Business real-name authentication method and device, electronic equipment and readable storage medium

By introducing an authentication information lock between the authentication server and the user terminal, the problem of low authentication security in business real-name authentication is solved, and the secure transmission and authenticity verification of authentication information are realized, thereby improving authentication security.

CN118827104BActive Publication Date: 2026-01-20中国移动通信集团江西有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311606519.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-28
Publication Date
2026-01-20
Estimated Expiration
2043-11-28

AI Technical Summary

Technical Problem

The security of real-name authentication for business in existing technologies is low. There is a risk of information tampering when information is exchanged between user terminals and authentication servers, which allows non-compliant businesses to be completed normally.

Method used

An authentication information lock is introduced between the authentication server and the user terminal. The authentication information lock carries the information to be authenticated, and the authentication information lock is generated and transmitted to lock the authenticity of the authentication information and ensure the security of the authentication information during the interaction process.

Benefits of technology

The introduction of authentication information locks enhances the security of real-name authentication for businesses, prevents information tampering, ensures the authenticity of authentication information, and thus guarantees the security of businesses to be authenticated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827104B_ABST
    Figure CN118827104B_ABST
Patent Text Reader

Abstract

The application discloses a business real-name authentication method and device, electronic equipment and a readable storage medium, which are applied to an authentication server, the authentication server is in communication connection with a user terminal, and the method comprises the following steps: acquiring a real-name authentication request sent by the user terminal for a to-be-authenticated business; feeding back a real-name authentication result corresponding to the real-name authentication request to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated business according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information; and performing real-name authentication on the to-be-authenticated business according to the to-be-authenticated information. The application solves the technical problem of low authentication security of business real-name authentication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a business real-name authentication method and device, electronic equipment and readable storage medium. BACKGROUND

[0002] With the continuous development of computer technology, the importance of business information security is also increasing, and in order to ensure the security of business information, more and more businesses use additional real-name authentication process to achieve, such as telecommunications business or financial business, etc.

[0003] At present, when performing real-name authentication on a business, it is usually first determined whether the user needs to perform real-name authentication operation during business operation, and for the business that needs real-name authentication, the real-name authentication result is obtained by calling the authentication capability of the authentication platform to control the security of the business, but since multiple nodes are involved in the user terminal during the process of business real-name authentication, at the same time, the user behavior of the user terminal is difficult to constrain, resulting in the risk of information tampering when the user terminal and the authentication server interact, and thus the situation that the non-compliant business can normally complete the real-name authentication occurs, so the current authentication security of business real-name authentication is low. SUMMARY

[0004] The main purpose of the present application is to provide a business real-name authentication method, device, electronic equipment and readable storage medium, which aims to solve the technical problem of low authentication security in the prior art of business real-name authentication.

[0005] To achieve the above purpose, the present application provides a business real-name authentication method applied to an authentication server, wherein the authentication server and a user terminal are in communication connection, and the business real-name authentication method comprises:

[0006] Obtaining a real-name authentication request sent by the user terminal for a to-be-authenticated business;

[0007] Feeding back a real-name authentication result corresponding to the real-name authentication request to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated business according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information;

[0008] Performing real-name authentication on the to-be-authenticated business according to the to-be-authenticated information.

[0009] To achieve the above purpose, the present application also provides a business real-name authentication method applied to a user terminal, wherein the user terminal and an authentication server are in communication connection, and the business real-name authentication method comprises:

[0010] send, to the authentication server, a real-name authentication request for a to-be-authenticated service, so that the authentication server feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal;

[0011] generate an authentication information lock of the to-be-authenticated service according to the real-name authentication result, wherein the authentication information lock carries to-be-authenticated information;

[0012] send the authentication information lock to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0013] To achieve the above object, the application further provides a service real-name authentication device applied to an authentication server, wherein the authentication server is in communication connection with a user terminal, and the service real-name authentication device comprises:

[0014] an obtaining module configured to obtain a real-name authentication request sent by the user terminal for a to-be-authenticated service;

[0015] a feedback module configured to feed back a real-name authentication result corresponding to the real-name authentication request to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated service according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information;

[0016] an authentication module configured to perform real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0017] To achieve the above object, the application further provides a service real-name authentication device applied to a user terminal, wherein the user terminal is in communication connection with an authentication server, and the service real-name authentication device comprises:

[0018] a first sending module configured to send, to the authentication server, a real-name authentication request for a to-be-authenticated service, so that the authentication server feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal;

[0019] a generating module configured to generate an authentication information lock of the to-be-authenticated service according to the real-name authentication result, wherein the authentication information lock carries to-be-authenticated information;

[0020] a second sending module configured to send the authentication information lock to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0021] The application further provides an electronic device, comprising at least one processor and a memory connected with the at least one processor, the memory storing instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the steps of the business real-name authentication method.

[0022] The application further provides a computer readable storage medium, the computer readable storage medium storing a program for implementing a business real-name authentication method, and the program for implementing the business real-name authentication method is executed by a processor to implement the steps of the business real-name authentication method.

[0023] The application further provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the steps of the business real-name authentication method.

[0024] In the application, when performing business real-name authentication, the application is applied to an authentication server, the authentication server is connected with a user terminal in communication, and first, an authentication request is acquired, which is sent by the user terminal and is directed to a to-be-authenticated business; a real-name authentication result corresponding to the authentication request is fed back to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated business according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information; and the to-be-authenticated business is authenticated according to the to-be-authenticated information, so that the purpose of locking the authentication information interacted between the authentication server and the user terminal by the authentication information lock is achieved, so that the authentication server can complete the business real-name authentication of the user terminal by the real to-be-authenticated information.

[0025] After the user terminal sends the authentication request to the authentication server, the user terminal generates a specific authentication information lock for the to-be-authenticated business according to the real-name authentication result fed back by the authentication server, and then the authentication server completes the real-name authentication of the to-be-authenticated business by the to-be-authenticated information in the authentication information lock, that is, the authentication information lock is used as the authenticity of the authentication information interacted between the authentication server and the user terminal, so that the purpose of ensuring that the to-be-authenticated information is not tampered with in the whole business real-name authentication interaction process between the authentication server and the user terminal is achieved, and finally the security of the real-name authentication of the to-be-authenticated business is ensured by the to-be-authenticated information.

[0026] Based on this, the application adds an authentication information lock in the service real-name authentication process of the authentication server and the user terminal, and then ensures the security of the transmission of the to-be-authenticated information between the authentication server and the user terminal through the authentication information lock, so that the real-name authentication of the to-be-authenticated service is finally completed through the to-be-authenticated information. Instead of directly interacting between the user terminal and the authentication server in the authentication information of the service real-name authentication process. Therefore, the technical defects that the user terminal and the authentication server interact with each other in the information, and the user behavior of the user terminal is difficult to constrain, resulting in the risk of information tampering, and the situation that the illegal business can be normally completed real-name authentication is easily occurred are overcome, and the authentication security of the service real-name authentication is improved. BRIEF DESCRIPTION OF DRAWINGS

[0027] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the application.

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.

[0029] Figure 1 The flowchart of the service real-name authentication method provided by the first embodiment of the present application is shown in the figure.

[0030] Figure 2 The architecture diagram of the lock storage model of the service real-name authentication method provided by the first embodiment of the present application is shown in the figure.

[0031] Figure 3 The execution timing diagram of the service real-name authentication of the service real-name authentication method provided by the first embodiment of the present application is shown in the figure.

[0032] Figure 4 The flowchart of the service real-name authentication method provided by the second embodiment of the present application is shown in the figure.

[0033] Figure 5 The flowchart of the service real-name authentication method provided by the third embodiment of the present application is shown in the figure.

[0034] Figure 6 The structure diagram of the service real-name authentication device provided by the fourth embodiment of the present application is shown in the figure.

[0035] Figure 7 The structure diagram of the electronic device provided by the fifth embodiment of the present application is shown in the figure.

[0036] The objectives, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0037] In order to make the above objectives, features and advantages of the present application more apparent, clear and complete, the technical solutions in the embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0038] Embodiment one

[0039] Firstly, it can be understood that, at present, when performing real-name authentication operation through the browser of the user terminal, the browser client needs to transmit the judgment instruction of the real-name authentication operation to the authentication server, and after the authentication server performs judgment, the final judgment result is returned to the browser front end of the user terminal. However, in the process of information interaction between the browser client and the authentication server, the judgment result may be tampered with, for example, the real judgment result is "need to judge real-name authentication", but due to the tampering of the execution operation of the user terminal, it is changed to "no need to judge real-name authentication", which makes the security of the business have great risk. Similarly, in the process of interaction between the browser client and the authentication platform, the judgment result may also be tampered with, for example, the judgment result of "not the real person" of the authentication platform is tampered with to "the real person", which also brings great threat to the security of business operation. However, the current system cannot determine whether there is tampering in the information interaction process of the previous authentication node when finally performing business submission, which finally leads to that the business that does not meet the regulations can also be finally submitted normally, that is, the authenticity of the authentication information between the user terminal and the authentication server cannot be ensured. Therefore, at present, there is an urgent need for a method for improving the authentication security of business real-name authentication.

[0040] The present application provides a business real-name authentication method, applied to an authentication server, the authentication server and a user terminal are in communication connection. In embodiment one of the business real-name authentication method of the present application, referring to Figure 1 , the business real-name authentication method comprises:

[0041] Step S10, obtaining a real-name authentication request sent by the user terminal for a to-be-authenticated business;

[0042] Step S20, feeding back the real-name authentication result corresponding to the real-name authentication request to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated service according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information.

[0043] Step S30, performing real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0044] In this embodiment, it should be noted that, although Figure 1 The logical sequence is shown, but in some cases, the steps shown or described can be performed in an order different from that shown here. The business real-name authentication method is applied to an authentication server, which is used to complete real-name authentication on a to-be-authenticated service. The authentication server can be a web server or an FTP server, etc. The authentication server and the user terminal are in communication connection. The user terminal has a front-end interactive page. The user can initiate business real-name authentication through the front-end interactive page of the user terminal. That is, the user can perform a preset operation on the front-end interactive interface of the user terminal to trigger a real-name authentication request. The real-name authentication request is used to initiate a real-name authentication process. In an implementable manner, the real-name authentication process can include three execution nodes: "judging whether real-name authentication is needed", "judging whether real-name authentication conditions are met", and "service submission". It can be understood that information interaction will exist in different execution nodes, that is, information tampering can occur in different execution nodes. The to-be-authenticated service represents a service waiting for real-name authentication. Specifically, it can be a telecommunications service, an accounting service, or a financial service, etc. For example, in an implementable manner, assuming that the to-be-authenticated service is a telecommunications service, the to-be-authenticated service can specifically be fixed telephone handling, mobile telephone handling, broadband service handling, wireless Internet card network access, and transfer, etc.

[0045] In addition, it should be noted that the real-name authentication result is used to feed back the execution result of the real-name authentication execution node. For example, assuming that the execution node is "judging whether real-name authentication is needed", the real-name authentication result can specifically be "real-name authentication is needed" or "real-name authentication is not needed". The authentication information lock is used to lock authentication information. The authentication information represents the authentication content fed back by the user terminal to the authentication server. For example, in an implementable manner, the authentication information can be a string. The authentication server can give the result of whether the to-be-authenticated service needs real-name authentication through the string. The authentication information lock can be generated by the user terminal deploying a lock storage model. The lock storage model can specifically correspond to the user terminal one by one. For example, refer to Figure 2, the architecture diagram of the lock storage model is shown, different lock storage models are used to record the authentication information locks of different users, different lock storage models can be distinguished by user IDs, one user ID can be used to open multiple menus, each menu corresponds to a lock map set, different types of authentication information locks in the lock map set correspond to different key-values, that is, the authentication information locks corresponding to the different execution nodes of the to-be-authenticated business are generated, the key and the value of the authentication information lock contain two parts, which can be separated by "|", the former represents the lock password of the authentication information lock, and the latter represents the lock state of the authentication information lock, the lock state can specifically include an open state or a closed state, for example, in an implementable manner, SK-A represents a password book, false represents a closed state, and true represents an open state, different authentication information locks have a life cycle, which can be created when a real-name authentication request is triggered, and can be cleared after the to-be-authenticated business completes real-name authentication, for example, the identification that the to-be-authenticated business completes real-name authentication can be that the front-end interaction interface of the user terminal is closed or the core real-name authentication business is submitted successfully.

[0046] In addition, it should be noted that the to-be-authenticated information is used to represent the information to be authenticated between the authentication server and the user terminal, for example, in an implementable manner, assuming that three execution nodes are involved in the business real-name authentication process between the user terminal and the authentication server, the interaction information at each execution node is A, B and C respectively, and the to-be-authenticated information is the sum of A, B and C, since the authentication server always has the real authentication information of the to-be-authenticated business, the real authentication information and the to-be-authenticated information can be compared to complete the real-name authentication of the to-be-authenticated business.

[0047] As an example, steps S10 to S30 include: receiving a real-name authentication request sent by the user terminal for the to-be-authenticated business; generating a corresponding real-name authentication result according to the real-name authentication request, and feeding back the real-name authentication result to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated business according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information; extracting real authentication information in a preset storage space, comparing the real authentication information and the to-be-authenticated information, and when the real authentication information and the to-be-authenticated information are consistent, determining that the to-be-authenticated business passes real-name authentication, and when the real authentication information and the to-be-authenticated information are inconsistent, determining that the to-be-authenticated business does not pass real-name authentication.

[0048] The embodiment of the application obtains a real-name authentication request for a to-be-authenticated service sent by a user terminal, and then feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal by an authentication server, so that the user terminal generates an authentication information lock of the to-be-authenticated service through real-name authentication information. Finally, after obtaining the authentication information lock, the authentication server completes real-name authentication of the to-be-authenticated service according to the to-be-authenticated information in the authentication information lock. Therefore, the purpose of locking the authentication information exchanged between the authentication server and the user terminal through the authentication information lock is achieved, so that the authentication server can complete the real-name authentication of the user terminal through real to-be-authenticated information. That is, the technical defect that the user terminal and the authentication server exchange information, and the user behavior of the user terminal is difficult to constrain, resulting in the risk of information tampering, and thus the situation that the non-compliant service can normally complete the real-name authentication is overcome. Therefore, the authentication security of the real-name authentication of the service is improved.

[0049] The real-name authentication request carries a first authentication information lock, and the step of feeding back the real-name authentication result corresponding to the real-name authentication request to the user terminal comprises:

[0050] Step A10, extracting authentication information from the first authentication information lock;

[0051] Step A20, detecting whether the to-be-authenticated service needs to be authenticated according to the authentication information;

[0052] Step A30, if yes, adjusting the lock state of the first authentication information lock to a closed state and encrypting the first lock password of the first authentication information lock to obtain the real-name authentication result;

[0053] Step A40, if no, adjusting the lock state of the first authentication information lock to an open state to obtain the real-name authentication result;

[0054] Step A50, feeding back the real-name authentication result to the user terminal.

[0055] In the embodiment, it is to be noted that by macroscopically discriminating whether the authentication information interacted between the user terminal and the authentication server is tampered, although the business real-name authentication process can be ensured to be carried out in a safe environment to a certain extent, since the execution nodes of the business real-name authentication process are more, the specific node and content where the information tampering occurs cannot be discriminated in detail, therefore, the embodiment of the application deploys multiple anti-tampering control points in the process of the business real-name authentication, so as to control the authentication information tampering problem that may occur in different stages of the interaction process, for example, in an implementable manner, assuming that the to-be-authenticated business is a telecommunications business, in the whole process from triggering the real-name authentication request to finally completing the real-name authentication, three interaction processes between the browser of the user terminal, the authentication server and the third-party platform are mainly involved, wherein the first interaction process refers to tampering the return value Q of the interaction result returned by the authentication server, the second refers to tampering the return value G of the interaction result returned by the third-party server, and the third refers to forging the judgment result G to join the acceptance message when the to-be-authenticated business is submitted, in order to prevent the bypassing in different stages from occurring, the authentication information lock can be adjusted in a targeted manner based on different authentication results of the authentication server.

[0056] Additionally, it needs to be noted that for the execution node whether real-name authentication is needed, an anti-tampering control point can be set on the authentication server, and the control interaction stage is: the browser of the user terminal → the authentication server → the browser of the user terminal, and the anti-tampering control point is for the password book SK-A in the lock storage model, and specifically, the third-party RSA public key can be used to encrypt the password book SK-A, and the encrypted SK-A+ and the real judgment result of “whether real-name authentication is needed” are returned to the user terminal together, so that the user terminal can store the SK-A+ in the corresponding authentication information lock; as described above, the browser of the user terminal can set the authentication information lock in the current session when initializing the page, and save the Q value (the judgment information of the core real-name authentication business of the authentication server by the browser) in a HashMap corresponding to the authentication information lock, the anti-tampering control point initiates a request to obtain the Q value and judges the Q value through the authentication server to execute corresponding processing logic according to the judgment result, when it is judged that real-name authentication is not needed, the authentication information lock in the lock storage model is set as follows: the authentication information lock is adjusted to SK-A|true, indicating that the lock state of the authentication information lock is in the open state, when it is judged that real-name authentication is needed, the password book SK-A is first RSA asymmetrically encrypted into the password book SK-A+ through the public key provided by the third-party platform, and a password lock is generated in the lock Map set, and the authentication information lock in the lock storage model is set as follows: the authentication information lock is set to the password book SK-A|false, at this time, the authentication information lock is in the closed state, and the Q value and the SK-A returned by the authentication server are returned to the user terminal together, wherein the default lock state of the authentication information lock is the open state, and the authentication information can be the Q value.

[0057] As an example, steps A10 to A50 include: extracting authentication information from the first authentication information lock; determining whether the to-be-authenticated business needs real-name authentication through the authentication information; if it is determined that the to-be-authenticated business needs real-name authentication, adjusting the lock state of the first authentication information lock to the closed state and encrypting the first lock password of the first authentication information lock to obtain the real-name authentication result; if it is determined that the to-be-authenticated business does not need real-name authentication, adjusting the lock state of the authentication information lock to the open state, and packaging the adjusted authentication information lock and the authentication information together as the real-name authentication result.

[0058] The step of adjusting the lock state of the first authentication information lock to the closed state and encrypting the first lock password of the first authentication information lock to obtain the real-name authentication result includes:

[0059] Step B10, obtaining a second authentication information lock by adjusting the lock state of the first authentication information lock to a closed state and encrypting the first lock password of the first authentication information lock;

[0060] Step B20, sending an encrypted authentication request carrying the second authentication information lock to an encryption authentication platform, so that the encryption authentication platform obtains the first lock password by decrypting the second authentication information lock, and generates an encrypted real-name authentication result according to the first lock password;

[0061] Step B30, taking the encrypted real-name authentication result as the real-name authentication result.

[0062] In the embodiment, it should be noted that after the to-be-authenticated business is determined to need real-name authentication, the authentication server needs to interact with the third-party platform to encrypt the information of "whether the real-name authentication condition is met", wherein the third-party platform can be specifically an encryption authentication platform, and the encryption authentication platform is used to complete encryption and decryption. For example, in an implementable manner, in order to ensure the security of the real-name authentication process of the to-be-authenticated business which needs to be authenticated, a tamper-proof control point can be set in the third-party platform, and the interaction stage controlled is: the browser of the user terminal→the third-party platform→the browser of the user terminal. The tamper-proof control point decrypts SK-A+ to obtain the original SK-A by using the RSA private key carried by itself, and encrypts the judgment result G of the third-party server to G+ by using SK-A, and generates a digest. It can be understood that the process of the encryption authentication platform decrypting the second authentication information lock and generating the encrypted real-name authentication result is as follows: if the request of the B tamper-proof control point is with SK-A+, the B tamper-proof control point obtains SK-A+ from the browser, and performs RSA asymmetric decryption SK-A+ to obtain SK-A by using the private key of the third-party server, and performs AES encryption to obtain G+ by using SK-A on the judgment result G of the third-party server, and combines SK-A and the judgment result G to generate a digest SK-A-G-MD5 by using MD5 encryption, and finally returns the judgment result G, the encrypted judgment result G+, and the digest SK-A-G-MD5 to the browser, that is, the judgment result G, the encrypted judgment result G+, and the digest SK-A-G-MD5 together constitute the encrypted real-name authentication result. When the encrypted real-name authentication result is returned to the user terminal as the real-name authentication result, the user terminal will directly encrypt the authentication information lock and the returned result, thereby avoiding the real-name verification condition which needs to be verified, and the information will not be tampered with when the information is interacted between the browser of the user terminal and the authentication server.

[0063] As an example, steps B10 to B30 include: obtaining a second authentication information lock by adjusting a lock state of the authentication information lock to a closed state and encrypting the first lock password of the authentication information lock; sending an encrypted authentication request carrying the second authentication information lock to an encrypted authentication platform, so that the encrypted authentication platform obtains the first lock password by decrypting the second authentication information lock, and generates an encrypted real-name authentication result according to the first lock password; and taking the encrypted real-name authentication result as the real-name authentication result.

[0064] The step of performing real-name authentication on the to-be-authenticated information according to the to-be-authenticated information includes:

[0065] Step C10, obtaining a third authentication information lock sent by the user terminal;

[0066] Step C20, extracting a second lock password from the third authentication information lock, and decrypting the real-name authentication result by using the second lock password to obtain real-name authentication information;

[0067] Step C30, generating target authentication information according to the second lock password and the real-name authentication information;

[0068] Step C40, determining that the real-name authentication of the to-be-authenticated service is passed when the target authentication information is consistent with the to-be-authenticated information;

[0069] Step C50, determining that the real-name authentication of the to-be-authenticated service is not passed when the target authentication information is inconsistent with the to-be-authenticated information.

[0070] In the embodiment, it is to be noted that, in addition to the determination of whether to perform real-name authentication and the determination of whether to meet the real-name authentication condition, the to-be-authenticated business can still be tampered with in the final submission process. Therefore, a tamper-proof control point can be further set on the authentication server to control the tamper-proof problem of the to-be-authenticated business in the submission stage. For example, in an implementable manner, the tamper-proof control point is set on the authentication server, and the controlled interactive stage is: the browser of the user terminal→the authentication server→the browser of the user terminal. The tamper-proof control point is to take the authentication information lock in the current session from the lock storage model, find the authentication information lock in the closed state according to the state of the authentication information lock, obtain the authentication information lock in the closed state at this time, and obtain SK-A from the authentication information lock in the closed state and the judgment result G, the encrypted judgment result G+, and the digest SK-A-G-MD5 from the browser of the user terminal. The judgment result G is decrypted by using the ARS algorithm, that is, the judgment result G, the encrypted judgment result G+, and the digest SK-A-G-MD5 are collectively used as the generated target authentication information. Then, the generated target authentication information and the to-be-authenticated information are compared, that is, the generated digest and the digest SK-A-G-MD5 are compared, and finally, whether the real-name authentication of the to-be-authenticated business passes is determined according to the comparison result.

[0071] As an example, steps C10 to C50 include: obtaining the third authentication information lock sent by the user terminal; extracting a second lock password in the second authentication information lock, and decrypting the real-name authentication result by using the second lock password to obtain real-name authentication information, wherein the real-name authentication information is used to represent the digest SK-A-G-MD5 obtained by decrypting the judgment result G+ by using the AES algorithm; comparing whether the target authentication information and the to-be-authenticated information are consistent, and when the target authentication information and the to-be-authenticated information are consistent, determining that the real-name authentication of the to-be-authenticated business passes; and when the target authentication information and the to-be-authenticated information are inconsistent, determining that the real-name authentication of the to-be-authenticated business does not pass.

[0072] In an implementable manner, the control flow of the tamper-proof control logic in the business submission stage is as follows: first, the authentication information lock in the closed state corresponding to the to-be-authenticated business is obtained through the session in the lock storage model. When the authentication information lock is in the closed state, the encrypted judgment result G+ and SK-A-G-MD5 are obtained from the browser of the user terminal. Then, SK-A is taken out from the authentication information lock in the closed state, the judgment result G is obtained by using the AES decryption on the encrypted judgment result G+ by using SK-A, the digest RK is generated by using the MD5 encryption on SK-A and the judgment result G, and finally, it is judged whether RK is equal to the previous SK-A-G-MD5. If they are equal, the authentication information lock can be opened. Otherwise, the real-name authentication of the to-be-authenticated business does not pass, that is, the browser of the user terminal displays that the submission of the to-be-authenticated business fails.

[0073] For example, in an implementable manner, with reference to Figure 3 , Figure 3 is shown to represent the execution timing diagram of the business real-name authentication, wherein X, Y and Z are used to represent different execution nodes in the business real-name process, and it can be understood that tampering of the authentication information can occur at X, Y and Z, and by setting anti-tampering control points at different execution nodes, the security of the authentication information exchanged between the browser of the user terminal, the authentication server and the third-party platform can be ensured, thereby improving the authentication security of the business real-name authentication.

[0074] In the business real-name authentication, the application is applied to an authentication server, which is in communication connection with a user terminal. First, a real-name authentication request sent by the user terminal for a to-be-authenticated business is acquired. A real-name authentication result corresponding to the real-name authentication request is fed back to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated business according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information. The to-be-authenticated business is authenticated according to the to-be-authenticated information. Therefore, the purpose of locking the authentication information exchanged between the authentication server and the user terminal through the authentication information lock is achieved, so that the authentication server can complete the business real-name authentication of the user terminal through the real to-be-authenticated information.

[0075] After the user terminal sends a real-name authentication request to the authentication server for a to-be-authenticated business, the user terminal generates a specific authentication information lock for the to-be-authenticated business according to the real-name authentication result fed back by the authentication server, and then the authentication server completes the real-name authentication of the to-be-authenticated business through the to-be-authenticated information in the authentication information lock. That is, the authentication information lock is used as the authenticity evidence of the authentication information exchanged between the authentication server and the user terminal, so that the purpose of ensuring that the to-be-authenticated information of the authentication server and the user terminal is not tampered with in the entire business real-name authentication interaction process is achieved, and finally the security of the real-name authentication of the to-be-authenticated business is ensured through the to-be-authenticated information.

[0076] Based on this, the embodiments of the present application add an authentication information lock in the service real-name authentication process of the authentication server and the user terminal, and then ensure the security of the transmission of the to-be-authenticated information between the authentication server and the user terminal through the authentication information lock, so as to finally complete the real-name authentication of the to-be-authenticated service through the to-be-authenticated information. Instead of directly interacting between the user terminal and the authentication server for the authentication information in the service real-name authentication process. Therefore, the technical defects that the user terminal and the authentication server interact with each other in the process of service real-name authentication, and the user behavior of the user terminal is difficult to constrain, resulting in the risk of information tampering, and the situation that the non-compliant service can be normally completed real-name authentication is overcome, so that the authentication security of the service real-name authentication is improved.

[0077] Embodiment two

[0078] Further, with reference to Figure 4 In another embodiment of the present application, the same or similar contents as the above embodiment one can be referred to the above introduction, and the subsequent will not be described again. On this basis, applied to a user terminal, the user terminal and an authentication server are in communication connection, and the service real-name authentication method comprises:

[0079] Step D10, sending a real-name authentication request for a to-be-authenticated service to the authentication server, so that the authentication server feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal;

[0080] Step D20, generating an authentication information lock of the to-be-authenticated service according to the real-name authentication result, wherein the authentication information lock carries to-be-authenticated information;

[0081] Step D30, sending the authentication information lock to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0082] In this embodiment, it should be noted that in order to improve the authentication security of the service real-name authentication, the security of the authentication information depends on the cooperation of the user terminal and the authentication server, and then the user terminal needs to deploy a lock storage model compared with the existing terminal to support the secure transmission of the interactive information between the user terminal and the authentication server. The same technical features of the embodiments of the present application as the above embodiments can be referred to the related description of the above embodiments, and the embodiments of the present application will not be described again here.

[0083] As an example, the step D10 to the step D30 include: sending, to the authentication server, a real-name authentication request for a to-be-authenticated service, so that the authentication server feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal; generating an authentication information lock of the to-be-authenticated service according to the real-name authentication result, wherein the authentication information lock carries to-be-authenticated information; and sending the authentication information lock to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0084] The real-name authentication request includes a first authentication information lock, and the step of generating the authentication information lock of the to-be-authenticated service according to the real-name authentication result includes:

[0085] The step E10 includes: detecting, according to the real-name authentication result, whether the first authentication information lock needs to be updated.

[0086] The step E20 includes: if yes, updating the first authentication information lock according to the real-name authentication result to obtain the authentication information lock of the to-be-authenticated service.

[0087] The step E30 includes: if no, taking the first authentication information lock as the authentication information lock of the to-be-authenticated service.

[0088] In this embodiment, it should be noted that when the real-name authentication request is triggered, the user terminal synchronously generates a corresponding first authentication information lock, and the content of the first authentication information lock stored in the user terminal changes according to different business demand authentication logics, and then the first authentication information lock of the user terminal can be processed based on different processing logics, thereby laying a foundation for subsequent improvement of authentication security of business real-name authentication.

[0089] As an example, the step E10 to the step E30 include: detecting, according to the real-name authentication result, whether the first authentication information lock needs to be updated; if it is detected that the first authentication information lock needs to be updated, updating the first authentication information lock according to the real-name authentication result to obtain the authentication information lock of the to-be-authenticated service; and if it is detected that the first authentication information lock does not need to be updated, taking the first authentication information lock as the authentication information lock of the to-be-authenticated service.

[0090] The embodiment of the application provides a business real-name authentication method, the embodiment of the application sends a real-name authentication request for a to-be-authenticated business to the authentication server, so that the authentication server feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal; according to the real-name authentication result, an authentication information lock of the to-be-authenticated business is generated, wherein the authentication information lock carries to-be-authenticated information; and the authentication information lock is sent to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated business according to the to-be-authenticated information, thereby achieving the purpose of locking the authentication information interacted between the authentication server and the user terminal through the authentication information lock, so that the authentication server can complete the business real-name authentication of the user terminal through the real to-be-authenticated information.

[0091] After the user terminal sends a real-name authentication request to the authentication server for a to-be-authenticated business, the user terminal generates a specific authentication information lock for the to-be-authenticated business according to the real-name authentication result fed back by the authentication server, and then the authentication server completes the real-name authentication on the to-be-authenticated business through the to-be-authenticated information in the authentication information lock, that is, the authentication information lock is used as the authenticity voucher of the authentication information interacted between the authentication server and the user terminal, so that the purpose of ensuring that the to-be-authenticated information is not tampered with in the whole business real-name authentication interaction process between the authentication server and the user terminal is achieved, and finally the security of the real-name authentication of the to-be-authenticated business is ensured through the to-be-authenticated information.

[0092] Based on this, the authentication information lock is added in the business real-name authentication process of the authentication server and the user terminal, and then the security of the to-be-authenticated information transmitted between the authentication server and the user terminal is ensured through the authentication information lock, so that the real-name authentication of the to-be-authenticated business is finally completed through the to-be-authenticated information. Instead of directly normally interacting the authentication information in the business real-name authentication process between the user terminal and the authentication server. Therefore, the technical defect that the user terminal and the authentication server exist the risk of information tampering when interacting information, and the situation that the non-compliant business can be normally completed real-name authentication occurs due to the fact that the user terminal usually involves multiple nodes in the process of business real-name authentication and the user behavior of the user terminal is difficult to constrain is overcome, and therefore the authentication security of the business real-name authentication is improved.

[0093] Embodiment three

[0094] The embodiment of the application also provides a business real-name authentication device, referring to Figure 5 , the business real-name authentication device comprises:

[0095] The acquisition module 101 is used for acquiring a real-name authentication request sent by the user terminal for a to-be-authenticated business;

[0096] The feedback module 102 is configured to feed back, to the user terminal, a real-name authentication result corresponding to the real-name authentication request, so that the user terminal generates an authentication information lock of the to-be-authenticated service according to the real-name authentication result and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information.

[0097] The authentication module 103 is configured to perform real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0098] Optionally, the real-name authentication request carries a first authentication information lock, and the feedback module 102 is further configured to:

[0099] extract authentication information from the first authentication information lock;

[0100] detect whether the to-be-authenticated service needs to be authenticated according to the authentication information;

[0101] if yes, adjust a lock state of the first authentication information lock to a closed state and encrypt a first lock password of the first authentication information lock to obtain the real-name authentication result;

[0102] if no, adjust the lock state of the first authentication information lock to an open state to obtain the real-name authentication result;

[0103] feed back the real-name authentication result to the user terminal.

[0104] Optionally, the feedback module 102 is further configured to:

[0105] adjust the lock state of the first authentication information lock to the closed state and encrypt the first lock password of the first authentication information lock to obtain a second authentication information lock;

[0106] send, to an encryption authentication platform, an encryption authentication request carrying the second authentication information lock, so that the encryption authentication platform obtains a first lock password by decrypting the second authentication information lock and generates an encrypted real-name authentication result according to the first lock password;

[0107] use the encrypted real-name authentication result as the real-name authentication result.

[0108] Optionally, the authentication module 103 is further configured to:

[0109] obtain a third authentication information lock sent by the user terminal;

[0110] extract a second lock password from the third authentication information lock and decrypt the real-name authentication result by using the second lock password to obtain real-name authentication information;

[0111] generating target authentication information according to the second lock password and the real-name authentication information;

[0112] when the target authentication information is consistent with the to-be-authenticated information, determining that the real-name authentication of the to-be-authenticated service is passed;

[0113] when the target authentication information is inconsistent with the to-be-authenticated information, determining that the real-name authentication of the to-be-authenticated service is failed.

[0114] The service real-name authentication device provided by the application solves the technical problem of low authentication security of service real-name authentication, and has the same beneficial effects as the service real-name authentication method provided by the above-mentioned embodiment.

[0115] Embodiment Four

[0116] The application also provides a service real-name authentication device, which refers to Figure 5 , and the service real-name authentication device comprises:

[0117] a first sending module 201 configured to send a real-name authentication request for a to-be-authenticated service to the authentication server, so that the authentication server feeds back a real-name authentication result corresponding to the real-name authentication request to the user terminal;

[0118] a generating module 202 configured to generate an authentication information lock of the to-be-authenticated service according to the real-name authentication result, wherein the authentication information lock carries to-be-authenticated information;

[0119] a second sending module 203 configured to send the authentication information lock to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0120] Optionally, the real-name authentication request comprises a first authentication information lock, and the authentication module 202 is further configured to:

[0121] detect whether the first authentication information lock needs to be updated according to the real-name authentication result;

[0122] if yes, update the first authentication information lock according to the real-name authentication result to obtain the authentication information lock of the to-be-authenticated service;

[0123] if no, take the first authentication information lock as the authentication information lock of the to-be-authenticated service.

[0124] The business real-name authentication device provided by the application solves the technical problem of low authentication security of business real-name authentication by using the business real-name authentication method in the second embodiment. Compared with the prior art, the business real-name authentication device provided by the embodiments of the application has the same beneficial effects as the business real-name authentication method provided by the embodiments of the application, and other technical features of the business real-name authentication device are the same as the features disclosed in the method embodiments, which will not be repeated here.

[0125] Embodiment five

[0126] The electronic device provided by the embodiments of the application comprises at least one processor and a memory connected with the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the business real-name authentication method in the first embodiment.

[0127] Reference will now be made to Figure 7 , which shows a structural schematic diagram of an electronic device suitable for implementing the embodiments of the present disclosure. The electronic device in the embodiments of the present disclosure can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablets), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and the like, and fixed terminals such as digital TVs, desktop computers, and the like. Figure 7 The electronic device shown is only an example and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.

[0128] As shown in Figure 7 , the electronic device can include a processing device 1001 (such as a central processor, a graphics processor, etc.), which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage device 1003 into a random access memory (RAM) 1004. In the RAM 1004, various programs and data required for the operation of the electronic device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus.

[0129] Generally, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 1003 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 1009. The communication devices can allow the electronic device to communicate wirelessly or wiredly with other devices to exchange data. Although the electronic device is illustrated as having various systems, it is understood that all of the illustrated systems are not required to implement or have the electronic device. More or less systems can alternatively be implemented or have.

[0130] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program code for performing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication devices 1009, or installed from the storage devices 1003, or installed from the ROM 1002. When the computer program is executed by the processing devices 1001, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are performed.

[0131] The electronic device provided by the present application adopts the business real-name authentication method in the above-mentioned embodiments, and solves the technical problem of low authentication security of business real-name authentication. Compared with the prior art, the electronic device provided by the embodiments of the present application has the same beneficial effects as the business real-name authentication method provided by the above-mentioned embodiments, and other technical features in the electronic device are the same as the features disclosed in the above-mentioned method, which will not be repeated here.

[0132] It should be understood that parts of the present disclosure can be realized by hardware, software, firmware or a combination thereof. In the description of the above-mentioned embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0133] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0134] Embodiment six

[0135] The embodiment provides a computer readable storage medium having computer readable program instructions stored thereon, and the computer readable program instructions are used for executing the business real-name authentication method in the above embodiment.

[0136] The computer readable storage medium provided by the embodiment of the application may be, for example, a U disk, but is not limited to an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system, system, or device, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electric connection having one or more conductive lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment, the computer readable storage medium can be any tangible medium containing or storing a program, which can be used by or in combination with an instruction execution system, system, or device. The program code contained on the computer readable storage medium can be transmitted by any appropriate medium, including but not limited to an electric wire, an optical cable, an RF (radio frequency), and the like, or any suitable combination of the above.

[0137] The computer readable storage medium described above can be included in an electronic device, or can exist separately without being assembled into an electronic device.

[0138] The computer readable storage medium described above carries one or more programs, and when the one or more programs are executed by an electronic device, the electronic device is caused to perform the following: obtaining a real-name authentication request sent by a user terminal for a to-be-authenticated service; feeding back, to the user terminal, a real-name authentication result corresponding to the real-name authentication request, so that the user terminal generates an authentication information lock of the to-be-authenticated service according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information; and performing real-name authentication on the to-be-authenticated service according to the to-be-authenticated information. Or,

[0139] Sending a real-name authentication request for a to-be-authenticated service to the authentication server, so that the authentication server feeds back, to the user terminal, a real-name authentication result corresponding to the real-name authentication request;

[0140] Generating an authentication information lock of the to-be-authenticated service according to the real-name authentication result, wherein the authentication information lock carries to-be-authenticated information;

[0141] Sending the authentication information lock to the authentication server, so that the authentication server performs real-name authentication on the to-be-authenticated service according to the to-be-authenticated information.

[0142] Computer program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0143] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0144] The modules involved in the embodiments of the present disclosure can be implemented in the manner of software or hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.

[0145] The computer readable storage medium provided by the present application stores computer readable program instructions for executing the business real-name authentication method, and solves the technical problem of low authentication security of business real-name authentication. Compared with the prior art, the beneficial effects of the computer readable storage medium provided by the embodiments of the present application are the same as those of the business real-name authentication method provided by the above-mentioned embodiments, and are not described here.

[0146] Embodiment seven

[0147] The application further provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the business real-name authentication method as described above.

[0148] The computer program product provided by the application solves the technical problem of low authentication security of business real-name authentication. Compared with the prior art, the computer program product provided by the embodiment of the application has the same beneficial effects as the business real-name authentication method provided by the above-mentioned embodiment, and will not be described here.

[0149] The above is only the preferred embodiment of the application, and does not limit the patent scope of the application, and any equivalent structure or equivalent process transformation using the content of the specification and drawings, or direct or indirect application in other related technical fields, are also included in the patent processing scope of the application.

Claims

1. A business real-name authentication method, characterized in that, The authentication method is applied to an authentication server, which communicates with the user terminal. The authentication method includes: Obtain the real-name authentication request sent by the user terminal for the service to be authenticated; The system feeds back the real-name authentication result corresponding to the real-name authentication request to the user terminal, so that the user terminal can generate an authentication information lock for the service to be authenticated based on the real-name authentication result, and send the authentication information lock to the authentication server, wherein the authentication information lock carries the authentication information. Based on the information to be authenticated, perform real-name authentication on the business to be authenticated; The real-name authentication request carries a first authentication information lock, and the step of feeding back the real-name authentication result corresponding to the real-name authentication request to the user terminal includes: Extract authentication information from the first authentication information lock; Based on the authentication information, determine whether the business to be authenticated needs to undergo real-name authentication; If so, the lock state of the first authentication information lock is adjusted to the closed state and the first lock password of the first authentication information lock is encrypted to obtain the real-name authentication result; If not, the lock state of the first authentication information lock is adjusted to the open state to obtain the real-name authentication result; The real-name authentication result is then fed back to the user terminal.

2. The business real-name authentication method as described in claim 1, characterized in that, The steps of adjusting the lock state of the first authentication information lock to the closed state and encrypting the first lock password of the first authentication information lock to obtain the real-name authentication result include: A second authentication information lock is obtained by adjusting the lock state of the first authentication information lock to the closed state and encrypting the first lock password of the first authentication information lock; Send an encrypted authentication request carrying the second authentication information lock to the encrypted authentication platform, so that the encrypted authentication platform can obtain the first lock password by decrypting the second authentication information lock, and generate an encrypted real-name authentication result based on the first lock password; The encrypted real-name authentication result shall be used as the real-name authentication result.

3. The business real-name authentication method as described in claim 2, characterized in that, The step of performing real-name authentication on the service to be authenticated based on the authentication information includes: Obtain the third authentication information lock sent by the user terminal; Extract the second lock password from the third authentication information lock, and decrypt the real-name authentication result using the second lock password to obtain the real-name authentication information; Target authentication information is generated based on the second lock password and the real-name authentication information; When the target authentication information and the information to be authenticated are consistent, it is determined that the real-name authentication of the service to be authenticated has passed. If the target authentication information and the information to be authenticated are inconsistent, it is determined that the real-name authentication of the business to be authenticated has failed.

4. A business real-name authentication method, characterized in that, Applied to a user terminal, wherein the user terminal and the authentication server are connected in communication, the business real-name authentication method includes: A real-name authentication request for the service to be authenticated is sent to the authentication server. The authentication server extracts authentication information from the first authentication information lock carried in the real-name authentication request. Based on the authentication information, it checks whether the service to be authenticated needs real-name authentication. If yes, the lock state of the first authentication information lock is adjusted to the closed state and the first lock password of the first authentication information lock is encrypted to obtain the real-name authentication result. If no, the lock state of the first authentication information lock is adjusted to the open state to obtain the real-name authentication result. The real-name authentication result is then fed back to the user terminal. Based on the real-name authentication result, an authentication information lock for the service to be authenticated is generated, wherein the authentication information lock carries the authentication information. The authentication information lock is sent to the authentication server so that the authentication server can perform real-name authentication on the service to be authenticated based on the authentication information.

5. The business real-name authentication method as described in claim 4, characterized in that, The step of generating the authentication information lock for the service to be authenticated based on the real-name authentication result includes: Based on the real-name authentication result, determine whether the first authentication information lock needs to be updated; If so, then based on the real-name authentication result, update the first authentication information lock to obtain the authentication information lock for the service to be authenticated; If not, then the first authentication information lock shall be used as the authentication information lock for the service to be authenticated.

6. A business real-name authentication device, characterized in that, The authentication server is used in a communication connection with the user terminal, and the business real-name authentication device includes: The acquisition module is used to acquire the real-name authentication request sent by the user terminal for the service to be authenticated; The feedback module is used to provide the user terminal with the real-name authentication result corresponding to the real-name authentication request, so that the user terminal can generate an authentication information lock for the service to be authenticated based on the real-name authentication result and send the authentication information lock to the authentication server. The authentication information lock carries the information to be authenticated, and the real-name authentication request carries a first authentication information lock. The feedback module is also used to extract authentication information from the first authentication information lock; based on the authentication information, detect whether the service to be authenticated needs real-name authentication; if yes, adjust the lock state of the first authentication information lock to a closed state and encrypt the first lock password of the first authentication information lock to obtain the real-name authentication result; if no, adjust the lock state of the first authentication information lock to an open state to obtain the real-name authentication result; and provide the real-name authentication result back to the user terminal. The authentication module is used to perform real-name authentication on the business to be authenticated based on the authentication information.

7. A business real-name authentication device, characterized in that, Applied to a user terminal, the user terminal and the authentication server are communicatively connected, and the business real-name authentication device includes: The first sending module is configured to send a real-name authentication request for the service to be authenticated to the authentication server, so that the authentication server can extract authentication information from the first authentication information lock carried in the real-name authentication request, and detect whether the service to be authenticated needs to undergo real-name authentication based on the authentication information; if yes, the lock state of the first authentication information lock is adjusted to the closed state and the first lock password of the first authentication information lock is encrypted to obtain the real-name authentication result; if no, the lock state of the first authentication information lock is adjusted to the open state to obtain the real-name authentication result; and the real-name authentication result is fed back to the user terminal. The generation module is used to generate an authentication information lock for the service to be authenticated based on the real-name authentication result, wherein the authentication information lock carries the authentication information. The second sending module is used to send the authentication information lock to the authentication server, so that the authentication server can perform real-name authentication on the service to be authenticated based on the authentication information.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; A memory that is communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the steps of the business real-name authentication method according to any one of claims 1 to 5.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program that implements a business real-name authentication method, which is executed by a processor to implement the steps of the business real-name authentication method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Service authentication method, system, and related devices

    CN109328348A

  • Hard wallet and verification method based on hard wallet

    CN109754241A