 in the corresponding embodiments will not be repeated here.
[0188] The second sub-information display module 20 is used to respond to an information input operation for the character area to be input when it obtains second verification sub-information with (NM) characters from the server, and display the second verification sub-information in the character area to be input.
[0189] The second sub-information display module 20 includes: a summary display unit 201, a notification information display unit 202, a first display unit 203, an encrypted information receiving unit 204, a decryption processing unit 205, and a second display unit 206.
[0190] The summary display unit 201 is used to display a summary of the notification information when the notification information returned by the server is obtained; the notification information includes second verification sub-information with (NM) characters;
[0191] The notification information display unit 202 is used to display notification information in response to a trigger operation on the notification summary;
[0192] The first display unit 203 is used to respond to information input operations for the input character area and display (NM) characters in the second verification sub-information in the input character area according to the position information corresponding to the notification information.
[0193] Both the client and the server are blockchain nodes in the blockchain network;
[0194] The encrypted information receiving unit 204 is used to receive encrypted data information sent by the server; the encrypted data information is obtained by the server encrypting the second verification sub-information using the public key of the object corresponding to the client.
[0195] The decryption processing unit 205 is used to decrypt the encrypted data information using the object private key corresponding to the object public key to obtain the second verification sub-information;
[0196] The second display unit 206 is used to respond to an information input operation for the input character area and display (NM) characters in the second verification sub-information in the input character area.
[0197] The specific implementation methods of the summary display unit 201, notification information display unit 202, first display unit 203, encrypted information receiving unit 204, decryption processing unit 205, and second display unit 206 can be found above. Figure 3 The description of step S102 in the corresponding embodiment will not be repeated here.
[0198] The verification information determination module 30 is used to determine the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification.
[0199] Both the client and the server are blockchain nodes in the blockchain network;
[0200] The module 40 for determining the information to be signed is used to determine the information to be signed based on the total number of verification characters N, the first verification sub-information, and the object information corresponding to the client.
[0201] The signature processing module 50 is used to obtain the object private key associated with the client, and perform signature processing on the information to be signed based on the object private key to obtain the client signature information;
[0202] The request generation module 60 is used to generate a verification information generation request to be sent to the server based on the client signature information and the information to be signed; the client signature information is used to instruct the server to verify the information to be signed.
[0203] The verification information sending module 70 is used to send verification information to the server, so that the server can generate an information verification result based on the received verification information and the verification information associated with the client stored in the server; the verification information is the complete information recorded by the server based on the first verification sub-information and the second verification sub-information sent by the client;
[0204] The information verification result receiving module 80 is used to receive the information verification result returned by the server.
[0205] The success notification display module 90 is used to determine the information verification result as a successful verification result if the information verification result indicates that the verification information is consistent with the verification information, and to display a successful verification notification that matches the successful verification result.
[0206] The failure notification display module 91 is used to determine that the information verification result is a verification failure result if the information verification result indicates that the verification information is inconsistent with the verification information, and to display a verification failure notification that matches the verification failure result.
[0207] The specific implementation methods of the first sub-information display module 10, the second sub-information display module 20, the verification information determination module 30, the signature-to-be-signed information determination module 40, the signature processing module 50, the request generation module 60, the verification information sending module 70, the information verification result receiving module 80, the success notification display module 90, and the failure notification display module 91 can be found above. Figure 3 The descriptions of steps S101-S103 in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0208] Further, please see Figure 9 , Figure 9This is a schematic diagram of the structure of a data processing apparatus provided in an embodiment of this application. The data processing apparatus 2 can be a computer program (including program code) running on a computer device; for example, the data processing apparatus 2 is application software. The data processing apparatus 2 can be used to execute corresponding steps in the method provided in the embodiments of this application. Figure 9 As shown, the data processing device 2 can operate on a computer device with data security verification functions, and this computer device can be the aforementioned Figure 1 The corresponding embodiment is server 10F. The data processing device 2 may include: a request acquisition module 100, a second sub-information generation module 200, a second sub-information sending module 300, a public key acquisition module 400, a signature verification result determination module 500, a verification success module 600, a verification failure module 700, a verification information determination module 800, a packaging module 900, a block broadcasting module 1000, a block writing module 1100, a verification information acquisition module 1200, a verification information splitting module 1300, a first comparison module 1400, a second comparison module 1500, a first result generation module 1600, and a second result generation module 1700.
[0209] The request acquisition module 100 is used to acquire the verification information generation request sent by the client. The verification information generation request is generated by the client based on the total number of verification characters N, the first verification sub-information, and the client's corresponding object information. The first verification sub-information is used to constitute the verification information, and the first verification sub-information consists of M characters displayed in the verification information display area when the client responds to the trigger operation for the verification information generation function. The first verification sub-information includes M characters; M is a positive integer; N is a positive integer greater than M.
[0210] The second sub-information generation module 200 is used to generate a second verification sub-information with (NM) characters based on N, the first verification sub-information, and the object information;
[0211] The second sub-information sending module 300 is used to send the second verification sub-information to the client so that the client responds to the information input operation for the input character area in the verification information display area, displays the second verification sub-information in the input character area, and determines the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification.
[0212] In this context, both the server and the client are blockchain nodes in the blockchain network; the verification information generation request includes information to be signed and client signature information; the client signature information is obtained by the client signing the information to be signed using the object's private key; the information to be signed is determined by the first verification sub-information and the object information corresponding to the client;
[0213] The public key acquisition module 400 is used to obtain the object public key corresponding to the object private key when it receives a verification information generation request sent by the client.
[0214] The signature verification result determination module 500 is used to verify the client signature information based on the object public key and obtain the signature verification result;
[0215] The successful verification module 600 is used to determine that the client is a legitimate node if the signature verification result indicates successful verification, and to determine the verification information generation request as a legitimate request.
[0216] The verification failure module 700 is used to determine that the client is an illegal node and to determine the verification information generation request as an illegal request if the signature verification result indicates that the verification has failed.
[0217] The server is a blockchain node in the blockchain network;
[0218] The verification information determination module 800 is used to determine the verification information for data security verification of the client based on the first verification sub-information and the second verification sub-information sent by the client when generating the second verification sub-information;
[0219] The packaging module 900 is used to package the verification information to obtain the unverified block of the blockchain to be written into the blockchain network.
[0220] The block broadcasting module 1000 is used to broadcast the block to be verified to the consensus nodes in the blockchain network, so that the consensus nodes can reach a consensus on the obtained block to be verified and obtain a consensus result to be returned to the server; the consensus nodes are blockchain nodes in the blockchain network.
[0221] The block writing module 1100 is used to determine that the blockchain nodes in the blockchain network have reached a consensus if there is a consensus result in the consensus result that exceeds the consensus threshold, indicating that the consensus is successful, and to write the block to be verified as the target block into the blockchain.
[0222] The verification information acquisition module 1200 is used to acquire verification information for data security verification of the verification information when it receives the verification information returned by the client; the verification information includes first verification sub-information and second verification sub-information.
[0223] The verification information splitting module 1300 is used to split the verification information to obtain the first splitting sub-information and the second splitting sub-information;
[0224] The first comparison module 1400 is used to compare the first split sub-information with the first verification sub-information to obtain the first comparison result;
[0225] The second comparison module 1500 is used to compare the second sub-information with the second verification sub-information if the first comparison result indicates that the first sub-information is consistent with the first verification sub-information, and to obtain the second comparison result.
[0226] The first result generation module 1600 is used to generate an information verification result indicating successful verification if the second comparison result indicates that the second split sub-information is consistent with the second verification sub-information.
[0227] The second result generation module 1700 is used to generate an information verification result indicating verification failure if the first comparison result indicates that the first split sub-information and the first verification sub-information are inconsistent.
[0228] The specific implementation methods of the following modules can be found above: request acquisition module 100, second sub-information generation module 200, second sub-information sending module 300, public key acquisition module 400, signature verification result determination module 500, verification success module 600, verification failure module 700, verification information determination module 800, packaging module 900, block broadcasting module 1000, block writing module 1100, verification information acquisition module 1200, verification information splitting module 1300, first comparison module 1400, second comparison module 1500, first result generation module 1600, and second result generation module 1700. Figure 4 The descriptions of steps S201-S206 in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0229] Further, please see Figure 10 , Figure 10 This is a schematic diagram of a computer device provided in an embodiment of this application. Figure 10 As shown, the computer device 3000 can be the above-mentioned Figure 2 Corresponding to client a or server 2F in the embodiment, the computer device 3000 may include: at least one processor 3001, such as a CPU; at least one network interface 3004; a user interface 3003; a memory 3005; and at least one communication bus 3002. The communication bus 3002 is used to implement communication between these components. The user interface 3003 may include a display screen and a keyboard. The network interface 3004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 3005 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 3005 may also be at least one storage device located remotely from the aforementioned processor 3001. Figure 10 As shown, the memory 3005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a device control application program.
[0230] exist Figure 10 In the computer device 3000 shown, the network interface 3004 is mainly used for network communication; the user interface 3003 is mainly used to provide an input interface for the user; and the processor 3001 can be used to call the device control application stored in the memory 3005 to achieve the desired result.
[0231] It should be understood that the computer device 3000 described in the embodiments of this application can execute the foregoing text. Figure 3 or Figure 4 The description of the data processing method in the corresponding embodiment can also be performed as described above. Figure 8 The corresponding embodiment refers to the data processing device 1 or Figure 9 The description of the data processing device 2 in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated here.
[0232] Furthermore, it should be noted that this application embodiment also provides a computer-readable storage medium storing a computer program executed by the aforementioned data processing device 1 or data processing device 2, and the computer program includes program instructions. When the processor executes the program instructions, it can execute the aforementioned... Figure 3 or Figure 4 The description of the data processing method in the corresponding embodiments is already provided and will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the computer-readable storage medium embodiments related to this application, please refer to the description of the method embodiments of this application. As an example, program instructions can be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network. These multiple computing devices distributed across multiple locations and interconnected via a communication network can constitute a blockchain system.
[0233] This application provides a computer program product or computer program, including a computer program / instructions, which, when executed by a processor, enable the computer device to perform the aforementioned... Figure 3 or Figure 4 The description of the data processing method in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0234] For further details, please see Figure 11 , Figure 11 This is a schematic diagram of the structure of a data processing system provided in an embodiment of this application. The data processing system 3 may include a data processing device 1a and a data processing device 2a. The data processing device 1a may be the one described above. Figure 8 Regarding the data processing device 1 in the corresponding embodiment, it is understood that the data processing device 1a can be integrated into the aforementioned client with verification information generation function, and the client can be used in the aforementioned... Figure 1 The terminal device in the terminal device cluster corresponding to the embodiment, for example, terminal device 100a, will not be described in detail here. The data processing device 2a can be one of the aforementioned... Figure 9 Regarding the data processing device 2 in the corresponding embodiment, it is understood that the data processing device 2a can be integrated into the aforementioned computer device with data security verification function, and the computer device can be the aforementioned Figure 1 The server 10F in the corresponding embodiment will not be described again here. Furthermore, the beneficial effects of using the same method will also not be described again. For technical details not disclosed in the data processing system embodiments of this application, please refer to the description of the method embodiments of this application.
[0235] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover a non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.
[0236] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0237] The methods and related apparatus provided in this application are described with reference to the method flowcharts and / or structural diagrams provided in this application. Specifically, each block of the method flowcharts and / or structural diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions are provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, create means for implementing the functions specified in one or more blocks of the flowcharts and / or one or more blocks of the structural diagrams. These computer program instructions may also be stored in a computer-readable storage medium capable of directing a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more blocks of the flowcharts and / or one or more blocks of the structural diagrams. These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the function specified in one or more processes in the flowchart and / or one or more blocks in the structural diagram.
[0238] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A data processing method, characterized in that, The method is executed by the client and includes: In response to a trigger operation for the verification information generation function, a first verification sub-information with M characters and an input character area with (NM) display positions are displayed in the verification information display area; where N is a positive integer and M is a positive integer less than N; the number M of fixed characters corresponding to the first verification sub-information, the M characters, and the position information of the M characters in the verification information display area are all randomly generated in response to the trigger operation for the verification information generation function; the first verification sub-information is not editable in the verification information display area. When the server receives second verification sub-information with (NM) characters, it responds to an information input operation for the input character area and displays the second verification sub-information in the input character area. The second verification sub-information is generated by the server based on the first verification sub-information sent by the client, the total number of verification characters N, and the client's object information. The server is also used to store verification information composed of the first verification sub-information and the second verification sub-information. The first verification sub-information and the second verification sub-information in the verification information display area are determined as verification information for data security verification; the server is also used to obtain the verification information and compare and verify the verification information through the verification information.
2. The method according to claim 1, characterized in that, The response is a trigger operation for the verification information generation function, which displays a first verification sub-information with M characters and an input character area with (NM) display positions in the verification information display area, including: In the client service page of the client, in response to the trigger operation for the verification information generation function, the display page of the client is switched from the client service page to the verification information filling page; the verification information filling page includes a verification information display area; the verification information display area includes N display positions; M characters are displayed in M display positions in the verification information display area. The M characters and their corresponding position information are determined as the first verification sub-information. The (NM) display positions other than the M display positions are determined as the input character area.
3. The method according to claim 1, characterized in that, When the second verification sub-information with (NM) characters is obtained from the server, in response to the information input operation for the input character area, the second verification sub-information is displayed in the input character area, including: Upon receiving notification information returned by the server, a notification summary corresponding to the notification information is displayed; the notification information includes second verification sub-information with (NM) characters; In response to a triggering action on the notification summary, the notification information is displayed; In response to an information input operation targeting the input character area, (NM) characters from the second verification sub-information are displayed in the input character area according to the position information corresponding to the notification information.
4. The method according to claim 1, characterized in that, The response is a trigger operation for the verification information generation function, which displays a first verification sub-information with M characters and an input character area with (NM) display positions in the verification information display area, including: In the client service page of the client, in response to the trigger operation for the verification information generation function, a first verification sub-information with M characters is generated; The verification information display area displays the first verification sub-information with M characters and the input character area with (NM) display positions.
5. The method according to claim 4, characterized in that, In the client service page of the client, in response to the trigger operation for the verification information generation function, a first verification sub-information with M characters is generated, including: In the client service page of the client, in response to the trigger operation for the verification information generation function, the total number of verification characters N is obtained, and the number of solidified characters M is determined based on the N; Obtain the information character region associated with the verification information, and determine the M characters from the information character region; The position information of the M characters in the verification information is determined, and based on the M characters and their respective position information, the first verification sub-information for constituting the verification information is determined.
6. The method according to claim 4, characterized in that, In the client service page of the client, in response to the trigger operation for the verification information generation function, a first verification sub-information with M characters is generated, including: In response to a trigger operation for the verification information generation function, obtain object information associated with the client; Based on a hash conversion strategy, the object information is processed into a string to obtain object conversion information; Based on object transformation information, the first verification sub-information used to constitute the verification information is determined.
7. The method according to claim 1, characterized in that, Both the client and the server are blockchain nodes in a blockchain network. The method further includes: Based on the total number of verification characters N, the first verification sub-information, and the object information corresponding to the client, the information to be signed is determined; Obtain the object private key associated with the client, and perform signature processing on the information to be signed based on the object private key to obtain the client signature information; Based on the client signature information and the information to be signed, a verification information generation request is generated for sending to the server; the client signature information is used to instruct the server to verify the information to be signed.
8. The method according to claim 1, characterized in that, Both the client and the server are blockchain nodes in a blockchain network. When the second verification sub-information with (NM) characters is obtained from the server, in response to the information input operation for the input character area, the second verification sub-information is displayed in the input character area, including: The server receives encrypted data information sent by the server; the encrypted data information is obtained by the server encrypting the second verification sub-information using the public key of the object corresponding to the client. The encrypted data information is decrypted using the private key corresponding to the public key of the object to obtain the second verification sub-information; In response to an information input operation for the input character area, (NM) characters from the second verification sub-information are displayed in the input character area.
9. The method according to claim 1, characterized in that, The method further includes: The verification information is sent to the server so that the server generates an information verification result based on the received verification information and the verification information associated with the client stored by the server; the verification information is the complete information recorded by the server based on the first verification sub-information and the second verification sub-information sent by the client. Receive the verification result returned by the server; If the information verification result indicates that the verification information is consistent with the validation information, then the information verification result is determined to be a successful verification result, and a successful verification notification matching the successful verification result is displayed; If the information verification result indicates that the verification information is inconsistent with the validation information, then the information verification result is determined to be a verification failure result, and a verification failure notification matching the verification failure result is displayed.
10. A data processing method, characterized in that, The method is executed by the server and includes: The system retrieves a verification information generation request sent by the client. This request is generated by the client based on the total number of verification characters N, first verification sub-information, and the client's corresponding object information. The first verification sub-information constitutes the verification information, and consists of M characters displayed in the verification information display area when the client responds to a trigger operation for the verification information generation function. M is a positive integer, and N is a positive integer greater than M. The number of fixed characters M corresponding to the first verification sub-information, the M characters themselves, and their respective positions in the verification information display area are all randomly generated when responding to a trigger operation for the verification information generation function. The first verification sub-information is not editable in the verification information display area. Based on the N, the first verification sub-information, and the object information, a second verification sub-information with (NM) characters is generated; the server is also used to store verification information composed of the first verification sub-information and the second verification sub-information; The second verification sub-information is sent to the client so that the client responds to an information input operation for the input character area in the verification information display area, displays the second verification sub-information in the input character area, and determines the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification; the server is also used to obtain the verification information and compare and verify the verification information through the verification information.
11. The method according to claim 10, characterized in that, Both the server and the client are blockchain nodes in the blockchain network; the verification information generation request includes information to be signed and client signature information; the client signature information is obtained by the client after signing the information to be signed using the object's private key; The information to be signed is determined by the first verification sub-information and the object information corresponding to the client; The method further includes: Upon receiving the verification information generation request sent by the client, obtain the object public key corresponding to the object private key; The signature information of the client is verified based on the public key of the object to obtain the verification result. If the signature verification result indicates successful verification, then the client is determined to be a legitimate node, and the verification information generation request is determined to be a legitimate request. If the signature verification result indicates that the verification failed, the client is determined to be an illegal node, and the verification information generation request is determined to be an illegal request.
12. The method according to claim 10, characterized in that, The server is a blockchain node in the blockchain network; The method further includes: When generating the second verification sub-information, based on the first verification sub-information and the second verification sub-information sent by the client, verification information for performing data security verification on the client is determined; The verification information is packaged to obtain a block to be verified in the blockchain network. The block to be verified is broadcast to the consensus nodes in the blockchain network, so that the consensus nodes can reach a consensus on the obtained block to be verified and obtain a consensus result to be returned to the server; the consensus nodes are blockchain nodes in the blockchain network. If any consensus result in the consensus results exceeds the consensus threshold, indicating successful consensus, then it is determined that the blockchain nodes in the blockchain network have reached a consensus, and the block to be verified is written into the blockchain as the target block.
13. The method according to claim 10, characterized in that, The method further includes: Upon receiving the verification information returned by the client, verification information for performing data security verification on the verification information is obtained; the verification information includes the first verification sub-information and the second verification sub-information. The verification information is split into first sub-information and second sub-information. The first split sub-information is compared with the first verification sub-information to obtain the first comparison result; If the first comparison result indicates that the first split sub-information is consistent with the first verification sub-information, then the second split sub-information is compared with the second verification sub-information to obtain a second comparison result; If the second comparison result indicates that the second split sub-information is consistent with the second verification sub-information, then an information verification result is generated to indicate successful verification.
14. The method according to claim 13, characterized in that, The method further includes: If the first comparison result indicates that the first split sub-information is inconsistent with the first verification sub-information, then an information verification result is generated to indicate that the verification failed.
15. A data processing apparatus, characterized in that, include: The first sub-information display module is used to respond to a trigger operation for the verification information generation function, and to display a first verification sub-information with M characters and an input character area with (NM) display positions in the verification information display area; where N is a positive integer and M is a positive integer less than N; the number M of fixed characters corresponding to the first verification sub-information, the M characters, and the position information of the M characters in the verification information display area are all randomly generated when responding to the trigger operation for the verification information generation function; the first verification sub-information is not editable in the verification information display area. The second sub-information display module is used to respond to an information input operation for the input character area when it receives second verification sub-information with (NM) characters from the server, and to display the second verification sub-information in the input character area; the second verification sub-information is generated by the server based on the first verification sub-information sent by the client, the total number of verification characters N, and the object information of the client; the server is also used to store verification information composed of the first verification sub-information and the second verification sub-information. The verification information determination module is used to determine the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification; the server is also used to obtain the verification information and compare and verify the verification information through the verification information.
16. A data processing apparatus, characterized in that, include: The request retrieval module is used to obtain the verification information sent by the client and generate a request. The verification information generation request is generated by the client based on the total number of verification characters N, the first verification sub-information, and the object information corresponding to the client. The first verification sub-information is used to constitute the verification information, and the first verification sub-information consists of M characters displayed in the verification information display area when the client responds to the trigger operation for the verification information generation function. The first verification sub-information includes M characters, where M is a positive integer and N is a positive integer greater than M. The number of fixed characters M corresponding to the first verification sub-information, the M characters, and the position information of the M characters in the verification information display area are all randomly generated when responding to the trigger operation for the verification information generation function. The first verification sub-information is not editable in the verification information display area. The second sub-information generation module is used to generate a second verification sub-information with (NM) characters based on the N, the first verification sub-information, and the object information, and to store verification information composed of the first verification sub-information and the second verification sub-information; The second sub-information sending module is used to send the second verification sub-information to the client, so that the client responds to the information input operation for the input character area in the verification information display area, displays the second verification sub-information in the input character area, and determines the first verification sub-information and the second verification sub-information in the verification information display area as verification information for data security verification; the second sub-information sending module is also used to obtain the verification information and compare and verify the verification information through the verification information.
17. A computer device, characterized in that, include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to invoke the computer program to cause the computer device to perform the method according to any one of claims 1 to 14.
18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1 to 14.
19. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method of any one of claims 1 to 14.
Citation Information
Patent Citations
Combined password verification method, hardware terminal and password system
CN111028392A
Business data information processing method, device and equipment and readable storage medium
CN111431707A