Method, device and storage medium for secure online verification of mobile terminal equipment

Through multi-factor security verification methods, using multiple certificates and secondary verification of random VPN user passwords, the data transmission security problem between mobile terminal devices and business servers is solved, the data transmission security level is improved, and the risk of user and password leakage is reduced.

CN118972142BActive Publication Date: 2025-09-23中国邮政储蓄银行股份有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411169296.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-23
Publication Date
2025-09-23
Estimated Expiration
2044-08-23

AI Technical Summary

Technical Problem

In the prior art, when a mobile terminal device accesses an intranet through a VPN, a single certificate and user password authentication are at risk of being misused, allowing criminals to invade the business system and resulting in low data transmission security.

Method used

Adopting a multi-factor security verification method, a VPN connection is established through the first certificate in the target APP software, the device information is verified using the MDM server, and after the verification is passed, the second VPN account and password are sent. The first VPN connection is disconnected and the second VPN connection is established. Multiple certificates and a random VPN user password are used for secondary verification to improve data transmission security.

Benefits of technology

It effectively reduces the risk of user and password leakage, improves the data transmission security level between mobile terminal devices and business servers, and solves the security risks of single certificate and password verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972142B_ABST
    Figure CN118972142B_ABST
Patent Text Reader

Abstract

The present application provides a method, apparatus and storage medium for secure online verification of a mobile terminal device. The method comprises: starting the target APP software of the mobile terminal device, establishing a first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, using the MDM server to verify the device information of the mobile terminal device, sending the second VPN account and the second VPN password to the mobile terminal device, verifying that the private key of the second certificate and the public key of the third certificate of the mobile terminal device exist and have not expired, disconnecting the first VPN connection, establishing a second VPN connection between the mobile terminal device and the VPN server, using the MDM server to verify the device information of the mobile terminal device for the second time through the VPN server, and realizing business interaction between the mobile terminal device and the business end through the VPN server. The method solves the problem of low data transmission security between the mobile terminal device and the business end in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of secure online verification of mobile terminal devices, and more specifically, to a method, apparatus, storage medium, and electronic device for secure online verification of mobile terminal devices. Background Art

[0002] With the country's push for informatization and digitalization, the digital development of the banking industry is steadily advancing. To efficiently improve the digitalization process and provide more convenient services to users, users and tellers are increasingly demanding mobile office work. Because banking systems are deployed in closed intranet environments, if mobile terminals or Wi-Fi are required to interact with intranet servers, they must access the intranet through a VPN. Currently, user validity is verified by integrating CA digital certificates with user passwords, and signature certificates are used to sign and review transactions. After successful review, access to the business network is granted. However, this existing technology has shortcomings. Mobile devices access the intranet through VPN, but the method of using a single certificate and user and password authentication has the following disadvantages: there is a risk of user and password theft. Once the user and password are stolen, criminals can download or copy software to other devices to log in to the VPN and successfully hack into the business system. Criminals can also crack the CA digital certificate through decompilation and other methods to obtain the VPN user and password, and use this information to hack into the server. Summary of the Invention

[0003] The main purpose of this application is to provide a method, device, storage medium and electronic device for secure online verification of a mobile terminal device, so as to at least solve the problem of low data transmission security between a mobile terminal device and a business service end in the prior art.

[0004] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a method for secure online verification of a mobile terminal device is provided, comprising: starting the target APP software of the mobile terminal device, establishing a first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account and a first VPN password; in the case that the first VPN connection is successful, verifying the device information of the mobile terminal device through the VPN server using the MDM server, and in the case that the device information verification passes, sending the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, and verifying the private key of the second certificate and the third VPN password of the mobile terminal device using the MDM server. When the public keys of the certificates exist and have not expired, the VPN server is controlled to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying the VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server; a second VPN connection is established between the mobile terminal device and the VPN server according to the second VPN account, the second VPN password, the second certificate, and the third certificate, and the device information of the mobile terminal device is secondary verified by the VPN server using the MDM server. If the verification is successful, the mobile terminal device and the service end are enabled to perform service interaction through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection.

[0005] Optionally, before starting the target APP software of the mobile terminal device and establishing the first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, the method also includes: obtaining the device information of the mobile terminal device collected in the business end, and saving the device information to the MDM server through a scheduled task, so that the MDM server generates a fourth certificate based on the device information, wherein the fourth certificate is a prerequisite certificate for the second certificate; based on the fourth certificate, using the key platform to generate the second certificate, and saving the public key and private key of the second certificate to the MDM server; based on the second certificate, controlling the VPN server to generate the third certificate, and deploying the private key of the third certificate to the VPN server, and deploying the public key of the third certificate to the MDM server.

[0006] Optionally, after saving the device information to the MDM server through a scheduled task, the method further includes: deploying the first certificate to the mobile terminal device, and installing the target APP software to the mobile terminal device.

[0007] Optionally, after verifying the device information of the mobile terminal device using the MDM server through the VPN server, and after the device information verification is passed, the method further includes: sending the private key of the second certificate and the public key of the third certificate of the MDM server to the mobile terminal device through the VPN server.

[0008] Optionally, before sending the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, the method further includes: if the device information verification is passed, randomly obtaining the second VPN account and the second VPN password from the password pool; and storing the second VPN account and the second VPN password in the MDM server.

[0009] Optionally, after starting the target APP software of the mobile terminal device, the method further includes: controlling the mobile terminal device to automatically detect the device information, and if the automatic detection passes, establishing a first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software.

[0010] Optionally, the device information includes software information and hardware information. The hardware information includes device number, system version number, detection memory card information, wireless network card status, device mode, and encryption chip. The software information includes network status, VPN status, presence or absence of security components and version information, device activation status, application authorization, whether positioning is enabled, and security policy status.

[0011] According to another aspect of the present application, a device for secure online verification of a mobile terminal device is provided, comprising: a startup unit, configured to start a target APP software of a mobile terminal device, and establish a first VPN connection between the mobile terminal device and a VPN server through a first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account, and a first VPN password; a control unit, configured to verify the device information of the mobile terminal device through the VPN server using an MDM server when the first VPN connection is successful, and to send a second VPN account and a second VPN password of the MDM server to the mobile terminal device through the VPN server when the device information verification passes, and to verify the private key of the second certificate and the third certificate of the mobile terminal device using the MDM server. When the public keys of the second certificate and the third certificate exist and have not expired, the VPN server is controlled to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying the VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server; a verification unit is used to establish a second VPN connection between the mobile terminal device and the VPN server according to the second VPN account, the second VPN password, the second certificate and the third certificate, and use the MDM server to verify the device information of the mobile terminal device for a second time through the VPN server. If the verification is passed, the mobile terminal device and the service end are enabled to perform service interaction through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection.

[0012] According to another aspect of the present application, a computer-readable storage medium is provided, which includes a stored program, wherein when the program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the methods for secure online verification of a mobile terminal device.

[0013] According to another aspect of the present application, an electronic device is provided, comprising: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include a method for executing any one of the secure online verification methods of the mobile terminal device.

[0014] By applying the technical solution of the present application, the target APP software of the mobile terminal device is started, and a first VPN connection between the mobile terminal device and the VPN server is established through the first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account and a first VPN password; if the first VPN connection is successful, the device information of the mobile terminal device is verified by the MDM server through the VPN server, and if the device information verification is passed, the second VPN account and the second VPN password of the MDM server are sent to the mobile terminal device through the VPN server, and the private key of the second certificate and the public key of the third certificate of the mobile terminal device are verified by the MDM server. If the VPN connection exists and has not expired, the VPN server is controlled to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, and the third certificate is a certificate for verifying the VPN information. The public key of the second certificate and the private key of the third certificate are located in the VPN server; a second VPN connection is established between the mobile terminal device and the VPN server based on the second VPN account, the second VPN password, the second certificate, and the third certificate. The device information of the mobile terminal device is secondary verified by the VPN server using the MDM server. If the verification is successful, the mobile terminal device and the business end are enabled to interact with each other through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection. Through the multi-factor security verification method, the VPN connection is used to improve the data transmission security level of the business end system, effectively reducing the risk of user and password leakage, mobile terminal device cracking, and VPN key cracking, thereby solving the problem of low data transmission security between mobile terminal devices and business service ends in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The drawings that constitute part of this application are used to provide a further understanding of this application. The illustrative embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation on this application. In the drawings:

[0016] Figure 1 A hardware structure block diagram of a mobile terminal for executing a method for secure online verification of a mobile terminal device provided in an embodiment of the present application is shown;

[0017] Figure 2 A schematic diagram illustrating a flow chart of a method for secure online verification of a mobile terminal device provided according to an embodiment of the present application is shown;

[0018] Figure 3 A flowchart showing a secure local area network access method of an existing solution is shown;

[0019] Figure 4 A flow chart showing a VPN proprietary network access method of an existing solution is shown;

[0020] Figure 5 A flowchart of secure online verification of a mobile terminal device according to an embodiment of the present application is shown;

[0021] Figure 6 A flowchart of mobile terminal device certificate deployment provided according to an embodiment of the present application is shown;

[0022] Figure 7 A schematic diagram illustrating a flow chart of a method for secure online verification of a specific mobile terminal device provided in accordance with an embodiment of the present application is shown;

[0023] Figure 8 A schematic diagram of the process of the first verification phase of secure online verification of a mobile terminal device provided according to an embodiment of the present application is shown;

[0024] Figure 9 A schematic diagram of the process of the second verification phase of secure online verification of a mobile terminal device provided according to an embodiment of the present application is shown;

[0025] Figure 10 A schematic diagram of the process of interaction between a mobile terminal device and a service end service after secure online verification of a mobile terminal device according to an embodiment of the present application is shown;

[0026] Figure 11 A structural block diagram of an apparatus for secure online verification of a mobile terminal device provided according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0027] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0028] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0030] For ease of description, some nouns or terms involved in the embodiments of the present application are explained below:

[0031] Mobile terminal devices: IPAD tablet, POS machine.

[0032] Business end: Business system that provides services for software on mobile terminal devices.

[0033] Certificate: SM2 commercial national standard certificate.

[0034] Certificate P1 (first certificate): Integrates VPN encryption and decryption certificates and VPN user and password.

[0035] Certificate P2 (fourth certificate): a prerequisite for certificate P3. P2 applies to the key system to generate certificate P3.

[0036] Certificate P3 (second certificate): a certificate of terminal identity information, with the private key on the mobile terminal device and the public key on the VPN server.

[0037] Certificate P4 (third certificate): Verifies the VPN information certificate. The public key is on the mobile terminal device and the private key is on the VPN server.

[0038] MDM client: refers to mobile terminal devices.

[0039] VPN server: provides a dedicated secure channel for mobile terminal devices.

[0040] MDM server: security services and security monitoring system.

[0041] Key platform: A dedicated system that provides key production.

[0042] Business end: The system that ultimately provides business services to mobile terminal devices.

[0043] As introduced in the background technology, the existing technology has low security for data transmission between mobile terminal devices and business service ends. In order to solve the problem of low security for data transmission between mobile terminal devices and business service ends in the existing technology, the embodiments of the present application provide a method, device, storage medium and electronic device for secure online verification of mobile terminal devices.

[0044] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present invention.

[0045] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure diagram of a mobile terminal device according to an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1 Only one is shown) a processor 102 (the processor 102 may include but is not limited to a microprocessor MCU or a programmable logic device FPGA and other processing devices) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.

[0046] Memory 104 can be used to store computer programs, such as software programs and modules for application software, such as the computer program corresponding to the method for secure online authentication of a mobile terminal device in an embodiment of the present invention. Processor 102 executes the computer program stored in memory 104 to execute various functional applications and data processing, thereby implementing the aforementioned method. Memory 104 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, memory 104 may further include memory remotely located relative to processor 102, which can be connected to the mobile terminal via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. Transmission device 106 is used to receive or transmit data via a network. Specific examples of such networks may include a wireless network provided by the mobile terminal's telecommunications provider. In one example, transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0047] In this embodiment, a method for secure online verification of a mobile terminal device running on a mobile terminal, a computer terminal or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0048] Figure 2 This is a flow chart of a method for secure online verification of a mobile terminal device according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps:

[0049] Step S201: Start the target APP software of the mobile terminal device and establish a first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account number and a first VPN password;

[0050] Among them, the certificate is the SM2 commercial national standard certificate, the first certificate is the integrated VPN encryption and decryption certificate and the first VPN account and first VPN password;

[0051] Specifically, a first VPN connection is established with the VPN server through the integrated VPN encryption and decryption certificate of the first certificate and the input of the first VPN account and the first VPN password in the target APP software, wherein the first VPN connection gives the mobile terminal device little authority and only allows the second VPN account and the second VPN password to be sent to the mobile terminal device when the device information of the mobile terminal device is detected to be passed.

[0052] Step S202: If the first VPN connection is successful, the VPN server verifies the device information of the mobile terminal device using the MDM server. If the device information verification is successful, the VPN server sends the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server. If the MDM server verifies that the private key of the second certificate and the public key of the third certificate of the mobile terminal device are both present and not expired, the VPN server is controlled to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying the VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server.

[0053] Among them, the second certificate is the certificate of terminal identity information, the private key is on the mobile terminal device, and the public key is on the VPN server; the third certificate is the certificate for verifying VPN information, the public key is on the mobile terminal device, and the private key is on the VPN server.

[0054] When the device information verification passes, the method sends the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, and determines whether the private key of the second certificate and the public key of the third certificate of the mobile terminal device exist and whether they are expired. When the private key of the second certificate and / or the public key of the third certificate do not exist or are expired, the MDM server is used to update the private key of the second certificate and / or the public key of the third certificate of the mobile terminal device, so that the second VPN connection can be established when the device information verification of the mobile terminal device passes.

[0055] In addition, teller users do not need to enter the VPN login username and password. They use the public certificate P1 to log in to the MDZ security zone for the first time, which effectively isolates them from production. In the security zone, they verify the mobile terminal device information, obtain the VPN random user password, and verify whether the certificates P3 and P4 are normal. After successful verification, they disconnect the connection established by the certificate P1 (the first VPN connection).

[0056] In step S203, a second VPN connection is established between the mobile terminal device and the VPN server according to the second VPN account, the second VPN password, the second certificate, and the third certificate. The device information of the mobile terminal device is secondary verified by the VPN server using the MDM server. If the verification is successful, the mobile terminal device and the service end are enabled to perform service interaction through the VPN server. The bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection.

[0057] Bandwidth refers to the maximum transmission rate of a network connection, typically measured in data transferred per second. In VPN connections, bandwidth can be used to represent both the speed and capacity of the connection, specifically the amount of data the connection can transfer. By setting different bandwidth limits, you can control the permissions for each VPN connection. For example, if one connection has a bandwidth limit of 100Mbps and another has a bandwidth limit of 50Mbps, the former connection has greater permissions and can transfer more data, while the latter connection is restricted and can only transfer less data.

[0058] Specifically, the random user and password, certificate P3, and certificate P4 obtained after the first successful verification are used to verify login and establish a second VPN connection. The teller staff does not access the VPN user and password, which increases the security level of the VPN user and password and reduces the risk of users having to enter passwords tediously or losing their passwords.

[0059] Through this embodiment, the target APP software of the mobile terminal device is started, and the first VPN connection between the mobile terminal device and the VPN server is established through the first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account and a first VPN password; if the first VPN connection is successful, the device information of the mobile terminal device is verified by the MDM server through the VPN server, and if the device information verification is passed, the second VPN account and the second VPN password of the MDM server are sent to the mobile terminal device through the VPN server, and the private key of the second certificate and the public key of the third certificate of the mobile terminal device are verified by the MDM server. And if it has not expired, control the VPN server to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying the VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server; establish a second VPN connection between the mobile terminal device and the VPN server based on the second VPN account, the second VPN password, the second certificate and the third certificate, and use the MDM server to verify the device information of the mobile terminal device for a second time through the VPN server. If the verification is successful, the mobile terminal device and the business end can interact with each other through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection. Through the multi-factor security verification method, the VPN connection is used to improve the data transmission security level of the business end system, effectively reduce the risk of user and password leakage, mobile terminal device cracking, and VPN key cracking, and solve the problem of low data transmission security between mobile terminal devices and business service ends in the existing technology.

[0060] During the specific implementation process, before starting the target APP software of the mobile terminal device and establishing the first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, the method also includes: obtaining the device information of the mobile terminal device collected in the business end, and saving the device information to the MDM server through a scheduled task, so that the MDM server generates a fourth certificate based on the device information, wherein the fourth certificate is a prerequisite certificate for the second certificate; based on the fourth certificate, a second certificate is generated using a key platform, and the public key and private key of the second certificate are saved to the MDM server; based on the second certificate, the VPN server is controlled to generate a third certificate, and the private key of the third certificate is deployed to the VPN server, and the public key of the third certificate is deployed to the MDM server.

[0061] This method adopts multi-factor authentication, using certificate P1 (first certificate), certificate P2 (fourth certificate), certificate P3 (second certificate), certificate P4 (third certificate), VPN user and password, and mobile terminal device information. Although it is multi-factor authentication, the mobile terminal device only integrates certificate P1, which is a public certificate. Before verifying the mobile terminal device, the corresponding certificate is deployed to the target APP software of the mobile terminal device, the VPN server, and the MDM server.

[0062] Specifically, after the device information is saved to the MDM server through a scheduled task, the method further includes: deploying the first certificate to the mobile terminal device, and installing the target APP software to the mobile terminal device.

[0063] The method deploys a first certificate to a mobile terminal device and installs a target APP software to the mobile terminal device, and is used to establish a first VPN connection between the mobile terminal device and a VPN server to verify the device information of the mobile terminal device.

[0064] More specifically, after verifying the device information of the mobile terminal device using the MDM server through the VPN server, and after the device information verification is passed, the method also includes: sending the private key of the second certificate and the public key of the third certificate of the MDM server to the mobile terminal device through the VPN server.

[0065] When the device information of the mobile terminal device is verified successfully, this method sends the private key of the second certificate and the public key of the third certificate of the MDM server to the mobile terminal device through the VPN server, thereby improving the security level of security verification and avoiding the risk of the mobile terminal device being stolen.

[0066] Furthermore, before sending the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, the method also includes: if the device information verification is passed, randomly obtaining the second VPN account and the second VPN password from the password pool; and storing the second VPN account and the second VPN password in the MDM server.

[0067] This method randomly obtains a second VPN account and a second VPN password from a password pool, solving the problem of VPN user account and password updating. According to conventional security requirements, users need to update their VPN login passwords regularly. However, during user use, problems such as update delays may occur, resulting in users being unable to use the VPN. Using a random password can avoid this problem.

[0068] Furthermore, after starting the target APP software of the mobile terminal device, the method also includes: controlling the mobile terminal device to automatically detect device information, and if the automatic detection passes, establishing a first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software.

[0069] Before establishing the first VPN connection, the method controls the terminal device to perform a self-check on the device information, establishes the first VPN connection if the check passes, and checks the device information of the terminal device multiple times, thereby improving the security of service interaction between the mobile terminal device and the service end.

[0070] Specifically, device information includes software information and hardware information. Hardware information includes device number, system version number, detected storage card information, wireless network card status, device mode, and encryption chip. Software information includes network status, VPN status, presence and version information of security components, device activation status, application authorization, whether positioning is enabled, and security policy status.

[0071] In order to enable those skilled in the art to more clearly understand the technical solution of the present application, the implementation process of the method for secure online verification of a mobile terminal device of the present application will be described in detail below in conjunction with specific embodiments.

[0072] Currently, bank tellers use iPad tablets and POS mobile terminal hardware devices. When the mobile terminal devices are distributed to tellers for use, the following problems may occur:

[0073] (1) Multiple people use the same mobile terminal device alternately, using user names and passwords as security login verification. This single security verification method poses a security risk of user names and passwords being stolen or cracked.

[0074] (2) The mobile terminal software is used on different terminal devices, making it impossible to perform security verification on the mobile terminal devices;

[0075] (3) To ensure secure connection between the APP software installed on the mobile terminal device and the business end, a solidified closed local area network is used. Although this improves the security level, it sacrifices the flexibility of the mobile terminal device to access the business end system;

[0076] (4) Tellers use VPN to connect to the business end, which solves the restrictions on mobile terminal devices and network access. However, there is a risk of mobile terminal devices being lost. Once the mobile terminal device is lost, criminals can easily obtain mobile terminal device information, VPN key information, VPN user name and password by reverse compiling the mobile terminal device and software. Criminals can forge mobile terminal device information and use the cracked VPN user password to invade the server system.

[0077] Leveraging proven and reliable VPN encryption and decryption algorithms, combined with certificates, user names, and passwords for secure authentication, we address the issue of secure data transmission between mobile devices used by bank tellers and business clients. Currently, VPN technology is widely used across various industries and is also an essential security pillar in the banking industry. However, with the advancement of VPN technology, certificate types and algorithms are also evolving, such as CA certificates, national secret SM2 certificates, SM3 certificates, and SM4 certificates. The challenge is to leverage proven technology and design advanced business logic to address the issue of secure data transmission between mobile devices and business clients.

[0078] In existing technical solutions, there are two common security verification methods used to connect mobile devices to banking servers.

[0079] like Figure 3 As shown, a secure LAN access method is adopted, and the same secure LAN access is adopted. The mobile terminal device and the business end are in the same closed network and are not open to the external network, ensuring the security of the LAN and effectively ensuring the security of data in the LAN.

[0080] like Figure 4 As shown, VPN private network access method is adopted, using VPN private network to solve the connection between mobile terminal devices and banking business end, and mostly uses certificate plus VPN user and password to verify and connect to the server. Specific steps:

[0081] 1) Install CA digital certificate on mobile terminal;

[0082] 2) Create a VPN login password for the user on the server and send it to the user for deployment;

[0083] 3) Start connecting the mobile terminal device to the mobile network or WIFI network;

[0084] 4) The VPN server verifies the CA digital certificate;

[0085] 5) The user enters the VPN user name and password. After verification, a VPN secure channel is created;

[0086] 6) Login successful.

[0087] From the above methods, we can infer that the security authentication method using VPN technology, certificates, users and passwords has limitations in mobile environments. The following is a detailed analysis:

[0088] Using a secure LAN access method can solve network security connection problems, but while solving security problems, there are also certain disadvantages. Because there are many banking branches and various business systems are closely related, in the process of continuous business expansion, if the various business systems are not connected, the digitalization process of the banking industry will be hindered to a certain extent.

[0089] Adopting VPN proprietary network access method and using VPN certificate method can solve the limitation of local area network. Mobile devices can transmit data with business-end servers through secure WIFI and mobile network. It seems to solve the limitation of local area network and network security issues, but there are also certain security risks. Once the VPN user password is stolen or lost, the device is lost, the packaged certificate is cracked, etc., the bank's business end will also be invaded by criminals.

[0090] In response to the limitations of the current VPN network environment, the security of mobile terminal equipment, and the omission of users in VPN user password management, a multi-factor security verification method, mobile terminal information verification, multi-certificate secondary verification, VPN random user and password verification, and a method of isolating VPN users and passwords from users are invented to solve the above problems.

[0091] This embodiment relates to a specific method for secure online verification of a mobile terminal device, such as Figure 5 As shown, it involves login verification and data security between mobile terminal devices, APP software, VPN server, MDM server, and business end. The purpose is to solve the data transmission security between mobile terminal devices and business server. Through multi-factor security verification methods, it effectively reduces the security risks caused by device loss, user and password loss. Specifically, it includes the following:

[0092] 1. Certificate deployment, such as Figure 6 As shown, the specific steps include:

[0093] 1) Save the software and hardware data of the mobile terminal device collected from the business end to the MDM server through a scheduled task or manually; 2) Install the APP software with the integrated certificate P1 and the default user and password on the mobile terminal device; 3) The MDM server generates certificate P2 based on the software and hardware data of the mobile terminal device; 4) Based on the certificate P2 generated by the MDM server, apply to the key platform to generate certificate P3, and save both the public key and private key to the MDM server; 5) Generate certificate P4 on the VPN server, deploy the private key to the VPN server, and save the public key certificate to the MDM server; 6) The MDM server generates a random VPN user and password and deploys them to the VPN server;

[0094] 2. Specific verification process, including the verification process as follows: Figure 7 As shown, specifically including the following:

[0095] 2.1、The first verification phase, such as Figure 8 As shown, the specific steps include:

[0096] 1) Start deploying the APP software with integrated certificate P1; 2) Automatically detect device status, including hardware: device number, system version number, memory card information, wireless network card status, device mode, and encryption chip; software: network status, VPN status, security component presence and version information, device activation, application authorization, location activation, and security policy status. 3) The mobile terminal automatically detects that there is no abnormality and starts to establish a VPN connection; 4) For the first VPN connection verification, use the certificate P1 integrated in the APP software installed on the mobile terminal device to perform VPN connection security verification; 5) After the certificate P1 is verified, use the mobile terminal device information to perform security verification on the MDM server to verify the hardware of the mobile terminal device: device number, system version number, memory card information, wireless network card status, device mode, encryption chip, software: network status, VPN status, security component presence and version information, device activation, application authorization, location enablement, security policy status; 6) After the mobile terminal information is verified, randomly obtain the VPN user and password on the MDM server; 7) Check whether the certificate P3 and certificate P4 exist or have expired. If they do not exist or have expired, download or update the certificate; 8) The VPN server disconnects the VPN dedicated channel connected using certificate P1;

[0097] 2.2, the second verification phase, such as Figure 9 As shown, the specific steps include:

[0098] 1) Initiate the connection between the VPN server and the mobile terminal device for the second time; 2) Use certificate P4 and certificate P3 to establish the connection between the mobile terminal and the VPN server; 3) Use the randomly obtained VPN user and password for login verification; 4) Re-verify the declaration information of the mobile terminal device, use the mobile terminal device information to the MDM server for security verification, verify the hardware of the mobile terminal device: device number, system version number, detection memory card information, wireless network card status, device mode, encryption chip, software: network status, VPN status, security component presence and version information, whether the device is activated, application authorization, positioning, security policy status; 5) After the mobile terminal device information is verified, the verification information is synchronized to the business end; 6) At this time, the VPN connection is completed, and the mobile terminal device can interact with the business end. The flow chart of the business interaction between the mobile terminal device and the business end is as follows Figure 10As shown, the MDM server uses heartbeat detection technology to detect the connection status of mobile terminal devices and whether the policies of mobile terminal devices have been updated, and collects and stores information about mobile terminal devices for data analysis and BI presentation.

[0099] The differences between this embodiment and the currently used VPN authentication method include:

[0100] 1) Unlike existing VPN single certificate authentication, this method adopts multi-factor authentication, using certificates P1, P2, P3, P4, VPN user and password, and mobile terminal device information;

[0101] 2) Although it is multi-factor authentication, the mobile terminal device only integrates certificate P1, which is a public certificate;

[0102] 3) Multi-factor authentication certificates P3 and P4 are deployed on the mobile terminal device after the certificate P1 and the mobile terminal device information are successfully verified;

[0103] 4) Certificate P3 is generated through certificate P2;

[0104] 5) VPN user names and passwords are not directly issued to teller users. After verification of certificate P1 and device information, VPN user names and passwords are randomly obtained from the user and password pool. Teller personnel on mobile devices will not access VPN user names and passwords.

[0105] 6) The mobile terminal device verification method uses dual security verification. The first security verification uses public certificate P1 and mobile terminal device information verification to obtain a random VPN user name and password, certificates P3 and P4. The second security verification uses certificates P3 and P4, a random user name and password, and mobile terminal device information verification.

[0106] The embodiment of the present application solves the security risk of the existing technology that one certificate can be used for all. Currently, logging into the VPN requires a public certificate P1 and a VPN username and password. After a successful login, there are no security restrictions. The teller user of the present invention does not need to enter a VPN login username and password. The public certificate P1 is used to log in to the MDZ security zone for the first time, which effectively isolates it from production. In the security zone, the mobile terminal device information is verified, the VPN random user password is obtained, and whether the certificate P3 and certificate P4 are normal are verified. After successful verification, the connection established by the certificate P1 is disconnected. The second time the system uses the random user and password, certificate P3, and certificate P4 obtained after the first successful verification to verify the login. The teller staff does not touch the VPN user and password, which increases the security level of the VPN user and password and reduces the risk of users entering passwords or losing passwords; solves the problem of VPN user and password updates, because according to conventional security requirements, users need to update VPN login passwords regularly, but during user use, there are problems such as update delays, which make users unable to use VPN. Using random passwords can avoid this problem; solves the problem of software cracking and migration on mobile terminal devices. If the software on the mobile terminal device is cracked, the certificate is extracted and logged in on other devices. After VPN login, the device information needs to be submitted for verification. The submitted device information is compared with the database information, including IMEI information, device model information, device serial number, CPU information, storage information, and other information, to improve the security level of the VPN connection; solves the problem of VPN address tampering. Using a two-way certificate verification method in the secondary verification can avoid the security risk of data leakage caused by tampering of the connection VPN address.

[0107] The embodiments of the present application solve the above problems by adding mobile terminal device information verification, random VPN user and password, and VPN certificate two-way verification, while also reducing the complexity of VPN login verification and effectively improving the security level of VPN login verification without increasing costs.

[0108] The embodiments of the present application also provide a device for secure online verification of a mobile terminal device. It should be noted that the device for secure online verification of a mobile terminal device in the embodiments of the present application can be used to execute the method for secure online verification of a mobile terminal device provided in the embodiments of the present application. The device is used to implement the above-mentioned embodiments and preferred implementation methods, and those that have been explained will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and conceivable.

[0109] The following introduces the apparatus for secure online verification of a mobile terminal device provided in an embodiment of the present application.

[0110] Figure 11 Schematic diagram of a device for secure online verification of a mobile terminal device according to an embodiment of the present application. Figure 11 As shown, the device includes: a starting unit 1101, a control unit 1102, and a verification unit 1103.

[0111] The starting unit 1101 is configured to start a target APP software of a mobile terminal device and establish a first VPN connection between the mobile terminal device and a VPN server through a first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account, and a first VPN password;

[0112] Specifically, a first VPN connection is established with the VPN server through the integrated VPN encryption and decryption certificate of the first certificate and the input of the first VPN account and the first VPN password in the target APP software, wherein the first VPN connection gives the mobile terminal device little authority and only allows the second VPN account and the second VPN password to be sent to the mobile terminal device when the device information of the mobile terminal device is detected to be passed.

[0113] The control unit 1102 is configured to, if the first VPN connection is successful, verify the device information of the mobile terminal device using the MDM server through the VPN server, and if the device information verification is successful, send the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, and control the VPN server to disconnect the first VPN connection if the private key of the second certificate and the public key of the third certificate of the mobile terminal device are both present and not expired, verified by the MDM server. The second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying the VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server.

[0114] Among them, the second certificate is the certificate of terminal identity information, the private key is on the mobile terminal device, and the public key is on the VPN server; the third certificate is the certificate for verifying VPN information, the public key is on the mobile terminal device, and the private key is on the VPN server.

[0115] The verification unit 1103 is used to establish a second VPN connection between the mobile terminal device and the VPN server based on the second VPN account, the second VPN password, the second certificate and the third certificate, and to use the MDM server to secondary verify the device information of the mobile terminal device through the VPN server. If the verification is successful, the mobile terminal device and the service end can interact with each other through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection.

[0116] Specifically, the random user and password, certificate P3, and certificate P4 obtained after the first successful verification are used to verify login and establish a second VPN connection. The teller staff does not access the VPN user and password, which increases the security level of the VPN user and password and reduces the risk of users having to enter passwords tediously or losing their passwords.

[0117] In this embodiment, the startup unit is used to start the target APP software of the mobile terminal device, and establish a first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account and a first VPN password; the control unit is used to verify the device information of the mobile terminal device through the VPN server using the MDM server when the first VPN connection is successful, and send the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server when the device information verification is successful, and verify the private key of the second certificate and the public key of the third certificate of the mobile terminal device using the MDM server. When both exist and have not expired, the VPN server is controlled to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, and the third certificate is a certificate for verifying the VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server; the verification unit is used to establish a second VPN connection between the mobile terminal device and the VPN server based on the second VPN account, the second VPN password, the second certificate and the third certificate, and to use the MDM server to secondary verify the device information of the mobile terminal device through the VPN server. When the verification is passed, the mobile terminal device and the business end are enabled to interact with each other through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection. Through multi-factor security verification, the VPN connection is used to improve the data transmission security level of the business end system, effectively reduce the risk of user and password leakage, mobile terminal device cracking, and VPN key cracking, and solve the problem of low data transmission security between mobile terminal devices and business service ends in the existing technology.

[0118] As an optional solution, the device also includes a first acquisition unit, a storage unit and a first deployment unit; the first acquisition unit is used to obtain the device information of the mobile terminal device collected in the business end before starting the target APP software of the mobile terminal device and establishing the first VPN connection between the mobile terminal device and the VPN server through the first certificate in the target APP software, and save the device information to the MDM server through a scheduled task, so that the MDM server generates a fourth certificate based on the device information, wherein the fourth certificate is a prerequisite certificate for the second certificate; the storage unit is used to generate a second certificate based on the fourth certificate using a key platform, and save the public key and private key of the second certificate to the MDM server; the first deployment unit is used to control the VPN server to generate a third certificate based on the second certificate, and deploy the private key of the third certificate to the VPN server, and deploy the public key of the third certificate to the MDM server.

[0119] Specifically, multi-factor authentication is adopted, using certificate P1 (first certificate), certificate P2 (fourth certificate), certificate P3 (second certificate), certificate P4 (third certificate), VPN user and password, and mobile terminal device information. Although it is multi-factor authentication, the mobile terminal device only integrates certificate P1, which is a public certificate. Before verifying the mobile terminal device, the corresponding certificate is deployed to the target APP software of the mobile terminal device, the VPN server, and the MDM server.

[0120] In an optional solution, the device also includes a second deployment unit, which is used to deploy the first certificate to the mobile terminal device and install the target APP software to the mobile terminal device after saving the device information to the MDM server through a scheduled task.

[0121] Specifically, the first certificate is deployed to the mobile terminal device, and the target APP software is installed in the mobile terminal device, which is used to establish a first VPN connection between the mobile terminal device and the VPN server to verify the device information of the mobile terminal device.

[0122] An optional solution is that the device also includes a sending unit for verifying the device information of the mobile terminal device using the MDM server through the VPN server. After the device information verification is passed, the private key of the second certificate and the public key of the third certificate of the MDM server are sent to the mobile terminal device through the VPN server.

[0123] Specifically, when the device information of the mobile terminal device is verified, the private key of the second certificate and the public key of the third certificate of the MDM server are sent to the mobile terminal device through the VPN server, thereby improving the security level of the security verification and avoiding the risk of the mobile terminal device being stolen.

[0124] In an optional solution, the device also includes a second acquisition unit and a storage unit; the second acquisition unit is used to randomly obtain the second VPN account and the second VPN password from the password pool before sending the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, if the device information verification is passed; the storage unit is used to store the second VPN account and the second VPN password in the MDM server.

[0125] Specifically, a second VPN account and a second VPN password are randomly obtained from the password pool to solve the problem of updating VPN user accounts and passwords. According to conventional security requirements, users need to update VPN login passwords regularly. However, during user use, problems such as update delays may occur, resulting in users being unable to use VPN. Using random passwords can avoid this problem.

[0126] An optional solution is that the device also includes an establishment unit, which is used to control the mobile terminal device to automatically detect device information after starting the target APP software of the mobile terminal device. If the automatic detection passes, the first VPN connection between the mobile terminal device and the VPN server is established through the first certificate in the target APP software.

[0127] Specifically, before establishing the first VPN connection, the terminal device is controlled to perform a self-check on the device information, and the first VPN connection is established if the check passes. The device information of the terminal device is checked multiple times, thereby improving the security of service interaction between the mobile terminal device and the service end.

[0128] An optional solution, device information includes software information and hardware information. Hardware information includes device number, system version number, detected storage card information, wireless network card status, device mode, and encryption chip. Software information includes network status, VPN status, presence and version information of security components, device activation status, application authorization, whether positioning is enabled, and security policy status.

[0129] The apparatus for secure online verification of a mobile terminal device includes a processor and memory. The startup unit, control unit, verification unit, etc. are all stored as program units in the memory, and the processor executes the program units stored in the memory to implement the corresponding functions. The above modules are all located in the same processor; alternatively, the above modules can be located in different processors in any combination.

[0130] The processor includes a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be set, and the problem of low data security between mobile terminal devices and service terminals in the existing technology can be solved by adjusting kernel parameters.

[0131] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0132] An embodiment of the present invention provides a computer-readable storage medium, which includes a stored program. When the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for secure online verification of a mobile terminal device.

[0133] An embodiment of the present invention provides a processor, which is used to run a program, wherein the method for secure online verification of a mobile terminal device is executed when the program is running.

[0134] An embodiment of the present invention provides a device comprising a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the method for secure online verification of a mobile terminal device. The device herein may be a server, a PC, a PAD, a mobile phone, or the like.

[0135] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program for initializing the method for secure online verification of a mobile terminal device.

[0136] Obviously, those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, can be centralized on a single computing device, or can be distributed across a network of multiple computing devices. They can be implemented using program code executable by the computing device, and thus, can be stored in a storage device and executed by the computing device. In some cases, the steps shown or described herein can be performed in a different order than that shown, or can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.

[0137] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0138] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0139] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0140] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0141] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0142] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0143] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0144] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0145] The above description is merely a preferred embodiment of the present application and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of protection of the present application.

Claims

1. A method for secure online verification of a mobile terminal device, characterized in that: include: Launching a target APP software on a mobile terminal device, and establishing a first VPN connection between the mobile terminal device and a VPN server using a first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account, and a first VPN password; When the first VPN connection is successful, the VPN server verifies the device information of the mobile terminal device using the MDM server. When the device information verification passes, the VPN server sends the second VPN account and the second VPN password of the MDM server to the mobile terminal device. When the MDM server verifies that the private key of the second certificate and the public key of the third certificate of the mobile terminal device exist and have not expired, the VPN server is controlled to disconnect the first VPN connection, wherein the second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server. A second VPN connection is established between the mobile terminal device and the VPN server based on the second VPN account, the second VPN password, the second certificate, and the third certificate. The device information of the mobile terminal device is secondary verified by the VPN server using the MDM server. If the verification is successful, service interaction is implemented between the mobile terminal device and the service end through the VPN server. The bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection.

2. The method according to claim 1, characterized in that Before starting the target APP software of the mobile terminal device and establishing the first VPN connection between the mobile terminal device and the VPN server using the first certificate in the target APP software, the method further includes: Obtaining the device information of the mobile terminal device collected by the service end, and saving the device information to the MDM server through a scheduled task, so that the MDM server generates a fourth certificate based on the device information, wherein the fourth certificate is a prerequisite certificate for the second certificate; Generate the second certificate using the key platform based on the fourth certificate, and save the public key and private key of the second certificate to the MDM server; According to the second certificate, the VPN server is controlled to generate the third certificate, and the private key of the third certificate is deployed to the VPN server, and the public key of the third certificate is deployed to the MDM server.

3. The method according to claim 2, characterized in that After saving the device information to the MDM server through a scheduled task, the method further includes: Deploy the first certificate to the mobile terminal device, and install the target APP software to the mobile terminal device.

4. The method according to claim 1, wherein After verifying the device information of the mobile terminal device by using the MDM server through the VPN server, and if the device information verification passes, the method further includes: The private key of the second certificate and the public key of the third certificate of the MDM server are sent to the mobile terminal device through the VPN server.

5. The method according to claim 1, wherein Before sending the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, the method further includes: If the device information verification passes, randomly obtain the second VPN account and the second VPN password from the password pool; The second VPN account and the second VPN password are stored in the MDM server.

6. The method according to claim 1, wherein After starting the target APP software of the mobile terminal device, the method further includes: The mobile terminal device is controlled to automatically detect the device information, and if the automatic detection passes, a first VPN connection between the mobile terminal device and the VPN server is established through the first certificate in the target APP software.

7. The method according to any one of claims 1 to 6, characterized in that The device information includes software information and hardware information. The hardware information includes device number, system version number, detection memory card information, wireless network card status, device mode, and encryption chip. The software information includes network status, VPN status, presence and version information of security components, device activation status, application authorization, whether positioning is enabled, and security policy status.

8. A device for secure online verification of a mobile terminal device, characterized in that: include: A startup unit, configured to start a target APP software of a mobile terminal device and establish a first VPN connection between the mobile terminal device and a VPN server through a first certificate in the target APP software, wherein the first certificate includes a VPN encryption and decryption certificate, a first VPN account number, and a first VPN password; a control unit, configured to, if the first VPN connection is successful, verify the device information of the mobile terminal device through the VPN server using the MDM server, and if the device information verification passes, send the second VPN account and the second VPN password of the MDM server to the mobile terminal device through the VPN server, and control the VPN server to disconnect the first VPN connection if the private key of the second certificate and the public key of the third certificate of the mobile terminal device are both present and not expired, using the MDM server, wherein the second certificate is a certificate for the identity information of the mobile terminal device, the third certificate is a certificate for verifying VPN information, and the public key of the second certificate and the private key of the third certificate are located in the VPN server; a verification unit, configured to establish a second VPN connection between the mobile terminal device and the VPN server based on the second VPN account, the second VPN password, the second certificate, and the third certificate, and to secondary verify the device information of the mobile terminal device through the VPN server using the MDM server; if the verification is successful, to enable business interaction between the mobile terminal device and the business end through the VPN server, wherein the bandwidth of the second VPN connection is greater than the bandwidth of the first VPN connection.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for secure online verification of a mobile terminal device according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include a method for executing secure online verification of a mobile terminal device as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for achieving mobile office, terminal device and MDM device

    CN109842600A

  • Mobile enterprise smartcard authentication

    US20130297933A1