Method and apparatus for security authentication
By generating dynamic passwords based on terminal identifiers and geographic locations, the shortcomings of electronic signatures and dynamic password authentication are addressed, enabling convenient and efficient identity authentication and enhancing the non-repudiation and reliability of authentication.
Patent Information
- Application Number
- CN202411343452.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-09-25
AI Technical Summary
Existing electronic signature technology cannot provide more authentication information, affecting its non-repudiation and reliability, while dynamic password authentication requires additional hardware, increasing costs and being cumbersome, thus affecting user experience.
By receiving request messages from the terminal, the terminal identifier and geographical location are obtained, a dynamic password is generated, and it can be sent to the terminal without additional hardware. Geographical location information is integrated to improve the non-repudiation and reliability of authentication.
This provides a convenient and cost-effective identity authentication method that saves costs, eliminates the need to carry authentication devices, improves user experience, and further enhances the non-repudiation and reliability of authentication through geolocation verification.
Smart Images

Figure CN119276558B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of security, and particularly relates to a security authentication method and device, electronic equipment, storage medium and computer program product. BACKGROUND
[0002] With the development of technology, electronic signature technology as an identity authentication technology has been widely applied in various fields. Common electronic signature technologies include digital certificates, two-factor authentication, identity verification documents, in addition to which, dynamic passwords as another commonly used identity authentication technology are also widely used.
[0003] The security authentication technology in the related art has the following two significant deficiencies:
[0004] 1. Although the electronic signature technology can verify the identity information of the identity authenticator to a certain extent, the electronic signature technology cannot provide more authentication information, which affects the non-repudiation and reliability of the electronic signature technology.
[0005] 2. As for the dynamic password identity authentication method in the related art, an additional hardware device is usually needed to complete the authentication, and the user needs to carry the authentication device to perform identity authentication, which increases the cost of identity authentication and makes the identity authentication more cumbersome, affecting the user experience. SUMMARY
[0006] The embodiments of the present disclosure aim to provide a security authentication method and device, electronic equipment, storage medium and computer program product.
[0007] To solve the above technical problems, the embodiments of the present disclosure are implemented through the following aspects.
[0008] According to a first aspect of the embodiments of the present disclosure, a security authentication method is provided, which includes: receiving a first request message for obtaining a dynamic password sent by a terminal, the first request message including a first terminal identifier of the terminal; obtaining a first geographic position of the terminal according to the first terminal identifier; generating a first dynamic password based on the first geographic position, and sending a first response message including the first dynamic password to the terminal.
[0009] According to a second aspect of the embodiments of the present disclosure, a security authentication device is provided, which includes: a receiving module configured to receive a first request message for obtaining a dynamic password sent by a terminal, the first request message including a first terminal identifier of the terminal; an obtaining module configured to obtain a first geographic position of the terminal according to the first terminal identifier; and an authentication module configured to generate a first dynamic password based on the first geographic position, and send a first response message including the first dynamic password to the terminal.
[0010] According to a third aspect of the embodiments of the present disclosure, an electronic device is provided, comprising: a processor; a memory for storing instructions executable by the processor; wherein the processor is configured to perform the steps of the method for secure authentication according to the first aspect.
[0011] According to a fourth aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided, which stores one or more programs, which, when executed by an electronic device comprising a plurality of application programs, cause the electronic device to perform the steps of the method for secure authentication according to the first aspect.
[0012] According to a fourth aspect of the embodiments of the present disclosure, a computer program product is provided, which comprises a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions which, when executed by a computer, cause the computer to perform the method for secure authentication according to the first aspect.
[0013] One of the above technical solutions has the following advantages or beneficial effects: receiving a first request message for obtaining a dynamic password sent by a terminal; obtaining a first geographic position of the terminal according to the first terminal identifier; generating a first dynamic password based on the first geographic position, and sending a first response message comprising the first dynamic password to the terminal. A more convenient and cost-effective identity authentication method can be provided, which saves the cost of identity authentication, avoids carrying authentication equipment, improves user experience, and at the same time, the first dynamic password can be used to further verify the geographic position information of the identity authentication person while completing the identity authentication, thereby improving the non-repudiation and reliability of the identity authentication.
[0014] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure.
[0015] Other features and advantages of the present disclosure will be described in detail in the following specific embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments described in the present disclosure, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0017] Figure 1 A flowchart of a method for secure authentication provided by the embodiments of the present disclosure is shown.
[0018] Figure 2 Another flowchart of the method for security authentication provided by the embodiments of the present disclosure is shown.
[0019] Figure 3 Another flowchart of the method for security authentication provided by the embodiments of the present disclosure is shown.
[0020] Figure 4 Another flowchart of the method for security authentication provided by the embodiments of the present disclosure is shown.
[0021] Figure 5 Another flowchart of the method for security authentication provided by the embodiments of the present disclosure is shown.
[0022] Figure 6 A block diagram of a device for security authentication provided by the embodiments of the present disclosure is shown.
[0023] Figure 7 A hardware structure diagram of an electronic device for performing the method for security authentication provided by the embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0024] In order to enable persons skilled in the art to better understand the technical solutions in the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by persons skilled in the art without creative labor should fall within the scope of protection of the present disclosure.
[0025] The method for security authentication in the present disclosure can be performed by a server, a server cluster or a cloud server. The server, the server cluster and the cloud server can include an authentication server for generating a dynamic password, or an electronic signature server for identity authentication. The authentication server and the electronic signature server can be located on different servers, or can be integrated on the same server. The present disclosure does not limit this.
[0026] Figure 1 A flowchart of the method for security authentication provided by the embodiments of the present disclosure is shown. As shown in Figure 1 the method can include the following steps:
[0027] In step S101, a first request message for obtaining a dynamic password sent by a terminal is received.
[0028] The first request message includes a first terminal identifier of the terminal.
[0029] The terminal can be a mobile phone, a Tablet Personal Computer, a Laptop Computer, a notebook computer, a Personal Digital Assistant (PDA), a palm computer, a netbook, an Ultra-mobile Personal Computer (UMPC), a Mobile Internet Device (MID), an Augmented Reality (AR) device, a Virtual Reality (VR) device, and the like, without limitation.
[0030] The first terminal identifier can be in various forms, such as an MDN (Mobile Directory Number), an IMSI (International Mobile Subscriber Identity), or an IMEI (International Mobile Equipment Identity). The form of the terminal and the form of the first terminal identifier are not limited.
[0031] In some embodiments, after obtaining the first terminal identifier, the MDN corresponding to the terminal can be obtained from the server according to the first terminal identifier.
[0032] In step S102, the first geographic location of the terminal is obtained according to the first terminal identifier.
[0033] In some possible implementations, the server can communicate with a positioning server in the wireless communication network, and obtain the first geographic location corresponding to the first terminal identifier from the positioning server.
[0034] The positioning server can complete the positioning of the terminal based on any wireless positioning technology in the related art, thereby obtaining the first geographic location information of the terminal. For example, the TDOA (time difference of arrival), TOA (time of arrival), AGPS (Assisted Global Positioning System), or the like can be used to obtain the location information of the terminal.
[0035] It can be understood that the terminal location information obtained by the positioning server is usually location information represented in latitude and longitude. In some embodiments, after obtaining the location information represented in latitude and longitude from the positioning server, the server can obtain the first geographic location according to a preset correspondence between latitude and longitude and geographic location. In this embodiment, the first geographic location can be coarse-grained location information represented as “XX City XX District XX Street” or “XX City XX District”.
[0036] In step S103, a first dynamic password is generated based on the first geographic location, and a first response message including the first dynamic password is sent to the terminal.
[0037] In some embodiments, a hash value of a preset number of bits of the first geographic location can be obtained based on a preset hash algorithm, for example, a 32-bit hash value of the first geographic location is obtained, and the first dynamic password is generated based on the 32-bit hash value of the first geographic location.
[0038] After the first dynamic password is generated, a first response message including the first dynamic password can be sent to the terminal.
[0039] With the above technical solution, the terminal can obtain the first dynamic password through interaction with the server, without the need for additional authentication hardware devices, avoiding the inconvenience of carrying authentication devices, and improving user experience. At the same time, the first dynamic password integrates the first geographic location information, which can further verify the geographic location information of the identity authenticator, complete the identity authentication of the terminal, and improve the non-repudiation and reliability of the identity authentication.
[0040] Figure 2 Another flowchart of a method for secure authentication provided by an embodiment of the present disclosure is shown in FIG. 6. As shown in FIG. 6, step S102 can specifically include the following steps: Figure 2
[0041] In step S1021, the first dynamic password is generated based on the first geographic location, the second terminal identifier of the terminal, and the first timestamp when the first dynamic password is generated.
[0042] The second terminal identifier is a terminal identifier input by the user during generation of the first dynamic password, and can be an MDN.
[0043] In some embodiments, the first dynamic password can be generated according to the first geographic location, the second terminal identifier of the terminal, and the first timestamp when the first dynamic password is generated based on Formula One as follows.
[0044] (One)
[0045] P2 is the second terminal identifier, to obtain the sum value of the bit-by-bit summation, for example T1 is a first time stamp when the first dynamic password is generated, L1 is a preset bit number of a hash value of the first geographic location (the preset bit number can be 32 bits, for example), K, N1 and N2 are preset constant values, is a modulo operator. In some possible implementation manners, N1 and N2 can be 10000 and 1000000 respectively.
[0046] It should be noted that the granularity of the first time stamp can be a preset larger time granularity, for example, a time granularity of hours, so that the value of the first time stamp remains unchanged within a longer time range, which facilitates subsequent dynamic password authentication.
[0047] In some embodiments, when the first dynamic password is generated, the server can first match the second terminal identifier and the saved first terminal identifier, and only generate the first dynamic password when the two identifiers match successfully.
[0048] With the technical solution described above, the terminal can obtain the first dynamic password through interaction with the server, without the need for additional authentication hardware devices, avoiding the inconvenience of carrying an authentication device, and being able to improve user experience. Meanwhile, the first dynamic password integrates the first geographic location information, and the terminal uses the first dynamic password to complete identity authentication, which can further verify the geographic location information of the identity authenticator, the terminal identifier information and the time interval of generating the dynamic password and identity authentication, further improving the non-repudiation and reliability of identity authentication.
[0049] Figure 3 Another flowchart of a method for secure authentication provided by an embodiment of the present disclosure is shown in FIG. 10B. Figure 3 As shown in FIG. 10B, step S1021 can specifically include the following steps:
[0050] In step 100, the server generates a first key according to a first encryption algorithm, the first key including a first public key and a first private key.
[0051] In some possible implementation manners, the first key can be generated based on an asymmetric encryption algorithm in any related technology according to the first terminal identifier, where the first public key is used to send to the terminal for encryption when the terminal sends the second terminal identifier. The first private key is used to decrypt the encrypted second terminal identifier. The principle of the specific asymmetric encryption algorithm can be referred to the description in related technologies, which will not be described here.
[0052] In step 101, a second request message for obtaining a user input second terminal identifier is sent to the terminal.
[0053] The first public key is included in the second request message.
[0054] In some embodiments, the corresponding temporary token can be sent to the terminal through the second request message, so that the terminal sends the second response message within the valid time of the temporary token.
[0055] In step 102, the second response message sent by the terminal is received.
[0056] The second response message includes the second terminal identifier encrypted by the first public key and the second public key, and the second public key is the public key in the second key generated by the terminal based on the second encryption algorithm.
[0057] In some possible implementations, the second terminal identifier can be the MDN of the user input terminal, and the terminal can encrypt the second terminal identifier by using the first public key in the second request message. Meanwhile, the terminal can generate the second key based on the second encryption algorithm, where the second key includes the second public key and the second private key, the second public key is used to be sent to the server for encryption when the server sends the first dynamic password. The second private key is used for the terminal to decrypt the encrypted first dynamic password. The first encryption algorithm and the second encryption algorithm can be the same encryption algorithm or different encryption algorithms, which are not limited by the present application.
[0058] In some embodiments, the terminal can send the received temporary token through the second response message.
[0059] In step 103, the encrypted second terminal identifier is decrypted by the first private key to obtain the second terminal identifier.
[0060] In some embodiments, the corresponding first terminal identifier can be obtained through the temporary token, and the first private key can be found according to the first terminal identifier. The encrypted second terminal identifier is decrypted by the first private key to obtain the decrypted second terminal identifier.
[0061] In step 104, in the case that the second terminal identifier matches the first terminal identifier, the first dynamic password is generated based on the first geographic location, the second terminal identifier of the terminal and the first timestamp when the first dynamic password is generated, and the first response message including the first dynamic password encrypted by the second public key is sent to the terminal.
[0062] In some embodiments, the second terminal identifier can be the MDN input by the user, and the type of the first terminal identifier and the type of the second terminal identifier can be the same or different.
[0063] When the terminal identifier matching is performed, if the type of the first terminal identifier and the type of the second terminal identifier are the same, in the case that the first terminal identifier is the same as the second terminal identifier, it can be determined that the second terminal identifier matches the first terminal identifier, and in the case that the first terminal identifier is not the same as the second terminal identifier, it can be determined that the second terminal identifier does not match the first terminal identifier.
[0064] If the type of the first terminal identity and the type of the second terminal identity are different, the terminal identity corresponding to the first terminal identity can be obtained according to the type of the second terminal identity, and whether the first terminal identity and the second terminal identity match can be determined by comparing the terminal identity corresponding to the first terminal identity and the second terminal identity.
[0065] For example, in the case that the type of the first terminal identity of the terminal is IMSI and the type of the second terminal identity is MDN, the corresponding MDN can be obtained according to the first terminal identity, and the obtained MDN corresponding to the first terminal identity and the second terminal identity are matched.
[0066] In some possible implementation manners, the server can obtain the terminal identity corresponding to the first terminal identity according to the type of the second terminal identity through a HSS (home subscriber server) of the wireless communication system.
[0067] In the case that the second terminal identity and the first terminal identity match, the first dynamic password can be generated based on Formula One, and the first dynamic password is encrypted by using the received second public key and then sent to the terminal through the first response message.
[0068] In the case that the second terminal identity and the first terminal identity do not match, a third response message for indicating failure can be sent to the terminal.
[0069] After receiving the first response message, the terminal can decrypt the encrypted first dynamic password by using the second private key, so as to obtain the decrypted first dynamic password.
[0070] By using the technical solution, the terminal can obtain the first dynamic password through interaction with the server, without the need of additional authentication hardware devices, thereby avoiding the trouble of carrying the authentication devices and improving user experience. Meanwhile, the first dynamic password integrates the first geographic location information, and the terminal can complete identity authentication by using the first dynamic password, so as to further verify the geographic location information of the identity authenticator, the terminal identity information, and the time interval of generating the dynamic password and identity authentication, thereby further improving the non-repudiation and reliability of identity authentication.
[0071] Figure 4 Another flowchart for illustrating the method of the security authentication provided by the embodiment of the present disclosure is shown in FIG. 4. Figure 4 As shown in FIG. 4, the method can further include the following steps.
[0072] In step S104, a third request message for verifying the dynamic password sent by the terminal is received.
[0073] The third request message includes the first dynamic password. For example, the first dynamic password included in the third request message can be a first dynamic password input by the user for security authentication.
[0074] In step S105, an IP address of a webpage corresponding to the third request message is acquired, and a second geographic location of the terminal is acquired according to the IP address.
[0075] In some embodiments, the second geographic location of the terminal can be acquired according to a preset correspondence between IP address segments and geographic locations.
[0076] For example, the server can store a preset correspondence between IP address segments and geographic locations, and the geographic location corresponding to the address segment in which the IP address of the webpage corresponding to the third request message is located can be acquired as the second geographic location from the correspondence according to the IP address of the webpage corresponding to the third request message.
[0077] In step S106, a second dynamic password is generated based on the second geographic location.
[0078] In some embodiments, the third request message can also include a third terminal identifier. In some possible implementation manners, the third terminal identifier can be an MDN input by the user when performing identity authentication. The second dynamic password can be generated based on the second geographic location, the third terminal identifier, and a second timestamp when the second dynamic password is generated.
[0079] In some possible implementation manners, the second dynamic password can be generated based on Formula Two as follows according to the second geographic location, the third terminal identifier of the terminal, and the second timestamp when the second dynamic password is generated.
[0080] Formula Two
[0081] wherein P3 is the third terminal identifier, to acquire a sum value of bit-by-bit summation, T2 is the second timestamp when the second dynamic password is generated, L2 is a hash value of the second geographic location with a preset number of bits, K, N1, and N2 are preset constant values, is a modulo operator. In some possible implementation manners, N1 and N2 can be 10000 and 1000000 respectively.
[0082] It can be understood that the parameters in Formula One and Formula Two need to be consistent, including K, N1, N2 (N1 and N2 can be 10000 and 1000000 respectively), and the preset number of bits of the hash value (for example, the preset number of bits can be 32 bits), and the granularity of the first timestamp and the second timestamp also need to be consistent.
[0083] In step S107, a verification result of the dynamic password is determined according to a matching result of the first dynamic password and the second dynamic password.
[0084] In some embodiments, in a case where the first dynamic password and the second dynamic password are the same, the verification result of the dynamic password can be determined as passed. In a case where the first dynamic password and the second dynamic password are not the same, the verification result of the dynamic password can be determined as failed.
[0085] For example, taking an electronic signature as an example, in a case where the verification result of the dynamic password is passed, the verification result can be associated to a to-be-signed file, so as to complete the electronic signature of the to-be-signed file.
[0086] It can be understood that even if the user inputs a correct first dynamic password, in a case where the first geographic location and the second geographic location are different, and / or the first timestamp and the second timestamp are different, the first dynamic password and the second dynamic password are still not matched. Therefore, when identity authentication is performed, the authentication time and the authentication location information are further verified, and the non-repudiation and reliability of the identity authentication are improved.
[0087] Figure 5 Another flowchart of a method of security authentication provided by an embodiment of the present disclosure is shown in FIG. 6. As shown in FIG. 6, the method can further include the following steps. Figure 5
[0088] In step S108, scene indication information is sent to the terminal.
[0089] The scene indication information is used to indicate a transformation rule for transforming the first dynamic password when the dynamic password verification is performed.
[0090] In a specific implementation, the scene indication information can be sent to the terminal through a separate message, or the scene indication information can be sent to the terminal through the first response message. The scene indication information can include one transformation rule, or can include multiple transformation rules. The multiple transformation rules can be a correspondence between a preset time period and a transformation rule, for example, the multiple transformation rules can be: time period 1: transformation rule 1, time period 2: transformation rule 2, …, time period n: transformation rule n. The multiple transformation rules can also be a correspondence between a preset condition and a transformation rule, for example, the transformation rule can be: condition 1: transformation rule 1, condition 2: transformation rule 2, …, condition n: transformation rule n.
[0091] In some embodiments, the transformation rule includes a base transformation rule, a digit order transformation rule, or a digit transformation rule.
[0092] The base conversion rule is to convert the first dynamic password into a base. For example, the first dynamic password is 987642 in base 10, and the scenario indication information can be "input the first dynamic password in base x" (x can be 8, 10, 16, or 32, for example). At this time, the conversion rule is to convert the first dynamic password into the corresponding base. For example, (3610772)8, (987642)10, (F11FA)16, (U4FQ)32. In order to avoid the cumbersome operation of the user, in some embodiments, the server can also send the first dynamic password in different bases to the terminal through the first response message when sending the first response message including the first dynamic password, so as to facilitate the user to select and input.
[0093] The digit sequence conversion rule is to convert the sequence of the digits of the first dynamic password. For example, the first dynamic password is 987426 in base 10, and the digit sequence conversion rule can be, for example, digit reverse order, that is, the sequence of the digits of the first dynamic password is converted in reverse order, and the converted first dynamic password is 624789. The digit sequence conversion rule can also be to sort the digits of the first dynamic password according to the digit values. For example, the first dynamic password is 987426 in base 10, and the digit sequence conversion rule can be, for example, digit value descending order, that is, the digits of the first dynamic password are arranged in descending order according to the digit values, and the converted first dynamic password is 987642.
[0094] The digit conversion rule is to convert the value of at least one digit of the first dynamic password. For example, the digit conversion rule is "add 1 to the fourth digit, and if the value of the fourth digit is 9, convert it to 0", and the first dynamic password is 987426 in base 10. The converted first dynamic password is 988426.
[0095] In step S109, a fourth request message for verifying the dynamic password sent by the terminal is received.
[0096] The fourth request message includes the third dynamic password.
[0097] For example, the third dynamic password included in the third request message can be a password obtained by the user converting the first dynamic password according to the conversion rule in the scenario indication information and inputting, or a password selected by the user from the first dynamic password in different bases according to the conversion rule in the scenario indication information and inputting.
[0098] In step S110, the IP address of the web page corresponding to the fourth request message is obtained, and the third geographic location of the terminal is obtained according to the IP address.
[0099] This step is similar to step S106, which will not be described in detail here.
[0100] In step S111, a fourth dynamic password is generated based on the third geographic location, and a fifth dynamic password is generated by transforming the fourth dynamic password according to a transformation rule.
[0101] In some embodiments, the fourth dynamic password can be generated based on the third geographic location, a fourth terminal identifier, and a third timestamp when the fourth dynamic password is generated. The specific steps are similar to those in step S107, which will not be described here. After the fourth dynamic password is generated, the fourth dynamic password can be transformed according to the transformation rule to obtain the fifth dynamic password, so as to be matched with the third dynamic password.
[0102] In step S112, the verification result of the dynamic password is determined according to the matching of the third dynamic password and the fifth dynamic password.
[0103] In some embodiments, in the case that the third dynamic password and the fifth dynamic password are the same, the verification result of the dynamic password can be determined as passed. In the case that the third dynamic password and the fifth dynamic password are not the same, the verification result of the dynamic password can be determined as failed.
[0104] By using the above technical solution, the generated dynamic password can be flexibly transformed by sending scene indication information, and the identity authentication can be further improved in flexibility based on the transformed dynamic password.
[0105] Figure 6 A block diagram of a device for security authentication is shown, as shown in Figure 6 The device for security authentication 200 includes:
[0106] The receiving module 210 is configured to receive a first request message for obtaining a dynamic password sent by a terminal, and the first request message includes a first terminal identifier of the terminal.
[0107] The obtaining module 220 is configured to obtain a first geographic location of the terminal according to the first terminal identifier.
[0108] The authentication module 230 is configured to generate a first dynamic password based on the first geographic location, and send a first response message including the first dynamic password to the terminal.
[0109] Optionally, the authentication module 230 is further configured to generate the first dynamic password based on the first geographic location, a second terminal identifier of the terminal, and a first timestamp when the first dynamic password is generated.
[0110] Optionally, the authentication module 230 is further configured to generate a first key according to a first encryption algorithm, and the first key includes a first public key and a first private key.
[0111] send a second request message for acquiring a second terminal identifier of a user input to the terminal, the second request message comprising the first public key;
[0112] receive a second response message sent by the terminal, the second response message comprising the second terminal identifier encrypted by the first public key and a second public key, the second public key being a public key in a second key generated by the terminal based on a second encryption algorithm;
[0113] decrypt the encrypted second terminal identifier by the first private key to acquire the second terminal identifier;
[0114] in a case where the second terminal identifier matches the first terminal identifier, generate the first dynamic password based on the first geographic location, the second terminal identifier of the terminal and a first timestamp when the first dynamic password is generated, and send a first response message comprising the first dynamic password encrypted by the second public key to the terminal; or
[0115] in a case where the second terminal identifier does not match the first terminal identifier, send a third response message for indicating failure to the terminal.
[0116] Optionally, the receiving module 210 is further configured to receive a third request message for verifying the dynamic password sent by the terminal, the third request message comprising the first dynamic password;
[0117] The obtaining module 220 is further configured to obtain an IP address of a web page corresponding to the third request message, and obtain a second geographic location of the terminal according to the IP address.
[0118] The authentication module 230 is further configured to generate a second dynamic password based on the second geographic location, and determine a verification result of the dynamic password according to a matching relationship between the first dynamic password and the second dynamic password.
[0119] Optionally, the obtaining module 220 is further configured to obtain the second geographic location of the terminal according to a preset corresponding relationship between an IP address segment and a geographic location.
[0120] Optionally, the authentication module 230 is further configured to generate the second dynamic password based on the second geographic location, a third terminal identifier and a second timestamp when the second dynamic password is generated.
[0121] Optionally, the authentication module 230 is further configured to send scene indication information to the terminal, the scene indication information being used to indicate a transformation rule for transforming the first dynamic password when the dynamic password is verified.
[0122] Optionally, the receiving module 210 is further configured to obtain a fourth request message for verifying the dynamic password sent by the terminal, the fourth request message comprising a third dynamic password;
[0123] The acquisition module 220 is further configured to acquire an IP address of the web page corresponding to the fourth request message, and acquire a third geographic location of the terminal according to the IP address.
[0124] The authentication module 230 is further configured to generate a fourth dynamic password based on the third geographic location, and transform the fourth dynamic password according to a transformation rule to obtain a fifth dynamic password.
[0125] The authentication result of the dynamic password is determined according to a matching result of the third dynamic password and the fifth dynamic password.
[0126] Optionally, the authentication module 230 is further configured to generate the fourth dynamic password based on the third geographic location, the fourth terminal identifier, and a third timestamp when the fourth dynamic password is generated.
[0127] The apparatus 200 provided in the embodiments of the present application can perform the methods in the foregoing method embodiments, and achieve the functions and advantages of the methods in the foregoing method embodiments, which will not be described herein again.
[0128] Figure 7 A hardware structure schematic diagram of an electronic device for implementing the embodiments of the present disclosure is shown as follows, Figure 7 At the hardware level, the electronic device includes at least one processor, and optionally includes an internal bus, a network interface, and a memory. The memory can include an internal memory such as a random access memory (RAM), and can also include a non-volatile memory such as at least one disk memory. Of course, the electronic device can also include other hardware required by the business.
[0129] The processor, the network interface, and the memory can be connected to each other through the internal bus. The internal bus can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, and a control bus. For the convenience of representation, only one bidirectional arrow is used in the figure, but it does not mean that there is only one bus or only one type of bus.
[0130] The memory stores programs. Specifically, the programs can include program codes including at least one computer operation instruction. The memory can include an internal memory and a non-volatile memory, and provide instructions and data to the processor.
[0131] The at least one processor reads the corresponding computer program from the nonvolatile memory into the memory and then runs, and forms the device for locating the target user at a logical level. The at least one processor executes the program stored in the memory, and specifically executes the method disclosed in the embodiment of the first aspect and realizes the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.
[0132] The method disclosed in the embodiment of the first aspect of the present disclosure can be applied to at least one processor or implemented by at least one processor. The processor can be an integrated circuit chip with a processing capability of signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the at least one processor. The processor mentioned above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. Each method, step and logic block disclosed in the embodiments of the present disclosure can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present disclosure can be directly embodied as a hardware coding processor for execution, or a combination of hardware and software modules in the coding processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium in the art. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method.
[0133] The electronic device can also execute the methods described in the foregoing method embodiments, and realize the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.
[0134] Of course, in addition to the software implementation, the electronic device of the present disclosure does not exclude other implementation manners, such as logic devices or a combination of software and hardware, etc. That is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or a logic device.
[0135] The embodiment of the present disclosure further provides a computer readable storage medium, which stores one or more programs. The one or more programs, when executed by at least one processor, implement the method disclosed in the embodiment of the first aspect and achieve the functions and advantages of the methods described in the foregoing method embodiments, which will not be repeated here.
[0136] The computer readable storage medium includes a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disc or an optical disc, etc.
[0137] Further, the embodiment of the present disclosure further provides a computer program product, which includes a computer program stored on a non-transitory computer readable storage medium. The computer program includes program instructions, which, when executed by a computer, cause the computer to perform the method disclosed in the embodiment of the first aspect and achieve the functions and advantages of the methods described in the foregoing method embodiments, which will not be repeated here.
[0138] The embodiment of the present application provides a computer program product, which includes a computer program. The computer program, when executed by a processor, implements each process of the method disclosed in the embodiment of the first aspect and achieves the same technical effects. To avoid repetition, details will not be repeated here.
[0139] In summary, the above only describes the preferred embodiments of the present disclosure, and does not limit the protection scope of the present disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.
[0140] The system, module or unit illustrated in the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer. Specifically, the computer may, for example, be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0141] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can store information accessible by a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0142] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed, or inherent to such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0143] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.
Claims
1. A method for security authentication, characterized in that, The method includes: The receiving terminal sends a first request message for obtaining a dynamic password, the first request message including a first terminal identifier of the terminal; The first geographical location of the terminal is obtained based on the first terminal identifier; If the second terminal identifier and the first terminal identifier of the terminal match, the first dynamic password is generated based on the first geographical location, the second terminal identifier and the first timestamp when the first dynamic password was generated, and a first response message including the first dynamic password is sent to the terminal. The second terminal identifier is the terminal identifier entered by the user during the generation of the first dynamic password.
2. The method according to claim 1, characterized in that, The method further includes: A first key is generated according to a first encryption algorithm, the first key including a first public key and a first private key; Send a second request message to the terminal for obtaining a second terminal identifier input by the user, the second request message including the first public key; The receiving terminal sends a second response message, the second response message including a second terminal identifier and a second public key encrypted with the first public key, the second public key being the public key in a second key generated by the terminal based on a second encryption algorithm; The encrypted second terminal identifier is decrypted using the first private key to obtain the second terminal identifier; Sending a first response message including the first dynamic password to the terminal includes: The first response message, which includes the first dynamic password encrypted with the second public key, is sent to the terminal.
3. The method according to claim 2, characterized in that, The method further includes: If the second terminal identifier and the first terminal identifier do not match, a third response message indicating failure is sent to the terminal.
4. The method according to claim 1, characterized in that, The first formula for generating the first dynamic password is: ; Wherein, P is the identifier of the second terminal. To obtain the sum of bits, T1 is the first timestamp when the first dynamic password was generated, L1 is the hash value of the first address location with a preset number of bits, and K, N1, and N2 are preset constant values. This is the modulo operator.
5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The receiving terminal sends a third request message for verifying the dynamic password, the third request message including the first dynamic password; Obtain the IP address of the webpage corresponding to the third request message, and obtain the second geographical location of the terminal based on the IP address; A second dynamic password is generated based on the second geographical location; The verification result of the dynamic password is determined based on the matching of the first dynamic password and the second dynamic password.
6. The method according to claim 5, characterized in that, The step of obtaining the second geographical location of the terminal based on the IP address includes: The second geographical location of the terminal is obtained based on the preset correspondence between IP address ranges and geographical locations.
7. The method according to claim 5, characterized in that, The third request message also includes a third terminal identifier, and the generation of the second dynamic password based on the second geographical location includes: The second dynamic password is generated based on the second geographical location, the third terminal identifier, and the second timestamp when the second dynamic password was generated.
8. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Send scenario indication information to the terminal, the scenario indication information being used to indicate the transformation rules for transforming the first dynamic password during dynamic password verification; The receiving terminal sends a fourth request message for verifying the dynamic password, the fourth request message including the third dynamic password; Obtain the IP address of the webpage corresponding to the fourth request message, and obtain the third geographical location of the terminal based on the IP address; A fourth dynamic password is generated based on the third geographical location, and the fourth dynamic password is transformed according to the transformation rules to obtain a fifth dynamic password; The verification result of the dynamic password is determined based on the matching of the third dynamic password and the fifth dynamic password.
9. The method according to claim 8, characterized in that, The fourth request message also includes a fourth terminal identifier, and the generation of the fourth dynamic password based on the third geographical location includes: The fourth dynamic password is generated based on the third geographical location, the fourth terminal identifier, and the third timestamp when the fourth dynamic password was generated.
10. The method according to claim 8, characterized in that, The transformation rules include number system transformation rules, digit order transformation rules, or digit transformation rules.
11. A security authentication device, characterized in that, The device includes: The receiving module is configured to receive a first request message sent by the terminal for obtaining a dynamic password, wherein the first request message includes a first terminal identifier of the terminal. The acquisition module is used to acquire the first geographical location of the terminal based on the first terminal identifier; The authentication module is used to generate the first dynamic password based on the first geographical location, the second terminal identifier, and the first timestamp when the first dynamic password is generated, when the second terminal identifier of the terminal matches the first terminal identifier, and then send a first response message including the first dynamic password to the terminal. The second terminal identifier is the terminal identifier entered by the user during the generation of the first dynamic password.
12. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the method of secure authentication as described in any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of security authentication as described in any one of claims 1 to 10.
14. A computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform a method of security authentication as described in any one of claims 1 to 10.
Citation Information
Patent Citations
Method, device and system for dynamic password authentication
CN103368918A
Identity authentication method and system
CN112152976A