Authentication Method, Apparatus, Electronic Device, Storage Medium, and Computer Program Product

By using algorithm identifiers to encrypt user credentials, the method simplifies dual-factor authentication without hardware, maintaining security and convenience.

CN118590238BActive Publication Date: 2025-07-15AVIC GOLD NETWORK (BEIJING) TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410627855.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-20
Publication Date
2025-07-15
Estimated Expiration
2044-05-20

AI Technical Summary

Technical Problem

The existing two-factor authentication method requires additional hardware equipment, resulting in a cumbersome authentication process, affecting user experience and security.

Method used

By obtaining the user account and encryption algorithm identifier, the password is encrypted using the encryption algorithm corresponding to the algorithm identifier to achieve authentication without the need for additional hardware devices.

Benefits of technology

Simplifies the authentication process, improves user convenience and security, and reduces authentication complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118590238B_ABST
    Figure CN118590238B_ABST
Patent Text Reader

Abstract

The present application discloses an authentication method, apparatus, electronic device, storage medium, and computer program product. Among them, the method includes: obtaining account verification information detected on a front-end interaction interface, where the account verification information includes: a user account, a first authentication factor, and a second authentication factor; when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, using the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field; when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in advance, determining that the user account authentication is passed. The present application solves the technical problem that the authentication process is cumbersome due to the fact that the two-factor authentication method in the related art requires additional hardware devices to complete identity verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of security authentication, and in particular, to an authentication method, apparatus, electronic device, storage medium, and computer program product. Background Art

[0002] With the continuous increase of network security threats, two-factor authentication (2FA) has become an important means to protect user accounts and data security.

[0003] However, the two-factor authentication methods in the related art usually require users to provide a password (cognitive factor) and an additional hardware device (possession factor, such as a USB token, smart card, etc.) to complete the authentication. Due to the need for additional tools or media, the authentication process is cumbersome and may impose a burden on users. For example, the loss, damage, or inconvenience of carrying the hardware device may all affect the user experience and security.

[0004] For the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of this application provide an authentication method, apparatus, electronic device, storage medium, and computer program product to at least solve the technical problem that the authentication process is cumbersome due to the need for an additional hardware device in the two-factor authentication method in the related art to complete the authentication.

[0006] According to one aspect of the embodiments of this application, an authentication method is provided, including: obtaining account authentication information detected on a front-end interaction interface, where the account authentication information includes: a user account, a first authentication factor, and a second authentication factor, the first authentication factor is the password corresponding to the system for logging in to the user account, and the second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to identify a uniquely determined encryption algorithm; when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account pre-stored, using the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field; when the first encrypted field is consistent with the second encrypted field corresponding to the user account pre-stored, determining that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

[0007] Optionally, before obtaining the account verification information detected on the front-end interaction interface, the method further includes: when it is detected that the user account logs in to the system for the first time, sending an authentication factor binding prompt message to the front-end interaction interface for display, where the authentication factor binding prompt message is used to prompt the user to set a first authentication factor and a second authentication factor corresponding to the user account; in response to an input instruction detected on the front-end interaction interface, obtaining the first authentication factor and the second authentication factor input by the user, and storing the first authentication factor and the second authentication factor in the system database.

[0008] Optionally, the authentication factor binding prompt message includes: a list of encryption algorithms, where the list of encryption algorithms includes multiple encryption algorithms supported by the system, and the input instruction includes: a first input instruction and a second input instruction; the method further includes: in response to the first input instruction detected on the front-end interaction interface, obtaining the first authentication factor input by the user; in response to the second input instruction detected on the front-end interaction interface, determining the encryption algorithm corresponding to the second input instruction; using the encryption algorithm corresponding to the second input instruction to encrypt the first authentication factor to obtain a second encrypted field.

[0009] Optionally, determining the encryption algorithm corresponding to the second input instruction includes: determining the algorithm type of the encryption algorithm corresponding to the second input instruction, where the algorithm type includes: a first type that can encrypt without a secret key and a second type that requires a secret key for encryption; in the case where the algorithm type of the encryption algorithm is the first type, obtaining the algorithm identifier set by the user for the encryption algorithm; in the case where the algorithm type of the encryption algorithm is the second type, obtaining the algorithm identifier set by the user for the encryption algorithm and generating multiple random secret keys corresponding to the encryption algorithm, and sending the multiple random secret keys to the front-end interaction interface for display.

[0010] Optionally, in the case where the algorithm type of the encryption algorithm is the first type, the method includes: obtaining the algorithm identifier set by the user for the encryption algorithm, and using the encryption algorithm to encrypt the first authentication factor to obtain a second encrypted field; storing the algorithm identifier corresponding to the encryption algorithm and the second encrypted field in the system database.

[0011] Optionally, in the case where the algorithm type of the encryption algorithm is the second type, after sending the multiple random secret keys to the front-end interaction interface for display, the method further includes: in response to a third input instruction on the front-end interaction interface, determining the random secret key corresponding to the third input instruction, and obtaining the secret key identifier set by the user for the random secret key; based on the random secret key, using the encryption algorithm to encrypt the first authentication factor to obtain a second encrypted field; storing the algorithm identifier corresponding to the encryption algorithm, the random secret key and the corresponding secret key identifier, and the second encrypted field in the system database.

[0012] Optionally, the second authentication factor further includes: a key identifier; the method further includes: when the algorithm identifier and the key identifier in the second authentication factor are consistent with the algorithm identifier and the key identifier corresponding to the user account stored in the system, determining the encryption algorithm corresponding to the algorithm identifier and the random key corresponding to the key identifier; encrypting the first authentication factor using the encryption algorithm according to the random key to obtain a first encrypted field; when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in the system, determining that the user account authentication is passed.

[0013] According to another aspect of the embodiments of the present application, there is also provided an authentication device, including: an information acquisition module, configured to acquire account verification information detected on a front-end interaction interface, where the account verification information includes: a user account, a first authentication factor, and a second authentication factor, the first authentication factor is the password corresponding to the system for logging in to the user account, and the second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to identify a uniquely determined encryption algorithm; a first authentication module, configured to, when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, encrypt the first authentication factor using the encryption algorithm corresponding to the algorithm identifier to obtain a first encrypted field; a second authentication module, configured to, when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in advance, determine that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

[0014] According to yet another aspect of the embodiments of the present application, there is also provided an electronic device, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes the authentication method.

[0015] According to still another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, where the non-volatile storage medium includes a stored computer program, and the device where the non-volatile storage medium is located executes the authentication method by running the computer program.

[0016] According to still another aspect of the embodiments of the present application, there is also provided a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the authentication method.

[0017] In the embodiments of the present application, account verification information detected on the front-end interaction interface is obtained. The account verification information includes: a user account, a first authentication factor, and a second authentication factor. The first authentication factor is the password corresponding to the system for logging in to the user account, and the second authentication factor includes: an algorithm identifier, which is used to identify a uniquely determined encryption algorithm. When the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, the encryption algorithm corresponding to the algorithm identifier is used to encrypt the first authentication factor to obtain a first encrypted field. When the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in advance, it is determined that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field. In this way, the credibility of identity authentication is enhanced through the user's own thinking, achieving the purpose of completing authentication without the need for additional hardware devices, and the user's convenience and security are not reduced due to the reduction of usage complexity. Furthermore, it solves the technical problem of the cumbersome authentication process caused by the need for additional hardware devices to complete identity verification in the two-factor authentication method in the related art. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0019] Figure 1 is a hardware structure block diagram of a computer terminal (or electronic device) for implementing an authentication method according to an embodiment of the present application;

[0020] Figure 2 is a schematic diagram of a method flow for an authentication method according to an embodiment of the present application;

[0021] Figure 3 is a schematic diagram of a method flow for two-factor authentication in a security scenario according to an embodiment of the present application;

[0022] Figure 4 is a schematic diagram of an authentication login interface according to an embodiment of the present application;

[0023] Figure 5 is a schematic diagram of the structure of an authentication device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] To enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0026] To facilitate better understanding of the embodiments of this application by those skilled in the art, some technical terms or noun explanations related to the embodiments of this application are as follows:

[0027] Two-Factor Authentication (2FA): Also known as dual authentication or two-factor authentication, it is an authentication method that combines two conditions (such as a password and a physical object, including a credit card, a mobile phone, a token, or a biometric such as a fingerprint, etc.) to authenticate a user. This method has been adopted by some enterprises, especially in the remote access scenario. However, its application in other fields is relatively limited. An important reason for this situation is that this method requires additional tools and may impose a burden on IT and technical support personnel. Additionally, although 2FA is relatively secure, it may also be subject to certain types of attacks, such as man-in-the-middle attacks.

[0028] Multi-Factor Authentication (MFA): Also known as multi-factor verification or multi-factor authentication, it is a method of computer access control. In this method, a user needs to pass more than two authentication mechanisms to obtain authorization to use computer resources.

[0029] Both 2FA and MFA are authentication methods designed to enhance the security of authentication. By requiring users to provide multiple forms of credentials, they prevent unauthorized access. However, in related technologies, they both require additional media in specific implementation and application, resulting in a cumbersome authentication process.

[0030] To solve the above problems, relevant solutions are provided in the embodiments of this application. While ensuring security, it reduces the complexity of MFA (taking 2FA as an example) in the authentication stage, thereby enhancing the user experience. The following details the solutions of this application.

[0031] According to the embodiments of this application, a method embodiment for authentication is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0032] The method embodiments provided by the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal (or electronic device) for implementing the authentication method is shown. As Figure 1 shown, the computer terminal 10 (or electronic device) may include one or more processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.

[0033] It should be noted that one or more of the above-mentioned processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. This data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of the other components in the computer terminal 10 (or electronic device). As involved in the embodiments of the present application, this data processing circuit is a kind of processor control (such as the selection of a variable resistor terminal path connected to an interface).

[0034] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage devices corresponding to the authentication method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned authentication method. The memory 104 can include high-speed random access memory, and can also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 can further include memories remotely provided relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.

[0035] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network can include the wireless network provided by the communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0036] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of the computer terminal 10 (or electronic device).

[0037] Under the above operating environment, the embodiments of the present application provide an authentication method, Figure 2 which is a schematic diagram of a method flow for authentication provided according to the embodiments of the present application. As Figure 2 shown, the method includes the following steps:

[0038] Step S202: Obtain the account verification information detected on the front-end interaction interface. The account verification information includes: user account, first authentication factor, and second authentication factor. The first authentication factor is the password corresponding to the system for logging in to the user account, and the second authentication factor includes: algorithm identifier, which is used to identify a uniquely determined encryption algorithm.

[0039] Step S204: When the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account pre-stored, use the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field.

[0040] Step S206: When the first encrypted field is consistent with the second encrypted field corresponding to the user account pre-stored, determine that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

[0041] Through the above steps, the credibility of identity authentication is enhanced through the user's own thinking, achieving the purpose of completing authentication without additional hardware devices. Moreover, the user's convenience and security in use are not reduced due to the reduction in usage complexity, thus solving the technical problem of the cumbersome authentication process caused by the need for additional hardware devices in the two-factor authentication method in related technologies.

[0042] The authentication method in steps S202 to S206 of the embodiment of the present application will be further introduced below.

[0043] Figure 3 It is a schematic diagram of the method flow of two-factor authentication in a security scenario provided by an embodiment of the present application, as Figure 3 shown.

[0044] When the user logs in for the first time using the initial password or default password of the system, the system will require the user to modify the login password (first authentication factor) and bind the second authentication factor. The specific steps are as follows.

[0045] In some embodiments of the present application, before obtaining the account verification information detected on the front-end interaction interface, the method further includes the following steps: when it is detected that the user account logs in to the system for the first time, send an authentication factor binding prompt message to the front-end interaction interface for display, where the authentication factor binding prompt message is used to prompt the user to set the first authentication factor and the second authentication factor corresponding to the user account; in response to the input instruction detected in the front-end interaction interface, obtain the first authentication factor and the second authentication factor input by the user, and store the first authentication factor and the second authentication factor in the system database.

[0046] Specifically, when a user first uses the system to log in with the initial password created by the browser or client, the system forcibly requires the first authentication factor to be modified to a strong password and the corresponding second authentication factor to be bound (taking the option field Option as an example). If the modification or binding of Option is not performed, the remaining functions of the system are prohibited from being used and the account is locked.

[0047] Among them, the first authentication factor is the login password defined by the user himself, which can be composed of Chinese and English characters (case-sensitive), numbers, and symbols; the second authentication factor (Option option field) contains an algorithm identifier. After the initial login, the user will be required to select an encryption algorithm as the option field for subsequent logins. The specific steps are as follows.

[0048] In some embodiments of the present application, the authentication factor binding prompt information includes: an encryption algorithm list, which includes multiple encryption algorithms supported by the system. The input instructions include: a first input instruction and a second input instruction; the method further includes the following steps: in response to the first input instruction detected in the front-end interaction interface, obtaining the first authentication factor input by the user; in response to the second input instruction detected in the front-end interaction interface, determining the encryption algorithm corresponding to the second input instruction; using the encryption algorithm corresponding to the second input instruction to encrypt the first authentication factor to obtain a second encrypted field.

[0049] Specifically, after the user first logs in and modifies the password, the system will display an encryption algorithm list, requiring the user to customize the algorithm identifier corresponding to the encryption algorithm in the encryption algorithm list (the type and length value of the characters are not restricted here), and select one of the encryption algorithms as the algorithm for double-encrypting the first authentication factor, and use the algorithm identifier corresponding to the selected encryption algorithm as the Option option field bound to the user account.

[0050] As an alternative implementation, determining the encryption algorithm corresponding to the second input instruction includes the following steps: determining the algorithm type of the encryption algorithm corresponding to the second input instruction, where the algorithm type includes: a first type that can encrypt without a secret key, and a second type that requires a secret key for encryption; in the case where the algorithm type of the encryption algorithm is the first type, obtaining the algorithm identifier set by the user for the encryption algorithm; in the case where the algorithm type of the encryption algorithm is the second type, obtaining the algorithm identifier set by the user for the encryption algorithm, and generating multiple random secret keys corresponding to the encryption algorithm, and sending the multiple random secret keys to the front-end interaction interface for display.

[0051] The above encryption algorithm list contains a series of encryption algorithms preset by the system, such as cryptographic algorithms like MD5, SHA1, SHA256, RSA, ECC, SM1, SM2, SM3, SM4, ZUC, etc. In the embodiments of the present application, the algorithms in the encryption algorithm list can be divided into two types. One is the first type that can perform encryption without a secret key, including: hash cryptographic algorithms such as MD5, SHA-1, SHA-256, SHA-384, SHA-512, SM3, etc. The other is the second type that requires a secret key for encryption, including: symmetric / non-symmetric encryption algorithms such as RSA, ECC, SM4, SM2, etc.

[0052] The following will introduce the processing flows when the user selects two different types of encryption algorithms respectively.

[0053] In some embodiments of the present application, when the algorithm type of the encryption algorithm is the first type, the method includes the following steps: obtaining the algorithm identifier set by the user for the encryption algorithm, and using the encryption algorithm to encrypt the first authentication factor to obtain a second encrypted field; storing the algorithm identifier corresponding to the encryption algorithm and the second encrypted field into the system database.

[0054] Specifically, for the encryption algorithm that can perform encryption without a secret key, after the user selects one algorithm of this type and customizes the algorithm identifier corresponding to this algorithm, the system will use this algorithm identifier as the Option option field for subsequent login of this user account to verify the user's identity. And the system will use the algorithm identifier (Option option field) set by the user as the code value representing the encryption algorithm used for secondary encryption of this user account, and store the hash value corresponding to the algorithm identifier, as well as the second encrypted field obtained by performing secondary encryption on the first authentication factor after front-end encryption through this encryption algorithm, into the database.

[0055] For example, the algorithm identifier customized by the user, and the corresponding hash value and encryption algorithm are shown in the following table.

[0056]

[0057] In some embodiments of the present application, when the algorithm type of the encryption algorithm is the second type, after sending multiple random secret keys to the front-end interaction interface for display, the method further includes the following steps: in response to a third input instruction in the front-end interaction interface, determining the random secret key corresponding to the third input instruction, and obtaining the secret key identifier set by the user for the random secret key; based on the random secret key, using the encryption algorithm to encrypt the first authentication factor to obtain a second encrypted field; storing the algorithm identifier corresponding to the encryption algorithm, the random secret key and the corresponding secret key identifier, and the second encrypted field into the system database.

[0058] Specifically, for encryption algorithms that require a secret key for encryption, in addition to customizing the algorithm identifier, the user also needs to select a random secret key and customize the secret key identifier. At this time, the Option option field corresponding to the user account can consist of two parts: the algorithm identifier and the secret key identifier. For example, as shown in the following table.

[0059] Algorithm identifier Encryption algorithm Secret key identifier Random secret key A01 RSA 6685 <![CDATA[K a > ABC ECC 7878 <![CDATA[K b > Hehe SM$ Abc# <![CDATA[K c > weather SM2 Tick <![CDATA[K d >

[0060] After the user modifies the login password (the first authentication factor) and binds the second authentication factor during the first login, during subsequent logins, the user needs to log in through the Figure 4 interface shown. Among them, the password field needs to enter the first authentication factor, and the option field needs to enter the second authentication factor.

[0061] Specifically, after the user enters the user account, password (i.e., the first authentication factor), and "algorithm identifier" + "secret key identifier" (i.e., the second authentication factor, where for encryption algorithms that do not require a secret key, the "secret key identifier" can be empty), the client (or browser) will encrypt the password field and submit it to the backend server for processing together with the username and custom content.

[0062] For example, the fields submitted to the backend are: username = zhangsan&password = sha-256($pass)&option = sha-1($option), that is, the user account is zhangsan, the transmitted password (the first authentication factor) is the ciphertext encrypted by the SHA-256 algorithm, and the option option field (the second authentication factor) is the result of encrypting the algorithm identifier by SHA-1.

[0063] For the first type of encryption algorithm, the backend server will verify the data after receiving it. Specifically, first verify whether the algorithm identifier part is consistent with the stored hash value, that is, determine whether the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance. After successful verification, find the corresponding secondary encryption algorithm (hash algorithm) through the algorithm substitution table for encryption, and compare the encrypted result (i.e., the first encrypted field) with the hash value (i.e., the second encrypted field) stored in the database for this user. If they are consistent, this user is considered trustworthy; otherwise, the login fails.

[0064] For the second type of encryption algorithm, the method further includes the following steps: when the algorithm identifier and the secret key identifier in the second authentication factor are consistent with the algorithm identifier and the secret key identifier corresponding to the user account stored in the system, determining the encryption algorithm corresponding to the algorithm identifier and the random secret key corresponding to the secret key identifier; encrypting the first authentication factor using the encryption algorithm based on the random secret key to obtain a first encrypted field; when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in the system, determining that the user account authentication is passed.

[0065] Specifically, after receiving the data, the backend server splits the custom content, finds the corresponding secondary encryption algorithm through algorithm identifier mapping, and encrypts the first authentication factor using the random secret key corresponding to the secret key identifier. The backend server compares the content of the secondary encryption (i.e., the first encrypted field) with the stored hash value or the decrypted password (i.e., the second encrypted field). If they are consistent, the user is considered trustworthy; otherwise, the login fails.

[0066] The solution of this application simplifies the two-factor authentication process, eliminates the need for additional hardware devices, and improves the user's convenience of use; through the user-defined input box, efficient and fast identity verification is achieved. At the same time, the appearance of the user-defined input box will confuse attackers, and the newly added verification mechanism is not easily guessed or cracked due to the diversity of password algorithms; the application of the algorithm identifier and the secret key identifier can also effectively prevent man-in-the-middle attacks from sniffing and decrypting traffic; in addition, the use of the secondary encryption algorithm enhances the security of two-factor authentication, reduces the complexity of application development, and decreases the complexity of application integration.

[0067] According to an embodiment of the present application, an embodiment of an authentication device is also provided. Figure 5 It is a schematic structural diagram of an authentication device provided according to an embodiment of the present application. As Figure 5 shown, the device includes:

[0068] An information acquisition module 50, configured to acquire account verification information detected on the front-end interaction interface, where the account verification information includes: a user account, a first authentication factor, and a second authentication factor. The first authentication factor is the password corresponding to the system to which the logged-in user account belongs, and the second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to uniquely identify an encryption algorithm;

[0069] A first authentication module 52, configured to encrypt the first authentication factor using the encryption algorithm corresponding to the algorithm identifier when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, to obtain a first encrypted field;

[0070] The second authentication module 54 is configured to determine that the user account authentication is passed when the first encrypted field is consistent with the second encrypted field corresponding to the pre-stored user account, wherein the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

[0071] Optionally, before obtaining the account verification information detected on the front-end interaction interface, the authentication device is further configured to: when detecting that the user account logs in to the system for the first time, send an authentication factor binding prompt message to the front-end interaction interface for display, where the authentication factor binding prompt message is used to prompt the user to set the first authentication factor and the second authentication factor corresponding to the user account; in response to the input instruction detected on the front-end interaction interface, obtain the first authentication factor and the second authentication factor input by the user, and store the first authentication factor and the second authentication factor in the system database.

[0072] Optionally, the authentication factor binding prompt message includes: a list of encryption algorithms, where the list of encryption algorithms includes multiple encryption algorithms supported by the system, and the input instructions include: a first input instruction and a second input instruction; the authentication device is further configured to: in response to the first input instruction detected on the front-end interaction interface, obtain the first authentication factor input by the user; in response to the second input instruction detected on the front-end interaction interface, determine the encryption algorithm corresponding to the second input instruction; use the encryption algorithm corresponding to the second input instruction to encrypt the first authentication factor to obtain a second encrypted field.

[0073] Optionally, determining the encryption algorithm corresponding to the second input instruction includes: determining the algorithm type of the encryption algorithm corresponding to the second input instruction, where the algorithm type includes: a first type that can encrypt without a secret key and a second type that requires a secret key for encryption; when the algorithm type of the encryption algorithm is the first type, obtain the algorithm identifier set by the user for the encryption algorithm; when the algorithm type of the encryption algorithm is the second type, obtain the algorithm identifier set by the user for the encryption algorithm, and generate multiple random secret keys corresponding to the encryption algorithm, and send the multiple random secret keys to the front-end interaction interface for display.

[0074] Optionally, when the algorithm type of the encryption algorithm is the first type, the authentication device is further configured to: obtain the algorithm identifier set by the user for the encryption algorithm, and use the encryption algorithm to encrypt the first authentication factor to obtain a second encrypted field; store the algorithm identifier corresponding to the encryption algorithm and the second encrypted field in the system database.

[0075] Optionally, when the algorithm type of the encryption algorithm is the second type, after sending multiple random secret keys to the front-end interaction interface for display, the authentication device is further configured to: in response to a third input instruction in the front-end interaction interface, determine the random secret key corresponding to the third input instruction, and obtain the secret key identifier set by the user for the random secret key; encrypt the first authentication factor using the encryption algorithm based on the random secret key to obtain a second encrypted field; store the algorithm identifier corresponding to the encryption algorithm, the random secret key and the corresponding secret key identifier, and the second encrypted field in the system database.

[0076] Optionally, the second authentication factor further includes: a secret key identifier; the authentication device is further configured to: when the algorithm identifier and the secret key identifier in the second authentication factor are consistent with the algorithm identifier and the secret key identifier corresponding to the user account stored in the system, determine the encryption algorithm corresponding to the algorithm identifier and the random secret key corresponding to the secret key identifier; encrypt the first authentication factor using the encryption algorithm based on the random secret key to obtain a first encrypted field; determine that the user account authentication is passed when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in the system.

[0077] It should be noted that each module in the above authentication device may be a program module (for example, a set of program instructions that implement a specific function), or a hardware module. For the latter, it may be presented in the following forms, but not limited to: the presentation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0078] It should be noted that the authentication device provided in this embodiment can be used to execute Figure 2 the authentication method shown, therefore, the relevant explanations of the above authentication method also apply to the embodiments of the present application, and will not be repeated here.

[0079] The embodiments of the present application further provide a non-volatile storage medium, which includes a stored computer program. Wherein, the device where the non-volatile storage medium is located executes the following authentication method by running the computer program: obtaining account verification information detected on the front-end interaction interface, where the account verification information includes: user account, first authentication factor, second authentication factor, the first authentication factor is the password corresponding to the system for logging in to the user account, and the second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to identify a uniquely determined encryption algorithm; when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, using the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field; when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in advance, determining that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

[0080] The embodiments of the present application further provide a computer program product, including a computer program, which when executed by a processor, implements the steps of the authentication method described in each embodiment of the present application: obtaining account verification information detected on the front-end interaction interface, where the account verification information includes: user account, first authentication factor, second authentication factor, the first authentication factor is the password corresponding to the system for logging in to the user account, and the second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to identify a uniquely determined encryption algorithm; when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, using the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field; when the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in advance, determining that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

[0081] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0082] In the above embodiments of the present application, the descriptions of the respective embodiments have their own focuses. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0083] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0084] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0085] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0086] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.

[0087] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A certification method, characterized in that, Including: Obtain the account verification information detected on the front-end interaction interface. The account verification information includes: user account, first authentication factor, and second authentication factor. The first authentication factor is the password corresponding to logging in to the system corresponding to the user account. The second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to identify a uniquely determined encryption algorithm; When the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account pre-stored, use the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field; Among them, the algorithm identifier corresponding to the user account is determined based on the second input instruction detected on the front-end interaction interface when the user account first logs in to the system. The steps of determining the encryption algorithm corresponding to the algorithm identifier corresponding to the second input instruction include: determining the algorithm type of the encryption algorithm corresponding to the second input instruction, where the algorithm type includes: a first type that can be encrypted without a secret key, and a second type that requires a secret key for encryption; when the algorithm type of the encryption algorithm is the first type, obtain the algorithm identifier set by the user for the encryption algorithm; when the algorithm type of the encryption algorithm is the second type, obtain the algorithm identifier set by the user for the encryption algorithm, and generate multiple random secret keys corresponding to the encryption algorithm, and send the multiple random secret keys to the front-end interaction interface for display; When the first encrypted field is consistent with the second encrypted field corresponding to the user account pre-stored, determine that the user account authentication is passed, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

2. The authentication method according to claim 1, wherein Before obtaining the account verification information detected on the front-end interaction interface, the method further includes: When it is detected that the user account first logs in to the system, send an authentication factor binding prompt message to the front-end interaction interface for display, where the authentication factor binding prompt message is used to prompt the user to set the first authentication factor and the second authentication factor corresponding to the user account; In response to the input instruction detected on the front-end interaction interface, obtain the first authentication factor and the second authentication factor input by the user, and store the first authentication factor and the second authentication factor in the system database.

3. The authentication method according to claim 2, wherein The authentication factor binding prompt message includes: an encryption algorithm list, and the encryption algorithm list includes multiple encryption algorithms supported by the system. The input instructions include: a first input instruction and a second input instruction. The method further includes: In response to the first input instruction detected on the front-end interaction interface, obtain the first authentication factor input by the user; In response to the second input instruction detected on the front-end interaction interface, determine the encryption algorithm corresponding to the second input instruction; Use the encryption algorithm corresponding to the second input instruction to encrypt the first authentication factor to obtain the second encrypted field.

4. The authentication method according to claim 3, wherein When the algorithm type of the encryption algorithm is the first type, the method includes: Obtain the algorithm identifier set by the user for the encryption algorithm, and use the encryption algorithm to encrypt the first authentication factor to obtain the second encrypted field; Store the algorithm identifier corresponding to the encryption algorithm and the second encrypted field in the system database.

5. The authentication method according to claim 3, wherein When the algorithm type of the encryption algorithm is the second type, after sending multiple random secret keys to the front-end interaction interface for display, the method further includes: In response to a third input instruction in the front-end interaction interface, determine the random secret key corresponding to the third input instruction, and obtain the secret key identifier set by the user for the random secret key; According to the random secret key, use the encryption algorithm to encrypt the first authentication factor to obtain the second encrypted field; Store the algorithm identifier corresponding to the encryption algorithm, the random secret key and the corresponding secret key identifier, and the second encrypted field in the system database.

6. The authentication method according to claim 5, wherein The second authentication factor further includes: the secret key identifier; the method further includes: When the algorithm identifier and the secret key identifier in the second authentication factor are consistent with the algorithm identifier and the secret key identifier corresponding to the user account stored in the system, determine the encryption algorithm corresponding to the algorithm identifier and the random secret key corresponding to the secret key identifier; According to the random secret key, use the encryption algorithm to encrypt the first authentication factor to obtain the first encrypted field; When the first encrypted field is consistent with the second encrypted field corresponding to the user account stored in the system, determine that the user account authentication is passed.

7. An authentication device, characterized in that, Includes: An information acquisition module, configured to acquire account verification information detected in a front-end interaction interface, where the account verification information includes: a user account, a first authentication factor, and a second authentication factor, the first authentication factor is the password corresponding to logging in to the system corresponding to the user account, and the second authentication factor includes: an algorithm identifier, and the algorithm identifier is used to uniquely identify an encryption algorithm; A first authentication module, configured to, when the algorithm identifier in the second authentication factor is consistent with the algorithm identifier corresponding to the user account stored in advance, use the encryption algorithm corresponding to the algorithm identifier to encrypt the first authentication factor to obtain a first encrypted field; Among them, the algorithm identifier corresponding to the user account is determined according to the second input instruction detected in the front-end interaction interface when the user account logs in to the system for the first time. The steps of determining the encryption algorithm corresponding to the algorithm identifier corresponding to the second input instruction include: determining the algorithm type of the encryption algorithm corresponding to the second input instruction, where the algorithm type includes: a first type that can be encrypted without a secret key, and a second type that requires a secret key for encryption; in the case where the algorithm type of the encryption algorithm is the first type, obtaining the algorithm identifier set by the user for the encryption algorithm; in the case where the algorithm type of the encryption algorithm is the second type, obtaining the algorithm identifier set by the user for the encryption algorithm, generating a plurality of random secret keys corresponding to the encryption algorithm, and sending the plurality of random secret keys to the front-end interaction interface for display; A second authentication module, configured to determine that the user account authentication is passed when the first encrypted field is consistent with the second encrypted field corresponding to the pre-stored user account, where the encryption algorithm corresponding to the second encrypted field is the same as the encryption algorithm corresponding to the first encrypted field.

8. An electronic device, characterized in that, Including: A memory and a processor, the processor is configured to run a program stored in the memory, where the program, when running, executes the authentication method according to any one of claims 1 to 6.

9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, where the device where the non-volatile storage medium is located executes the authentication method according to any one of claims 1 to 6 by running the computer program.

10. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the authentication method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Dynamic multi-factor identity authentication and authentication method and storage medium

    CN114385987A

  • Security authentication method, device and equipment and storage medium

    CN115022057A