Authentication authorization method, apparatus and electronic device

CN117278292BActive Publication Date: 2026-10-09INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311278372.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-28
Publication Date
2026-10-09
Estimated Expiration
2043-09-28

AI Technical Summary

Technical Problem

[0003]本发明提供一种认证授权方法、装置和电子设备,用以解决现有技术中认证授权方案采用的验证方法较简单,安全性较低,容易造成用户信息泄露,并导致无法正常进行身份验证的缺陷

Benefits of technology

[0043] This invention provides an authentication and authorization method, apparatus, and electronic device applied to an authentication and authorization system. It obtains authentication information input by a user through a client, processes the authentication information, sends the processed authentication information to N servers, receives verification results from the N servers, counts the verification results sent by the N servers, and determines whether the number of verified results that pass the verification reaches a preset threshold. If yes, the verification is successful, and the user is allowed to log in; otherwise, the verification fails, and the user's access is denied. The N servers store N sets of encrypted credentials pre-sent by the client for authentication information verification. Each server can verify the processed authentication information. This invention effectively protects user information security, improves the system's disaster recovery capabilities, and can maintain normal system operation and ensure continuous business operation and data availability even if a single server fails.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117278292B_ABST
    Figure CN117278292B_ABST
Patent Text Reader

Abstract

The application provides an authentication authorization method, device and electronic equipment, and belongs to the technical field of computers, wherein the method comprises the following steps: obtaining authentication information input by a user; processing the authentication information, and sending the processed authentication information to N servers respectively; receiving verification results sent by the N servers; counting the verification results sent by the N servers, and judging whether the number of verification results that pass the check reaches a preset threshold; if yes, the verification is passed, the user is allowed to log in, and if not, the check fails and the user is denied access; N sets of credential ciphertexts for checking the authentication information, which are sent by a user end in advance, are stored on the N servers; each server is used for checking the processed authentication information according to the credential ciphertext stored on each server, obtaining a verification result, and sending the verification result to the user end. The application can guarantee the safety of user information, improve the disaster recovery capability of the system, and maintain the normal operation of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to an authentication and authorization method, apparatus, and electronic device. Background Technology

[0002] In the computer field, with the development and widespread application of information technology, more and more systems need to authenticate users and restrict their permissions and access scope. Current authentication and authorization schemes employ relatively simple verification methods, resulting in low security, easy leakage of user information, and failure to perform authentication correctly. Summary of the Invention

[0003] This invention provides an authentication and authorization method, apparatus, and electronic device to address the shortcomings of existing authentication and authorization schemes, which employ simple verification methods, have low security, are prone to user information leakage, and result in the inability to perform identity verification normally.

[0004] In a first aspect, the present invention provides an authentication and authorization method applied to a user terminal of an authentication and authorization system, wherein the authentication and authorization system further includes N servers, where N is a natural number greater than 1, and the method includes:

[0005] Obtain the authentication information input by the user;

[0006] The authentication information is processed, and the processed authentication information is sent to the N servers respectively;

[0007] Receive the verification results sent by the N servers;

[0008] The system counts the verification results sent by the N servers and determines whether the number of verification results that pass the verification reaches a preset threshold. If so, the verification is passed and the user is allowed to log in; otherwise, the verification fails and the user is denied access.

[0009] The N servers disperse the N sets of encrypted credentials sent in advance by the user for authentication information verification. Each server verifies the processed authentication information based on the encrypted credentials stored on each server, obtains the verification result, and sends the verification result to the user.

[0010] In some embodiments, processing the authentication information and sending the processed authentication information to the N servers respectively includes:

[0011] The authentication information is divided into important information and ordinary information. The important information is divided into multiple first data blocks, and the ordinary information is divided into multiple second data blocks.

[0012] The plurality of first data blocks and the plurality of second data blocks are combined to obtain N authentication data blocks;

[0013] The N authentication data blocks are encrypted sequentially using the random numbers sent by the N servers to obtain N squared encrypted authentication data blocks;

[0014] The N squared encrypted authentication data blocks are divided into N groups of authentication ciphertexts; each group of authentication ciphertexts is obtained by encrypting the N authentication data blocks using different random numbers.

[0015] The N sets of authentication ciphertexts are matched with the N servers, and each set of authentication ciphertexts is sent to the server that matches each set of authentication ciphertexts.

[0016] In some embodiments, the N sets of credential ciphertext are obtained by pre-obtaining the registration information of the target user, dividing the registration information into N registration data blocks, encrypting the N registration data blocks sequentially using random numbers sent by the N servers to obtain N squared encrypted registration data blocks, and then grouping the N squared encrypted registration data blocks; wherein each set of credential ciphertext is obtained by encrypting the N registration data blocks using different random numbers.

[0017] In some embodiments, dividing the registration information into N registration data blocks includes:

[0018] Based on preset rules, the registration information is divided into important data and ordinary data, wherein the preset rules are pre-set based on the field corresponding to the registration information;

[0019] The ordinary data is divided into multiple ordinary data blocks, and the important data is divided into multiple important data blocks according to the principle of minimum unitization;

[0020] The multiple important data blocks are combined with the multiple ordinary data blocks to obtain the N registered data blocks.

[0021] In some embodiments, dividing the registration information into N registration data blocks includes:

[0022] The registration information is input into the hybrid partitioning model to obtain the N registration data blocks output by the hybrid partitioning model;

[0023] The hybrid partitioning model is obtained by training the target training user's registration training information as training samples and using N registration data blocks corresponding to the registration training information as sample labels.

[0024] In some embodiments, the hybrid partitioning model includes a partitioning layer and a combination layer.

[0025] Correspondingly, the registration information is input into the hybrid partitioning model to obtain the N registration data blocks output by the hybrid partitioning model, specifically including:

[0026] The registration information is input into the partitioning layer to obtain multiple important data blocks and multiple ordinary data blocks output by the partitioning layer;

[0027] The multiple important data blocks and multiple ordinary data blocks are input into the combination layer to obtain the N registered data blocks output by the combination layer.

[0028] Secondly, the present invention also provides an authentication and authorization method applied to the server side of an authentication and authorization system, the authentication and authorization system comprising a user terminal and N servers, wherein N is a natural number greater than 1, the method comprising:

[0029] Each of the N servers receives the processed authentication information sent by the user client.

[0030] Each server verifies the processed authentication information based on the encrypted credentials stored on each server, obtains a verification result, and sends the verification result to the user terminal.

[0031] The N servers contain N sets of encrypted credentials pre-sent by the user for authentication information verification.

[0032] Thirdly, the present invention also provides an authentication and authorization device applied to the user end of an authentication and authorization system, wherein the authentication and authorization system further includes N servers, where N is a natural number greater than 1, and the device includes:

[0033] The acquisition unit is used to acquire authentication information input by the user.

[0034] The first sending unit is used to process the authentication information and send the processed authentication information to the N servers respectively.

[0035] The first receiving unit is used to receive the verification results sent by the N servers;

[0036] The judgment unit is used to count the verification results sent by the N servers and determine whether the number of verification results that have passed the verification reaches a preset threshold. If so, the verification is passed and the user is allowed to log in; otherwise, the verification fails and the user is denied access.

[0037] The N servers dispersedly store N sets of encrypted credentials for authentication information verification pre-sent by the user. Each server verifies the processed authentication information based on the encrypted credentials stored on each server, obtains a verification result, and sends the verification result to the user.

[0038] Fourthly, the present invention also provides an authentication and authorization device applied to the server side of an authentication and authorization system, the authentication and authorization system including a user terminal and N servers, where N is a natural number greater than 1, the device comprising:

[0039] The second receiving unit is used to receive the processed authentication information sent by the user terminal;

[0040] The second sending unit is used to verify the processed authentication information based on the ciphertext stored on each server, obtain the verification result, and send the verification result to the user terminal.

[0041] The N servers contain N sets of encrypted credentials pre-sent by the user for authentication information verification.

[0042] Fifthly, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the authentication and authorization methods described above.

[0043] This invention provides an authentication and authorization method, apparatus, and electronic device applied to an authentication and authorization system. It obtains authentication information input by a user through a client, processes the authentication information, sends the processed authentication information to N servers, receives verification results from the N servers, counts the verification results sent by the N servers, and determines whether the number of verified results that pass the verification reaches a preset threshold. If yes, the verification is successful, and the user is allowed to log in; otherwise, the verification fails, and the user's access is denied. The N servers store N sets of encrypted credentials pre-sent by the client for authentication information verification. Each server can verify the processed authentication information. This invention effectively protects user information security, improves the system's disaster recovery capabilities, and can maintain normal system operation and ensure continuous business operation and data availability even if a single server fails. Attached Figure Description

[0044] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0045] Figure 1 This is one of the flowcharts illustrating the authentication and authorization method provided in this embodiment of the invention;

[0046] Figure 2 This is a second schematic flowchart of the authentication and authorization method provided in this embodiment of the invention;

[0047] Figure 3 This is a schematic diagram of the process provided by an embodiment of the present invention to obtain N sets of encrypted credentials based on registration information and to distribute and store the N sets of encrypted credentials on N servers.

[0048] Figure 4 This is a flowchart illustrating the process of dividing registration information into N registration data blocks according to an embodiment of the present invention;

[0049] Figure 5 This is the third flowchart illustrating the authentication and authorization method provided in this embodiment of the invention;

[0050] Figure 6 This is one of the structural schematic diagrams of the authentication and authorization device provided by the present invention;

[0051] Figure 7 This is the second structural schematic diagram of the authentication and authorization device provided by the present invention.

[0052] Figure 8 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0053] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0054] Currently, various authentication and authorization models exist. For the most common username and password authentication model, a single management server is typically used. When registering with the system, users provide a unique username and password. The system associates these credentials with the user and stores them on one or two servers. When a user attempts to log in, the system verifies whether the provided username and password match the stored credentials. The system compares the provided password with the stored password; if they match, the user is allowed to log in; otherwise, access is denied. However, if the core server is attacked or the server itself has security vulnerabilities, user information can be leaked, preventing the system from properly authenticating user information.

[0055] To address the aforementioned issues, embodiments of the present invention provide an authentication and authorization method, apparatus, and electronic device applied to an authentication and authorization system. The method involves acquiring authentication information input by a user through a client, processing the authentication information, sending the processed authentication information to N servers, receiving verification results from the N servers, counting the verification results from the N servers, and determining whether the number of successful verification results reaches a preset threshold. If yes, the verification is successful, and the user is allowed to log in; otherwise, the verification fails, and access is denied. The N servers store N sets of encrypted credentials pre-sent by the client for authentication information verification. Each server can verify the processed authentication information and send the verification result to the client. This invention effectively protects user information security, improves the system's disaster recovery capabilities, and maintains normal system operation even in the event of a single server failure, ensuring continuous business operation and data availability.

[0056] Figure 1 This is one of the flowcharts illustrating the authentication and authorization method provided in an embodiment of the present invention. For example... Figure 1 As shown, an authentication and authorization method is provided, applied to the user end of an authentication and authorization system. The authentication and authorization system also includes N servers, where N is a natural number greater than 1. The method includes the following steps: step 110, step 120, step 130, and step 140. These method steps are merely one possible implementation of the present invention.

[0057] Step 110: Obtain the authentication information entered by the user.

[0058] Optionally, the authentication information can be a username / account and password, a mobile phone number and verification code, or answers to pre-set security questions, etc.

[0059] Step 120: Process the authentication information and send the processed authentication information to N servers respectively.

[0060] Optionally, the authentication information can be a username / account and password, a mobile phone number and verification code, or answers to pre-set security questions, etc.

[0061] Optionally, the client can copy the processed authentication information into N requests, or use a mechanism such as a message queue to send the processed authentication information to N servers.

[0062] Optionally, the authentication information can be filtered, grouped, encrypted, or processed.

[0063] In some embodiments, step 120 includes the following steps:

[0064] Step 121: Divide the authentication information into important information and ordinary information. Divide the important information into multiple first data blocks and the ordinary information into multiple second data blocks.

[0065] Step 122: Combine multiple first data blocks and multiple second data blocks to obtain N authentication data blocks.

[0066] Step 123: Use random numbers sent by N servers to encrypt N authentication data blocks in sequence to obtain N squared encrypted authentication data blocks.

[0067] It should be noted that by grouping the authentication information into N authentication data blocks and encrypting the N authentication data blocks with different random numbers, the security of the authentication information is improved.

[0068] Step 124: Divide the N squared encrypted authentication data blocks into N groups of authentication ciphertexts; each group of authentication ciphertexts is obtained by encrypting the N authentication data blocks with different random numbers.

[0069] Step 125: Match the N sets of authentication ciphertexts with the N servers, and send each set of authentication ciphertexts to the server that matches each set of authentication ciphertexts.

[0070] Understandably, by obtaining and processing the authentication information input by the user, and then sending the processed authentication information to N servers, each server can independently verify the processed authentication message, thereby improving the system's availability, fault tolerance, and security.

[0071] Step 130: Receive verification results sent by N servers.

[0072] The verification results typically include the authentication status (such as successful or failed authentication), authentication identifier, authentication timestamp, authorization information, etc.

[0073] It should be noted that since each server independently verifies the processed authentication information, the verification results sent by N servers include N independent verification results.

[0074] Step 140: Count the verification results sent by N servers, and determine whether the number of verification results that pass the verification reaches the preset threshold. If yes, the verification is passed and the user is allowed to log in. If no, the verification fails and the user is denied access.

[0075] Among them, N sets of encrypted credentials pre-sent by the user for authentication information verification are distributed on N servers. Each server is used to verify the processed authentication information based on the encrypted credentials stored on each server, obtain the verification result, and send the verification result to the user.

[0076] For example, in an authentication and authorization system with 4 servers and a preset threshold of 2, the verification results sent by the 4 servers are "verification successful, verification successful, verification successful, verification failed". That is, the number of verification results that pass the verification is 3, which is greater than the preset threshold of 2. Therefore, the verification is successful and the authorization information allows the user to log in.

[0077] It should be noted that the N sets of ciphertexts are all different, and the client sends the N sets of ciphertexts to the N servers in advance; optionally, each server may randomly store one set of ciphertexts.

[0078] Figure 2 This is a second schematic flowchart illustrating the authentication and authorization method provided in an embodiment of the present invention. For example... Figure 2 As shown, an authentication and authorization method is provided for use in an authentication and authorization system, comprising the following steps:

[0079] Step 210: Respond to the user authentication request;

[0080] Step 220: Obtain the authentication information input by the user;

[0081] Step 230: Process the authentication information to obtain N sets of authentication ciphertext;

[0082] Optionally, the authentication information can be divided, combined, and encrypted to obtain N sets of authentication ciphertext.

[0083] Step 240: Distribute the N sets of authentication ciphertexts to N servers;

[0084] Optionally, each set of authentication ciphertext can be sent to a server that matches it.

[0085] Step 250: Receive verification results sent by N servers;

[0086] The verification result includes whether the verification was successful or failed.

[0087] Step 260: Count the verification results sent by N servers;

[0088] Step 270: Determine whether the number of verification results that pass the verification reaches the preset threshold. If yes, the verification is successful and passes the verification. If no, the verification fails.

[0089] Step 280, Verification complete.

[0090] In this embodiment of the invention, authentication information input by the user is obtained through the user terminal, processed, and then sent to N servers. Verification results from the N servers are received, and the number of successful verification results is counted. If the number of successful verification results reaches a preset threshold, the user is allowed to log in; otherwise, the verification fails and access is denied. The N servers store N sets of encrypted credentials pre-sent by the user terminal for authentication information verification. Each server can verify the processed authentication information and send the verification result to the user terminal. This invention effectively protects user information security, improves system disaster recovery capabilities, and maintains normal system operation even in the event of a single server failure, ensuring continuous business operation and data availability.

[0091] It should be noted that each embodiment of the present invention can be freely combined, rearranged, or executed individually, and does not need to rely on or depend on a fixed execution order.

[0092] In some embodiments, the N sets of credential ciphertext are obtained by pre-obtaining the registration information of the target user, dividing the registration information into N registration data blocks, encrypting the N registration data blocks sequentially using random numbers sent by N servers, resulting in N squared encrypted registration data blocks, and then grouping the N squared encrypted registration data blocks into groups; wherein each set of credential ciphertext is obtained by encrypting the N registration data blocks using different random numbers.

[0093] Optionally, the registration information may include at least one of the following: username, password, email address, mobile phone number, name, contact address, etc.

[0094] Table 1 shows an example of N squared encrypted registration data blocks in N sets of ciphertext provided in this embodiment of the invention. As shown in Table 1, there are 5 servers in the authentication and authorization system, i.e., N is "5". The registration information K is divided into 5 data blocks, namely K1, K2, K3, K4, and K5. The random numbers sent by the 5 servers are Q1, Q2, Q3, Q4, and Q5, respectively. K1 is encrypted using an encryption algorithm and random number Q1 to obtain encrypted data block AK1; K2 is encrypted using an encryption algorithm and random number Q1 to obtain encrypted data block AK2, ..., K5 is encrypted using an encryption algorithm and random number Q1 to obtain encrypted data block AK5; K1 is encrypted using an encryption algorithm and random number Q2 to obtain encrypted data block BK1; K2 is encrypted using an encryption algorithm and random number Q2 to obtain encrypted data block BK2, ..., K5 is encrypted using an encryption algorithm and random number Q2 to obtain encrypted data block BK5; and so on, resulting in 25 encrypted data blocks.

[0095] Table 1. Examples of N squared encrypted registration data blocks in N sets of credential ciphertext.

[0096]

[0097] Optionally, the 25 encrypted data in Table 1 above are divided into 5 groups of credential ciphertexts, namely "AK1, BK2, CK3, DK4, EK5", "BK1, CK2, DK3, EK4, AK5", "CK1, DK2, EK3, AK4, BK5", "DK1, EK2, AK3, BK4, CK5", and "EK1, AK2, BK3, CK4, DK5".

[0098] Figure 3 This is a schematic diagram illustrating the process of obtaining N sets of encrypted credentials based on registration information and distributing these N sets of encrypted credentials across N servers, as provided in an embodiment of the present invention. Figure 3 As shown, N sets of encrypted credentials are obtained based on the registration information, and these N sets of encrypted credentials are distributed and stored on N servers, including the following steps:

[0099] Step 310: Obtain the user's registration information K.

[0100] Step 320: Determine the sensitivity and importance of the registration information K to obtain the judgment result.

[0101] Step 330: Based on the judgment result, divide the registration information K into N registration data blocks.

[0102] For example, the registration information K can be divided into K1, K2, K3, K4, and K5.

[0103] Step 340: Obtain random numbers sent by N servers.

[0104] For example, N servers send random numbers Q1, Q2, Q3, Q4, and Q5 respectively.

[0105] Step 350: Encrypt N registered data blocks using random numbers sent by N servers respectively to obtain a ciphertext matrix.

[0106] For example, Q1, Q2, Q3, Q4, and Q5 are used to encrypt the five data blocks corresponding to the registration information K, respectively, to obtain a 5*5 ciphertext matrix.

[0107] Step 360: Group the data based on the ciphertext matrix to obtain N sets of ciphertext credentials, and then distribute and send the N sets of ciphertext credentials to N servers.

[0108] Each set of credential ciphertext is obtained by encrypting N registration data blocks with different random numbers.

[0109] Understandably, by pre-obtaining the target user's registration information, dividing the registration information into N registration data blocks, and then sequentially using random numbers sent by N servers to encrypt each of the N registration data blocks in segments, N can be obtained. 2 By encrypting and registering data blocks, the randomness and complexity of data encryption can be improved; for N 2 The encrypted registration data blocks are grouped to obtain N sets of ciphertext. Each set of ciphertext is obtained by encrypting N registration data blocks with different random numbers. This method has high security and is difficult to crack, thus ensuring the security of user information.

[0110] Figure 4 This is a flowchart illustrating the process of dividing registration information into N registration data blocks, provided as an embodiment of the present invention. Figure 4 As shown, in some embodiments, the registration information is divided into N registration data blocks, including:

[0111] Step 410: Based on preset rules, divide the registration information into important data and ordinary data, where the preset rules are pre-set based on the field corresponding to the registration information;

[0112] Step 420: Divide ordinary data into multiple ordinary data blocks, and divide important data into multiple important data blocks according to the principle of minimum unitization;

[0113] Step 430: Combine multiple important data blocks with multiple ordinary data blocks to obtain N registered data blocks.

[0114] For example, if the registration information corresponds to the financial sector, the default rule could be: bank card number and password in the registration information are important data, and other information is ordinary data; if the registration information corresponds to the online shopping sector, the default rule could be: mobile phone number and address in the registration information are important data, and other information is ordinary data.

[0115] The principle of minimum unitization refers to the principle of dividing data into the smallest units for processing and management. For example, if the registration information is "abcdefghi", and the important data is "bcd", then according to the principle of minimum unitization, "bcd" can be divided into three data blocks: "b", "c", and "d".

[0116] For example, if N is "5" and the registration information is "abcde12345", where "abcde" is important data and "12345" is ordinary data, the important data can be split into "a / b / c / d / e" and the ordinary data can be split into "1 / 2 / 3 / 4 / 5". The five data blocks obtained after recombination can be "a1 / b2 / c3 / d4 / e5" or "a2 / b3 / c4 / d5 / e1".

[0117] Understandably, by dividing registration information into important data and ordinary data, further dividing the ordinary data and important data separately, and then recombining the two types of data to obtain N registration data blocks, the risk of leakage of users' sensitive information is reduced.

[0118] In some embodiments, the registration information is divided into N registration data blocks, including:

[0119] The registration information is input into the hybrid partitioning model, and N registration data blocks are output by the hybrid partitioning model.

[0120] The hybrid partitioning model is trained using the registration training information of the target training user as the training sample and the N registration data blocks corresponding to the registration training information as sample labels.

[0121] Optionally, the training steps for the hybrid partitioning model include:

[0122] Obtain the registration and training information of the target training users;

[0123] The N registration data blocks corresponding to the registration training information are identified as sample labels;

[0124] The initial hybrid partitioning model is trained using the registration training information of the target training users as training samples and the N registration data blocks corresponding to the registration training information as sample labels.

[0125] The initial hybrid partitioning model is optimized by iterative parameter optimization to obtain the hybrid partitioning model.

[0126] Understandably, the hybrid partitioning model can achieve automated partitioning of registration information, quickly dividing the registration information into N registration data blocks.

[0127] In some embodiments, the hybrid partitioning model includes a partitioning layer and a combination layer.

[0128] Correspondingly, the registration information is input into the hybrid partitioning model, resulting in N registration data blocks output by the hybrid partitioning model, specifically including:

[0129] The registration information is input into the partitioning layer, and multiple important data blocks and multiple ordinary data blocks are output by the partitioning layer.

[0130] Multiple important data blocks and multiple ordinary data blocks are input into the combination layer to obtain N registered data blocks output by the combination layer.

[0131] It should be noted that the partitioning layer stores preset rules for dividing registration information into important data and ordinary data. These preset rules are pre-set based on the domain to which the registration information belongs.

[0132] It is understandable that by inputting registration information into the partitioning layer of the hybrid partitioning model, multiple important data blocks and multiple ordinary data blocks are obtained from the output of the partitioning layer. Then, these multiple important data blocks and multiple ordinary data blocks are input into the combination layer of the hybrid partitioning model to obtain N registration data blocks output by the combination layer. This can improve the efficiency of data partitioning and combination and reduce the risk of information leakage.

[0133] Figure 5 This is the third flowchart illustrating the authentication and authorization method provided in this embodiment of the invention. Figure 5 As shown, an authentication and authorization method is provided, which is applied to the server side of an authentication and authorization system. The authentication and authorization system includes a client and N servers, where N is a natural number greater than 1. The method includes the following steps:

[0134] Step 510: Each of the N servers receives the processed authentication information sent by the client.

[0135] The user terminal is used to obtain the authentication information input by the user, process the authentication information, and obtain the processed authentication information.

[0136] Step 520: Each server verifies the processed authentication information based on the encrypted credentials stored on each server, obtains the verification result, and sends the verification result to the user terminal.

[0137] Among them, N sets of encrypted credentials sent in advance by the user client for authentication information verification are stored on N servers.

[0138] In this embodiment of the invention, each server can verify the processed authentication information based on the ciphertext stored on each server to obtain the verification result, thereby improving the availability of the system. Even if a single server fails, user authentication can be completed through other servers.

[0139] The authentication and authorization device provided in the embodiments of the present invention is described below. The authentication and authorization device described below can be referred to in correspondence with the authentication and authorization method described above.

[0140] Figure 6 This is one of the structural schematic diagrams of the authentication and authorization device provided by the present invention. This device is applied to the user end of an authentication and authorization system. The authentication and authorization system also includes N servers, where N is a natural number greater than 1, such as... Figure 6 As shown, the device 600 includes:

[0141] The acquisition unit 610 is used to acquire authentication information input by the user;

[0142] The first sending unit 620 is used to process the authentication information and send the processed authentication information to N servers respectively.

[0143] The first receiving unit 630 is used to receive verification results sent by N servers;

[0144] The judgment unit 640 is used to count the verification results sent by N servers and determine whether the number of verification results that have passed the verification has reached a preset threshold. If so, the verification is passed and the user is allowed to log in; otherwise, the verification fails and the user is denied access.

[0145] The system consists of N servers that store N sets of encrypted credentials pre-sent by the client for authentication information verification. Each server verifies the processed authentication information based on the encrypted credentials stored on its own server, obtains the verification result, and sends the verification result to the client.

[0146] Optionally, the authentication information is processed, and the processed authentication information is sent to N servers respectively, including:

[0147] The authentication information is divided into important information and ordinary information. The important information is further divided into multiple first data blocks, and the ordinary information is further divided into multiple second data blocks.

[0148] Multiple first data blocks and multiple second data blocks are combined to obtain N authentication data blocks;

[0149] The N authentication data blocks are encrypted sequentially using random numbers sent by N servers, resulting in N squared encrypted authentication data blocks;

[0150] Divide the N squared encrypted authentication data blocks into N groups of authentication ciphertexts; each group of authentication ciphertexts is obtained by encrypting the N authentication data blocks with different random numbers.

[0151] Match N sets of authentication ciphertexts with N servers, and send each set of authentication ciphertexts to the server that matches it.

[0152] Optionally, the N sets of credential ciphertext are obtained by pre-obtaining the target user's registration information, dividing the registration information into N registration data blocks, encrypting the N registration data blocks sequentially using random numbers sent by N servers, resulting in N squared encrypted registration data blocks, and then grouping the N squared encrypted registration data blocks into groups; wherein each set of credential ciphertext is obtained by encrypting the N registration data blocks using different random numbers.

[0153] Optionally, the registration information can be divided into N registration data blocks, including:

[0154] Based on preset rules, registration information is divided into important data and ordinary data. The preset rules are pre-set based on the field corresponding to the registration information.

[0155] Ordinary data is divided into multiple ordinary data blocks, and important data is divided into multiple important data blocks according to the principle of minimum unitization;

[0156] Multiple important data blocks are combined with multiple ordinary data blocks to obtain N registered data blocks.

[0157] Optionally, the registration information can be divided into N registration data blocks, including:

[0158] The registration information is input into the hybrid partitioning model, and N registration data blocks are output by the hybrid partitioning model.

[0159] The hybrid partitioning model is trained using the registration training information of the target training user as the training sample and the N registration data blocks corresponding to the registration training information as sample labels.

[0160] Optionally, the hybrid partitioning model includes a partitioning layer and a combination layer.

[0161] Correspondingly, the registration information is input into the hybrid partitioning model, resulting in N registration data blocks output by the hybrid partitioning model, specifically including:

[0162] The registration information is input into the partitioning layer, and multiple important data blocks and multiple ordinary data blocks are output by the partitioning layer.

[0163] Multiple important data blocks and multiple ordinary data blocks are input into the combination layer to obtain N registered data blocks output by the combination layer.

[0164] Figure 7 This is the second schematic diagram of the authentication and authorization device provided by the present invention. This device is applied to the server side of an authentication and authorization system, which includes a user terminal and N servers, where N is a natural number greater than 1. Figure 7 As shown, the device 700 includes:

[0165] The second receiving unit 710 is used to receive the processed authentication information sent by the user terminal;

[0166] The second sending unit 720 is used to verify the processed authentication information based on the ciphertext stored on each server, obtain the verification result, and send the verification result to the user terminal.

[0167] Among them, N sets of encrypted credentials sent in advance by the user client for authentication information verification are stored on N servers.

[0168] It should be noted that the authentication and authorization device provided in this embodiment of the invention can implement all the method steps implemented in the above-described authentication and authorization method embodiments and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiments will not be described in detail here.

[0169] Figure 8 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 8As shown, the electronic device may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840. The processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can call logical instructions from the memory 830 to execute authentication and authorization methods applied to the user end of the authentication and authorization system, or to execute authentication and authorization methods applied to the server end of the authentication and authorization system. The authentication and authorization system includes a user end and N servers, where N is a natural number greater than 1. The authentication and authorization method applied to the user terminal of the authentication and authorization system includes: obtaining authentication information input by the user; processing the authentication information and sending the processed authentication information to N servers; receiving verification results sent by the N servers; counting the verification results sent by the N servers, determining whether the number of verification results that pass the verification reaches a preset threshold; if so, the verification is passed and the user is allowed to log in; if not, the verification fails and the user's access is denied. The N servers store N sets of encrypted credentials pre-sent by the user terminal for authentication information verification. Each server verifies the processed authentication information based on the encrypted credentials stored on its own server, obtains a verification result, and sends the verification result to the user terminal. The server-side authentication and authorization method applied to the authentication and authorization system includes: each of the N servers receiving the processed authentication information sent by the user terminal; each server verifying the processed authentication information based on the encrypted credentials stored on its own server, obtaining a verification result, and sending the verification result to the user terminal; the N servers store N sets of encrypted credentials pre-sent by the user terminal for authentication information verification.

[0170] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0171] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the authentication and authorization methods provided above for a user terminal of an authentication and authorization system, or for a server terminal of an authentication and authorization system. The authentication and authorization system includes a user terminal and N servers, where N is a natural number greater than 1. The authentication and authorization method for the user terminal of the authentication and authorization system includes: acquiring authentication information input by a user; processing the authentication information and sending the processed authentication information to the N servers respectively; receiving verification results sent by the N servers; counting the verification results sent by the N servers, determining whether the number of verified results that pass the verification reaches a preset threshold; if so, the verification is passed and the user is allowed to log in; if not, the verification fails and the user's access is denied. The N servers disperse N sets of encrypted credentials pre-sent by the user terminal for authentication information verification. Each server verifies the processed authentication information based on the encrypted credentials stored on its own server, obtains a verification result, and sends the verification result to the user terminal. The authentication and authorization method applied to the server side of the authentication and authorization system includes: each of the N servers receives the processed authentication information sent by the user; each server verifies the processed authentication information according to the ciphertext stored on each server, obtains the verification result, and sends the verification result to the user; wherein, the N servers disperse and store N sets of ciphertext for authentication information verification pre-sent by the user.

[0172] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0173] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of various embodiments or some parts of embodiments.

[0174] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An authentication and authorization method, applied to the user end of an authentication and authorization system, wherein the authentication and authorization system further comprises N servers, where N is a natural number greater than 1, characterized in that, The method includes: Obtain the authentication information entered by the user; The authentication information is processed to obtain processed authentication information, and the processed authentication information is sent to the N servers respectively. Receive the verification results sent by the N servers; The system counts the verification results sent by the N servers and determines whether the number of verification results that pass the verification reaches a preset threshold. If so, the verification is passed and the user is allowed to log in; otherwise, the verification fails and the user is denied access. The N servers disperse and store N sets of encrypted credentials for authentication information verification pre-sent by the user. Each of the N sets of encrypted credentials is different. Each server randomly stores one set of encrypted credentials. Each server is used to verify the processed authentication information based on the encrypted credentials stored on each server, obtain a verification result, and send the verification result to the user. The process of processing the authentication information to obtain processed authentication information, and then sending the processed authentication information to the N servers respectively, includes: The authentication information is divided into important information and ordinary information. The important information is divided into multiple first data blocks, and the ordinary information is divided into multiple second data blocks. The plurality of first data blocks and the plurality of second data blocks are combined to obtain N authentication data blocks; The N authentication data blocks are encrypted sequentially using the random numbers sent by the N servers to obtain N squared encrypted authentication data blocks; The N squared encrypted authentication data blocks are divided into N groups of authentication ciphertexts; each group of authentication ciphertexts is obtained by encrypting the N authentication data blocks using different random numbers. The N sets of authentication ciphertexts are matched with the N servers, and each set of authentication ciphertexts is sent to the server that matches each set of authentication ciphertexts. The N sets of credential ciphertext are obtained by pre-obtaining the target user's registration information, dividing the registration information into N registration data blocks, encrypting the N registration data blocks sequentially using random numbers sent by the N servers, resulting in N squared encrypted registration data blocks, and then grouping the N squared encrypted registration data blocks into groups; wherein each set of credential ciphertext is obtained by encrypting the N registration data blocks using different random numbers. The step of dividing the registration information into N registration data blocks includes: The registration information is input into the partitioning layer of the hybrid partitioning model to obtain multiple important data blocks and multiple ordinary data blocks output by the partitioning layer; The multiple important data blocks and multiple ordinary data blocks are input into the combination layer of the hybrid partitioning model to obtain the N registered data blocks output by the combination layer; The hybrid partitioning model is obtained by training the target training user's registration training information as training samples and using N registration data blocks corresponding to the registration training information as sample labels.

2. The authentication and authorization method according to claim 1, characterized in that, The step of dividing the registration information into N registration data blocks includes: Based on preset rules, the registration information is divided into important data and ordinary data, wherein the preset rules are pre-set based on the field corresponding to the registration information; The ordinary data is divided into multiple ordinary data blocks, and the important data is divided into multiple important data blocks according to the principle of minimum unitization; The multiple important data blocks are combined with the multiple ordinary data blocks to obtain the N registered data blocks.

3. An authentication and authorization method applied to the server side of an authentication and authorization system, the authentication and authorization system comprising a user terminal and N servers, the user terminal being used to execute the authentication and authorization method as described in any one of claims 1-2, wherein N is a natural number greater than 1, characterized in that... The method includes: Each of the N servers receives the processed authentication information sent by the user client. Each server verifies the processed authentication information based on the encrypted credentials stored on each server, obtains a verification result, and sends the verification result to the user terminal. The N servers contain N sets of encrypted credentials pre-sent by the user for authentication information verification.

4. An authentication and authorization device, applied to the user end of an authentication and authorization system, wherein the authentication and authorization system further includes N servers, where N is a natural number greater than 1, characterized in that, The device includes: The acquisition unit is used to acquire authentication information input by the user. The first sending unit is used to process the authentication information to obtain processed authentication information, and send the processed authentication information to the N servers respectively. The first receiving unit is used to receive the verification results sent by the N servers; The judgment unit is used to count the verification results sent by the N servers and determine whether the number of verification results that have passed the verification reaches a preset threshold. If so, the verification is passed and the user is allowed to log in; otherwise, the verification fails and the user is denied access. The N servers are distributed and stored in a distributed manner, containing N sets of encrypted credentials for authentication information verification pre-sent by the user. Each of the N sets of encrypted credentials is different, and each server randomly stores one set of encrypted credentials. Each server is used to verify the processed authentication information based on the encrypted credentials stored on each server, obtain a verification result, and send the verification result to the user. The process of processing the authentication information to obtain processed authentication information, and then sending the processed authentication information to the N servers respectively, includes: The authentication information is divided into important information and ordinary information. The important information is divided into multiple first data blocks, and the ordinary information is divided into multiple second data blocks. The plurality of first data blocks and the plurality of second data blocks are combined to obtain N authentication data blocks; The N authentication data blocks are encrypted sequentially using the random numbers sent by the N servers to obtain N squared encrypted authentication data blocks; The N squared encrypted authentication data blocks are divided into N groups of authentication ciphertexts; each group of authentication ciphertexts is obtained by encrypting the N authentication data blocks using different random numbers. The N sets of authentication ciphertexts are matched with the N servers, and each set of authentication ciphertexts is sent to the server that matches each set of authentication ciphertexts. The N sets of credential ciphertext are obtained by pre-obtaining the target user's registration information, dividing the registration information into N registration data blocks, encrypting the N registration data blocks sequentially using random numbers sent by the N servers, resulting in N squared encrypted registration data blocks, and then grouping the N squared encrypted registration data blocks into groups; wherein each set of credential ciphertext is obtained by encrypting the N registration data blocks using different random numbers. The step of dividing the registration information into N registration data blocks includes: The registration information is input into the partitioning layer of the hybrid partitioning model to obtain multiple important data blocks and multiple ordinary data blocks output by the partitioning layer; The multiple important data blocks and multiple ordinary data blocks are input into the combination layer of the hybrid partitioning model to obtain the N registered data blocks output by the combination layer; The hybrid partitioning model is obtained by training the target training user's registration training information as training samples and using N registration data blocks corresponding to the registration training information as sample labels.

5. An authentication and authorization device, applied to the server side of an authentication and authorization system, the authentication and authorization system comprising a user terminal and N servers, the user terminal being used to execute the authentication and authorization method as described in any one of claims 1-2, wherein N is a natural number greater than 1, characterized in that... The device includes: The second receiving unit is used to receive the processed authentication information sent by the user terminal; The second sending unit is used to verify the processed authentication information based on the ciphertext stored on each server, obtain the verification result, and send the verification result to the user terminal. The N servers contain N sets of encrypted credentials pre-sent by the user for authentication information verification.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the authentication and authorization method as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Password based threshold token generation

    CN112106322A

  • User information authentication method and system

    CN115801382A