A login verification method, device and equipment of an application, a storage medium and a program product

By using image association information for secondary verification of a preset image after username verification, the problem of insufficient security and convenience in login verification in existing technologies is solved, achieving higher security and convenience.

CN118353669BActive Publication Date: 2025-12-26CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410481299.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-22
Publication Date
2025-12-26
Estimated Expiration
2044-04-22

AI Technical Summary

Technical Problem

Existing login verification methods are vulnerable to attacks, are cumbersome for users to remember, and lack security and convenience. There is a risk that unauthorized users may pass verification if they randomly enter the correct username.

Method used

After the username is verified, the preset image is verified a second time using the image processing rules in the image association information. The preset image is displayed to improve the user's memory convenience, and the two verifications of username and preset image enhance security.

Benefits of technology

By using a preset image for secondary verification, unauthorized users are prevented from randomly entering the correct username, which improves the security and convenience of application login and reduces the risk of username brute-force attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118353669B_ABST
    Figure CN118353669B_ABST
Patent Text Reader

Abstract

The application provides a login verification method of an application, and relates to the technical field of communication, and comprises the following steps: an application login interface is displayed according to a received application login request; when a username input in a username input box is received, the username is sent to a server, so that the server verifies the username to obtain picture association information; when it is determined that the picture association information comprises a preset picture and a picture processing rule, the preset picture is verified based on the picture processing rule; and when it is determined that the preset picture passes the verification, it is determined that the login verification passes. The preset picture is subjected to secondary verification by using the picture processing rule in the case that the username verification passes, so that the preset picture is prevented from being obtained by an illegal user by randomly filling in a correct username, the return information adopts the form of the preset picture, the user's memory is facilitated, the convenience of user login is improved, and the security of the application login verification is improved through the twice verification of the username and the preset picture.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and particularly relates to an application login verification method and device, equipment, a storage medium and a program product. BACKGROUND

[0002] With the popularity of mobile devices and the wide application of APP, the account security problem is increasingly concerned by users. The login verification method usually depends on the user inputting a username and a password. However, this method is vulnerable to various attack means, such as a fake phishing APP. In order to improve the login security, the reserved information of the user during registration can be used to effectively identify a bank website and an APP, and prevent online fraud by illegal users using a fake bank website or APP.

[0003] The existing reserved information is usually a string, which is relatively cumbersome and difficult for the user to remember, so that the user's login verification experience is poor. In addition, since the username input by an illegal user is random, when the randomly input username of the illegal user is correct, the reserved information will be directly displayed and verified, so that the existing login verification method based on the reserved information display has a certain security risk. SUMMARY

[0004] The present application provides an application login verification method, device, equipment, storage medium and program product, to realize safe and convenient login verification of the application.

[0005] In a first aspect, the present application provides an application login verification method, comprising: displaying an application login interface according to a received application login request, wherein the application login interface comprises a username input box;

[0006] When the username input in the username input box is received, the username is sent to a server to make the server verify the username and obtain picture association information;

[0007] The picture association information is received, and when it is determined that the picture association information comprises a preset picture and a picture processing rule, the preset picture is displayed on the application login interface, wherein the number of the preset picture is at least one, and the picture processing rule comprises a preset picture trigger sequence;

[0008] When it is determined that the user performs a point selection operation on the preset picture according to the preset picture trigger sequence, it is determined that the preset picture verification is passed.

[0009] When it is determined that the preset picture verification is passed, the application login is performed.

[0010] In a second aspect, the application provides a login verification device of an application, comprising:

[0011] An application login interface display module is configured to display an application login interface according to the received application login request, wherein the application login interface comprises a username input box;

[0012] A username verification module is configured to send the username input in the username input box to a server to make the server verify the username and obtain picture association information;

[0013] A preset picture display module is configured to receive the picture association information, and display a preset picture on the application login interface when it is determined that the picture association information comprises the preset picture and a picture processing rule, wherein the number of the preset picture is at least one, and the picture processing rule comprises a preset picture trigger sequence;

[0014] A preset picture verification module is configured to determine that the preset picture verification is passed when it is determined that a user performs a click operation on the preset picture according to the preset picture trigger sequence;

[0015] An application login module is configured to perform application login when it is determined that the preset picture verification is passed.

[0016] In a third aspect, the application provides an electronic device, comprising a processor and a memory connected with the processor;

[0017] The memory stores computer execution instructions;

[0018] The processor executes the computer execution instructions stored in the memory to realize the method described in the application.

[0019] In a fourth aspect, the application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the method described in the application.

[0020] In a fifth aspect, the application provides a computer program product, comprising a computer program, wherein the computer program is executed by the processor to realize the method described in the application.

[0021] The application provides an application login verification method, device, equipment, storage medium and program product, which obtains picture association information when verifying a username, and adopts a picture processing rule in the picture association information to perform secondary verification on a preset picture in a case where the username verification is passed, so that it is avoided that the preset picture is obtained due to random filling of a correct username by an illegal user, and since the return information adopts the form of the preset picture, the user's memory is facilitated and the convenience of user login is improved, and the security of application login verification is improved through twice verification of the username and the preset picture. BRIEF DESCRIPTION OF DRAWINGS

[0022] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the application and, together with the description, serve to explain the principles of the application.

[0023] Figure 1 A flowchart of an application login verification method provided for the first embodiment of the application;

[0024] Figure 2 A flowchart of an application login verification method provided for the second embodiment of the application;

[0025] Figure 3 A structural schematic diagram of an application login verification device provided for the third embodiment of the application;

[0026] Figure 4 A structural schematic diagram of an electronic equipment provided for the fourth embodiment of the application.

[0027] The above-described drawings have shown the specific embodiments of the application, and the following will have a more detailed description. These drawings and the written description are not intended to limit the scope of the concept of the application by any means, but to illustrate the concept of the application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0028] The exemplary embodiments will be described in detail herein with reference to the attached drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the application. Instead, they are merely examples of apparatuses and methods consistent with some aspects of the application as detailed in the appended claims.

[0029] The technical solutions of the present application and how the technical solutions solve the above technical problems will be described in detail below with specific examples. The following specific examples can be combined with each other, and the same or similar concepts or processes can not be described again in some examples. The embodiments of the present application will be described below with reference to the accompanying drawings. The acquisition, storage, use, processing, etc. of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.

[0030] The present embodiment aims at the prior art in order to improve login security, by returning the information reserved by the user at the time of registration, the bank website and APP can be effectively identified, and online fraud by illegal users using fake bank websites or APPs can be prevented. However, the existing reserved information is usually a string, which is relatively cumbersome and makes it difficult for users to remember, resulting in a poor user login verification experience. In addition, since the username input by the illegal user is random, if the randomly input username by the illegal user happens to be correct, the reserved information will be directly displayed and verified, so the existing login verification method based on the return of the reserved information has certain security risks. The present application provides a login verification method, device, equipment, storage medium and program product for an application, by obtaining picture association information when verifying the username, and using the picture processing rule in the picture association information to perform secondary verification on the preset picture when the username verification is passed, so as to avoid that the preset picture is obtained due to the illegal user randomly filling in the correct username. Since the returned information adopts the form of a preset picture, it is convenient for users to remember and improves the convenience of user login, and the security of application login verification is improved through the two verifications of the username and the preset picture.

[0031] Embodiment One

[0032] Figure 1 The flow of the login verification method for the application provided by the present embodiment can be applied to the case of safe and convenient login verification of the application. The method can be executed by a login verification device for the application, which can be realized in the form of hardware and / or software. As shown in Figure 1 the method includes the following steps:

[0033] Step S101, displaying an application login interface according to the received application login request.

[0034] The present embodiment mainly aims at the scenario of safe and convenient login verification of application. The application can be a financial application or a shopping application, and the like, which needs to perform username verification. The specific type of the application is not limited in the present embodiment. When the user triggers the application to be logged in on the terminal device, the terminal device will receive an application login request in response to the application login request, and display an application login interface. At this time, the application login interface will include a username input box.

[0035] It should be noted that the initial login interface displayed in response to the login request can only include a username input box. When it is determined that the username filled by the user is verified, a password input box will be displayed. Alternatively, the initial login interface can include a username input box and a password input box. However, the user only has the right to fill in the username input box, and the username input box is displayed in the form of a solid box. The user does not have the right to fill in the password input box, and the password input box is displayed in the form of a dashed box. Only when it is determined that the username is verified, the user's filling right for the password input box is enabled, and the password input box is converted into a solid box. Of course, the present embodiment is only an example, and the specific display form of the username input box and the password input box is not limited. As long as the user's input of the password can be limited when the username verification fails, it is within the protection scope of the present application.

[0036] Step S102, when the username input in the username input box is received, the username is sent to the server to verify the username and obtain picture association information.

[0037] Optionally, the username is sent to the server to verify the username and obtain picture association information, including: sending the username to the server to query whether the username is a registered legal username. If yes, the preset picture and the picture processing rule bound with the username are called, and the preset picture and the picture processing rule are taken as the picture association information. Otherwise, a random picture is selected from the secure picture database, and the selected random picture is taken as the picture association information.

[0038] Specifically, in the login stage, when the terminal device receives the username input by the user, the username is sent to the server for verification. Specifically, the username is matched with the user registration list, wherein the user registration list contains the usernames of registered and activated legal users. When the username is found in the user registration list, it is determined that the username is a registered and activated legal user. When the username is not found, it is determined that the username is an unregistered and activated illegal user. For registered and activated legal users, the server also binds a preset picture and a picture processing rule to the username of the user. The preset picture refers to the picture selected by the user from the security database in the registration stage and displayed in the login stage to verify the username input by the user. The number of preset pictures bound to each registered legal username is at least one. For example, the number of preset pictures can be related to the protection security level of the username. The higher the protection security level, the more preset pictures bound. The number of preset pictures bound in the embodiment is not limited. The picture processing rule refers to the operation specification configured by the user in the registration stage and required to be followed by the login user when verifying the displayed picture. For example, the picture processing rule includes a preset picture trigger sequence, i.e., the login user needs to trigger the displayed preset picture in a specified order. Or, the picture processing rule includes a preset picture number, i.e., when the displayed picture includes not only the preset picture but also other random pictures for interference, the login user needs to filter the preset picture corresponding to the preset picture number from the displayed picture. Therefore, in the embodiment, the content of the displayed picture is different according to the security level required by the username, and the corresponding picture processing rule is also different according to the different displayed picture content. Of course, the embodiment is only an example and does not limit the number of preset pictures bound to the username and the content of the picture processing rule. The server will feed back the preset picture and the picture processing rule bound to the username of the registered and activated legal user to the terminal device receiving the application login request as picture association information.

[0039] It should be noted that when the login user is an illegal user, the username input on the terminal device is an unregistered and activated username, and the corresponding server cannot query the username in the user registration list. At this time, in order to avoid the username from being exhausted attack, the server will also select a random picture from the security picture database, and feed back the selected random picture as the picture association information to the terminal device, so that even when the illegal login user fills in the wrong username, the terminal device will also receive and display the random picture, so that the server will feed back the picture association information to the terminal device regardless of the username filling error or not, but the picture content in the picture association information is different for different situations. For example, the picture association information fed back to the legal user includes the preset picture selected by the user during registration, and the picture association information fed back to the illegal user includes the random picture selected by the server, so as long as the login user inputs the username on the terminal device, the picture content will be displayed on the terminal device, so that the illegal user cannot determine whether the username filled by himself is correct, thereby interfering with the illegal login user, thereby avoiding the username from being exhausted attack.

[0040] Step S103, receiving the picture association information, when determining that the picture association information includes the preset picture and the picture processing rule, displaying the preset picture on the application login interface.

[0041] Specifically, the number of preset pictures is at least one, and the picture processing rule includes a preset picture trigger sequence. When the terminal device receives the picture association information fed back by the server, it will identify the picture association information. When it is determined that the received picture association information includes the picture processing rule, it is determined that the picture in the picture association information is a preset picture. When it is determined that the received picture association information does not include the picture processing rule, it is determined that the picture in the picture association information is a random picture. Therefore, the terminal device can determine the type of the picture included in the picture association information according to whether the picture processing rule is included in the received picture association information. When the received picture association information only contains a random picture, it can be determined that the username input by the login user is incorrect. In the case of username error, it is directly determined that the login verification fails, and the random picture is displayed on the application login interface. When it is determined that the picture association information includes the preset picture and the picture processing rule, it can be determined that the username input by the login user is correct, that is, it is a registered and activated legal username.

[0042] In addition, the picture association information further includes random pictures, and the picture processing rule includes preset picture numbers. In the embodiment, the specific content in the picture association information and the picture processing rule is not limited, as long as the subsequent verification of the preset pictures can be facilitated, and the specific content is within the protection scope of the application. In the embodiment, the preset pictures fed back by the server are displayed on the application login interface.

[0043] In step S104, when it is determined that the user performs the point selection operation on the preset pictures according to the preset picture trigger sequence, it is determined that the preset picture verification is passed.

[0044] Optionally, the preset picture is verified based on the picture processing rule, including: displaying the preset pictures on the application login interface, wherein the number of the preset pictures is at least one; when it is determined that the user operates the preset pictures according to the picture processing rule, it is determined that the preset picture verification is passed; and when it is determined that the user does not operate the preset pictures according to the picture processing rule, it is determined that the preset picture verification is not passed.

[0045] When the login user is an illegal user, there may also be a case of randomly writing a correct username. Although the probability of this case is relatively low, it may occur. At this time, in order to avoid causing the illegal user to pass the verification, the preset picture is verified based on the picture processing rule in the embodiment. Since the picture processing rule is configured by the user during registration, if the user is a legal user, the user knows the specific operation specification in the picture processing rule, and thus can perform the related operation on the displayed preset picture according to the operation specification in the picture processing rule. Therefore, when the terminal device receives the instruction that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture verification is passed, otherwise, it is determined that the preset picture verification is not passed.

[0046] Optionally, the picture processing rule includes a preset picture trigger sequence, and when it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture verification is passed, including: when it is determined that the user performs the point selection operation on the preset picture according to the preset picture trigger sequence, it is determined that the preset picture verification is passed.

[0047] In one specific implementation, when only preset pictures are included in the application login interface, for example, the number of preset pictures is three, A, B and C, and the preset picture trigger sequence included in the picture processing rule is B-A-C, when the three preset pictures are displayed on the application login interface, the user is required to confirm whether the pictures are the preset pictures of the user, that is, the prompt information "please select the preset picture" is displayed, at this time, if the terminal device receives the selection instruction of the user in the order of B-A-C, it is determined that the preset picture verification is passed, so that it is determined that the username is input by the legal user. If the terminal device receives the selection instruction of the user in the order of A-B-C or other orders, it is determined that the preset picture verification is not passed, so that it is determined that the username is input by an illegal user, and in order to protect the security of login and avoid attacks by illegal users, the filling permission of the username filling box on the application login interface by the login user is closed, and in order to avoid the selection order error caused by the forgetting of the legal user, the filling permission is reopened after a specified time period, so as to give the user an opportunity to fill in the username again.

[0048] Optionally, the picture association information further includes a random picture, and the picture processing rule includes a preset picture number, when it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture verification is passed, including: when it is determined that the user accurately selects the preset picture corresponding to the preset picture number, it is determined that the preset picture verification is passed.

[0049] In another specific implementation, when not only preset pictures but also random pictures are included in the application login interface, for example, the number of preset pictures is three, A, B and C, the number of random pictures is two, D and E, and the picture processing rule includes the preset picture numbers A, B and C, when the three preset pictures and the two random pictures are displayed on the application login interface, the user is required to select the preset picture from the displayed pictures, that is, the prompt information "please select the preset picture" is displayed, at this time, if the terminal device receives the selection instruction of the user for the preset pictures A, B and C, the terminal device compares the number of the selected picture of the user with the number in the picture processing rule, since they are consistent, it is determined that the preset picture verification is passed, so that it is determined that the username is input by the legal user. If the terminal device receives the selection instruction of the user for the preset pictures A and B and the random picture D, the terminal device compares the number of the selected picture of the user with the number in the picture processing rule, since they are inconsistent, it is determined that the preset picture verification is not passed, so that it is determined that the username is input by an illegal user, at this time, in order to protect the security of login and avoid attacks by illegal users, the filling permission of the username filling box on the application login interface by the login user is closed, and in order to avoid the selection order error caused by the forgetting of the legal user, the filling permission is reopened after a specified time period, so as to give the user an opportunity to fill in the username again.

[0050] It should be noted that in the present embodiment, the preset picture and the random picture for interference can also be displayed simultaneously in the login interface, and the picture processing rule includes not only the preset picture number, but also the preset picture trigger sequence, that is, the login user is required to select the preset picture specified by the user in the registration stage from the multiple pictures displayed on the login interface, and is also required to click according to the trigger sequence specified in the registration. Only when it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture verification is passed. The specific content of the picture association information received by the terminal device can be determined according to the protection security level of the user name set by the user in the registration. In the present embodiment, the specific verification method of the preset picture by the picture processing rule is not limited.

[0051] Step S105, when the preset picture verification is passed, the application login is performed.

[0052] Optionally, when the preset picture verification is passed, the application login is performed, including: when the preset picture verification is passed, a password filling box is displayed on the application login interface; receiving the login password input by the user in the password filling box, and performing the application login according to the login password.

[0053] Specifically, in the present embodiment, when it is determined that the user performs the click operation on the preset picture according to the preset picture trigger sequence, it is determined that the preset picture verification is passed. When the login interface only includes the user name filling box, in the case that the preset picture verification is passed, it is indicated that the current login is a legal user, and at this time, the password filling box is displayed on the login interface to receive the login password input by the user in the password filling box, and the application login is performed according to the login password. In addition, if the login interface simultaneously includes the user name filling box and the password filling box, but the user only has the filling authority for the user name filling box, the filling authority of the user for the password filling box is enabled to receive the login password input by the user in the password filling box. Of course, the present embodiment is only an example, and the display method of the password filling box is not limited, as long as the user can input the password in the password filling box in the case that the preset picture verification is passed. It is within the protection scope of the present application. It can be known that the present embodiment provides a more secure login verification method, which displays the preset picture while verifying the user name, increases the security of the login, and in order to avoid the user name from being attacked by exhaustion, the random picture is displayed to reduce the difficulty of cracking by illegal users, and the reserved information adopts the picture mode, so that the user does not need to remember too much reserved content, and the convenience and experience of the user login are improved.

[0054] The embodiment of the present application acquires picture association information when verifying a username, and in the case that the username verification is passed, a preset picture is subjected to secondary check using the picture processing rule in the picture association information, so as to avoid that the preset picture is acquired due to that an illegal user randomly fills in a correct username, and since the return information adopts the form of the preset picture, it is convenient for the user to remember and improves the convenience of user login, and the security of application login verification is improved through twice check of the username and the preset picture.

[0055] Embodiment Two

[0056] Figure 2 A flowchart of an application login verification method provided by the embodiment two of the present application, based on the above-mentioned embodiment, before an application login interface is displayed according to the received application login request, the embodiment further includes: displaying a security picture setting interface when it is determined that the username activation is successful in the registration stage, and determining the preset picture and the picture processing rule according to the operation of the user in the security picture setting interface. As shown in the figure, the method includes the following steps: Figure 2

[0057] Step S201, displaying a security picture setting interface when it is determined that the username activation is successful in the registration stage.

[0058] Specifically, when the user uses an application installed on a terminal device for the first time, a registration page is displayed, the user can fill in a username and a login password on the registration page to register, and the terminal device activates the username registered by the user, and displays a security picture setting interface when the user logs in for the first time after it is determined that the username activation is successful, the security picture setting interface includes a security level selection box, a picture selectable area and a picture processing rule filling area, wherein the user can operate in the security picture setting interface to determine the preset picture and the picture processing rule displayed in the login stage, and also set the security level of the username.

[0059] Step S202, determining the preset picture and the picture processing rule according to the operation of the user in the security picture setting interface.

[0060] ​Optionally, the preset picture and the picture processing rule are determined according to the operation of the user in the security picture setting interface, comprising: receiving a username security level selected by the user in a security level selection box, determining the number of security pictures selected in a picture selection area according to the username security level, and displaying the number of security pictures; receiving the security picture selected by the user in the picture security area based on the number of security pictures, and taking the selected security picture as the preset picture; receiving the picture processing rule added by the user for the preset picture in the picture processing rule filling area; determining the number of the preset picture, and uploading the number of the preset picture, the picture processing rule and the username to the server, so that the server determines the preset picture according to the number of the preset picture, and binds the preset picture, the picture processing rule and the username.

[0061] Specifically, in the security level selection box, multiple protection security levels are provided for the user to select, for example, a first security level, a second security level, and a third security level, and the protection security levels are sequentially increased, the user can select the protection security level of the registered account according to the security level of the application used, and the higher the protection security level, the more the number of preset pictures displayed, for example, the number of preset pictures corresponding to the first security level is two, the number of preset pictures corresponding to the second security level is three, and the number of preset pictures corresponding to the third security level is four, of course, the number of preset pictures corresponding to each protection security level in the embodiment is only an example and is not limited. In addition, the picture selection area contains a specified number of security pictures randomly retrieved from the database, for example, nine security pictures. Since the terminal device will display a prompt message of the number of corresponding security pictures in the protection security level setting for the user to refer to, the user can select the corresponding number of security pictures in the picture selection area according to the prompt, and the terminal device will select the security pictures selected by the user as the preset pictures to be displayed in the login stage, for example, when the user selects the first security level, only two security pictures can be selected from the picture selection area as preset pictures, of course, the user-selected protection security level and the number of selected preset pictures in the embodiment are only examples and are not limited, as long as the selected protection security level and the number of preset pictures are corresponding, they are within the protection scope of the application. In addition, the user can also add picture processing rules in the picture processing rule filling area, for example, for the two preset pictures A and B determined for the first security level, the added picture processing rule is: the preset pictures are triggered in the order of A-B, that is, the user needs to trigger the two preset pictures displayed in the login stage in the specified order. For the three preset pictures A, B, and C determined for the second security level, the added picture processing rule is: display two random pictures and the numbers A, B, and C of the preset pictures, that is, the user will not only display the three preset pictures selected by the user in the login stage, but also randomly select two security pictures that are not selected by the user from the security database as random pictures for interference, and the login user needs to select the preset pictures A, B, and C corresponding to the preset picture numbers from the displayed pictures.The added picture processing rule for the four preset pictures A, B, C and D determined according to the three security levels is: displaying three random pictures and the numbers A, B, C and D of the preset pictures, and triggering the preset pictures in the order of A-B-C-D by clicking, that is, in the login stage, the user will not only display the four preset pictures selected by the user, but also randomly select three security pictures that are not selected by the user from the security database as random pictures for interference. The login user not only needs to filter out the preset pictures A, B, C and C corresponding to the numbers of the preset pictures from the displayed pictures, but also needs to trigger the clicking in the order of A-B-C-D. As can be seen, the higher the security protection level of the selected username, the more complex the corresponding picture processing rule, and therefore the more complex the operation requirements of the user in the login stage. Of course, the embodiment only illustrates and does not limit the content selected or filled in the security level selection box, the picture selectable area and the picture processing rule filling area.

[0062] It should be noted that in the embodiment, the terminal device uploads the number of the preset picture, the picture processing rule and the username to the server after obtaining the number of the preset picture and the picture processing rule for each registered user's username. The server determines the preset picture according to the number of the preset picture, and binds the preset picture, the picture processing rule and the username, so that in the user login stage, after inputting the username on the login interface, the server can query the preset picture and the picture processing rule bound with the username, display the preset picture on the terminal device, and verify the displayed preset picture with the picture processing rule to ensure the security of the login.

[0063] Step S203: displaying an application login interface according to the received application login request.

[0064] In the embodiment, the application is mainly used for security and convenient login verification, and the application can be a financial application or a shopping application that needs to verify the username. The specific type of the application is not limited in the embodiment. When the user triggers the application to be logged in on the terminal device, the application login request is received, and the terminal device displays an application login interface in response to the application login request. The application login interface includes a username filling box.

[0065] Step S204: when receiving the username input in the username filling box, sending the username to the server to verify the username and obtain picture association information.

[0066] Optionally, the username is sent to the server to enable the server to verify the username and obtain picture association information, including: sending the username to the server to enable the server to query whether the username is a registered legal username, if yes, calling a preset picture and a picture processing rule bound to the username, and taking the preset picture and the picture processing rule as the picture association information, otherwise, selecting a random picture from a secure picture database, and taking the selected random picture as the picture association information.

[0067] Step S205, receiving the picture association information, and when it is determined that the picture association information includes a preset picture and a picture processing rule, displaying the preset picture on an application login interface.

[0068] Optionally, the picture processing rule includes a preset picture trigger sequence, or the picture association information further includes a random picture, and the picture processing rule includes a preset picture number.

[0069] Step S206, when it is determined that the user performs a point selection operation on the preset picture according to the preset picture trigger sequence, it is determined that the preset picture passes the verification.

[0070] Optionally, the preset picture is verified based on the picture processing rule, including: displaying the preset picture on the application login interface, wherein the number of preset pictures is at least one; when it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture passes the verification; when it is determined that the user does not operate the preset picture according to the picture processing rule, it is determined that the preset picture fails the verification.

[0071] Optionally, the picture processing rule includes a preset picture trigger sequence, when it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture passes the verification, including: when it is determined that the user performs a point selection operation on the preset picture according to the preset picture trigger sequence, it is determined that the preset picture passes the verification.

[0072] Optionally, the picture association information further includes a random picture, and the picture processing rule includes a preset picture number, when it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture passes the verification, including: when it is determined that the user accurately selects the corresponding preset picture according to the preset picture number, it is determined that the preset picture passes the verification.

[0073] Step S207, when it is determined that the preset picture passes the verification, the application is logged in.

[0074] Optionally, when it is determined that the preset picture check passes, the application login is performed, including: when it is determined that the preset picture check passes, a password filling box is displayed on the application login interface; a login password input by a user in the password filling box is received, and the application login is performed according to the login password.

[0075] The embodiment of the application obtains picture association information when verifying a username, and in the case that the username verification passes, a picture processing rule in the picture association information is used to perform secondary check on a preset picture, so that the preset picture is prevented from being obtained due to random filling of a correct username by an illegal user, the return information in the form of the preset picture is convenient for user memory and improves user login convenience, and the security of application login verification is improved through twice check of the username and the preset picture.

[0076] Embodiment three

[0077] Figure 3 The structure schematic diagram of the application login verification device provided by the embodiment of the application is shown in FIG. 1. Figure 3 As shown in the figure, the application login verification device includes an application login interface display module 310, a username verification module 320, a preset picture display module 330, a preset picture check module 340 and an application login module 350.

[0078] The application login interface display module 310 is configured to display an application login interface according to a received application login request, wherein the application login interface includes a username filling box.

[0079] The username verification module 320 is configured to send a username input in the username filling box to a server when the username is received, so that the server verifies the username and obtains picture association information.

[0080] The preset picture display module 330 is configured to receive the picture association information, and when it is determined that the picture association information includes a preset picture and a picture processing rule, display the preset picture on the application login interface, wherein the number of the preset pictures is at least one, and the picture processing rule includes a preset picture trigger sequence.

[0081] The preset picture check module is configured to determine that the preset picture check passes when a user performs a point-click operation on the preset picture according to the preset picture trigger sequence.

[0082] The application login module 340 is configured to perform application login when it is determined that the preset picture check passes.

[0083] Optionally, the username verification module is configured to send the username to the server to enable the server to query whether the username is a registered legal username, and if so, to retrieve a preset picture and a picture processing rule bound to the username, and use the preset picture and the picture processing rule as the picture association information,

[0084] Otherwise, a random picture is selected from the secure picture database, and the selected random picture is used as the picture association information.

[0085] Optionally, the preset picture verification module is configured to display the preset picture on the application login interface, wherein the number of preset pictures is at least one.

[0086] When it is determined that the user operates the preset picture according to the picture processing rule, it is determined that the preset picture verification is passed.

[0087] When it is determined that the user does not operate the preset picture according to the picture processing rule, it is determined that the preset picture verification is not passed.

[0088] Optionally, the picture association information further includes a random picture, and the picture processing rule includes a preset picture number, and the preset picture verification module is configured to determine that the preset picture verification is passed when it is determined that the user accurately selects the corresponding preset picture according to the preset picture number.

[0089] Optionally, the device further includes a random picture display module configured to directly determine that the login verification is not passed when it is determined that the picture association information only includes a random picture.

[0090] The random picture is displayed on the application login interface when the login verification is not passed.

[0091] Optionally, the device further includes a registration module configured to display a secure picture setting interface when it is determined that the username activation is successful in the registration stage, wherein the secure picture setting interface includes a security level selection box, a picture selection area, and a picture processing rule filling area.

[0092] The preset picture and the picture processing rule are determined according to the user's operation on the secure picture setting interface.

[0093] Optionally, the registration module is further configured to receive the username security level selected by the user in the security level selection box, determine the number of secure pictures selected in the picture selection area according to the username security level, and display the number of secure pictures.

[0094] The secure picture selected by the user in the picture selection area based on the number of secure pictures is received, and the selected secure picture is used as the preset picture.

[0095] The picture processing rule added by the user in the picture processing rule filling area for the preset picture is received.

[0096] determine the number of the preset picture, and upload the number of the preset picture, the picture processing rule and the username to a server, so that the server determines the preset picture according to the number of the preset picture, and binds the preset picture, the picture processing rule and the username.

[0097] Optionally, the application login module is configured to display a password filling box on an application login interface when it is determined that the preset picture passes the verification.

[0098] The login password input by the user in the password filling box is received, and the application is logged in according to the login password.

[0099] The application login verification device provided by the embodiment of the application can execute the application login verification method provided by any embodiment of the application, and has the corresponding function modules and beneficial effects of the execution method.

[0100] The embodiment of the application obtains picture association information when verifying the username, and performs secondary verification on the preset picture by using the picture processing rule in the picture association information when the username passes the verification, so that the preset picture is prevented from being obtained by an illegal user by randomly filling in a correct username, the return information is in the form of the preset picture, the user's memory is facilitated, the convenience of user login is improved, and the security of application login verification is improved by twice verification of the username and the preset picture.

[0101] Embodiment Four

[0102] Figure 4 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the applications described and / or claimed in this document.

[0103] As Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., connected to the at least one processor 11 in communication. The memory stores a computer program executable by the at least one processor 11, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0104] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.

[0105] The processor 11 can be various general and / or special-purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the login verification method of an application.

[0106] In some embodiments, the login verification method of an application can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the login verification method of an application described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the login verification method of an application by any other appropriate means, such as by means of firmware.

[0107] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0108] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, can cause instructions defined in the flow charts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine or entirely on a remote machine or server.

[0109] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0110] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0111] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), blockchain network, and the Internet.

[0112] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.

[0113] Embodiment Five

[0114] The embodiment of the application further provides a computer program product, comprising a computer program which, when executed by a processor, implements the login verification method of the application provided in any embodiment of the present application.

[0115] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0116] It is to be understood that the above description is directed to the preferred embodiments and that those skilled in the art will be able to devise various modifications which, although not specifically described herein, embody the principles of the application and are included within the spirit and scope of the application. Accordingly, while the preferred embodiments have been described above, those skilled in the art will understand that they are not to be limited to the preferred embodiments, but are to include all such embodiments falling within the scope of the application as defined by the appended claims.

Claims

1. A login verification method of an application, characterized by, The method comprises: displaying an application login interface according to the received application login request, wherein the application login interface comprises a username input box; when receiving the username input in the username input box, sending the username to a server to make the server verify the username and obtain picture association information; receiving the picture association information, and when determining that the picture association information comprises a preset picture and a picture processing rule, displaying the preset picture on the application login interface, wherein the number of the preset picture is at least one, and the picture processing rule comprises a preset picture trigger sequence; when determining that the user performs a click operation on the preset picture according to the preset picture trigger sequence, determining that the preset picture passes the verification; when determining that the preset picture passes the verification, performing application login; the step of performing application login when determining that the preset picture passes the verification comprises: when determining that the preset picture passes the verification, displaying a password input box on the application login interface; 2. The method of claim 1, wherein, receiving a login password input by the user in the password input box, and performing application login according to the login password. The step of sending the username to the server to make the server verify the username and obtain picture association information comprises: sending the username to the server to make the server query whether the username is a registered legal username, if yes, calling a preset picture and a picture processing rule bound to the username, and taking the preset picture and the picture processing rule as the picture association information, 3. The method of claim 1, wherein, otherwise, selecting a random picture from a secure picture database, and taking the selected random picture as the picture association information. The picture association information further comprises a random picture, and the picture processing rule comprises a preset picture number. The step of determining that the preset picture passes the verification when determining that the user performs an operation on the preset picture according to the picture processing rule comprises:

4. The method of claim 1, wherein, when determining that the user accurately clicks the corresponding preset picture according to the preset picture number, determining that the preset picture passes the verification. The method further comprises: when determining that the picture association information only comprises a random picture, directly determining that the login verification fails; 5. The method of claim 1, wherein, when the login verification fails, displaying the random picture on the application login interface. Before displaying the application login interface according to the received application login request, the method further comprises: when determining that the username activation succeeds in the registration stage, displaying a secure picture setting interface, wherein the secure picture setting interface comprises a security level selection box, a picture selectable area, and a picture processing rule input area; 6. The method of claim 5, wherein, determining the preset picture and the picture processing rule according to the user operation on the secure picture setting interface. The step of determining the preset picture and the picture processing rule according to the user operation on the secure picture setting interface comprises: receive a user name security level selected by a user in the security level selection box, determine a security picture number selected in the picture selectable area according to the user name security level, and display the security picture number; receive a security picture selected by a user in the picture security area based on the security picture number, and use the selected security picture as the preset picture; receive a picture processing rule added by a user for the preset picture in the picture processing rule filling area; determine a number of the preset picture, and upload the number of the preset picture, the picture processing rule, and the user name to a server, so that the server determines the preset picture according to the number of the preset picture, and binds the preset picture, the picture processing rule, and the user name.

7. An application log-in authentication apparatus characterized by comprising: comprise: an application login interface display module configured to display an application login interface according to a received application login request, wherein the application login interface comprises a user name filling box; a user name verification module configured to, when receiving a user name input in the user name filling box, send the user name to a server, so that the server verifies the user name to obtain picture association information; a preset picture display module configured to receive the picture association information, and when determining that the picture association information comprises a preset picture and a picture processing rule, display the preset picture on the application login interface, wherein the number of the preset picture is at least one, and the picture processing rule comprises a preset picture trigger sequence; a preset picture verification module configured to, when determining that a user performs a point selection operation on the preset picture according to the preset picture trigger sequence, determine that the preset picture verification is passed; an application login module configured to, when determining that the preset picture verification is passed, log in to the application; the application login module is configured to, when determining that the preset picture verification is passed, display a password filling box on the application login interface; receive a login password input by a user in the password filling box, and log in to the application according to the login password.

8. The apparatus of claim 7, wherein, the user name verification module is configured to send the user name to the server, so that the server queries whether the user name is a registered legal user name, if yes, calls preset pictures and picture processing rules bound to the user name, and uses the preset pictures and the picture processing rules as the picture association information, otherwise, selects a random picture from a security picture database, and uses the selected random picture as the picture association information.

9. The apparatus of claim 7, wherein, The device further comprises a registration module configured to, when determining that a user name activation is successful in a registration stage, display a security picture setting interface, wherein the security picture setting interface comprises a security level selection box, a picture selectable area, and a picture processing rule filling area; determine the preset picture and the picture processing rule according to an operation of a user in the security picture setting interface.

10. The apparatus of claim 9, wherein, The registration module is further configured to receive a username security level selected by the user in the security level selection box, determine a number of security pictures selected in the picture selection area according to the username security level, and display the number of security pictures; receive a security picture selected by the user in the picture security area based on the number of security pictures, and use the selected security picture as the preset picture; receive a picture processing rule added by the user in the picture processing rule filling area for the preset picture; determine a number of the preset picture, and upload the number of the preset picture, the picture processing rule, and the username to a server, so that the server determines the preset picture according to the number of the preset picture, and binds the preset picture, the picture processing rule, and the username.

11. An electronic device, comprising: comprising: a processor, and a memory connected to the processor in communication; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method of any one of claims 1-6.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are executed by the processor to implement the method of any one of claims 1-6.

13. A computer program product, characterised in that, comprising a computer program, which, when executed by the processor, implements the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Method and system for visiting website

    CN104144146A

  • Safe verifying method and device based on graphic feature

    CN105450604A