A remote security verification method, system, device and medium

By obtaining and registering the device identifier and verification code of the controlled device on the server side, and then assisting in the connection after security verification, the reliability and convenience issues of traditional remote security verification are solved, and efficient security verification is achieved.

CN118972122BActive Publication Date: 2025-12-12CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411052882.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-01
Publication Date
2025-12-12
Estimated Expiration
2044-08-01

AI Technical Summary

Technical Problem

Traditional remote security verification technologies are not very reliable when the server is under network attack, and are cumbersome to operate when controlling multiple controlled devices in a local area network.

Method used

A remote security verification method based on registration key-value pairs is adopted. The server obtains blank key-value pairs, receives the device identifier and verification code of the controlled end for registration, performs security verification, and assists the control end and the controlled end to connect after successful verification, and clears the registration key-value pairs.

Benefits of technology

It improves the convenience and reliability of security verification, reduces the possibility of registration key-value pairs being stolen, and realizes unified verification between the control end and the controlled end.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972122B_ABST
    Figure CN118972122B_ABST
Patent Text Reader

Abstract

The application provides a remote security verification method, system, device and medium, wherein the method obtains a blank key-value pair and a service connection request, obtains a first device identifier corresponding to a controlled terminal according to the service connection request, returns the first device identifier to the controlled terminal, obtains a service registration request returned by the controlled terminal, performs key-value registration on the blank key-value pair according to the first device identifier and a first security verification code in the service registration request, obtains a registered key-value pair, receives a service control request sent by a control terminal, and performs security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair, and obtains a security verification result. If the security verification result is verified, the control terminal and the controlled terminal are connected, and the registered key-value pair is cleared. The remote security verification method can effectively improve the reliability and convenience of security verification. The application relates to the technical field of Internet.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and particularly relates to a remote security verification method, system, device and medium. BACKGROUND

[0002] At present, traditional remote security verification technologies can be generally divided into two categories. The first category of method is based on an access password stored in a server database to realize security verification between a control device and a controlled device. When the server is attacked by a network, the access password of the controlled device is easily stolen, and the reliability is not high. The second category of method is based on directly storing an access password in a corresponding controlled device. When there are multiple controlled devices in a local area network or an internal network, the operation required for realizing security verification between multiple devices is relatively cumbersome, and the convenience is not high.

[0003] In summary, the technical problems in the related art need to be improved. SUMMARY

[0004] The present application aims to at least partially solve one of the technical problems in the related art.

[0005] The main purpose of the embodiments of the present application is to provide a remote security verification method, system, device and medium, wherein the remote security verification method can effectively improve the reliability and convenience of security verification.

[0006] To achieve the above-mentioned purpose, one aspect of the embodiments of the present application provides a remote security verification method applied to a server, the method comprising:

[0007] Obtaining a blank key-value pair;

[0008] Receiving a service connection request sent by a controlled end, and obtaining a first device identifier corresponding to the controlled end according to the service connection request;

[0009] Returning the first device identifier to the controlled end, so that the controlled end performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled end;

[0010] Performing key-value registration on the blank key-value pair according to the first device identifier and a first security verification code in the service registration request to obtain a registered key-value pair;

[0011] Receiving a service control request sent by a control end, and performing security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair to obtain a security verification result, the second device identifier being used to represent a device identifier corresponding to a target controlled device of the control end, and the second security verification code being a security verification code corresponding to the target controlled device.

[0012] If the security verification result is a verification pass, assisting the control end and the controlled end to connect, and clearing the registration key-value pair.

[0013] In some embodiments, the blank key-value pair includes an identification key and a verification key, and the key-value registration of the blank key-value pair according to the first device identification and the first security verification code to obtain a registration key-value pair includes:

[0014] According to the first device identification, the identification key is registered to obtain a registered identification key;

[0015] According to the first security verification code, the verification key is registered to obtain a registered verification key.

[0016] In some embodiments, the security verification of the second device identification and the second security verification code in the service control request according to the registration key-value pair to obtain a security verification result includes:

[0017] According to the registered identification key, the second device identification is matched to obtain an identification matching result;

[0018] If the identification matching result is an identification matching success, the second security verification code is matched according to the registered verification key to obtain the security verification result.

[0019] In some embodiments, the assisting the control end and the controlled end to connect includes:

[0020] Obtaining a first port address corresponding to the controlled end and a second port address corresponding to the control end;

[0021] According to the first port address and the second port address, assisting the controlled end and the control end to connect.

[0022] In some embodiments, the method further includes:

[0023] Obtaining connection state information, the connection state information is used to represent the connection state between the server and the controlled end, or the connection state between the server and the control end;

[0024] If the connection state information is disconnected, the target port address is cleared, and the target port address is the first port address or the second port address.

[0025] An aspect of an embodiment of the application proposes a remote security verification method applied to a controlled end, and the method includes:

[0026] sending a service connection request to a service end, so that the service end obtains a first device identifier corresponding to the controlled end according to the service connection request;

[0027] receiving the first device identifier returned by the service end, and performing service registration processing on the first device identifier to obtain a service registration request;

[0028] sending the service registration request to the service end, so that the service end performs key-value registration on a blank key-value pair according to the first device identifier and a first security verification code in the service registration request to obtain a registered key-value pair; the service end is configured to receive a service control request sent by a control end, and perform security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair to obtain a security verification result, the second device identifier is used to represent a device identifier corresponding to a target controlled device of the control end, and the second security verification code is a security verification code corresponding to the target controlled device; the service end is configured to assist the control end and the controlled end to be connected in a case where the security verification result is verification passed, and clear the registered key-value pair.

[0029] In some embodiments, the service registration processing on the first device identifier to obtain the service registration request comprises:

[0030] obtaining a first port address and a first security verification code corresponding to the controlled end;

[0031] performing request construction on the first device identifier according to the first security verification code and the first port address to obtain the service registration request.

[0032] To achieve the above object, another aspect of the embodiment of the present application proposes a remote security verification system applied to a service end, which comprises:

[0033] an obtaining unit configured to obtain a blank key-value pair;

[0034] a first receiving unit configured to receive a service connection request sent by a controlled end, and obtain a first device identifier corresponding to the controlled end according to the service connection request;

[0035] a sending unit configured to return the first device identifier to the controlled end, so that the controlled end performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled end;

[0036] a key-value unit configured to perform key-value registration on the blank key-value pair according to the first device identifier and a first security verification code in the service registration request to obtain a registered key-value pair;

[0037] a second receiving unit, configured to receive a service control request sent by a control terminal, and perform security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair, to obtain a security verification result, the second device identifier being used to represent a device identifier corresponding to a target controlled device of the control terminal, and the second security verification code being a security verification code corresponding to the target controlled device;

[0038] an assisting unit, configured to assist the control terminal and the controlled terminal to be connected if the security verification result is verified, and clear the registered key-value pair.

[0039] To achieve the above object, another aspect of the embodiments of the present application provides an electronic device, which comprises a memory and a processor, the memory stores a computer program, and the processor implements the method described above when executing the computer program.

[0040] To achieve the above object, another aspect of the embodiments of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method described above.

[0041] The embodiments of the present application at least have the following beneficial effects:

[0042] The present application provides a remote security verification method, system, device and medium, wherein the method comprises the following steps: obtaining a blank key-value pair; receiving a service connection request sent by a controlled terminal, and obtaining a first device identifier corresponding to the controlled terminal according to the service connection request; returning the first device identifier to the controlled terminal, so that the controlled terminal performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled terminal; performing key-value registration on the blank key-value pair according to a first device identifier and a first security verification code in the service registration request to obtain a registered key-value pair; receiving a service control request sent by a control terminal, and performing security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair, to obtain a security verification result, the second device identifier being used to represent a device identifier corresponding to a target controlled device of the control terminal, and the second security verification code being a security verification code corresponding to the target controlled device; and assisting the control terminal and the controlled terminal to be connected if the security verification result is verified, and clearing the registered key-value pair. The method realizes unified verification of the control terminal connecting the controlled terminal based on the registered key-value pair, improves the convenience of security verification, and can effectively reduce the possibility of the registered key-value pair being stolen and improve the reliability of security verification, since the registered key-value pair exists only when the controlled terminal is connected to the service terminal and the controlled terminal is not connected to the control terminal. Attached Figure Description

[0043] Figure 1 This is a flowchart illustrating the first remote security verification method provided in this application embodiment;

[0044] Figure 2 This is a timing flowchart of a remote security verification method provided in an embodiment of this application;

[0045] Figure 3 This is a detailed flowchart of step S140 provided in an embodiment of this application;

[0046] Figure 4 This is a detailed flowchart of step S150 provided in an embodiment of this application;

[0047] Figure 5 This is a detailed flowchart of step S160 provided in an embodiment of this application;

[0048] Figure 6 This is a schematic diagram of one optional process of a remote security verification method provided in an embodiment of this application;

[0049] Figure 7 This is a flowchart illustrating the second remote security verification method provided in this application embodiment;

[0050] Figure 8 This is a detailed flowchart of step S220 provided in an embodiment of this application;

[0051] Figure 9 This is a schematic diagram of the framework of a remote security verification system provided in an embodiment of this application;

[0052] Figure 10 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0053] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses / devices and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0054] It can be understood that the terms "first", "second", and the like used in the present application can be used herein to describe various concepts, but unless specifically stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or "upon determining" or "in response to determining".

[0055] The terms "at least one", "multiple", "each", "any", and the like used in the present application include one, two or more, multiple includes two or more, each refers to each of the corresponding multiple, and any refers to any one of the multiple.

[0056] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as understood by a person skilled in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0057] At present, the traditional remote security verification technology can be generally divided into two categories. The first method is based on the access password stored in the server database to realize the security verification between the control device and the controlled device. When the server is attacked by the network, the access passwords of a plurality of controlled devices in the server database are easily stolen by the illegal persons. The controlled devices are usually arranged in the internal network. After the illegal persons obtain the access password of one or more controlled devices, the illegal persons can attack the servers of the internal network by means of the controlled devices, which has a high security risk and low reliability.

[0058] The second method is based on storing the access password directly in the corresponding controlled device. When there are a plurality of controlled devices in the local area network or the internal network, the control device needs to perform security verification with each controlled device respectively, which is relatively cumbersome and has low convenience.

[0059] Therefore, the present application provides a remote security verification method, system, device and medium. The method is based on the registration key-value pair to realize the unified verification of the control terminal connecting the controlled terminal, and improve the convenience of security verification. In addition, the registration key-value pair with the access password of the controlled terminal is recorded in the server only when the controlled terminal is connected to the server. The registration key-value pair is automatically destroyed by the server when the controlled terminal is connected to the control terminal. The registration key-value pair can effectively reduce the possibility of being stolen, and improve the reliability of security verification.

[0060] Further, the storage location of the registration key-value pair of the method can be set in the service end process memory, and specifically, the registration key-value pair data in the service end process memory is protected at the kernel level, and it is very difficult to read. In the implementation, the unified verification of the control end to the controlled end is realized, the security verification convenience is improved, and the situation that the access password of the controlled device is stolen in the service end database is avoided.

[0061] In addition, since the method only

[0062] The remote security verification method provided by the embodiments of the present application can be applied to an Internet application scenario. In the Internet application scenario, an Internet service provider can perform security verification and connection between a control end and a controlled end through a service end by using the remote security verification method provided by the embodiments of the present application, and the reliability and convenience of security verification can be effectively improved.

[0063] The remote security verification method provided by the embodiments of the present application can be applied to a terminal, can be applied to a server, and can also be software running in the terminal or the server. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, and the like, but is not limited thereto. The server end can be configured as an independent physical server, can be configured as a server cluster or a distributed system formed by multiple physical servers, can be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDNs, and big data and artificial intelligence platforms, and the server can also be a node server in a blockchain network. The software can be an application that implements the method, but is not limited to the above forms.

[0064] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected by a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0065] Reference is made toFigure 1 and Figure 2 , Figure 1 is an optional flow diagram of a remote security verification method provided by an embodiment of the present application, applied to a server, Figure 1 The method in the server can include, but is not limited to, steps S110 to S160.

[0066] Step S110, obtaining a blank key-value pair;

[0067] In the embodiment of the present application, the server can first generate a blank key-value pair after starting, which can be temporarily stored in the server database or temporarily stored in the server process memory. Specifically, when the blank key-value pair is stored in the server process memory, the blank key-value pair can be stored in the server process memory in the form of HashMAP.

[0068] It can be understood that the attribute format of the blank key-value pair can be represented as <key, value>, wherein the position of key is the identification key position, and the position of value is the verification key position. Each key can correspond to only one value, and multiple keys can correspond to one value. In addition, the number of obtained blank key-value pairs can be set according to actual conditions. When the number of obtained blank key-value pairs is greater than or equal to 2, each blank key-value pair corresponds to one controlled device (controlled end), which can realize unified verification of multiple controlled devices. For the convenience of description and understanding, the subsequent description of the embodiment of the present application takes the number of obtained blank key-value pairs as equal to 1, that is, there is one controlled end to be controlled as an example.

[0069] Step S120, receiving a service connection request sent by a controlled end, and obtaining a first device identifier corresponding to the controlled end according to the service connection request;

[0070] In the embodiment of the present application, if the controlled end needs to be controlled, the controlled end can send a service connection request to the server, and the service connection request can be a TCP connection request. After the server receives the service connection request, the server searches the server according to the information carried by the service connection request to determine whether there is an identifier corresponding to the controlled end. If there is, the searched identifier is taken as the first device identifier. Otherwise, the server generates a unique ID as the first device identifier corresponding to the controlled end.

[0071] Step S130, returning the first device identifier to the controlled end, so that the controlled end performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled end;

[0072] In the embodiment of the present application, after the server obtains the first device identifier based on the retrieval or generation, the server can return the first device identifier to the controlled terminal based on the connection link between the server and the controlled terminal, obtain the service registration request returned by the controlled terminal, and the service registration request carries the first device identifier and the access password (i.e., the first security verification code) of the controlled terminal, which is used to register the hash value of the first security verification code in the memory of the server process, and specifically, the hash value can be registered in HashMAP in the memory of the server process.

[0073] In step S140, the blank key-value pair is registered based on the first device identifier and the first security verification code in the service registration request, and a registered key-value pair is obtained.

[0074] In some embodiments, the blank key-value pair includes an identification key and a verification key, and referring to Figure 3 , the step S140 of registering the blank key-value pair based on the first device identifier and the first security verification code to obtain a registered key-value pair includes:

[0075] A1, the identification key is registered based on the first device identifier, and a registered identification key is obtained.

[0076] A2, the verification key is registered based on the first security verification code, and a registered verification key is obtained.

[0077] In the embodiment of the present application, after the server receives the service registration request sent by the controlled terminal based on the established TCP connection, the server can replace and add the first device identifier of the controlled terminal to the identification key based on the service registration request, and replace and add the hash value corresponding to the first security verification code of the controlled terminal to the verification key, thereby obtaining a registered key-value pair.

[0078] It can be understood that if the aforementioned blank key-value pair is stored in the server database, the server can move the registered key-value pair to the process memory of the server for storage after obtaining the registered key-value pair. In addition, the server can also store the public network port address of the controlled terminal (i.e., the socket address of the controlled terminal) in the process memory of the server based on the port information carried by the service registration request when obtaining the registered key-value pair, and the public network source IP and port number of the controlled terminal are recorded in the socket address.

[0079] In step S150, the server receives the service control request sent by the control terminal, and performs security verification on the second device identifier and the second security verification code in the service control request based on the registered key-value pair, and obtains a security verification result, the second device identifier is used to represent the device identifier corresponding to the target controlled device of the control terminal, and the second security verification code is the security verification code corresponding to the target controlled device.

[0080] In some embodiments, with reference to Figure 4 , the step S150, according to the registered key-value pair, performing security verification on the second device identifier and the second security verification code in the service control request, obtaining a security verification result, comprises:

[0081] B1, according to the registered identifier key, performing identifier matching on the second device identifier, obtaining an identifier matching result;

[0082] B2, if the identifier matching result is identifier matching success, according to the registered verification key, performing verification matching on the second security verification code, obtaining the security verification result.

[0083] In the embodiments of the present application, when the control end needs to control the controlled end, the control end sends a service control request for connecting the controlled end after establishing a TCP connection with the service end, and the service control request records a unique identifier (i.e. the second device identifier) corresponding to the controlled end and an access password (i.e. the second security verification code).

[0084] It can be understood that the step B1 can be that the service end searches in the HashMAP whether there is a registered identifier key matching the second device identifier, if the service end does not find a registered identifier key matching the second device identifier, an identifier matching result indicating that the identifier matching is unsuccessful can be obtained, and the service end can return a prompt information of "the device is not online" to the control end; or, if the service end finds a registered identifier key matching the second device identifier, the service end can perform a hash operation on the corresponding verification key to obtain a first security verification code, and then match the first security verification code with the second security verification code sent by the control end, if the first security verification code is inconsistent with the second security verification code, the security verification result obtained is verification failure; or, if the first security verification code is consistent with the second security verification code, the security verification result obtained is verification success.

[0085] It should be noted that when the service end receives the service control request, the service end can store the public network port address of the control end (i.e. the socket address of the control end) in the process memory of the service end based on the port information carried by the service control request, and the public network source IP and port number of the control end are recorded in the socket address.

[0086] The step S160, if the security verification result is verification success, assisting the control end and the controlled end to connect, and clearing the registered key-value pair.

[0087] In some embodiments, with reference to Figure 5 , the step S160, assisting the control end and the controlled end to connect, comprises:

[0088] C1, obtaining a first port address corresponding to the controlled terminal and a second port address corresponding to the control terminal;

[0089] C2, assisting the controlled terminal and the control terminal to connect according to the first port address and the second port address.

[0090] In the embodiments of the present application, if the security verification result is passed, the server first assists the control terminal and the controlled terminal to establish a direct connection, or assists the control terminal and the controlled terminal to establish an indirect connection. Specifically, the server can first obtain the public socket address (i.e. the second port address) of the control terminal and the public socket address (i.e. the first port address) of the controlled terminal, and then sends the public socket address of the control terminal to the controlled terminal, and sends the socket address of the controlled terminal to the control terminal, so as to assist the control terminal and the controlled terminal to establish a TCP connection directly,

[0091] It can be understood that after the TCP connection is successfully established, the TCP connection between the control terminal and the server is disconnected, and the TCP connection between the controlled terminal and the server is disconnected, at this time, the server clears the stored public socket addresses of the control terminal and the controlled terminal, and clears the registration key-value pair (i.e. the device ID and the access password of the controlled terminal stored in the HashMAP of the server process memory) stored in the server process memory.

[0092] It should be noted that if the server fails to assist the control terminal and the controlled terminal to establish a direct TCP connection, the server assists the control terminal and the controlled terminal to establish an indirect connection, at this time, the server acts as a relay terminal between the control terminal and the controlled terminal, and the server can also destroy the stored public socket addresses of the control terminal and the controlled terminal, and clear the registration key-value pair stored in the server process memory.

[0093] In some embodiments, referring to Figure 6 , the remote security verification method further comprises:

[0094] D1, obtaining connection state information, the connection state information being used to represent the connection state between the server and the controlled terminal, or the connection state between the server and the control terminal;

[0095] D2, if the connection state information is disconnected, the target port address is cleared, the target port address being the first port address or the second port address.

[0096] In the embodiments of the present application, when the control terminal and the service terminal successfully establish a TCP connection and / or the controlled terminal and the service terminal successfully establish a TCP connection, the service terminal can detect the connection state between the control terminal or the controlled terminal in real time, and perform corresponding operations according to the obtained connection state.

[0097] Specifically, the embodiments of the present application take the connection state information representing the connection state between the service terminal and the control terminal as an example, at this time the corresponding target port address is the second port address, if the obtained connection state information is disconnected, the service terminal can clear the control terminal public network socket address stored in the service terminal process memory, so that the service terminal only stores the data content of the corresponding device when connecting with the corresponding device, that is, the data content is stored in the service terminal process memory for the shortest time.

[0098] It can be understood that the content of the connection state information representing the connection state between the service terminal and the controlled terminal is similar to the foregoing content, which can be simply analogized, and the present application will not be repeated here.

[0099] Figure 7 is another optional flow diagram of a remote security verification method provided by the embodiments of the present application, applied to a controlled terminal, Figure 7 The method in the above embodiment can include but is not limited to steps S210 to S230.

[0100] Step S210, send a service connection request to a service terminal, so that the service terminal obtains a first device identifier corresponding to the controlled terminal according to the service connection request;

[0101] In the embodiments of the present application, the content of step S210 is similar to that of the foregoing step S120, which can be analogized.

[0102] Step S220, receive the first device identifier returned by the service terminal, and perform service registration processing on the first device identifier to obtain a service registration request;

[0103] In some embodiments, referring to Figure 8 The step S220, performing service registration processing on the first device identifier to obtain the service registration request, includes:

[0104] E1, obtaining a first port address and a first security verification code corresponding to the controlled terminal;

[0105] E2, constructing the first device identifier according to the first security verification code and the first port address to obtain the service registration request.

[0106] In the embodiment of the application, after receiving the first device identifier returned by the server, the controlled end can take its own public network socket address as the first port address, and take its own access password as the first security verification code; and then generates a corresponding service registration request according to the first port address and the first security verification code, and the first device identifier returned by the server.

[0107] Step S230, the service registration request is sent to the server, so that the server performs key-value registration on the blank key-value pair according to the first device identifier and the first security verification code in the service registration request, to obtain a registered key-value pair; the server is configured to receive a service control request sent by the control end, and perform security verification on the second device identifier and the second security verification code in the service control request according to the registered key-value pair, to obtain a security verification result, the second device identifier is used to represent the device identifier corresponding to the target controlled device of the control end, and the second security verification code is the security verification code corresponding to the target controlled device; the server is configured to assist the control end and the controlled end to connect in the case that the security verification result is verified, and clear the registered key-value pair.

[0108] In some embodiments, the step S230 is similar to the aforementioned steps S140 to S160, which can be simply analogized.

[0109] The following is explained and described with specific embodiments.

[0110] First embodiment

[0111] A client as a control end, B client as a controlled end, in the public network deployment server (namely the server).

[0112] Step F: start B client, B client starts to establish TCP connection with the server, the local socket address is 127.0.0.1:61323, and the B client public network socket address converted by the local public network net is 49.136.212.55:58966; after B client logs in the server, it starts to register, and the server saves the hash value of the ID and the security verification code of B end to the HashMap in the server process memory;

[0113] Step G: A client establishes TCP connection with the server, at this time, the socket address of A client is 127.0.0.0:62533, and the public network socket address of A client converted by the public network net is 202.128.111.23:61288;

[0114] Step H: The A client sends a request to the server to connect the B client. After the server verifies the B client ID and password input by the A client, it confirms the correctness and sends the B client public socket address 49.136.212.55:58966 to the A client, and sends the A client public socket address 202.128.111.23:61288 to the B client, and then assists the A client and the B client to directly connect; then the server process memory HashMap of the B client ID and password hash value is deleted;

[0115] Second embodiment

[0116] The C client acts as a control end, the jump machine acts as a server, and the intranet server acts as a controlled end.

[0117] The intranet server registers its access address, password hash value, and account in the HashMAP in the jump machine process memory based on step F in the first embodiment.

[0118] After the C client is verified by the jump machine, it accesses the intranet server according to the access address provided by the HashMAP in the jump machine process memory, and performs secondary login after connecting the intranet server.

[0119] Please refer to Figure 9 The embodiments of the present application also provide a remote security verification system applied to a server, which comprises:

[0120] An acquisition unit 810 is configured to acquire a blank key-value pair.

[0121] A first receiving unit 820 is configured to receive a service connection request sent by a controlled end, and obtain a first device identifier corresponding to the controlled end according to the service connection request.

[0122] A sending unit 830 is configured to return the first device identifier to the controlled end, so that the controlled end performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled end.

[0123] A key-value unit 840 is configured to perform key-value registration on the blank key-value pair according to the first device identifier and the first security verification code in the service registration request to obtain a registered key-value pair.

[0124] The second receiving unit 850 is configured to receive a service control request sent by the control terminal, and perform security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair, to obtain a security verification result, wherein the second device identifier is used to represent a device identifier corresponding to a target controlled device of the control terminal, and the second security verification code is a security verification code corresponding to the target controlled device.

[0125] The assisting unit 860 is configured to assist the control terminal and the controlled terminal to be connected if the security verification result is passed, and clear the registered key-value pair.

[0126] It can be understood that the content in the above method embodiments is applicable to the present system embodiment, the present system embodiment specifically implements the same functions as the above method embodiments, and achieves the same beneficial effects as the above method embodiments.

[0127] The present application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above method. The electronic device can be any smart terminal, such as a tablet computer or a vehicle-mounted computer.

[0128] It can be understood that the content in the above method embodiments is applicable to the present device embodiment, the present device embodiment specifically implements the same functions as the above method embodiments, and achieves the same beneficial effects as the above method embodiments.

[0129] Please refer to Figure 10 , Figure 10 Fig. 1 shows a hardware structure of an electronic device according to an embodiment, which includes:

[0130] The processor 901 can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute related programs to implement the technical solutions provided by the present application.

[0131] The memory 902 can be implemented in the form of a Read Only Memory (ROM), a static storage device, a dynamic storage device, or a Random Access Memory (RAM), etc. The memory 902 can store an operating system and other application programs. When the technical solutions provided by the embodiments of the present specification are implemented by software or firmware, the related program codes are stored in the memory 902 and are called and executed by the processor 901 to perform the method of the embodiments of the present application.

[0132] The input / output interface 903 is configured to realize information input and output.

[0133] The communication interface 904 is configured to realize the communication interaction between the device and other devices. The communication can be realized by a wired manner (for example, a USB, a network cable, etc.) or a wireless manner (for example, a mobile network, a WI-FI, a Bluetooth, etc.).

[0134] The bus 905 is configured to transmit information between various components (for example, the processor 901, the memory 902, the input / output interface 903, and the communication interface 904) of the device.

[0135] The processor 901, the memory 902, the input / output interface 903, and the communication interface 904 are connected to each other through the bus 905 to realize the communication connection between the device.

[0136] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the above method.

[0137] It can be understood that the contents in the above method embodiments are applicable to the present storage medium embodiments. The present storage medium embodiments specifically implement the functions of the above method embodiments, and achieve the same beneficial effects as the above method embodiments.

[0138] The memory is a non-transitory computer readable storage medium, which can be used to store non-transitory software programs and non-transitory computer executable programs. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely arranged relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0139] The embodiments described in the specification are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of technology and the appearance of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0140] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and can include more or fewer steps than shown in the figures, or combine certain steps, or different steps.

[0141] The device embodiments described above are merely illustrative, and the units described as separate components can or can not be physically separated, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0142] Those skilled in the art can understand that all or some of the steps in the above disclosed method, the functional modules / units in the system and the device can be implemented as software, firmware, hardware and their appropriate combinations.

[0143] The terms "first", "second", "third", "fourth" and the like (if any) in the specification of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0144] It should be understood that, in the application, "at least one" refers to one or more, and "multiple" refers to two or more. "And / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases of only A, only B, and A and B existing at the same time, wherein A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can represent a, b, c, "a and b", "a and c", "b and c", or "a and b and c", wherein a, b, and c can be single or multiple.

[0145] In several embodiments provided in the application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the above units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed mutual ones can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0146] The units described above as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment scheme.

[0147] In addition, each functional unit in each embodiment of the application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0148] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application, essentially or in other words, the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program storage media.

[0149] The preferred embodiments of the embodiments of the present application are described above with reference to the accompanying drawings, and are not limited to the scope of the embodiments of the present application. Any modifications, equivalent replacements and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the embodiments of the present application.

Claims

1. A method of remote security verification, characterized by, Applied to a server, the method comprises: Obtaining a blank key-value pair; Receiving a service connection request sent by a controlled end, and obtaining a first device identifier corresponding to the controlled end according to the service connection request; Returning the first device identifier to the controlled end, so that the controlled end performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled end; According to the first device identifier and the first security verification code in the service registration request, the blank key-value pair is registered to obtain a registered key-value pair; Receiving a service control request sent by a control end, and according to the registered key-value pair, the second device identifier and the second security verification code in the service control request are verified to obtain a security verification result, the second device identifier is used to represent the device identifier corresponding to the target controlled device of the control end, and the second security verification code is the security verification code corresponding to the target controlled device; If the security verification result is verified, assist the control end and the controlled end to connect, and clear the registered key-value pair; The blank key-value pair includes an identification key and a verification key, and according to the first device identifier and the first security verification code, the blank key-value pair is registered to obtain a registered key-value pair, which comprises: According to the first device identifier, the identification key is registered to obtain a registered identification key; According to the first security verification code, the verification key is registered to obtain a registered verification key; According to the registered key-value pair, the second device identifier and the second security verification code in the service control request are verified to obtain a security verification result, which comprises: According to the registered identification key, the second device identifier is matched to obtain an identification matching result; If the identification matching result is identification matching success, according to the registered verification key, the second security verification code is verified to obtain the security verification result.

2. The method of claim 1, wherein, The method further comprises: Obtaining connection state information, the connection state information is used to represent the connection state between the server and the controlled end, or the connection state between the server and the control end; If the connection state information is disconnected, the target port address is cleared, and the target port address is the first port address or the second port address.

3. The method of claim 2, wherein, Applied to a controlled end, the method comprises: Sending a service connection request to a server, so that the server obtains a first device identifier corresponding to the controlled end according to the service connection request; Receiving the first device identifier returned by the server, and performing service registration processing on the first device identifier to obtain a service registration request; 4. A method of remote security verification, characterized by, ​ ​ ​ The service registration request is sent to the service end, so that the service end performs key-value registration on a blank key-value pair according to the first device identifier and the first security verification code in the service registration request, to obtain a registered key-value pair; the service end is configured to receive a service control request sent by a control end, and perform security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair, to obtain a security verification result, the second device identifier is used to represent a device identifier corresponding to a target controlled device of the control end, and the second security verification code is a security verification code corresponding to the target controlled device; the service end is configured to assist the control end and the controlled end to be connected in a case where the security verification result is verification passed, and clear the registered key-value pair; The blank key-value pair includes an identification key and a verification key, and the key-value registration on the blank key-value pair according to the first device identifier and the first security verification code obtains a registered key-value pair, including: The identification key is registered according to the first device identifier to obtain a registered identification key; The verification key is registered according to the first security verification code to obtain a registered verification key; The security verification on the second device identifier and the second security verification code in the service control request according to the registered key-value pair obtains a security verification result, including: The second device identifier is matched according to the registered identification key to obtain an identification matching result; If the identification matching result is identification matching success, the verification matching on the second security verification code according to the registered verification key obtains the security verification result.

5. The security verification method of claim 4, wherein, The service registration processing on the first device identifier obtains the service registration request, including: A first port address and a first security verification code corresponding to the controlled end are obtained; The first device identifier is constructed according to the first security verification code and the first port address to obtain the service registration request.

6. A remote security verification system characterized by, The system applied to the service end includes: An obtaining unit is configured to obtain a blank key-value pair; A first receiving unit is configured to receive a service connection request sent by a controlled end, and obtain a first device identifier corresponding to the controlled end according to the service connection request; A sending unit is configured to return the first device identifier to the controlled end, so that the controlled end performs service registration processing on the first device identifier to obtain a service registration request returned by the controlled end; A key-value unit is configured to perform key-value registration on the blank key-value pair according to a first device identifier and a first security verification code in the service registration request, to obtain a registered key-value pair. The second receiving unit is configured to receive a service control request sent by the control terminal, and perform security verification on a second device identifier and a second security verification code in the service control request according to the registered key-value pair, to obtain a security verification result, wherein the second device identifier is used to represent a device identifier corresponding to a target controlled device of the control terminal, and the second security verification code is a security verification code corresponding to the target controlled device. The assisting unit is configured to assist the control terminal and the controlled terminal to be connected if the security verification result is a verification pass, and clear the registered key-value pair. The blank key-value pair includes an identification key and a verification key, and the blank key-value pair is registered according to the first device identifier and the first security verification code to obtain the registered key-value pair, including: The identification key is registered according to the first device identifier to obtain a registered identification key. The verification key is registered according to the first security verification code to obtain a registered verification key. The security verification of the second device identifier and the second security verification code in the service control request is performed according to the registered key-value pair to obtain a security verification result, including: The second device identifier is matched according to the registered identification key to obtain an identification matching result. If the identification matching result is identification matching success, the second security verification code is matched according to the registered verification key to obtain the security verification result.

7. An electronic device, comprising: The computer program is executed by the processor to implement the method in any one of claims 1-5. The computer program is executed by the processor to implement the method in any one of claims 1-5. ​ ​ 8. A computer-readable storage medium storing a computer program, the computer-readable storage medium comprising: ​

Citation Information

Patent Citations

  • Security authentication system and method for end-to-end encrypted chat of edge computing device

    CN116015747A