A digital account security management method and system
By using the account security pre-unit unit to convert and splice identity information in the account security management system, replacing the encryption logic of traditional keys, the problem of key security risks is solved, and high security and simplified key management are achieved in the account login process.
Patent Information
- Application Number
- CN202411319447.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-20
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-09-20
AI Technical Summary
The existing account security management system uses keys during the transmission of identity information, which poses security risks, such as the keys being stolen or cracked, resulting in the identity information being intercepted and tampered with. The key management is complex, and it is difficult to detect and redistribute it in time after being lost or leaked.
The account security pre-unit unit receives identity information data, performs parity determination to determine redundant characters, extracts facial image data and incremental data, splices and converts it into a binary combination data, and transmits it to the resource service platform for identity authentication, replacing the encryption logic of traditional keys.
Through dynamically changing identity information data, it increases the difficulty of identity information being cracked, ensures the security of the account login process, and reduces the complexity of key management.
Smart Images

Figure CN119227039B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of account security management, and in particular to a digital account security management method and system. Background Art
[0002] In today's era of rapid digital development, with the continuous advancement of Internet technology and the widespread application of various online services, account security management has become a crucial issue. Users usually need to use various digital accounts to access different service platforms, such as online banking, social media, e-commerce platforms, etc. These accounts often contain users' important personal information and sensitive data. Once the account security is threatened, it may cause serious losses to users.
[0003] Currently, many account security management systems use multi-factor login to improve account security. Multi-factor login usually combines multiple factors such as what the user knows (such as a password), what the user has (such as a mobile phone verification code), and what the user is (such as biometric recognition) for identity authentication. However, despite the use of multi-factor login, most existing systems still use keys in the transmission of identity information.
[0004] This method of transmitting identity information using keys has many security risks. On the one hand, the keys may be stolen or cracked by hackers. If hackers obtain the keys, they can easily intercept and tamper with the identity information and impersonate legitimate users to log in to the account. On the other hand, key management is also difficult. If the key is lost or leaked, the user may not be able to find it in time. In addition, the process of regenerating and distributing keys is also complicated and time-consuming, requiring a lot of financial and time resources.
[0005] In order to solve the above problems, the present invention proposes a solution. Summary of the invention
[0006] The purpose of the present invention is to provide a digital account security management method and system to solve the problems raised in the above background technology;
[0007] The purpose of the present invention can be achieved through the following technical solutions:
[0008] A digital account security management method comprises the following steps:
[0009] Step 1: After receiving the transmitted identity information data of the current pre-logged-in user, the account security front-end unit first performs an odd-even determination on the number of logins stored in the account security front-end unit, and determines the redundant characters of the current pre-logged-in user's pre-login according to the determination result, wherein the identity information data includes the facial image data, account information data and fingerprint information data of the current pre-logged-in user, and the account information data includes the login account and login password;
[0010] Step 2: The account security pre-setting unit converts the identity information data of the current pre-logged-in user according to the preset security pre-setting rules to obtain the account security pre-setting data of the current pre-logged-in user;
[0011] Step 3: The account security pre-processing unit transmits the account security pre-processing data and the login account included in the identity information data to the resource service platform;
[0012] Step 4: After receiving the transmitted account security pre-data and login account, the resource service platform first restores the account security pre-data to obtain the combined information data of the current pre-logged-in user, and then matches the authorization information data of the corresponding authorized user according to the received login account. The obtained combined information data of the current pre-logged-in user is authenticated according to the authorization information data. The authorized identity information includes the number of logins, authorized account, authorized password, dynamic facial image data and authorized fingerprint data.
[0013] Furthermore, in step 2, the security pre-setting rules for converting the security pre-setting data of the account of the current pre-logged-in user are as follows:
[0014] S11: extracting facial image data from the received identity information data, and comparing it with the dynamic facial graphic data of the current pre-logged-in user updated and stored in the account security front-end unit, and extracting incremental data in the facial image data compared with the dynamic facial image data;
[0015] S12: extracting all data except the login account from the identity information data remaining after extraction in S11, splicing all the extracted data, the incremental data and the redundant characters of the current pre-logged-in user to obtain the combined information data of the current pre-logged-in user, and performing binary conversion on the data, marking the converted data as the binary combined data of the current pre-logged-in user, wherein the redundant characters are at the leftmost end and the incremental data are at the rightmost end during the splicing process;
[0016] S13: from left to right, taking every four characters in the binary combination data as a group of character arrays to obtain a plurality of character arrays, and marking all the character arrays as A1, A2, ..., Aa, a≥1, from left to right according to the position of each character array in the binary combination data;
[0017] S14: Generate a fused string of the character array A1 according to a preset first generation rule;
[0018] S15: Generate a comparison fusion string of the character array A2 according to a preset second generation rule;
[0019] S16: Generate comparison fusion substrings of character arrays A3, A4, ...Aa in sequence according to S15. In the process of generating the comparison fusion substring of character array A3, character array A3 and character array A2 are compared bit by bit. The generation process of comparison fusion substrings of other character arrays is similar.
[0020] The fused string of character arrays A1, A2 ... Aa is concatenated using "," to obtain the account security pre-data of the current pre-logged-in user.
[0021] Furthermore, if the identity authentication is passed, the dynamic facial image data of the corresponding authorized user is updated according to the facial image data of the current pre-logged-in user, and the number of login times of the authorized user is increased by 1.
[0022] A digital account security management system, comprising:
[0023] The login unit obtains the identity information data of the current pre-logged-in user, wherein the identity information data includes the facial image data, account information data and fingerprint information data of the current pre-logged-in user, and the account information data includes the login account and login password;
[0024] The account security front-end unit updates and stores the dynamic facial image data and login times of the current pre-logged-in user. After receiving the identity information data of the current pre-logged-in user, the account security front-end unit first performs an odd-even determination on the login times, and determines the redundant characters of the current pre-logged-in user for this pre-login based on the determination result.
[0025] Then, the identity information data of the current pre-logged-in user is converted according to the preset security pre-setting rules to obtain the account security pre-setting data of the current pre-logged-in user, and the pre-setting data and the login account included in the identity information data are transmitted to the resource service platform together;
[0026] The resource service platform is used to provide recruitment information reading services to authorized users. The resource service platform includes an account security unit.
[0027] The account security unit stores the authorized identity information of all authorized users, which includes the number of logins, authorized account, authorized password, dynamic facial image data, and authorized fingerprint data;
[0028] After receiving the transmitted account security pre-data and login account of the current pre-logged-in user, the account security unit first restores the account security pre-data to obtain the combined information data of the current pre-logged-in user, then matches the authorization information data of the corresponding authorized user according to the received login account, and performs identity authentication on the obtained combined information data of the current pre-logged-in user according to the authorization information data. During the authentication process, the facial image data of the current pre-logged-in user can be obtained according to the combined information data and the dynamic facial image data of the corresponding authorized user;
[0029] If the identity authentication is successful, the dynamic facial image data of the corresponding authorized user is updated according to the facial image data of the current pre-logged-in user, and the number of logins of the authorized user is increased by 1, and an authentication success instruction is generated at the same time, and the authentication success instruction is transmitted to the client module;
[0030] After receiving the transmitted authentication success instruction, the client module updates and stores the dynamic facial image data of the current pre-logged-in user stored in the account security front unit according to the acquired facial image data of the current pre-logged-in user, and increases the number of login times stored therein by 1.
[0031] Beneficial effects of the present invention:
[0032] After obtaining the identity information data of the current pre-logged-in user, the present invention uses an account security front-end unit to determine the redundant characters of this login according to the number of logins of the current pre-logged-in user, and then extracts facial image data from the identity information data of the current pre-logged-in user to obtain incremental data, and then splices the incremental data, account information data, fingerprint information data and redundant data to obtain binary combination data, converts and transmits the binary combination data, thereby ensuring the dynamic variability of the identity information data used for conversion during each login process, greatly increasing the difficulty of cracking the identity information data, and ensuring the security of the account login process;
[0033] In the process of converting binary combination data, the present invention changes the redundant characters based on the first character array, and all the remaining character arrays are compared based on the previous character array to obtain the corresponding comparison fusion string. In the process of obtaining the comparison fusion string, the comparison fusion string is generated according to the number of consistent characters, and when the number of consistent characters is 2, the conversion process is mapped to a change path using a table and a plane rectangular coordinate system, and randomness is added in the process of generating the comparison fusion string according to the change path, so that the corresponding comparison fusion string finally obtained is more complex and difficult to find a pattern. In this way, the encryption logic using the replacement key has a high degree of complexity and difficulty to crack, and the security management of the account is further guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The present invention will be further described below in conjunction with the accompanying drawings.
[0035] Figure 1 is a system block diagram of the present invention;
[0036] Figure 2 It is a flow chart of the method of the present invention. DETAILED DESCRIPTION
[0037] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0038] like Figure 1 , 2 As shown, a digital account security management method and system include a client module and a resource service platform;
[0039] The client module is used to pre-login a user to the resource service platform, and the client module includes a login unit and an account security pre-setting unit;
[0040] The login unit acquires the identity information data of the current pre-logged-in user and transmits it to the account security front-end unit, wherein the identity information data includes the facial image data, account information data and fingerprint information data of the current pre-logged-in user, wherein the account information data includes the login account and login password;
[0041] In this embodiment, the resource service platform has three authentication methods for authorized users, namely account and password recognition authentication, facial recognition authentication, and fingerprint recognition authentication;
[0042] The account security front-end unit updates and stores the dynamic facial image data and login times of the current pre-login user. After receiving the transmitted identity information data of the current pre-login user, the account security front-end unit first performs an odd-even judgment on the login times. If it is an odd number, character 1 is used as a redundant character for the current pre-login user's current pre-login. Otherwise, character 0 is used as a redundant character for the current pre-login user's current pre-login.
[0043] Then, the identity information data of the current pre-logged-in user is converted according to the preset security pre-setting rules to obtain the account security pre-setting data of the current pre-logged-in user. The security pre-setting rules are as follows:
[0044] S11: extracting facial image data from the received identity information data, and comparing it with the dynamic facial graphic data of the current pre-logged-in user updated and stored in the account security front-end unit, extracting incremental data from the facial image data compared to the dynamic facial image data. In this embodiment, the incremental data may include subtle changes in facial expressions, slight displacements of facial features, image differences caused by changes in lighting conditions, etc.;
[0045] S12: extracting all data except the login account from the identity information data remaining after extraction in S11, splicing all the extracted data, the incremental data and the redundant characters of the current pre-logged-in user to obtain the combined information data of the current pre-logged-in user, and performing binary conversion on the data, marking the converted data as the binary combined data of the current pre-logged-in user, wherein the redundant characters are at the leftmost end and the incremental data are at the rightmost end during the splicing process;
[0046] S13: from left to right, taking every four characters in the binary combination data as a group of character arrays to obtain a plurality of character arrays, and marking all the character arrays as A1, A2, ..., Aa, a≥1, from left to right according to the position of each character array in the binary combination data;
[0047] S14: Generate the fused string of the character array A1 according to a preset first generation rule, the generation rule is as follows:
[0048] S141: marking all characters constituting the character array A1 as B1, B2, B3 and B4 in order from left to right, wherein when marking the characters in the character array A1, the subscript of the mark is the position of the corresponding character in the character array A1;
[0049] S142: respectively compare the characters B1, B2, B3, and B4 with the redundant characters for consistency, and generate a fused string of the character array A1 according to the comparison results, wherein the comparison results include four cases SS11-SS14:
[0050] SS11: If only one of characters B1, B2, B3, and B4 is consistent with the redundant character, character 11 is used as the direction string of the character array A1, and the mark subscript C1 of the character consistent with the redundant character is recorded at the same time, and the binary number of the value after C1-1 is used as the feature string of the character array A1, and the direction string and the feature string are concatenated to obtain the fusion string of the character array A1;
[0051] SS12: If two characters among characters B1, B2, B3, and B4 are consistent with the redundant characters, character 00 is used as the direction string of character array A1, and the mark subscripts C2 and C3 of the characters consistent with the redundant characters are recorded at the same time, where the value of C2 is greater than C3, and the binary numbers of the values of C2-1 and C3-1 are spliced, and the data obtained after splicing is used as the feature string of character array A1. During the splicing process, the binary number of the value of C2-1 is spliced at the leftmost end;
[0052] The direction string and the characteristic string are concatenated to obtain a fused string of the character array A1;
[0053] SS13: If three characters among characters B1, B2, B3, and B4 are consistent with the redundant characters, character 00 is used as the direction string of character array A1, and the mark subscript C4 of the character inconsistent with the redundant characters is recorded, and the binary number of the value of C4-1 is used as the feature string of character array A1, and the direction string and the feature string are concatenated to obtain the fusion string of character array A1;
[0054] SS14: If no character among characters B1, B2, B3, and B4 is consistent with the redundant character, character 10 is used as the fused string of character array A1;
[0055] The splicing process of the fused string is performed in the order of the direction string and the feature string;
[0056] S15: Generate a comparison fusion string of the character array A2 according to a preset second generation rule, the second generation rule is as follows:
[0057] S151: Mark the characters constituting the character array A2 as D1, D2, D3, and D4 in order from left to right, and compare the character array A1 and the character array A2 bit by bit, that is, compare B1 and D1, B2 and D2, B3 and D3, and B4 and D4 for consistency, extract the total number of characters in the character array A2 that are inconsistent with the character array A1, determine the total number, and obtain the comparison fusion string of the character array A2 based on the determination result, wherein the determination result includes four cases SS21-SS24:
[0058] SS21: If the total number is 1, then 10 is used as the breadth string of the character array A2, the character mark subscript E1 that is inconsistent with the character array A1 is obtained, and the value of E1-1 is marked as the depth string of the character array A2;
[0059] The width string and the depth string of the character array A2 are concatenated to obtain a comparison fusion string of the character array A2, wherein the width string is concatenated at the leftmost end during the concatenation process;
[0060] SS22: If the total number is 2, extract the subscripts of the characters in character array A2 that are inconsistent with those in character array A1, mark them as E2 and E3 respectively, where E2 is less than E3, and then generate the comparison fusion string of the character array A2 according to the preset search generation rule, the search generation rule is as follows:
[0061] SS31: First, create a 4*4 table, and then fill all cells in the first row of the table with characters 1, 2, 3, and 4 from left to right, fill all cells in the second row of the table with characters 2, 2, 3, and 4 from left to right, fill all cells in the third row of the table with characters 3, 3, 3, and 4 from left to right, and fill all cells in the fourth row of the table with characters 4, 4, 4, and 4 from left to right. It should be noted that the first, second, third, and fourth rows of the table are described in order from top to bottom, and in the process of filling cells in the table with characters, only one character is filled in each cell;
[0062] SS32: Establish a plane rectangular coordinate system according to the table. In the plane rectangular coordinate system, the coordinate origin is the lower left corner vertex of the table. With the origin as a reference, determine the horizontal right direction as the x-axis and the vertical upward direction as the y-axis;
[0063] SS33: According to the subscripts E2 and E3, several cells corresponding to the characters filled in with E2 and E3 are found in the plane rectangular coordinate system, one cell is selected as the starting cell from all the cells found to be filled in with the character E2, and one cell is selected as the ending cell from all the cells found to be filled in with the character E3, and the selected starting cell and ending cell meet the preset selection conditions:
[0064] The number of cells passed from the starting cell to the final cell is the largest. In this embodiment, only one cell can be moved each time;
[0065] SS34: Obtain all changeable paths from the starting cell to the ending cell, and randomly select a changeable path as the selected path of the array character A2, wherein the changeable path includes a number of cells passed through during the change process, and the cells are arranged from left to right in the order of passing;
[0066] SS35: Obtain all cells contained in the selected path in order from left to right, and find the corresponding position coordinates of the cells in the plane rectangular coordinate system;
[0067] SS36: splicing the position coordinates of all cells in the selected path in order from left to right, and performing binary conversion on the spliced data to obtain the comparison fusion string of the character array A2. During the splicing process, for any cell, the horizontal and vertical coordinates of the cell are first spliced to obtain the coordinate array of the corresponding cell, and then the coordinate arrays of all cells are spliced to obtain the final comparison fusion string;
[0068] SS23: If the total number is 3, use 01 as the breadth string of the character array A2, obtain the character mark subscript E4 that is consistent with the character array A1, and mark the array of E4-1 as the depth string of the character array A2;
[0069] The width string and the depth string of the character array A2 are concatenated to obtain a comparison fusion string of the character array A2, wherein the width string is concatenated at the leftmost end during the concatenation process;
[0070] SS24: The total number is 4, then 1001 is used as the comparison fusion string of the character array A2;
[0071] S16: Generate comparison fusion substrings of character arrays A3, A4, ...Aa in sequence according to S15. In the process of generating the comparison fusion substring of character array A3, character array A3 and character array A2 are compared bit by bit. The generation process of comparison fusion substrings of other character arrays is similar.
[0072] The fused string of the character arrays A1, A2...Aa is concatenated using "," to obtain the account security pre-data of the current pre-logged-in user, and the pre-data is transmitted together with the login account included in the identity information data to the resource service platform;
[0073] The resource service platform is used to provide recruitment information reading services for authorized users. The resource service platform includes a resource service unit, an account security unit and a reading record unit. The account security unit stores the authorized identity information of all authorized users. The authorized identity information includes the number of logins, authorized account number, authorized password, dynamic facial image data and authorized fingerprint data.
[0074] After receiving the transmitted account security pre-data and login account of the current pre-logged-in user, the account security unit first restores the account security pre-data to obtain the combined information data of the current pre-logged-in user, then matches the authorization information data of the corresponding authorized user according to the received login account, and performs identity authentication on the obtained combined information data of the current pre-logged-in user according to the authorization information data. During the authentication process, the facial image data of the current pre-logged-in user can be obtained according to the combined information data and the dynamic facial image data of the corresponding authorized user;
[0075] If the identity authentication is successful, the dynamic facial image data of the corresponding authorized user is updated according to the facial image data of the current pre-logged-in user, and the number of logins of the authorized user is increased by 1, and an authentication success instruction is generated at the same time, and the authentication success instruction is transmitted to the client module;
[0076] After receiving the transmitted authentication success instruction, the client module updates and stores the dynamic facial image data of the current pre-logged-in user stored in the account security front-end unit according to the acquired facial image data of the current pre-logged-in user, and increases the number of logins stored therein by 1;
[0077] The resource service unit pre-stores a number of recruitment information data for authorized users to view, wherein the recruitment information data includes position information, position description, salary and benefits, company information and recruitment process information;
[0078] The reading record unit is used to record the recruitment information data clicked by the authorized user during the process of reading the recruitment information data, so as to provide for the subsequent behavior analysis of the authorized user;
[0079] In the description of the specification, the description with reference to the terms "one embodiment", "example", "specific example" and the like means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. The above contents are merely examples and explanations of the present invention. A person skilled in the art may make various modifications or supplements to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the invention or exceed the scope defined by the claims, they shall all fall within the scope of protection of the present invention.
[0080] The above is a detailed description of an embodiment of the present invention, but the content is only a preferred embodiment of the present invention and cannot be considered to limit the scope of implementation of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.
Claims
1. A digital account security management method, characterized in that: The following steps are involved: Step 1: After receiving the transmitted identity information data of the current pre-logged-in user, the account security front-end unit first performs an odd-even determination on the number of logins stored in the account security front-end unit, and determines the redundant characters of the current pre-logged-in user's pre-login according to the determination result, wherein the identity information data includes the facial image data, account information data and fingerprint information data of the current pre-logged-in user, and the account information data includes the login account and login password; Step 2: The account security pre-setting unit converts the identity information data of the current pre-logged-in user according to the preset security pre-setting rules to obtain the account security pre-setting data of the current pre-logged-in user. The security pre-setting rules are as follows: S11: extracting facial image data from the received identity information data, and comparing it with the dynamic facial image data of the current pre-logged-in user updated and stored in the account security front-end unit, and extracting incremental data from the facial image data compared to the dynamic facial image data; S12: extracting all data except the login account from the identity information data remaining after extraction in S11, splicing all the extracted data, the incremental data and the redundant characters of the current pre-logged-in user to obtain the combined information data of the current pre-logged-in user, and performing binary conversion on the data, marking the converted data as the binary combined data of the current pre-logged-in user, wherein the redundant characters are at the leftmost end and the incremental data are at the rightmost end during the splicing process; S13: from left to right, taking every four characters in the binary combination data as a group of character arrays to obtain a plurality of character arrays, and marking all the character arrays as A1, A2, ..., Aa, a≥1, from left to right according to the position of each character array in the binary combination data; S14: Generate the fused string of the character array A1 according to a preset first generation rule, as follows: S141: marking all characters constituting the character array A1 as B1, B2, B3 and B4 in order from left to right, wherein when marking the characters in the character array A1, the subscript of the mark is the position of the corresponding character in the character array A1; S142: respectively compare the characters B1, B2, B3, and B4 with the redundant characters for consistency, and generate a fused string of the character array A1 according to the comparison results, wherein the comparison results include four cases, namely, SS11-SS14; SS11: If only one of characters B1, B2, B3, and B4 is consistent with the redundant character, character 11 is used as the direction string of the character array A1, and the mark subscript C1 of the character consistent with the redundant character is recorded at the same time, and the binary number of the value after C1-1 is used as the feature string of the character array A1, and the direction string and the feature string are concatenated to obtain the fusion string of the character array A1; SS12: If two characters among characters B1, B2, B3, and B4 are consistent with the redundant characters, character 00 is used as the direction string of character array A1, and the mark subscripts C2 and C3 of the characters consistent with the redundant characters are recorded at the same time, where the value of C2 is greater than C3, and the binary numbers of the values of C2-1 and C3-1 are spliced, and the data obtained after splicing is used as the feature string of character array A1. During the splicing process, the binary number of the value of C2-1 is spliced at the leftmost end; The direction string and the characteristic string are concatenated to obtain a fused string of the character array A1; SS13: If three characters among characters B1, B2, B3, and B4 are consistent with the redundant characters, character 00 is used as the direction string of the character array A1, and the mark subscript C4 of the character inconsistent with the redundant characters is recorded, and the binary number of the value of C4-1 is used as the feature string of the character array A1, and the direction string and the feature string are concatenated to obtain the fusion string of the character array A1; SS14: If no character among characters B1, B2, B3, and B4 is consistent with the redundant character, character 10 is used as the fused string of character array A1; The splicing process of the fused string is performed in the order of the direction string and the feature string; S15: Generate a comparison fusion string of the character array A2 according to a preset second generation rule, as follows: S151: Mark the characters constituting the character array A2 as D1, D2, D3, and D4 in order from left to right, and compare the character array A1 and the character array A2 bit by bit, that is, compare B1 and D1, B2 and D2, B3 and D3, and B4 and D4 for consistency, extract the total number of characters in the character array A2 that are inconsistent with the character array A1, determine the total number, and obtain the comparison fusion string of the character array A2 based on the determination result, wherein the determination result includes four cases SS21-SS24: SS21: If the total number is 1, then 10 is used as the breadth string of the character array A2, the character mark subscript E1 that is inconsistent with the character array A1 is obtained, and the value of E1-1 is marked as the depth string of the character array A2; The width string and the depth string of the character array A2 are concatenated to obtain a comparison fusion string of the character array A2, wherein the width string is concatenated at the leftmost end during the concatenation process; SS22: If the total number is 2, extract the subscripts of the characters in character array A2 that are inconsistent with those in character array A1, mark them as E2 and E3 respectively, where E2 is less than E3, and then generate the comparison fusion string of the character array A2 according to the preset search generation rule, the search generation rule is as follows: SS31: First, create a 4*4 table, and then fill all cells in the first row of the table with characters 1, 2, 3, and 4 from left to right, fill all cells in the second row of the table with characters 2, 2, 3, and 4 from left to right, fill all cells in the third row of the table with characters 3, 3, 3, and 4 from left to right, and fill all cells in the fourth row of the table with characters 4, 4, 4, and 4 from left to right. The first, second, third, and fourth rows of the table are described in order from top to bottom. In the process of filling characters into cells in the table, only one character is filled in each cell; SS32: Establish a plane rectangular coordinate system according to the table. In the plane rectangular coordinate system, the coordinate origin is the lower left corner vertex of the table. Taking the origin as a reference, determine the horizontal right direction as the x-axis and the vertical upward direction as the y-axis; SS33: According to the subscripts E2 and E3, several cells corresponding to the characters filled in with E2 and E3 are found in the plane rectangular coordinate system, one cell is selected as the starting cell from all the cells found to be filled in with the character E2, and one cell is selected as the ending cell from all the cells found to be filled in with the character E3, and the selected starting cell and ending cell meet the preset selection conditions: The number of cells passed from the starting cell to the final cell is the largest. In this embodiment, only one cell can be moved each time; SS34: Obtain all changeable paths from the starting cell to the ending cell, and randomly select a changeable path as the selected path of the character array A2, wherein the changeable path includes a number of cells passed through during the change process, and the cells are arranged from left to right in the order of passing; SS35: Obtain all cells contained in the selected path in order from left to right, and find the corresponding position coordinates of the cells in the plane rectangular coordinate system; SS36: splicing the position coordinates of all cells in the selected path in order from left to right, and performing binary conversion on the spliced data to obtain the comparison fusion string of the character array A2. During the splicing process, for any cell, the horizontal and vertical coordinates of the cell are first spliced to obtain the coordinate array of the corresponding cell, and then the coordinate arrays of all cells are spliced to obtain the final comparison fusion string; SS23: If the total number is 3, use 01 as the breadth string of the character array A2, obtain the character mark subscript E4 that is consistent with the character array A1, and mark the array of E4-1 as the depth string of the character array A2; The width string and the depth string of the character array A2 are concatenated to obtain a comparison fusion string of the character array A2, wherein the width string is concatenated at the leftmost end during the concatenation process; SS24: The total number is 4, then 1001 is used as the comparison fusion string of the character array A2; S16: Generate comparison fusion substrings of character arrays A3, A4, ...Aa in sequence according to S15. In the process of generating the comparison fusion substring of character array A3, character array A3 and character array A2 are compared bit by bit. The generation process of comparison fusion substrings of other character arrays is similar. Use "," to concatenate the fused string of character arrays A1, A2...Aa to obtain the account security pre-data of the current pre-logged-in user; Step 3: The account security pre-processing unit transmits the account security pre-processing data and the login account included in the identity information data to the resource service platform; Step 4: After receiving the transmitted account security pre-data and login account, the resource service platform first restores the account security pre-data to obtain the combined information data of the current pre-logged-in user, and then matches the authorization information data of the corresponding authorized user according to the received login account. The obtained combined information data of the current pre-logged-in user is authenticated according to the authorization information data. The authorized identity information includes the number of logins, authorized account, authorized password, dynamic facial image data and authorized fingerprint data.
2. A digital account security management method according to claim 1, characterized in that: If the identity authentication is passed, the dynamic facial image data of the corresponding authorized user is updated according to the facial image data of the current pre-logged-in user, and the number of login times of the authorized user is increased by 1.
3. A digital account security management system, characterized in that: include: The login unit obtains the identity information data of the current pre-logged-in user, wherein the identity information data includes the facial image data, account information data and fingerprint information data of the current pre-logged-in user, and the account information data includes the login account and login password; The account security front-end unit updates and stores the dynamic facial image data and login times of the current pre-logged-in user. After receiving the identity information data of the current pre-logged-in user, the account security front-end unit first performs an odd-even determination on the login times, and determines the redundant characters of the current pre-logged-in user for this pre-login based on the determination result. Then, the identity information data of the current pre-logged-in user is converted according to the preset security pre-setting rules to obtain the account security pre-setting data of the current pre-logged-in user, which is transmitted to the resource service platform together with the login account included in the identity information data. The security pre-setting rules are as follows: S11: extracting facial image data from the received identity information data, and comparing it with the dynamic facial image data of the current pre-logged-in user updated and stored in the account security front-end unit, and extracting incremental data from the facial image data compared to the dynamic facial image data; S12: extracting all data except the login account from the identity information data remaining after extraction in S11, splicing all the extracted data, the incremental data and the redundant characters of the current pre-logged-in user to obtain the combined information data of the current pre-logged-in user, and performing binary conversion on the data, marking the converted data as the binary combined data of the current pre-logged-in user, wherein the redundant characters are at the leftmost end and the incremental data are at the rightmost end during the splicing process; S13: from left to right, taking every four characters in the binary combination data as a group of character arrays to obtain a plurality of character arrays, and marking all the character arrays as A1, A2, ..., Aa, a≥1, from left to right according to the position of each character array in the binary combination data; S14: Generate the fused string of the character array A1 according to a preset first generation rule, as follows: S141: marking all characters constituting the character array A1 as B1, B2, B3 and B4 in order from left to right, wherein when marking the characters in the character array A1, the subscript of the mark is the position of the corresponding character in the character array A1; S142: respectively compare the characters B1, B2, B3, and B4 with the redundant characters for consistency, and generate a fused string of the character array A1 according to the comparison results, wherein the comparison results include four cases, namely, SS11-SS14; SS11: If only one of characters B1, B2, B3, and B4 is consistent with the redundant character, character 11 is used as the direction string of the character array A1, and the mark subscript C1 of the character consistent with the redundant character is recorded at the same time, and the binary number of the value after C1-1 is used as the feature string of the character array A1, and the direction string and the feature string are concatenated to obtain the fusion string of the character array A1; SS12: If two characters among characters B1, B2, B3, and B4 are consistent with the redundant characters, character 00 is used as the direction string of character array A1, and the mark subscripts C2 and C3 of the characters consistent with the redundant characters are recorded at the same time, where the value of C2 is greater than C3, and the binary numbers of the values of C2-1 and C3-1 are spliced, and the data obtained after splicing is used as the feature string of character array A1. During the splicing process, the binary number of the value of C2-1 is spliced at the leftmost end; The direction string and the characteristic string are concatenated to obtain a fused string of the character array A1; SS13: If three characters among characters B1, B2, B3, and B4 are consistent with the redundant characters, character 00 is used as the direction string of the character array A1, and the mark subscript C4 of the character inconsistent with the redundant characters is recorded, and the binary number of the value of C4-1 is used as the feature string of the character array A1, and the direction string and the feature string are concatenated to obtain the fusion string of the character array A1; SS14: If no character among characters B1, B2, B3, and B4 is consistent with the redundant character, character 10 is used as the fused string of character array A1; The splicing process of the fused string is performed in the order of the direction string and the feature string; S15: Generate a comparison fusion string of the character array A2 according to a preset second generation rule, as follows: S151: Mark the characters constituting the character array A2 as D1, D2, D3, and D4 in order from left to right, and compare the character array A1 and the character array A2 bit by bit, that is, compare B1 and D1, B2 and D2, B3 and D3, and B4 and D4 for consistency, extract the total number of characters in the character array A2 that are inconsistent with the character array A1, determine the total number, and obtain the comparison fusion string of the character array A2 based on the determination result, wherein the determination result includes four cases SS21-SS24: SS21: If the total number is 1, then 10 is used as the breadth string of the character array A2, the character mark subscript E1 that is inconsistent with the character array A1 is obtained, and the value of E1-1 is marked as the depth string of the character array A2; The width string and the depth string of the character array A2 are concatenated to obtain a comparison fusion string of the character array A2, wherein the width string is concatenated at the leftmost end during the concatenation process; SS22: If the total number is 2, extract the subscripts of the characters in character array A2 that are inconsistent with those in character array A1, mark them as E2 and E3 respectively, where E2 is less than E3, and then generate the comparison fusion string of the character array A2 according to the preset search generation rule, the search generation rule is as follows: SS31: First, create a 4*4 table, and then fill all cells in the first row of the table with characters 1, 2, 3, and 4 from left to right, fill all cells in the second row of the table with characters 2, 2, 3, and 4 from left to right, fill all cells in the third row of the table with characters 3, 3, 3, and 4 from left to right, and fill all cells in the fourth row of the table with characters 4, 4, 4, and 4 from left to right. The first, second, third, and fourth rows of the table are described in order from top to bottom. In the process of filling characters into cells in the table, only one character is filled in each cell; SS32: Establish a plane rectangular coordinate system according to the table. In the plane rectangular coordinate system, the coordinate origin is the lower left corner vertex of the table. Taking the origin as a reference, determine the horizontal right direction as the x-axis and the vertical upward direction as the y-axis; SS33: According to the subscripts E2 and E3, several cells corresponding to the characters filled in with E2 and E3 are found in the plane rectangular coordinate system, one cell is selected as the starting cell from all the cells found to be filled in with the character E2, and one cell is selected as the ending cell from all the cells found to be filled in with the character E3, and the selected starting cell and ending cell meet the preset selection conditions: The number of cells passed from the starting cell to the final cell is the largest. In this embodiment, only one cell can be moved each time; SS34: Obtain all changeable paths from the starting cell to the ending cell, and randomly select a changeable path as the selected path of the character array A2, wherein the changeable path includes a number of cells passed through during the change process, and the cells are arranged from left to right in the order of passing; SS35: Obtain all cells contained in the selected path in order from left to right, and find the corresponding position coordinates of the cells in the plane rectangular coordinate system; SS36: splicing the position coordinates of all cells in the selected path in order from left to right, and performing binary conversion on the spliced data to obtain the comparison fusion string of the character array A2. During the splicing process, for any cell, the horizontal and vertical coordinates of the cell are first spliced to obtain the coordinate array of the corresponding cell, and then the coordinate arrays of all cells are spliced to obtain the final comparison fusion string; SS23: If the total number is 3, use 01 as the breadth string of the character array A2, obtain the character mark subscript E4 that is consistent with the character array A1, and mark the array of E4-1 as the depth string of the character array A2; The width string and the depth string of the character array A2 are concatenated to obtain a comparison fusion string of the character array A2, wherein the width string is concatenated at the leftmost end during the concatenation process; SS24: The total number is 4, then 1001 is used as the comparison fusion string of the character array A2; S16: Generate comparison fusion substrings of character arrays A3, A4, ...Aa in sequence according to S15. In the process of generating the comparison fusion substring of character array A3, character array A3 and character array A2 are compared bit by bit. The generation process of comparison fusion substrings of other character arrays is similar. Use "," to concatenate the fused string of character arrays A1, A2...Aa to obtain the account security pre-data of the current pre-logged-in user; The resource service platform is used to provide recruitment information reading services to authorized users. The resource service platform includes an account security unit. The account security unit stores the authorized identity information of all authorized users, which includes the number of logins, authorized account, authorized password, dynamic facial image data, and authorized fingerprint data; After receiving the transmitted account security pre-data and login account of the current pre-logged-in user, the account security unit first restores the account security pre-data to obtain the combined information data of the current pre-logged-in user, then matches the authorization information data of the corresponding authorized user according to the received login account, and performs identity authentication on the obtained combined information data of the current pre-logged-in user according to the authorization information data. During the authentication process, the facial image data of the current pre-logged-in user can be obtained according to the combined information data and the dynamic facial image data of the corresponding authorized user; If the identity authentication is successful, the dynamic facial image data of the corresponding authorized user is updated according to the facial image data of the current pre-logged-in user, and the number of logins of the authorized user is increased by 1, and an authentication success instruction is generated at the same time, and the authentication success instruction is transmitted to the client module; After receiving the transmitted authentication success instruction, the client module updates and stores the dynamic facial image data of the current pre-logged-in user stored in the account security front unit according to the acquired facial image data of the current pre-logged-in user, and increases the number of login times stored therein by 1.
Citation Information
Patent Citations
Unlocking method and unlocking device of terminal equipment
CN104951679A