A system and method for generating and verifying a verification code

CN117421720BActive Publication Date: 2026-09-25THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311431589.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-31
Publication Date
2026-09-25
Estimated Expiration
2043-10-31

AI Technical Summary

Technical Problem

现有验证技术在有限的验证码图片库里随机挑选,无论库容量如何增加,总能通过打码方式破解并穷尽验证码,最终让验证码失去效果

Benefits of technology

[0043]本发明的有益技术效果在于:通过随机选取词语,生成图片,由选中词语和图片点击确定验证是否成功,大幅增加了验证码的破解难度。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117421720B_ABST
    Figure CN117421720B_ABST
Patent Text Reader

Abstract

The application provides a kind of verification code generation and check system and method, obtain the authentication request of client;According to the authentication request, generate the word set consisting of multiple words using the first trained model, and generate the check picture according to the word set, and the check picture contains the object object corresponding to each word in the word set;Feed back the word set to the client for user to select words, and receive the word selection result of client;Feed back the check picture to the client for user to click, and obtain the click position data;Using the second trained model to segment the object object in the check picture, obtain the object object segmentation result;Determine the check result according to the word selection result, click position data and object object segmentation result and feed back the check result to the client.The cracking difficulty of verification code is greatly increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security verification technology, and in particular to a system and method for generating and verifying verification codes. Background Technology

[0002] With the development of network technology and the widespread adoption of various application systems, higher demands have been placed on system security, especially for critical applications with significant impact. Currently, many critical systems use CAPTCHAs to ensure that critical operations are performed by the user themselves. Most current CAPTCHA technologies focus on the following: adding interference items, increasing the number of verification attempts, and setting complex conversion rules. Existing verification technologies randomly select CAPTCHA images from a limited database. No matter how much the database size increases, it can always be cracked and exhausted through decoding, ultimately rendering the CAPTCHA ineffective. These verification methods are easily cracked, and scripts can then be used to perform verification on behalf of humans, reducing the credibility of genuine user actions. Summary of the Invention

[0003] To address the aforementioned issues, this invention provides a system and method for generating and verifying CAPTCHAs, aiming to overcome the security shortcomings of existing CAPTCHAs and increase the difficulty of cracking them.

[0004] A system for generating and verifying verification codes, comprising:

[0005] The verification code module is used to interact with the client and calls the image generation module based on the client's verification request;

[0006] The image generation module, connected to the verification code verification module, is used to generate a word set consisting of multiple words using the trained first model according to the verification request, and to generate a verification image based on the word set. The verification image contains the object corresponding to each word in the word set.

[0007] The CAPTCHA verification module is also used to: send a set of words back to the client for the user to select words, and after receiving the word selection result from the client, send a verification image back to the client for the user to click;

[0008] After obtaining the click location data, the image segmentation module is called;

[0009] The image segmentation module, connected to the CAPTCHA verification module, is used to segment objects in the verification image using a trained second model to obtain object segmentation results.

[0010] The CAPTCHA verification module is used to determine the verification result based on the word selection result, click location data, and object segmentation result, and then send the verification result back to the client.

[0011] Furthermore, the first model is based on the diffusion model.

[0012] Furthermore, the second model is based on an arbitrary segmentation model.

[0013] Furthermore, it also includes a training module, which is connected to the image generation module and the image segmentation module respectively, for jointly training the first model and the second model, including:

[0014] The data acquisition unit is used to collect images of several objects and label them with words to form a dataset;

[0015] The training unit, connected to the data acquisition unit, is used to input the dataset into the first model, which extracts a word set and generates sample images based on the extracted word set. The sample images are then input into the second model for object segmentation, thereby jointly training the first and second models.

[0016] After receiving the verification request, the image generation module randomly extracts words from the dataset to generate a word set.

[0017] Furthermore, the verification code module includes:

[0018] The object filtering unit is used to filter the object segmentation results based on the word selection results, and select the object objects that correspond to the word selection results to form an object set;

[0019] The verification and determination unit, connected to the object filtering unit, is used to determine whether the click location data is within the internal space of an object in the object collection, and whether the internal space of each object in the object collection has been clicked, and to obtain the judgment result.

[0020] The feedback unit, connected to the verification and determination unit, is used for:

[0021] When the judgment result is that the click location data is in the internal space of the object, and the internal space of each object has been clicked, a feedback message of successful verification is generated;

[0022] If the judgment result is that some clicked location data is not in the internal space of the object, or that some internal space of the object has not been clicked, a verification failure feedback message will be generated.

[0023] A method for generating and verifying verification codes, using the aforementioned system for generating and verifying verification codes, includes:

[0024] Step A1: Obtain the client's verification request;

[0025] Step A2: Based on the verification request, use the trained first model to generate a word set consisting of multiple words, and generate a verification image based on the word set. The verification image contains the object corresponding to each word in the word set.

[0026] Step A3: Send the word set back to the client for the user to select words, and receive the word selection results from the client;

[0027] Step A4: Send a verification image to the client for the user to click, and obtain the click location data;

[0028] Step A5: Use the trained second model to segment the objects in the verification image to obtain the object segmentation results;

[0029] Step A6: Determine the verification result based on the word selection result, click location data, and object segmentation result, and then send the verification result back to the client.

[0030] Furthermore, the first model is based on the diffusion model.

[0031] Furthermore, the second model is based on an arbitrary segmentation model.

[0032] Furthermore, the training process for the first and second models includes the following steps:

[0033] Step B1: Collect images of several objects and label them with words to form a dataset;

[0034] Step B2: Input the dataset into the first model, which extracts the word set and generates sample images based on the extracted word set. Input the sample images into the second model for object segmentation, thereby jointly training the first and second models.

[0035] In step A2, after obtaining the verification request, words are randomly selected from the dataset to generate a word set.

[0036] Furthermore, step A6 includes:

[0037] Step A61: Filter the object segmentation results based on the word selection results, select the object objects corresponding to the word selection results, and form an object set;

[0038] Step A62: Determine whether the click location data is within the internal space of an object in the object collection, and whether the internal space of each object in the object collection has been clicked.

[0039] If the click location data is within the internal space of an object, and the internal space of each object has been clicked, proceed to step A63.

[0040] If some click location data is not in the internal space of the object, or if some internal space of the object is not clicked, proceed to step A64;

[0041] Step A63 generates a verification success feedback message;

[0042] Step A64 generates a feedback message indicating that the verification failed.

[0043] The beneficial technical effect of this invention is that by randomly selecting words and generating images, and then clicking on the selected words and images to determine whether the verification is successful, the difficulty of cracking the verification code is greatly increased. Attached Figure Description

[0044] Figure 1 This is a schematic diagram of the modules of a verification code generation and verification system according to the present invention;

[0045] Figure 2-4 This is a flowchart illustrating the steps of a method for generating and verifying verification codes according to the present invention. Detailed Implementation

[0046] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0047] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.

[0048] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, but this is not intended to limit the scope of the invention.

[0049] See Figure 1 This invention provides a system for generating and verifying verification codes, comprising:

[0050] The verification code verification module (1) is used to interact with the client and call the image generation module according to the client's verification request;

[0051] The image generation module (2) is connected to the verification code verification module (1). It is used to generate a word set consisting of multiple words using the trained first model according to the verification request, and generate a verification image based on the word set. The verification image contains the object corresponding to each word in the word set.

[0052] The verification code verification module (1) is also used to: send a set of words back to the client for the user to select words, and after receiving the word selection result from the client, send a verification image back to the client for the user to click; after obtaining the click location data, call the image segmentation module;

[0053] The image segmentation module (3) is connected to the verification code verification module (1) and is used to segment the objects in the verification image using the trained second model to obtain the object segmentation result.

[0054] The verification code verification module (1) is used to: determine the verification result based on the word selection result, click location data and object segmentation result and send the verification result back to the client.

[0055] This invention uses AI (artificial intelligence) to randomly select words and generate images. The success of the verification is determined by clicking on the selected words and images, which greatly increases the difficulty of cracking the verification code and ensures that the system user is the actual user.

[0056] In this invention, an object corresponds to an object that can be seen in the real world, and the word corresponding to the object can be the name of the object. For example, if the object is a banana, the corresponding word is banana, and the object is a picture of a banana.

[0057] Furthermore, the first model is based on the diffusion model.

[0058] Furthermore, the second model is based on an arbitrary segmentation model.

[0059] This invention generates and verifies CAPTCHAs based on the Diffusion Model and SAM (Segment Anything Model), which significantly increases the difficulty of cracking CAPTCHAs.

[0060] The diffusion model is a stochastic process model used in image processing and computer vision that simulates diffusion or propagation phenomena in the physical world. In the diffusion model, the value of each pixel is updated based on the values ​​of its neighbors; this update process is like the diffusion or propagation of information in an image. Different words generate different verification images. From a certain number of words, several words can be generated, forming different numbers of words to form a word set, such as 3 / 4 / 5 / 6 / 7 / 8 words, etc. The randomness of word combinations determines the randomness of the generated images. Compared to fixed verification images, more verification images can be generated, with greater randomness, making the verification codes difficult to exhaustively solve. After the user selects a word, they must again select the object corresponding to the previously selected word on the verification image. Verification is successful only when all objects in the verification image corresponding to the selected words are selected, while objects not corresponding to the selected words are not selected; otherwise, verification fails. This increases the difficulty of cracking the verification code.

[0061] The Segment Anything Model is a deep learning model primarily used for image segmentation. It can identify and segment various objects in an image, regardless of what those objects are, and generates masks for all objects in the image. This type of model typically uses a large amount of training data to learn how to identify and segment objects in an image.

[0062] Furthermore, it also includes a training module (4), which is connected to the image generation module (2) and the image segmentation module (3) respectively, for jointly training the first model and the second model, including:

[0063] The data acquisition unit (41) is used to acquire images of several objects and perform word annotation to form a dataset;

[0064] The training unit (42) is connected to the data acquisition unit (41) and is used to input the dataset into the first model, extract the word set by the first model and generate sample images based on the extracted word set, input the sample images into the second model for object segmentation, thereby jointly training the first model and the second model.

[0065] After receiving a verification request, the image generation module randomly extracts words from the dataset to generate a word set. The first and second models are trained simultaneously using the same dataset to ensure that SAM can correctly recognize the content of images generated by the distributed models. The dataset can be dynamically expanded and adjusted; for example, data can be added, deleted, or modified.

[0066] Furthermore, the verification code verification module (1) includes:

[0067] The object filtering unit (11) is used to filter the object segmentation results based on the word selection results, select the object corresponding to the word selection results, and form an object set.

[0068] The verification and determination unit (12) is connected to the object filtering unit (11) to determine whether the click position data is in the internal space of the object in the object set, and whether the internal space of each object in the object set has been clicked, and to obtain the judgment result.

[0069] The feedback unit (13) and the connection verification and determination unit (12) are used for:

[0070] When the judgment result is that the click location data is in the internal space of the object, and the internal space of each object has been clicked, a feedback message of successful verification is generated;

[0071] If the judgment result is that some clicked location data is not in the internal space of the object, or that some internal space of the object has not been clicked, a verification failure feedback message will be generated.

[0072] Click location data refers to the pixel that was clicked, while the internal space of an object refers to the set of pixels contained within that object. When a user selects one or more words from a set, the system first filters out the object objects corresponding to the selected words. Then, it sequentially retrieves the pixels contained in each object and determines whether the clicked pixel is within that object—that is, whether the object's pixel set contains the clicked pixel—thus determining whether the verification is successful. The user needs to perform two operations: first, select a word (any selection will not cause verification failure); second, click on the object represented by the previously selected word in the image. The user must remember the first selected word, recognize its object, determine the object's internal space, and click on any location within it to pass the verification, effectively increasing the difficulty of cracking the CAPTCHA.

[0073] See Figure 2 This invention provides a method for generating and verifying verification codes, using the aforementioned system for generating and verifying verification codes, comprising:

[0074] Step A1: Obtain the client's verification request;

[0075] Step A2: Based on the verification request, use the trained first model to generate a word set consisting of multiple words, and generate a verification image based on the word set. The verification image contains the object corresponding to each word in the word set.

[0076] Step A3: Send the word set back to the client for the user to select words, and receive the word selection results from the client;

[0077] Step A4: Send a verification image to the client for the user to click, and obtain the click location data;

[0078] Step A5: Use the trained second model to segment the objects in the verification image to obtain the object segmentation results;

[0079] Step A6: Determine the verification result based on the word selection result, click location data, and object segmentation result, and then send the verification result back to the client.

[0080] This invention uses AI (artificial intelligence) to randomly select words and generate images. The success of the verification is determined by clicking on the selected words and images, which greatly increases the difficulty of cracking the verification code and ensures that the system user is the actual user.

[0081] In this invention, an object corresponds to an object that can be seen in the real world, and the word corresponding to the object can be the name of the object. For example, if the object is a banana, the corresponding word is banana, and the object is a picture of a banana.

[0082] Furthermore, the first model is based on the diffusion model.

[0083] Furthermore, the second model is based on an arbitrary segmentation model.

[0084] This invention generates and verifies CAPTCHAs based on the Diffusion Model and SAM (Segment Anything Model), which significantly increases the difficulty of cracking CAPTCHAs.

[0085] The diffusion model is a stochastic process model used in image processing and computer vision that simulates diffusion or propagation phenomena in the physical world. In the diffusion model, the value of each pixel is updated based on the values ​​of its neighbors; this update process is like the diffusion or propagation of information in an image. Different words generate different verification images. From a certain number of words, several words can be generated, forming different numbers of words to form a word set, such as 3 / 4 / 5 / 6 / 7 / 8 words, etc. The randomness of word combinations determines the randomness of the generated images. Compared to fixed verification images, more verification images can be generated, with greater randomness, making the verification codes difficult to exhaustively solve. After the user selects a word, they must again select the object corresponding to the previously selected word on the verification image. Verification is successful only when all objects in the verification image corresponding to the selected words are selected, while objects not corresponding to the selected words are not selected; otherwise, verification fails. This increases the difficulty of cracking the verification code.

[0086] The Segment Anything Model is a deep learning model primarily used for image segmentation. It can identify and segment various objects in an image, regardless of what those objects are, and generates masks for all objects in the image. This type of model typically uses a large amount of training data to learn how to identify and segment objects in an image.

[0087] See Figure 3 Furthermore, the training process for the first and second models includes the following steps:

[0088] Step B1: Collect images of several objects and label them with words to form a dataset;

[0089] Step B2: Input the dataset into the first model, which extracts the word set and generates sample images based on the extracted word set. Input the sample images into the second model for object segmentation, thereby jointly training the first and second models.

[0090] In step A2, after obtaining the verification request, words are randomly selected from the dataset to generate a word set.

[0091] After receiving a verification request, the image generation module randomly extracts words from the dataset to generate a word set. The first and second models are trained simultaneously using the same dataset to ensure that SAM can correctly recognize the content of images generated by the distributed models. The dataset can be dynamically expanded and adjusted; for example, data can be added, deleted, or modified.

[0092] See Figure 4 Furthermore, step A6 includes:

[0093] Step A61: Filter the object segmentation results based on the word selection results, select the object objects corresponding to the word selection results, and form an object set;

[0094] Step A62: Determine whether the click location data is within the internal space of an object in the object collection, and whether the internal space of each object in the object collection has been clicked.

[0095] If the click location data is in the internal space of an object, and the internal space of each object has been clicked, proceed to step A63.

[0096] If some of the click location data is not in the internal space of the object, or if some of the internal space of the object is not clicked, proceed to step A64;

[0097] Step A63 generates a verification success feedback message;

[0098] Step A64 generates a feedback message indicating that the verification failed.

[0099] Click location data refers to the pixel that was clicked, while the internal space of an object refers to the set of pixels contained within that object. When a user selects one or more words from a set, the system first filters out the object objects corresponding to the selected words. Then, it sequentially retrieves the pixels contained in each object and determines whether the clicked pixel is within that object—that is, whether the object's pixel set contains the clicked pixel—thus determining whether the verification is successful. The user needs to perform two operations: first, select a word (any selection will not cause verification failure); second, click on the object represented by the previously selected word in the image. The user must remember the first selected word, recognize its object, determine the object's internal space, and click on any location within it to pass the verification, effectively increasing the difficulty of cracking the CAPTCHA.

[0100] The above are merely preferred embodiments of the present invention and are not intended to limit the implementation methods and protection scope of the present invention. Those skilled in the art should recognize that any equivalent substitutions and obvious changes made based on the description and illustrations of the present invention should be included within the protection scope of the present invention.

Claims

1. A system for generating and verifying verification codes, characterized in that, include: The verification code module is used to interact with the client and calls the image generation module based on the client's verification request; The image generation module is connected to the verification code verification module and is used to generate a word set consisting of multiple words using a trained first model according to the verification request, and generate a verification image based on the word set. The verification image contains an object corresponding to each word in the word set. The verification code verification module is also used to: send the word set back to the client for the user to select words, and after receiving the word selection result from the client, send the verification image back to the client for the user to click; After obtaining the click location data, the image segmentation module is called; The image segmentation module, connected to the verification code verification module, is used to segment the object in the verification image using a trained second model to obtain the object segmentation result. The verification code verification module is used to: determine the verification result based on the word selection result, the click location data, and the object segmentation result, and then report the verification result back to the client.

2. The system for generating and verifying verification codes as described in claim 1, characterized in that, The first model is based on the diffusion model.

3. The system for generating and verifying verification codes as described in claim 1, characterized in that, The second model is based on the arbitrary segmentation model.

4. The system for generating and verifying verification codes as described in claim 1, characterized in that, It also includes a training module, which is connected to the image generation module and the image segmentation module respectively, for jointly training the first model and the second model, including: The data acquisition unit is used to collect images of several objects and label them with words to form a dataset; The training unit, connected to the data acquisition unit, is used to input the dataset into the first model, whereby the first model extracts a word set and generates sample images based on the extracted word set, and inputs the sample images into the second model for object segmentation, thereby jointly training the first model and the second model. After receiving the verification request, the image generation module randomly extracts words from the dataset to generate the word set.

5. The system for generating and verifying verification codes as described in claim 1, characterized in that, The verification code verification module includes: An object filtering unit is used to filter the object segmentation results based on the word selection results, select the object objects corresponding to the word selection results, and form an object set. The verification and determination unit, connected to the object filtering unit, is used to determine whether the click location data is in the internal space of the object in the object set, and whether the internal space of each object in the object set has been clicked, and to obtain the determination result. The feedback unit, connected to the verification and determination unit, is used for: When the judgment result is that the click location data is in the internal space of the object, and the internal space of each object has been clicked, a verification success feedback message is generated; If the judgment result is that some of the clicked location data is not in the internal space of the object, or that some of the internal space of the object has not been clicked, a verification failure feedback message is generated.

6. A method for generating and verifying verification codes, characterized in that, A system for generating and verifying verification codes as described in any one of claims 1-5 includes: Step A1: Obtain the client's verification request; Step A2: Based on the verification request, a word set consisting of multiple words is generated using the trained first model, and a verification image is generated based on the word set. The verification image contains object objects corresponding to each word in the word set. Step A3: Feed back the word set to the client for the user to select words, and receive the word selection result from the client; Step A4: Send the verification image back to the client for the user to click, and obtain the click location data; Step A5: Use the trained second model to segment the objects in the verification image to obtain the object segmentation result; Step A6: Determine the verification result based on the word selection result, the click location data, and the object segmentation result, and then report the verification result back to the client.

7. The method for generating and verifying verification codes as described in claim 6, characterized in that, The first model is based on the diffusion model.

8. The method for generating and verifying verification codes as described in claim 6, characterized in that, The second model is based on the arbitrary segmentation model.

9. The method for generating and verifying verification codes as described in claim 6, characterized in that, The training process for the first model and the second model includes the following steps: Step B1: Collect images of several objects and label them with words to form a dataset; Step B2: Input the dataset into the first model, whereby the first model extracts a word set and generates sample images based on the extracted word set. Then, input the sample images into the second model for object segmentation, thereby jointly training the first model and the second model. In step A2, after obtaining the verification request, words are randomly extracted from the dataset to generate the word set.

10. The method for generating and verifying verification codes as described in claim 6, characterized in that, Step A6 includes: Step A61: Filter the object segmentation results according to the word selection results, select the object objects corresponding to the word selection results, and form an object set; Step A62: Determine whether the click location data is within the internal space of the object in the object set, and whether the internal space of each object in the object set has been clicked. If the click location data is in the internal space of the object, and each of the objects' internal spaces has been clicked, then execute step A63; If some of the click location data is not in the internal space of the object, or if some of the internal space of the object is not clicked, proceed to step A64; Step A63 generates a verification success feedback message; Step A64 generates a feedback message indicating that the verification failed.

Citation Information

Patent Citations

  • Man-machine identification method and device, medium and electronic equipment

    CN110162955A

  • Data processing method and device, computer equipment and storage medium

    CN111783061A