An authentication method, platform, system, and authentication server.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-29
- Publication Date
- 2026-08-14
AI Technical Summary
[0003]因此,相关技术在进行身份认证的过程中,至少存在操作复杂、耗时长的问题
[0030] Through the above technical solution, in the user authentication process, the business platform obtains the user's internet account directly from the authentication server based on the IP address, without waiting for the user to enter their mobile phone number or user account. This speeds up the authentication process and ensures the security of the user's internet account.
Smart Images

Figure CN116961957B_ABST
Abstract
Description
Technical Field
[0001] This application relates to, but is not limited to, the field of communications, and in particular to an authentication method, a business platform, a business support system, an authentication server, and an authentication system. Background Technology
[0002] With the development of the internet, information security issues related to internet products have become increasingly prominent. Currently, most internet products on the market require identity authentication before use. In these technologies, users need to manually enter their username and password, or manually enter their mobile phone number and a dynamic verification code, during authentication.
[0003] Therefore, the relevant technologies suffer from problems such as complexity and time consumption in the process of identity authentication. Summary of the Invention
[0004] This application provides an authentication method, a business platform, a business support system, an authentication server, and an authentication system.
[0005] Firstly, an authentication method is provided for application in a business platform, the method comprising:
[0006] In response to an authentication request initiated by a business client, obtain the Internet Protocol (IP) address of the first terminal device where the business client is located, which is carried in the authentication request;
[0007] At least based on the IP address, obtain the user's internet account information pre-stored in the authentication server;
[0008] Send the user's internet account information to the business support system so that the business support system can at least authenticate the user's internet account information and obtain an authentication result;
[0009] The system receives the authentication result sent by the business support system and sends the authentication result to the business client.
[0010] Secondly, an authentication method is provided for use in a business support system, the method comprising:
[0011] Receive user internet account information sent by the service platform; wherein, the user internet account information is obtained by the service platform from information pre-stored in the authentication server based at least on the IP address of the first terminal device where the service client is located;
[0012] At least the user's internet account information is authenticated to obtain the authentication result;
[0013] Send the authentication result to the business platform.
[0014] Thirdly, an authentication method is provided for use on an authentication server, the method comprising:
[0015] Send the user's internet account information corresponding to the IP address of the first terminal device where the business client is located to the business platform; wherein, the user's internet account information is pre-stored in the authentication server.
[0016] Fourthly, a business platform is provided, the business platform comprising:
[0017] The first obtaining module is used to respond to an authentication request initiated by the business client and obtain the Internet Protocol IP address of the first terminal device where the business client is located, which is carried in the authentication request.
[0018] The first obtaining module is further configured to obtain user internet account information pre-stored in the authentication server, based at least on the IP address;
[0019] The first sending module is used to send the user's internet account information to the business support system so that the business support system can at least authenticate the user's internet account information and obtain an authentication result.
[0020] The first receiving module is further configured to receive the authentication result sent by the business support system;
[0021] The first sending module is also used to send the authentication result to the business client.
[0022] Fifthly, a business support system is provided, the business support system comprising:
[0023] The second receiving module is used to receive user internet account information sent by the service platform; wherein, the user internet account information is obtained by the service platform from information pre-stored in the authentication server after the service client initiates an authentication request, based at least on the IP address of the first terminal device where the service client is located;
[0024] The second processing module is used to authenticate at least the user's internet account information and obtain the authentication result.
[0025] The second sending module is used to send the authentication result to the business platform.
[0026] Sixthly, an authentication server, the authentication server comprising:
[0027] The third sending module is used to send the user's internet account information corresponding to the IP address of the first terminal device where the business client is located to the business platform when the business client initiates an authentication request; wherein the user's internet account information is pre-stored in the authentication server.
[0028] In a seventh aspect, an authentication system is provided, the authentication system comprising: a processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory to execute the above-described authentication method.
[0029] Eighthly, a computer-readable storage medium is provided for storing a computer program that causes a computer to perform the above-described authentication method.
[0030] Through the above technical solution, in the user authentication process, the business platform obtains the user's internet account directly from the authentication server based on the IP address, without waiting for the user to enter their mobile phone number or user account. This speeds up the authentication process and ensures the security of the user's internet account. Attached Figure Description
[0031] Figure 1 This is an illustrative flow diagram of an authentication method provided in an embodiment of this application. Figure 1 ;
[0032] Figure 2 This is a schematic flowchart illustrating how internet account information and IP address are pre-stored on an authentication server, as provided in an embodiment of this application.
[0033] Figure 3 This is an illustrative flow diagram of an authentication method provided in an embodiment of this application. Figure 2 ;
[0034] Figure 4 This is a schematic diagram of a process for querying a user's broadband account on a business platform, provided in an embodiment of this application.
[0035] Figure 5 This is a schematic diagram of a business platform providing feedback on authentication results, as provided in an embodiment of this application.
[0036] Figure 6 This is a schematic block diagram of a business platform provided in an embodiment of this application;
[0037] Figure 7 This is a schematic block diagram of a first authentication system provided in an embodiment of this application;
[0038] Figure 8 This is a schematic block diagram of a business support system provided in an embodiment of this application;
[0039] Figure 9 This is a schematic block diagram of a second authentication system provided in an embodiment of this application;
[0040] Figure 10 This is a schematic block diagram of an authentication server provided in an embodiment of this application;
[0041] Figure 11 This is a schematic block diagram of a third authentication system provided in an embodiment of this application. Detailed Implementation
[0042] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein is for the purpose of describing embodiments of the invention only and is not intended to limit the invention.
[0044] Figure 1 This is a flowchart illustrating an authentication method provided in an embodiment of this application, as shown below. Figure 1 As shown, this method is applied to an authentication system, and the method includes:
[0045] Step 101: The business platform responds to the authentication request initiated by the business client and obtains the Internet Protocol IP address of the first terminal device where the business client is located, which is carried in the authentication request.
[0046] In this embodiment of the application, the service client initiates an authentication request to instruct the service platform to obtain the user's Internet account information.
[0047] In this embodiment, the service client is installed in the first terminal device, the service client is a client module in the first terminal device, and the first terminal device is the terminal device where the client is located.
[0048] In this embodiment of the invention, the first terminal device is equipped with a service client. If the first terminal device detects that the service client requires authentication, it generates an authentication request. It should be noted that the authentication request data is filled into the access message of the service platform. Further, the Optical Network Terminal (ONT) associated with the first terminal device encapsulates the Internet Protocol (IP) address of the local area network of the first terminal device where the service client resides, or the local area network IP address of the ONT, into the access message of the service platform. The ONT then sends the access message to the Broadband Remote Access Server (BRAS). The BRAS, through its bound Network Address Translation (NAT) card, translates the local area network IP address in the access message into a metropolitan area network (MAN) IP address or a wide area network (WAN) IP address, and encapsulates the MAN or WAN IP address into the access message. The BRAS then sends the service message to the service platform.
[0049] For example, the authentication request can be generated by the first terminal device after the user clicks on the corresponding icon in the business client. Of course, the first terminal device can also generate the above-mentioned activation request in other ways. For example, the user sends a voice message to the first terminal device, such as a message to use the business client. After the electronic device receives the message to use the business client, it generates an authentication request. This application does not specifically limit the way the first terminal device generates the authentication request.
[0050] In this embodiment of the application, the first terminal device may include mobile terminal devices such as mobile phones, tablets, laptops, personal digital assistants (PDAs), cameras, wearable devices, and in-vehicle devices, as well as fixed terminal devices such as desktop computers.
[0051] Step 102: The business platform obtains user internet account information pre-stored in the authentication server, based at least on the IP address.
[0052] In this embodiment, the service platform sends the IP address to the authentication server. The authentication server determines the user's internet account information corresponding to the IP address based on the mapping relationship between the IP address and the user's internet account information. The authentication server stores multiple mapping relationships between IP addresses and their corresponding user internet account information. Furthermore, the authentication server sends the user's internet account information corresponding to the IP address of the first terminal device where the service client is located to the service platform.
[0053] In this embodiment of the application, the authentication, authorization, and accounting (AAA) server pre-stores multiple user internet account information.
[0054] It should be noted that when a terminal device accesses the network, it requests an IP address. Furthermore, the BRAS assigns an IP address to the terminal device and pre-stores the terminal device's internet account information and IP address in the authentication server. Figure 2 This application provides a flowchart of a method for pre-storing internet account information and IP address on an authentication server. Figure 2 The steps shown include:
[0055] Step A1: The ONT requests an IP address to be assigned to the terminal device where the service client is located.
[0056] It should be noted that the terminal device where the business client is located is on the same local area network as the ONT and is directly connected.
[0057] Step A2: ONT encapsulates the user's internet account information and inserts it into the OPTION 60 field of the DISCOVER message, and then sends it to BRAS.
[0058] In this embodiment of the application, the user's internet account information includes the user's username and password.
[0059] It should be noted that the DISCOVER message is the first message sent by a business client when it first logs into the network to perform the Dynamic Host Configuration Protocol (DHCP) process, and is used to find the server.
[0060] In this embodiment of the application, the OPTION 60 field in the DISCOVER message is used to identify the resource category identifier.
[0061] Step A3: BRAS receives and parses the message information sent by ONT, assembles it into an authentication message, and sends it to the AAA authentication server.
[0062] In this embodiment, the BRAS determines whether the client meets the conditions for obtaining an IP address from the OPTION 60 field in the message information. If the conditions are met, the client assembles an authentication message and sends it to the AAA authentication server; otherwise, the BRAS ignores the message.
[0063] In this embodiment of the application, the authentication message contains the user's internet account information.
[0064] Step A4: The AAA authentication server parses the authentication message and verifies the user's internet account information.
[0065] Step A5: After the AAA authentication server successfully verifies the user's internet account information, the BRAS assigns the user a metropolitan area network (MAN) IP address / WAN IP address, port, and LAN IP address.
[0066] Step A6: BRAS encapsulates the MAN IP address / WAN IP address, port, and LAN IP address into the first packet.
[0067] In this embodiment of the application, the OPTION 43 field in the first message carries the client's IP address or domain name.
[0068] Step A7: The AAA authentication server receives the first message and parses it.
[0069] Step A8: The AAA authentication server stores the user's internet account information, MAN / WAN IP address, port, and LAN IP address in the storage module.
[0070] In this embodiment of the application, there is a mapping relationship between metropolitan area network IP address / wide area network IP address, port, local area network IP address and user Internet account information.
[0071] Step 103: The business platform sends the user's internet account information to the business support system.
[0072] Step 104: The business support system receives the user's internet account information and at least authenticates the user's internet account information to obtain the authentication result.
[0073] Among them, the user's internet account information is obtained by the business platform from the information pre-stored in the authentication server, based at least on the IP address of the first terminal device where the business client is located.
[0074] In some embodiments, the business support system authenticates a user's internet account information, which can be done by directly authenticating the user's identity based on their username and key; or by obtaining the user's mobile phone number based on their internet account information and then performing SMS authentication. It is understood that the specific authentication method used by the business support system can be selected according to the actual scenario, and this application does not impose specific restrictions on it.
[0075] In this embodiment of the application, the authentication result includes at least one of the following:
[0076] The business support system confirms that the user's internet account information has been successfully authenticated.
[0077] The business support system has determined that the user's internet account information authentication failed.
[0078] Step 105: The business support system sends the authentication result to the business platform.
[0079] Step 106: The business platform receives the authentication result and sends the authentication result to the business client.
[0080] Step 107: The business client receives the authentication result.
[0081] In this embodiment, if the authentication result indicates that the service support system has successfully authenticated the user's internet account information, the user can directly log in to the service client. If the authentication result indicates that the service support system has failed to authenticate the user's internet account information, a prompt message will be output.
[0082] Here, the output prompt information may include, but is not limited to, outputting colors, text, sounds, graphics, symbols, images, and anything else that can be used to prompt the user that the login has failed.
[0083] This application discloses an authentication method, which includes: responding to an authentication request initiated by a business client, obtaining the Internet Protocol (IP) address of the first terminal device where the business client is located, carried in the authentication request; obtaining user internet account information pre-stored in an authentication server, at least based on the IP address; sending the user internet account information to a business support system, so that the business support system at least authenticates the user internet account information and obtains an authentication result; receiving the authentication result sent by the business support system, and sending the authentication result back to the business client. In other words, in the user authentication process, the business platform obtains the user's internet account from the authentication server based on the direct IP address, without waiting for the user to enter a mobile phone number or user account, thus speeding up the authentication process and ensuring the security of the user's internet account.
[0084] Figure 3 This is a flowchart illustrating an authentication method provided in an embodiment of this application, as shown below. Figure 3 As shown, this method is applied to an authentication system, and the method includes:
[0085] Step 301: The service platform responds to the authentication request initiated by the service client and obtains the Internet Protocol (IP) metropolitan area network (MAN) IP address and port number of the first terminal device where the service client is located, which is carried in the authentication request.
[0086] In this embodiment, ports include two types: logical ports and physical ports. Physical ports are interfaces used to connect physical devices, such as interfaces on hubs, switches, and routers used to connect other network devices, like Registered Jack 45 (RJ-45) ports and fiber optic ports. Logical ports are ports used to distinguish services logically. For example, port 80 is used for web browsing services, and port 21 is used for File Transfer Protocol (FTP) services. Similarly, service ports in Transmission Control Protocol / Internet Protocol (TCP / IP) distinguish different services through different logical ports. Ports within an IP address are numbered using 16 bits. Ports are identified by port numbers, which are integers ranging from 0 to 65535.
[0087] Step 302: The business platform encapsulates the metropolitan area network IP address and port number into an authentication message and sends the authentication message to the authentication server.
[0088] In this embodiment, the service platform encapsulates the metropolitan area network IP address and port number in the corresponding fields of the authentication message.
[0089] Step 303: The authentication server receives the authentication message and parses it to obtain the metropolitan area network IP address and port number.
[0090] In this embodiment of the application, the user's internet account information includes at least one of the following:
[0091] SIM identifier;
[0092] SIM short identifier;
[0093] Username and password;
[0094] The account identifier is composed of the SIM identifier or short SIM identifier and the first identifier.
[0095] In this embodiment, the Subscriber Identity Module (SIM) identifier represents the long mobile phone number; the SIM short identifier represents the short mobile phone number; and the account identifier is composed of the long or short mobile phone number and a first identifier. Here, the first identifier is set by the operator according to the actual application scenario. For example, the account identifier can be composed of 123 + mobile phone number; or the account identifier can be composed of abc + short mobile phone number.
[0096] It should be noted that in scenarios where user verification requires a verification code, this application can extract the corresponding mobile phone number from the user's internet account information for SMS verification.
[0097] Step 304: The authentication server queries the local area network IP address of the first terminal device based on the metropolitan area network IP address and port number.
[0098] Step 305: The authentication server filters out multiple interaction records associated with the local area network IP address from the logs.
[0099] Step 306: The authentication server determines the user's internet account information based on multiple interaction records.
[0100] In this embodiment of the application, the authentication server directly extracts the user's internet account information from the interaction records.
[0101] Step 307: The authentication server sends the user's internet account information to the business platform.
[0102] Step 308: The business platform receives the user's internet account information and sends it to the business support system.
[0103] Step 309: The business support system receives the user's internet account information.
[0104] Step 310: The business support system retrieves the SIM identifier from the user's internet account information.
[0105] In this embodiment, the SIM identifier includes the SIM identifier (i.e., the mobile phone number) and the SIM short identifier (i.e., the short mobile phone number). Clearly, the service support system can retrieve the mobile phone number from the user's internet account information. Even when no SIM card is installed in the first terminal device, it can still obtain the user's mobile phone number for identity authentication, breaking the limitation that a SIM card needs to be inserted into the device in related one-click authentication scenarios.
[0106] Step 311: The business support system sends a dynamic verification code to the second terminal device corresponding to the SIM identifier.
[0107] In this embodiment, the first terminal device generates an auxiliary verification code based on the dynamic verification code and sends the auxiliary verification code to the business platform; the first terminal device and the second terminal device are the same device or related devices.
[0108] In this embodiment, if the first terminal device and the second terminal device are the same device, the first terminal device directly generates an auxiliary verification code based on the received dynamic verification code and sends it to the business platform. Alternatively, the first terminal device detects the auxiliary verification code entered by the user on the first interface after receiving the dynamic verification code and sends it to the business platform.
[0109] In this embodiment, if the first terminal device and the second terminal device are associated devices, the second terminal device sends a dynamic verification code to the first terminal device. The first terminal device directly generates an auxiliary verification code based on the received dynamic verification code and sends it to the service platform. Alternatively, the first terminal device detects that the user has entered an auxiliary verification code on the first interface of the first terminal device after receiving the dynamic verification code from the second terminal device, and then sends the auxiliary verification code to the service platform.
[0110] Here, the first interface can be the general official interface of the business client or a customized interface. The customized interface contains different content and / or layout of interface elements than the general official interface.
[0111] Step 312: The business platform receives the auxiliary verification code sent by the first terminal device and sends the auxiliary verification code to the business support system.
[0112] Step 313: The business support system receives the auxiliary verification code sent by the business platform.
[0113] Step 314: The business support system authenticates the user's internet account information and auxiliary verification code to obtain the authentication result.
[0114] In this embodiment of the application, the authentication of the auxiliary verification code can be determined by whether the auxiliary verification code is the same as the dynamic verification code. If they are the same, the verification passes; otherwise, the verification fails.
[0115] In some embodiments, authenticating a user's internet account information and auxiliary verification code can involve determining whether the user's internet account information is legitimate and whether the auxiliary verification code is the same as the dynamic verification code. If they are the same, the verification passes; otherwise, the verification fails.
[0116] Step 315: The business support system sends the authentication result to the business platform.
[0117] Step 316: The business platform receives the authentication result and sends the authentication result to the business client.
[0118] Step 317: The business client receives the authentication result.
[0119] It should be noted that the descriptions of the same steps and contents as in other embodiments in this embodiment can be found in the descriptions in other embodiments, and will not be repeated here.
[0120] Figure 4 This is a flowchart illustrating the process of querying a user's broadband account using a business platform provided in this application.
[0121] Step 401: The business client requests the business platform to obtain the user's broadband account.
[0122] Step 402: ONT encapsulates its local private network IP into the message sent by the user to access the Internet platform and sends it to BRAS.
[0123] Step 403: The BRAS uses the bound NAT card to convert the private network IP address into a public network IP address and port, and encapsulates the information into a packet.
[0124] Step 404: The business platform parses the message to obtain the user's public IP address and port, and then uses the user's public IP address and port to request the AAA authentication server to obtain the user's broadband account.
[0125] Step 405: The AAA authentication server queries the user's private IP address based on the user's public IP address and port, then queries the AAA authentication server log based on the private IP address, and returns the user's broadband account.
[0126] Figure 5 This is a flowchart illustrating the process of a business platform providing feedback on authentication results, as provided in this application.
[0127] Step 501: The business client requests broadband authentication.
[0128] Step 502: The business platform requests the Business & Operation Support System (BOSS) to query the user's registered mobile phone number based on the user's internet account.
[0129] Step 503: BOSS sends a dynamic verification code to the user's mobile phone through the SMS gateway.
[0130] Step 504: The user enters the dynamic verification code in the business client to initiate an authentication request.
[0131] Step 505: The business platform sends the dynamic verification code to BOSS for authentication.
[0132] Step 506: BOSS authenticates the user's broadband account and dynamic verification code, and returns the authentication result to the business client through the business platform.
[0133] Embodiments of this application provide a service platform that can be applied to... Figure 1 , Figure 3 In one authentication method provided in the corresponding embodiment, referencing Figure 6 As shown, the business platform 6 includes:
[0134] The first obtaining module 601 is used to respond to the authentication request initiated by the business client and obtain the Internet Protocol IP address of the first terminal device where the business client is located, which is carried in the authentication request.
[0135] The first obtaining module 601 is also used to obtain user Internet account information pre-stored in the authentication server, based at least on the IP address;
[0136] The first sending module 602 is used to send user internet account information to the business support system so that the business support system can at least authenticate the user internet account information and obtain the authentication result.
[0137] The first receiving module 603 is also used to receive the authentication result sent by the business support system;
[0138] The first sending module 602 is also used to send the authentication result to the business client.
[0139] In other embodiments of this application, the first receiving module 603 is further configured to receive an auxiliary verification code sent by the first terminal device;
[0140] The first sending module 602 is used to send an auxiliary verification code to the service support system so that the service support system can authenticate the user's Internet account information and the auxiliary verification code to obtain an authentication result; wherein, the auxiliary verification code is generated by the first terminal device based on the dynamic verification code sent by the service support system; after the service support system queries the user identification module SIM identifier from the user's Internet account information, the service support system sends a dynamic verification code to the second terminal device corresponding to the SIM identifier; the first terminal device and the second terminal device are the same device or related devices.
[0141] In other embodiments of this application, the request message also carries a port number, and the IP address includes a metropolitan area network IP address;
[0142] The first processing module 604 is used to encapsulate the metropolitan area network IP address and port number into an authentication message;
[0143] The first sending module 602 is used to send an authentication message to the authentication server so that the authentication server can obtain the user's Internet account information from the log based on the authentication message;
[0144] The first receiving module 603 is used to receive user internet account information sent by the authentication server.
[0145] In other embodiments of this application, the user's internet account information includes at least one of the following:
[0146] SIM identifier;
[0147] SIM short identifier;
[0148] Username and password;
[0149] The account identifier is composed of the SIM identifier or short SIM identifier and the first identifier.
[0150] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0151] It should be noted that if the above-described access method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application embodiment, or the part that contributes to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device to execute all or part of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.
[0152] Embodiments of this application provide a first authentication system, which can be applied to... Figure 1 , Figure 3 In one authentication method provided in the corresponding embodiment, referencing Figure 7 As shown, the first authentication system 7 ( Figure 6 Business platform 6 and Figure 7 The first authentication system 7 (corresponding to the first authentication system 7) includes: a first processor 701, a first memory 702, and a first communication bus 703, wherein:
[0153] The first communication bus 703 is used to realize the communication connection between the first processor 701 and the first memory 702.
[0154] The first processor 701 is used to execute the computer program stored in the first memory 702 to achieve, for example... Figure 1 , Figure 3 The corresponding embodiment provides an authentication method.
[0155] The first processor 701 described above can be a chip, such as an integrated circuit chip, with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by software instructions.
[0156] The aforementioned first processor 701 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor.
[0157] Embodiments of this application provide a business support system that can be applied to... Figure 1 , Figure 3 In one authentication method provided in the corresponding embodiment, referencing Figure 8 As shown, the business support system 8 includes:
[0158] The second receiving module 801 is used to receive user internet account information sent by the service platform; wherein, the user internet account information is obtained by the service platform from information pre-stored in the authentication server based at least on the IP address of the first terminal device where the service client is located;
[0159] The second processing module 802 is used to authenticate at least the user's internet account information and obtain the authentication result;
[0160] The second sending module 803 is used to send the authentication result to the business platform.
[0161] In other embodiments of this application, the second processing module 802 is used to query the SIM identifier from the user's internet account information;
[0162] The second sending module 803 is used to send a dynamic verification code to the second terminal device corresponding to the SIM identifier, so that the first terminal device generates an auxiliary verification code based on the dynamic verification code and sends the auxiliary verification code to the service platform; the first terminal device and the second terminal device are the same device or related devices;
[0163] The second receiving module 801 is used to receive the auxiliary verification code sent by the business platform;
[0164] The second processing module 802 is used to authenticate the user's internet account and auxiliary verification code to obtain the authentication result.
[0165] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0166] It should be noted that if the above-described access method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application embodiment, or the part that contributes to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device to execute all or part of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, external hard drives, ROMs, magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.
[0167] Embodiments of this application provide a second authentication system that can be applied to... Figure 1 , Figure 3 In one authentication method provided in the corresponding embodiment, referencing Figure 9 As shown, the second authentication system 9 ( Figure 8 Business Support System 8 and Figure 9 The second authentication system (corresponding to 9 in the system) includes: a second processor 901, a second memory 902, and a second communication bus 903, wherein:
[0168] The second communication bus 903 is used to realize the communication connection between the second processor 901 and the second memory 902.
[0169] The second processor 901 is used to execute the computer program stored in the second memory 902 to achieve, for example... Figure 1 , Figure 3 The corresponding embodiment provides an authentication method.
[0170] The second processor 901 described above can be a chip, such as an integrated circuit chip, with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by software instructions.
[0171] The aforementioned second processor 901 can also be a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor.
[0172] Embodiments of this application provide an authentication server that can be applied to... Figure 1 , Figure 3 In one authentication method provided in the corresponding embodiment, referencing Figure 10 As shown, the authentication server 10 includes:
[0173] The third sending module 1001 is used to send the user's Internet account information corresponding to the IP address of the first terminal device where the business client is located to the business platform; wherein, the user's Internet account information is pre-stored in the authentication server.
[0174] In other embodiments of this application, the third receiving module 1002 is used to receive authentication messages sent by the service platform;
[0175] The third processing module 1003 is used to parse the authentication message to obtain the metropolitan area network IP address and port number;
[0176] The third processing module 1003 is used to query the local area network IP address of the first terminal device based on the metropolitan area network IP address and port number.
[0177] The third processing module 1003 is used to filter out multiple interaction records associated with local area network IP addresses from the logs;
[0178] The third processing module 1003 is used to determine the user's internet account information based on multiple interaction records.
[0179] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0180] It should be noted that if the above-described access method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application embodiment, or the part that contributes to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device to execute all or part of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, external hard drives, ROMs, magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.
[0181] Embodiments of this application provide a third authentication system that can be applied to... Figure 1 , Figure 3 In one authentication method provided in the corresponding embodiment, referencing Figure 11 As shown, the third authentication system 11 ( Figure 10 Authentication server 10 and Figure 11 The third authentication system 11 (corresponding to the third authentication system 11) includes: a third processor 1101, a third memory 1102, and a third communication bus 1103, wherein:
[0182] The third communication bus 1103 is used to realize the communication connection between the third processor 1101 and the third memory 1102.
[0183] The third processor 1101 is used to execute the computer program stored in the third memory 1102 to achieve, for example... Figure 1 , Figure 3 The corresponding embodiment provides an authentication method.
[0184] The aforementioned third processor 1101 can be a chip, such as an integrated circuit chip, with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed through integrated logic circuits in the processor's hardware or through software instructions.
[0185] The aforementioned third processor 1101 can also be a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor.
[0186] It should be noted that, Figure 7The first authentication system in China, 7. Figure 9 The second authentication system 9 and Figure 11 The third authentication system 11 in this application is merely an example illustrating the system to which this application applies. Of course, the method shown in the embodiments of this application can also be applied to an aggregated authentication system; it can also be applied to other systems. Furthermore, the terms "system" and "network" are often used interchangeably in this document. Additionally, the character " / " in this document generally indicates an "or" relationship between the preceding and following objects. It should also be understood that "instruction" mentioned in the embodiments of this application can be a direct instruction, an indirect instruction, or an indication of a relationship. For example, A instructing B can mean that A directly instructs B, for example, B can obtain information through A; it can also mean that A indirectly instructs B, for example, A instructs C, B can obtain information through C; it can also mean that there is a relationship between A and B. It should also be understood that "correspondence" mentioned in the embodiments of this application can mean a direct or indirect correspondence between two entities, or an association between two entities, or a relationship of instruction and being instructed, configuration and being configured, etc. It should also be understood that in the embodiments of this application, the "protocol" can refer to standard protocols in the field of communication, such as the LTE protocol, the NR protocol, and related protocols applied to future communication systems; this application does not limit this.
[0187] Embodiments of this application provide a computer-readable storage medium storing a computer program that can be executed by one or more processors to perform, as follows: Figure 1 , Figure 3 The corresponding implementation provides the authentication method.
[0188] It should be noted that the descriptions of the storage medium and terminal device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and terminal device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0189] The aforementioned computer storage media / memory may include one or more of the following integrated: ROM, Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Ferromagnetic Random Access Memory (FRAM), Flash Memory, Magnetic Surface Memory, Optical Disc, Compact Disc Read-Only Memory (CD-ROM), etc.; or various terminals including one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0190] It should be understood that the phrases "an embodiment," "an embodiment," "an embodiment of this application," "the foregoing embodiment," "some implementations," or "some embodiments" mentioned throughout the specification mean that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, the phrases "an embodiment," "an embodiment," "an embodiment of this application," "the foregoing embodiment," "some implementations," or "some embodiments" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments of this application are merely descriptive and do not represent the superiority or inferiority of the embodiments.
[0191] Unless otherwise specified, any step in the embodiments of this application performed by the terminal device may be executed by the terminal device's processor. Unless otherwise specified, the embodiments of this application do not limit the order in which the terminal device performs the following steps. Furthermore, the methods used to process data in different embodiments may be the same or different methods. It should also be noted that any step in the embodiments of this application can be executed independently by the terminal device; that is, when the terminal device performs any step in the above embodiments, it may not depend on the execution of other steps.
[0192] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0193] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.
[0194] In addition, each functional unit in the various embodiments of this application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0195] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0196] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0197] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.
[0198] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0199] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0200] In the embodiments of this application, descriptions of the same steps and contents in different embodiments can be referred to each other. In the embodiments of this application, the term "and" does not affect the order of steps. For example, if the terminal device executes A and executes B, it can mean that the terminal device executes A first and then B, or that the terminal device executes B first and then A, or that the terminal device executes A and B simultaneously.
[0201] The singular forms “a,” “the,” and “the” used in the embodiments of this application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0202] It should be noted that in the various embodiments involved in this application, all steps or some steps may be performed, as long as a complete technical solution can be formed.
[0203] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An authentication method applied to a business platform, characterized in that, The method includes: In response to an authentication request initiated by a business client, obtain the Internet Protocol (IP) address of the first terminal device where the business client is located, which is carried in the authentication request; At least based on the IP address, obtain the user's internet account information pre-stored in the authentication server; Send the user's internet account information to the business support system; Receive the authentication result sent by the business support system and send the authentication result to the business client; Before receiving the authentication result sent by the business support system, the method further includes: The system receives an auxiliary verification code sent by the first terminal device and sends the auxiliary verification code to the business support system, so that the business support system can authenticate the user's internet account information and the auxiliary verification code to obtain the authentication result. The auxiliary verification code is generated by the first terminal device based on the dynamic verification code sent by the service support system; after the service support system retrieves the SIM identifier from the user's internet account information, the service support system sends the dynamic verification code to the second terminal device corresponding to the SIM identifier; the first terminal device and the second terminal device are the same device or related devices; authenticating the auxiliary verification code includes determining whether the auxiliary verification code is the same as the dynamic verification code.
2. The method according to claim 1, characterized in that, The request message also carries a port number, and the IP address includes a metropolitan area network IP address; obtaining the user's internet account information pre-stored in the authentication server, at least based on the IP address, includes: The metropolitan area network IP address and the port number are encapsulated into an authentication message; The authentication message is sent to the authentication server so that the authentication server can obtain the user's internet account information from the log based on the authentication message. Receive the user's internet account information sent by the authentication server.
3. The method according to claim 1, characterized in that, The user's internet account information includes at least one of the following: SIM identifier; SIM short identifier; Username and password; The account identifier is formed by the SIM identifier or the short SIM identifier and the first identifier.
4. An authentication method applied to a business support system, characterized in that, The method includes: Receive user internet account information sent by the service platform; wherein, the user internet account information is obtained by the service platform from information pre-stored in the authentication server based at least on the IP address of the first terminal device where the service client is located; At least the user's internet account information is authenticated to obtain the authentication result; Send the authentication result to the business platform; The step of authenticating at least the user's internet account information to obtain an authentication result includes: The SIM identifier was retrieved from the user's internet account information; A dynamic verification code is sent to the second terminal device corresponding to the SIM identifier, so that the first terminal device generates an auxiliary verification code based on the dynamic verification code, and sends the auxiliary verification code to the service platform; the first terminal device and the second terminal device are the same device or related devices; Receive the auxiliary verification code sent by the business platform; The user's internet account information and the auxiliary verification code are authenticated to obtain the authentication result; the authentication of the auxiliary verification code includes determining whether the auxiliary verification code is the same as the dynamic verification code.
5. An authentication method applied to an authentication server, characterized in that, The method includes: Send the user's internet account information corresponding to the IP address of the first terminal device where the business client is located to the business platform; wherein, the user's internet account information is pre-stored in the authentication server; The user's internet account information is used by the business support system to authenticate the user's internet account information and the auxiliary verification code after receiving the auxiliary verification code sent by the business platform, and to obtain an authentication result. The auxiliary verification code is generated by the first terminal device based on the dynamic verification code sent by the business support system. After the business support system retrieves the SIM identifier from the user's internet account information, it sends the dynamic verification code to the second terminal device corresponding to the SIM identifier. The first terminal device and the second terminal device are the same device or associated devices. Authentication of the auxiliary verification code includes determining whether the auxiliary verification code is the same as the dynamic verification code.
6. The method according to claim 5, characterized in that, Before sending the user's internet account information corresponding to the IP address of the first terminal device where the service client is located to the service platform, the method further includes: Receive authentication messages sent by the business platform; Parse the authentication message to obtain the metropolitan area network IP address and port number; Based on the metropolitan area network IP address and the port number, the local area network IP address of the first terminal device is retrieved; Filter out multiple interaction records associated with the local area network IP address from the logs; Based on the multiple interaction records, the user's internet account information is determined.
7. A business platform, characterized in that, The business platform includes: The first obtaining module is used to respond to an authentication request initiated by the business client and obtain the Internet Protocol IP address of the first terminal device where the business client is located, which is carried in the authentication request. The first obtaining module is further configured to obtain user internet account information pre-stored in the authentication server, based at least on the IP address; The first sending module is used to send the user's internet account information to the business support system; The first receiving module is also used to receive the authentication result sent by the business support system; The first sending module is further configured to send the authentication result to the service client; The first receiving module is further configured to receive an auxiliary verification code sent by the first terminal device; The first sending module is further configured to send the auxiliary verification code to the business support system, so that the business support system can authenticate the user's internet account information and the auxiliary verification code to obtain the authentication result; The auxiliary verification code is generated by the first terminal device based on the dynamic verification code sent by the service support system; after the service support system retrieves the SIM identifier from the user's internet account information, the service support system sends the dynamic verification code to the second terminal device corresponding to the SIM identifier; the first terminal device and the second terminal device are the same device or related devices; authenticating the auxiliary verification code includes determining whether the auxiliary verification code is the same as the dynamic verification code.
8. A business support system, characterized in that, The business support system includes: The second receiving module is used to receive user internet account information sent by the business platform; The user's internet account information is obtained by the business platform from information pre-stored in the authentication server, based at least on the IP address of the first terminal device where the business client is located, after the business client initiates an authentication request. The second processing module is used to authenticate at least the user's internet account information and obtain the authentication result. The second sending module is used to send the authentication result to the business platform; The second processing module is specifically used for: The SIM identifier was retrieved from the user's internet account information; A dynamic verification code is sent to the second terminal device corresponding to the SIM identifier, so that the first terminal device generates an auxiliary verification code based on the dynamic verification code, and sends the auxiliary verification code to the service platform; the first terminal device and the second terminal device are the same device or related devices; Receive the auxiliary verification code sent by the business platform; The user's internet account information and the auxiliary verification code are authenticated to obtain the authentication result; the authentication of the auxiliary verification code includes determining whether the auxiliary verification code is the same as the dynamic verification code.
9. An authentication server, characterized in that, The authentication server includes: The third sending module is used to send the user's Internet account information corresponding to the IP address of the first terminal device where the business client is located to the business platform when the business client initiates an authentication request. The user's internet account information is pre-stored in the authentication server; The user's internet account information is used by the business support system to authenticate the user's internet account information and the auxiliary verification code after receiving the auxiliary verification code sent by the business platform, and to obtain an authentication result. The auxiliary verification code is generated by the first terminal device based on the dynamic verification code sent by the business support system. After the business support system retrieves the SIM identifier from the user's internet account information, it sends the dynamic verification code to the second terminal device corresponding to the SIM identifier. The first terminal device and the second terminal device are the same device or associated devices. Authentication of the auxiliary verification code includes determining whether the auxiliary verification code is the same as the dynamic verification code.
10. An authentication system, characterized in that, The authentication system includes: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the authentication method according to any one of claims 1 to 6.
Citation Information
Patent Citations
User authentication method and system
CN102710621A
Network access control method with dynamic authentication
CN107770121A