A software login method and device
By authenticating users' identities using digital certificates from portable authentication devices, terminal devices can log in to the software when the signal strength meets a threshold, thus solving the problem of user account and password leakage and improving both security and convenience.
Patent Information
- Application Number
- CN202411255622.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-09-09
AI Technical Summary
The security and liability risks caused by the leakage of user accounts and passwords are difficult to effectively address during the software login process on computer devices.
A digital certificate mechanism is used to authenticate the portable authentication device. The terminal device will only log in to the preset software using the user login information when it detects that the signal strength of the portable authentication device is greater than or equal to the first preset strength threshold.
This avoids security and liability risks caused by the leakage of user accounts and passwords, and improves the security and convenience of software login.
Smart Images

Figure CN119603684B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a software login method and apparatus. Background Technology
[0002] In recent years, computer devices such as laptops, desktop computers, tablets, servers, and mobile phones have become increasingly common in people's daily lives and work. People use these computer devices for work, entertainment, shopping, surfing the internet, and other activities. It can be said that computer devices have become one of the essential tools in modern society.
[0003] With the widespread use of various computer devices, computer security issues have become increasingly prominent, including hardware security, software security, and network security. One of the more significant security problems is the leakage of user accounts and passwords. Typically, to enhance computer security, operating systems, application software, and other software require user accounts and passwords for login and authentication. After successful login, users can access various functions of the software.
[0004] However, in real life, security and liability risks often arise due to the leakage of user accounts and passwords, and the inventor has conducted research on this issue. Summary of the Invention
[0005] The embodiments of the present invention are intended to at least partially solve one of the technical problems in the related art.
[0006] To address this, this invention discloses a software login method and apparatus. The method employs a digital certificate mechanism to authenticate the portable authentication device. Furthermore, the terminal device only logs into the preset software using the user login information when it determines that the signal strength of the keep-connect signal sent by the portable authentication device is greater than or equal to a first preset strength threshold. This avoids security and liability risks caused by the leakage of user accounts and passwords.
[0007] In a first aspect, embodiments of the present invention provide a software login method applied to a communication system, the communication system including a terminal device and a portable authentication device, the terminal device and the portable authentication device being connected via short-range wireless communication, the terminal device pre-storing a target device identifier of the portable authentication device; the method includes:
[0008] The terminal device periodically detects short-range wireless communication signals;
[0009] After detecting a short-range wireless communication signal carrying a pre-stored target device identifier, the terminal device establishes a short-range wireless communication connection with the portable authentication device.
[0010] The terminal device receives the authorized login information sent by the portable authentication device and verifies the authorized login information using the public key in the digital certificate of the portable authentication device that is stored in advance; wherein, the authorized login information is obtained by the portable authentication device signing the user login information;
[0011] The terminal device determines whether the signal strength of the keep-connect signal received by the portable authentication device is greater than or equal to a first preset strength threshold.
[0012] When the signal strength of the connection-keeping signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, the terminal device inputs the user login information into the login port of the preset software in the terminal device to log in to the preset software.
[0013] Optionally, in some embodiments of the first aspect of the present invention, the user login information is pre-stored in the portable authentication device, and the method further includes:
[0014] When the signal strength of the connection-keeping signal is greater than or equal to the first preset strength threshold, the terminal device sends a login information acquisition request to the portable authentication device;
[0015] After receiving the login information acquisition request, the portable authentication device signs the user login information to obtain the authorized login information;
[0016] The portable authentication device sends the authorized login information to the terminal device.
[0017] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0018] The terminal device sends the user login information entered by the user to the portable authentication device;
[0019] The portable authentication device signs the user login information to obtain the authorized login information;
[0020] The portable authentication device sends the authorized login information to the terminal device.
[0021] Optionally, in some embodiments of the first aspect of the present invention, after the terminal device detects a short-range wireless communication signal carrying a pre-stored target device identifier, it establishes a short-range wireless communication connection with the portable authentication device, including:
[0022] When the terminal device detects a short-range wireless communication signal carrying a pre-stored target device identifier and the signal strength of the short-range wireless communication signal is greater than or equal to a second preset strength threshold, it establishes a short-range wireless communication connection with the portable authentication device.
[0023] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0024] The portable authentication device authenticates the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through a biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device;
[0025] Once the user's identity has been authenticated, the portable authentication device sends the authorized login information to the terminal device.
[0026] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0027] The portable authentication device authenticates the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through a biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device;
[0028] Once the user's identity has been authenticated, the portable authentication device sends a short-range wireless communication signal carrying the identifier of the target device.
[0029] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0030] Upon receiving the user's first operation, the portable authentication device enters passive mode;
[0031] In the passive mode, when the portable authentication device receives the user's second operation, it sends the authorized login information to the terminal device.
[0032] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0033] When the signal strength is less than the first preset strength threshold, the terminal device logs out of the preset software.
[0034] Optionally, in some embodiments of the first aspect of the present invention, when the signal strength is less than the first preset strength threshold, the terminal device exits the login of the preset software, including:
[0035] When the duration during which the signal strength is less than the first preset strength threshold exceeds the first preset duration, and the signal strength is greater than or equal to the third preset strength threshold, the terminal device logs out of the preset software.
[0036] When the signal strength is less than the third preset strength threshold, the terminal device logs out of the preset software.
[0037] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0038] The portable authentication device acquires its own location information;
[0039] The portable authentication device determines whether it is within a preset geographical range based on the location information;
[0040] When the portable authentication device is within a preset geographical range, the portable authentication device sends the authorized login information.
[0041] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0042] When the portable authentication device is not within the preset geographical range and receives a third operation from the user, the portable authentication device sends an emergency instruction message to the terminal device.
[0043] When the terminal device receives the emergency instruction information, it controls the preset software to enter emergency mode;
[0044] In the emergency mode, the terminal device sends a temporary login request to the backend management server via the Internet.
[0045] The terminal device receives temporary login information from the backend management server based on the temporary login request, and uses the temporary login information to log in to the preset software within a second preset time period.
[0046] Optionally, in some embodiments of the first aspect of the present invention, the method further includes:
[0047] Determine whether the user login information is in the login information list;
[0048] If the user login information is in the login information list, the terminal device will input the user login information into the login port of the preset software in the terminal device to log in to the preset software.
[0049] In a second aspect, embodiments of the present invention also provide a software login device applied to a communication system, the communication system including a terminal device and a portable authentication device, the terminal device and the portable authentication device being connected via short-range wireless communication, the terminal device pre-storing a target device identifier of the portable authentication device; the device includes: a detection module, an establishment module, a receiving module, a first judgment module, and a login module located in the terminal device; and a second sending module and a third sending module located in the portable authentication device;
[0050] The detection module is used to periodically detect short-range wireless communication signals;
[0051] The first transmitting module is used to transmit a short-range wireless communication signal carrying a target device identifier;
[0052] The establishment module is used to establish a short-range wireless communication connection with the portable authentication device after detecting a short-range wireless communication signal carrying a pre-stored target device identifier.
[0053] The second sending module is used to send the authorized login information to the terminal device;
[0054] The receiving module is used to receive the authorized login information sent by the portable authentication device, and to verify the authorized login information using the public key in the digital certificate of the portable authentication device that is stored in advance; wherein, the authorized login information is obtained by the portable authentication device signing the user login information;
[0055] The third sending module is used to send a keep-connection signal to the terminal device;
[0056] The first determination module is used to determine whether the signal strength of the keep-connect signal received by the portable authentication device is greater than or equal to a first preset strength threshold.
[0057] The login module is used to input the user login information into the login port of the preset software in the terminal device when the signal strength of the connection signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, so as to log in to the preset software.
[0058] Optionally, in some embodiments of the second aspect of the present invention, the user login information is pre-stored in the portable authentication device, and the device further includes: a fourth sending module located in the terminal device; and a first signature module located in the portable authentication device;
[0059] The fourth sending module is used to send a login information acquisition request to the portable authentication device when the signal strength of the keep-connect signal is greater than or equal to the first preset strength threshold.
[0060] The first signature module is used to sign the user login information after receiving the login information acquisition request to obtain the authorized login information.
[0061] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: a fifth transmitting module located in the terminal device; and a second signature module located in the portable authentication device;
[0062] The fifth sending module is used to send the user login information entered by the user to the portable authentication device;
[0063] The second signature module is used to sign the user login information to obtain the authorized login information.
[0064] Optionally, in some embodiments of the second aspect of the present invention, the establishing module is specifically used for:
[0065] When a short-range wireless communication signal carrying a pre-stored target device identifier is detected and the signal strength of the short-range wireless communication signal is greater than or equal to a second preset strength threshold, a short-range wireless communication connection is established with the portable authentication device.
[0066] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: a first identity authentication module located in the portable authentication device;
[0067] The first identity authentication module is used to authenticate the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through a biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device;
[0068] The second sending module is used to send the authorized login information to the terminal device after the user's identity authentication has been completed.
[0069] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: a second identity authentication module located in the portable authentication device;
[0070] The second identity authentication module is used to authenticate the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through a biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device;
[0071] The first transmitting module is used to transmit a short-range wireless communication signal carrying the identifier of the target device after user authentication has been completed.
[0072] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: a mode switching module;
[0073] The mode switching module is used to enter passive mode after receiving the user's first operation;
[0074] The second sending module is used to send the authorized login information to the terminal device when it receives the user's second operation in the passive mode.
[0075] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: an exit module located in the terminal device;
[0076] The exit module is used to exit the login of the preset software when the signal strength is less than the first preset strength threshold.
[0077] Optionally, in some embodiments of the second aspect of the present invention, the exit module is specifically used for:
[0078] When the duration during which the signal strength is less than the first preset strength threshold exceeds the first preset duration, and the signal strength is greater than or equal to the third preset strength threshold, log out of the preset software.
[0079] When the signal strength is less than the third preset strength threshold, log out of the preset software.
[0080] Optionally, in some embodiments of the second aspect of the present invention, the device further includes: a positioning module and a second judgment module located in the portable authentication device;
[0081] The positioning module acquires the positioning information of the portable authentication device;
[0082] The second judgment module is used to determine whether the portable authentication device is within a preset geographical range based on the location information;
[0083] The second sending module is used to send the authorized login information to the terminal device when the portable authentication device is within a preset geographical range.
[0084] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: a sixth transmitting module located in the portable authentication device; a control module and a seventh transmitting module located in the terminal device;
[0085] The sixth sending module is used to send emergency instruction information to the terminal device when the portable authentication device is not within the preset geographical range and receives a third operation from the user;
[0086] The control module is used to control the preset software to enter emergency mode when it receives the emergency instruction information;
[0087] The seventh sending module is used to send a temporary login request to the backend management server via the Internet in the emergency mode;
[0088] The receiving module is used to receive temporary login information fed back by the backend management server based on the temporary login request;
[0089] The login module is used to log in to the preset software within a second preset time period using the temporary login information.
[0090] Optionally, in some embodiments of the second aspect of the present invention, the apparatus further includes: a third determination module located in the terminal device;
[0091] The third judgment module is used to determine whether the user login information is in the login information list;
[0092] The login module is used to input the user login information into the login port of the preset software in the terminal device when the user login information is in the login information list, so as to log in to the preset software.
[0093] Beneficial effects of the embodiments of the present invention:
[0094] This invention provides a software login method and apparatus applied to a communication system. The communication system includes a terminal device and a portable authentication device, which are connected via short-range wireless communication. The terminal device pre-stores a target device identifier of the portable authentication device. The method includes: the terminal device periodically detecting short-range wireless communication signals; after detecting a short-range wireless communication signal carrying the pre-stored target device identifier, the terminal device establishes a short-range wireless communication connection with the portable authentication device; the terminal device receives authorized login information sent by the portable authentication device and verifies the authorized login information using the public key in the digital certificate of the pre-stored portable authentication device; the terminal device determines whether the signal strength of a keep-alive signal sent by the portable authentication device is greater than or equal to a first preset strength threshold; when the signal strength of the keep-alive signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, the terminal device inputs the user login information into the login port of a preset software in the terminal device to log in to the preset software. The technical solution of this invention uses a digital certificate mechanism to authenticate the portable authentication device, and the terminal device only logs in to the preset software using the user login information when it determines that the signal strength of the keep-alive signal sent by the portable authentication device is greater than or equal to the first preset strength threshold. As can be seen, the technical solution of this invention, without the participation of a portable authentication device, cannot directly log in to the preset software based on the user's login information, thus avoiding security and liability risks caused by the leakage of user accounts and passwords. Attached Figure Description
[0095] Figure 1 This is a flowchart illustrating a software login method provided in an embodiment of the present invention.
[0096] Figure 2 This is a schematic diagram of a software login device provided in an embodiment of the present invention. Detailed Implementation
[0097] To better understand the above-mentioned objectives, features, and advantages of the present invention, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the technical concept of the embodiments of the present invention are within the scope of protection of the present invention.
[0098] As mentioned in the background section, existing technologies that use user accounts and passwords to log in to operating systems, application software, etc., often encounter security and liability risks due to the leakage of user accounts and passwords. Therefore, this invention provides a software login method and apparatus that uses a portable authentication device to assist in the login process to complete authorization authentication.
[0099] Furthermore, a more specific technical concept of this embodiment is as follows: a short-range wireless communication method is used to establish a communication connection between the terminal device and the portable authentication device. The terminal device then obtains user login information from the portable authentication device and uses a digital certificate mechanism to authenticate the portable authentication device. Based on this, when the signal strength of the hold signal sent by the portable authentication device is greater than or equal to a first preset strength threshold (i.e., when the portable authentication device is within a first preset distance range of the terminal device), the terminal device inputs the user login information into the login port of a preset software in the terminal device to log in to the preset software. The technical solution of this embodiment uses a digital certificate mechanism to authenticate the portable authentication device, and the terminal device only uses the user login information to log in to the preset software when it determines that the signal strength of the hold signal sent by the portable authentication device is greater than or equal to the first preset strength threshold. Therefore, the technical solution of this embodiment cannot directly log in to the preset software based on user login information without the participation of the portable authentication device, avoiding security and liability risks caused by the leakage of user accounts and passwords.
[0100] After explaining the technical concept of the embodiments of the present invention, the technical solutions of the embodiments of the present invention will be specifically described below with reference to the accompanying drawings. See also Figure 1 The diagram shown is a flowchart illustrating a software login method provided in an embodiment of the present invention.
[0101] See Figure 1 As shown, Figure 1 This invention provides a software login method according to an embodiment of the present invention. Figure 1 The software login method shown is applied to a communication system, which includes a terminal device and a portable authentication device. The terminal device and the portable authentication device can be connected via short-range wireless communication, and the terminal device pre-stores the target device identifier of the portable authentication device.
[0102] In practical applications, terminal devices can be computer devices with communication, storage, and computing capabilities, such as laptops, desktop computers, tablets, and mobile phones. Portable authentication devices are small, portable hardware devices that provide identity authentication and user login services, such as Bluetooth keys, USB tokens, smart cards, and dynamic tokens. In daily life, portable authentication devices can usually be carried by putting them in a pocket or a special storage bag, or by hand.
[0103] Portable authentication devices and terminal devices can establish short-range wireless communication connections using short-range wireless communication technologies such as Bluetooth and Starlink. The terminal device pre-stores the target device identifier of the portable authentication device, indicating that the portable authentication device is a paired device with the terminal device. It is understood that the pairing process can be implemented at the factory for both the terminal device and the portable authentication device, or pre-implemented by the administrators of both devices.
[0104] Furthermore. Figure 1 The software login method shown may include the following steps:
[0105] In step S101, the terminal device periodically detects short-range wireless communication signals.
[0106] Specifically, the terminal device periodically detects short-range wireless communication signals transmitted by other hardware devices using the same short-range wireless communication protocol, in accordance with the standard specifications of the protocol used between the terminal device and the portable authentication device. These short-range wireless communication signals include device identifiers. In practical applications, the device identifier can be a device name, a device PIN (Personal Identification Number), or other characters that identify the hardware device.
[0107] Generally, the short-range wireless communication signals transmitted by other hardware devices are also periodic. The detection cycle of the terminal device, as well as the cycle of short-range wireless communication signals transmitted by other hardware devices, are related to the specific short-range wireless communication protocol used. Obviously, these other hardware devices include portable authentication devices.
[0108] In step S102, after detecting a short-range wireless communication signal carrying a pre-stored target device identifier, the terminal device establishes a short-range wireless communication connection with the portable authentication device.
[0109] Specifically, when a terminal device detects a short-range wireless communication signal carrying a pre-stored target device identifier, it indicates that the portable authentication device has entered the terminal device's effective connection range and is ready to connect. The terminal device then establishes a short-range wireless communication connection with the portable authentication device. The process of establishing this connection is determined by the short-range wireless communication protocol used between the terminal device and the portable authentication device. For example, if the terminal device and the portable authentication device use the Bluetooth communication protocol, the short-range wireless communication connection is established according to the pairing process specified in the Bluetooth protocol.
[0110] In step S103, the terminal device receives the authorized login information sent by the portable authentication device and verifies the authorized login information using the public key in the digital certificate of the pre-stored portable authentication device.
[0111] The authorized login information is obtained by the portable authentication device signing the user's login information. Generally, the user login information includes the user's username and password. On the portable authentication device side, the device uses its private key to sign the user's login information to obtain the authorized login information.
[0112] In practical applications, the terminal device can communicate with the Certificate Authority (CA) that issues the digital certificate for the portable authentication device to obtain the portable authentication device's digital certificate. It can also import the portable authentication device's digital certificate through its physical interface, or obtain the portable authentication device's digital certificate when establishing a short-range wireless communication connection for the first time. After receiving the authorized login information sent by the portable authentication device, the terminal device verifies the signature of the authorized login information using the public key in the digital certificate.
[0113] In step S104, the terminal device determines whether the signal strength of the keep-connect signal received from the portable authentication device is greater than or equal to a first preset strength threshold.
[0114] Specifically, after the terminal device and the portable authentication device establish a short-range wireless communication connection, the portable authentication device periodically sends a keep-alive signal to the terminal device to ensure a stable connection. The keep-alive signal serves to ensure a stable connection between the terminal device and the portable authentication device; in practice, it could be a heartbeat signal, etc.
[0115] In this step, when the terminal device receives the keep-alive signal from the portable authentication device, it can calculate the signal strength of the keep-alive signal and then determine whether the signal strength is greater than or equal to a first preset strength threshold. In practical applications, the signal strength of the keep-alive signal sent by the portable authentication device is consistent, and the signal strength of the keep-alive signal received by the terminal device reflects the distance between the terminal device and the portable authentication device. Therefore, the terminal device's determination of whether the received signal strength of the keep-alive signal sent by the portable authentication device is greater than or equal to the first preset strength threshold is actually determining whether the distance between the portable authentication device and the terminal device is within a first set distance. It should be noted that the selection criteria for the first set distance should consider both the security and convenience of the preset software login. Generally, the first set distance should allow the user of the portable authentication device to see the surroundings of the terminal device, preventing unauthorized login of the preset software, while also ensuring that the user of the portable authentication device can immediately log in to the preset software upon arriving at the terminal device. For example, the first set distance can be 3m, 2m, etc., and the corresponding first preset strength threshold can be obtained through calibration or set empirically.
[0116] In step S105, when the signal strength of the connection signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, the terminal device inputs the user login information into the login port of the preset software in the terminal device to log in to the preset software.
[0117] Specifically, maintaining a connection signal strength greater than or equal to a first preset strength threshold indicates that the distance between the portable authentication device user and the terminal device is within a first preset distance. Passing the authorized login information verification indicates that the portable authentication device's identity is legitimate. Therefore, the terminal device is ready to log in to the preset software. The terminal device inputs the user login information into the login port of the preset software within the terminal device to log in.
[0118] In practical applications, the pre-installed software can be system software or application software that requires user login information, such as operating systems, databases, and application software. The login interface of the pre-installed software can be a visible login window (i.e., a login window that is visible to the user) or a hidden login window (i.e., a login window that is not visible to the user).
[0119] The software login method provided in this invention is applied to a communication system, which includes a terminal device and a portable authentication device. The terminal device and the portable authentication device can be connected via short-range wireless communication. The terminal device pre-stores a target device identifier of the portable authentication device. The method includes: the terminal device periodically detecting short-range wireless communication signals; after detecting a short-range wireless communication signal carrying a pre-stored target device identifier, the terminal device establishes a short-range wireless communication connection with the portable authentication device; the terminal device receives authorized login information sent by the portable authentication device and verifies the authorized login information using the public key in the digital certificate of the pre-stored portable authentication device; the terminal device determines whether the signal strength of the keep-alive signal sent by the portable authentication device is greater than or equal to a first preset strength threshold; when the signal strength of the keep-alive signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, the terminal device inputs the user login information into the login port of a preset software in the terminal device to log in to the preset software. The technical solution of this invention uses a digital certificate mechanism to authenticate the portable authentication device, and the terminal device only logs in to the preset software using the user login information when it determines that the signal strength of the keep-alive signal sent by the portable authentication device is greater than or equal to the first preset strength threshold. As can be seen, the technical solution of this invention, without the participation of a portable authentication device, cannot directly log in to the preset software based on the user's login information, thus avoiding security and liability risks caused by the leakage of user accounts and passwords.
[0120] Furthermore, in practical applications, user login information can come from various sources depending on the actual needs and the design of the solution. Examples are given below.
[0121] Optionally, in some embodiments of the present invention, user login information is pre-stored in the portable authentication device. Specifically, user login information can be entered through a terminal device and then synchronized to the portable authentication device via short-range wireless communication; alternatively, it can be entered directly before the portable authentication device leaves the factory; or it can be entered directly through the input interface on the portable authentication device. The embodiments of the present invention do not limit this.
[0122] Furthermore, the software login method of this embodiment may further include:
[0123] While maintaining the signal strength of the connection signal greater than or equal to the first preset strength threshold, the terminal device sends a login information acquisition request to the portable authentication device;
[0124] After receiving a login information retrieval request, the portable authentication device signs the user's login information to obtain authorized login information;
[0125] The portable authentication device sends the authorized login information to the terminal device.
[0126] In this embodiment, user login information is pre-stored in the portable authentication device, preventing leakage through other means and ensuring its security. Furthermore, the process of obtaining authorized login information is only triggered when the signal strength of the connection signal is greater than or equal to a first preset strength threshold. This prevents the portable authentication device from sending user login information to the terminal device when the user has no intention of logging into the preset software, even if the terminal device is merely within the terminal device's effective communication range. This further enhances the security of user login information and reduces the power consumption of the portable authentication device to some extent. Additionally, in this embodiment, the user no longer needs to input user login information, increasing the convenience of logging into the preset software.
[0127] Of course, in some other implementations, the portable authentication device may immediately send the authorization login information to the terminal device after the terminal device establishes a short-range wireless communication connection with the portable authentication device.
[0128] Optionally, in some embodiments of the present invention, the software login method of the present invention may further include:
[0129] The terminal device sends the user login information entered by the user to the portable authentication device;
[0130] The portable authentication device signs the user's login information to obtain authorized login information;
[0131] The portable authentication device sends the authorized login information to the terminal device.
[0132] Obviously, in this implementation, a visible login window needs to be provided for the pre-installed software.
[0133] In this implementation, users are required to enter correct user login information, and a portable authentication device is needed for auxiliary authentication, thus ensuring the security of user login information.
[0134] Furthermore, considering that the effective communication distance of Bluetooth and StarFlash reaches 10m or even longer, and that it is unnecessary for the terminal device to connect to the portable authentication device prematurely, which would increase the power consumption of the portable authentication device, therefore, in some embodiments of the present invention, step S102 may include:
[0135] When the terminal device detects a short-range wireless communication signal carrying a pre-stored target device identifier and the signal strength of the short-range wireless communication signal is greater than or equal to a second preset strength threshold, it establishes a short-range wireless communication connection with the portable authentication device.
[0136] The second preset strength threshold is lower than the first preset strength threshold, and the second preset distance corresponding to the second preset strength threshold is greater than the first preset distance. Generally, the second preset distance should take into account the walking speed of a person and the time required for the terminal device and the portable authentication device to establish a short-range wireless communication connection. Specifically, it should ensure that when the person carrying the portable authentication device is at a first preset distance from the terminal device, the terminal device and the portable authentication device have completed the establishment of a short-range wireless communication connection. For example, the second preset distance can be 6m, 5m, etc., and the corresponding second preset strength threshold can be obtained through calibration or set empirically.
[0137] In this embodiment, the terminal device establishes a short-range wireless communication connection with the portable authentication device only when the signal strength of the short-range wireless communication signal is greater than or equal to a second preset strength threshold. Compared to an embodiment where the terminal device immediately establishes a short-range wireless communication connection with the portable authentication device upon detecting a short-range wireless communication signal carrying a pre-stored target device identifier, this reduces the power consumption of the portable authentication device.
[0138] Furthermore, considering scenarios such as the loss of the portable authentication device, where a third party other than the legitimate user of the portable authentication device illegally logs into the preset software using the portable authentication device, in some embodiments of the present invention, the software login method of the present invention may further include:
[0139] Portable authentication devices authenticate users based on their biometric information.
[0140] Once the user's identity has been authenticated, the portable authentication device will send the authorized login information to the terminal device.
[0141] The user's biometric information can be fingerprints, facial recognition data, etc. The portable authentication device collects this information via a built-in biometric sensor, or it receives biometric information sent from a terminal device. In the latter case, the biometric sensor is located on the terminal device, and the terminal device synchronizes the collected biometric information to the portable authentication device.
[0142] In this implementation, the portable authentication device only sends authorization login information to the terminal device after successfully authenticating the user's identity based on their biometric information. This ensures that the user of the portable authentication device is the legitimate user and effectively prevents third parties from illegally logging into the pre-set software using the portable authentication device. Furthermore, this implementation allows users to flexibly choose whether to trigger the portable authentication device to send authorization login information based on their own needs, avoiding unnecessary logins when the user has no intention of logging in.
[0143] Optionally, in other embodiments of the present invention, the software login method of the present invention may further include:
[0144] Portable authentication devices authenticate users based on their biometric information.
[0145] Once the user's identity has been authenticated, the portable authentication device sends a short-range wireless communication signal carrying the target device's identifier.
[0146] In this implementation, the portable authentication device only sends a short-range wireless communication signal carrying the target device identifier to the terminal device after successfully authenticating the user based on their biometric information. This ensures that the user of the portable authentication device is the legitimate user and effectively prevents third parties from illegally logging into the pre-set software using the portable authentication device. Furthermore, this implementation allows users to flexibly choose whether to trigger the portable authentication device to send the short-range wireless communication signal according to their needs, avoiding unnecessary connections and logins when the user has no intention of logging in, and reducing the power consumption of the portable authentication device.
[0147] Furthermore, considering the convenience of automatic login when the portable authentication device is near the terminal device and the actual need in some scenarios (such as when a user is performing tasks near the terminal device that do not require the terminal device) where the user carries the portable authentication device near the terminal device but has no intention of logging in, in some embodiments of the present invention, the portable authentication device can be configured with an active mode and a passive mode. In the active mode, when the portable authentication device is near the terminal device such that the signal strength of the keep-connect signal received by the terminal device is greater than or equal to a first preset strength threshold, the portable authentication device has already sent authorization login information (for example, when the terminal device and the portable authentication device establish a short-range wireless communication connection, the authorization login information is sent) or immediately sends authorization login information to the terminal device. In the passive mode, the portable authentication device only sends authorization login information to the terminal device when the user performs a second operation on the portable authentication device. Specifically, the software login method of the present invention may further include:
[0148] After receiving the user's first action, the portable authentication device enters passive mode;
[0149] When the portable authentication device receives a second operation from the user in passive mode, it sends the authorized login information to the terminal device.
[0150] In practical use, the first operation can be the user interacting with the input interface on the portable authentication device, which allows the user to switch between active and passive modes. If the portable authentication device is equipped with a gravity sensor or gyroscope, the first operation can also be a specific spatial movement operation of the device; for example, the user's downward arm movement (the first operation) triggers entry into passive mode, while the user's upward arm movement triggers active mode. The second operation can be the user interacting with the input interface on the portable authentication device, which triggers the sending of authorization login information. If the portable authentication device is equipped with a gravity sensor or gyroscope, the second operation can also be a specific spatial movement operation of the device; for example, the user's upward arm movement triggers the sending of authorization login information to the terminal device. Clearly, the portable authentication device can enter active mode either by the user performing the first operation again, or by the user performing a fourth operation different from the first operation.
[0151] Furthermore, considering the need for users to log out of the preset software login when leaving the terminal device with a portable authentication device, in some embodiments of the present invention, the software login method of the present invention may further include:
[0152] When the signal strength is less than the first preset strength threshold, the terminal device logs out of the preset software.
[0153] Furthermore, considering scenarios where users briefly leave the terminal device (e.g., to get water or to briefly interact with colleagues near the device), and the device remains within the user's perception range, there is no need to log out of the preset software. To improve the user experience in these scenarios, in some embodiments of this invention, when the signal strength is less than a first preset strength threshold, the terminal device logs out of the preset software, which may include:
[0154] If the signal strength is less than the first preset strength threshold for a period of time exceeding the first preset duration, and the signal strength is greater than or equal to the third preset strength threshold, the terminal device will exit the preset software login.
[0155] When the signal strength is less than the third preset strength threshold, the terminal device logs out of the preset software.
[0156] The first preset duration can be an empirical value, such as 30 seconds or 2 minutes. The third preset strength threshold is used to distinguish whether the user's distance from the device can guarantee the security of the preset software. The third preset strength threshold can be obtained through calibration or set empirically. Furthermore, when a second preset strength threshold is set to determine whether the terminal device establishes a short-range wireless communication connection with the portable authentication device, the third preset strength threshold should be greater than or equal to the second preset strength threshold, and typically should be greater than the second preset strength threshold.
[0157] Furthermore, considering security and the management regulations of some organizations, login to the terminal device is limited to a preset distance range (e.g., within a company-approved office location). Therefore, in some embodiments of the present invention, the software login method may further include:
[0158] Portable authentication devices acquire their own location information;
[0159] The portable authentication device determines whether it is within a preset geographical range based on location information;
[0160] When the portable authentication device is within a preset geographical range, it sends the authorized login information to the terminal device.
[0161] Furthermore, considering the special circumstances requiring emergency login to terminal devices, this embodiment of the invention also provides an emergency solution when the portable authentication device is not within a preset geographical range. Specifically, in some embodiments of this invention, the software login method may further include:
[0162] When the portable authentication device is outside the preset geographical range and receives a third operation from the user, the portable authentication device sends an emergency instruction message to the terminal device.
[0163] When the terminal device receives an emergency instruction, it controls the preset software to enter emergency mode;
[0164] In emergency mode, the terminal device sends a temporary login request to the backend management server via the Internet;
[0165] The terminal device receives temporary login information from the backend management server based on the temporary login request, and uses the temporary login information to log in to the preset software within a second preset time period.
[0166] In practical use, the third operation can be the user operating the input interface configured on the portable authentication device to trigger the device to send emergency instruction information. The second preset duration can be an empirical value. For example, the second preset duration can be 10 minutes, 30 minutes, 1 hour, etc.
[0167] Furthermore, considering scenarios such as the loss of portable authentication devices leading to the cancellation of corresponding user login information, in some embodiments of the present invention, the software login method of the present invention may further include:
[0168] Determine if the user's login information is in the login information list;
[0169] If the user's login information is in the login information list, the terminal device will input the user's login information into the login port of the preset software in the terminal device to log in to the preset software.
[0170] The preset login information list includes valid user login information. It is obvious that if a user's login information is not in this list, login to the preset software will be disabled.
[0171] It should be noted that the foregoing method embodiments are only some embodiments of the software login method. Other embodiments may also exist within the technical concept of this invention. For example, whether to send authorization login information can be determined by combining user biometric information and location information. When the portable authentication device completes identity authentication using the user's biometric information, and the location information of the portable authentication device indicates that the portable authentication device is within a preset geographical range, the portable authentication device sends authorization login information to the terminal device. It is understood that combinations of other implementation methods also constitute implementation methods of this invention.
[0172] Corresponding to the aforementioned method embodiments, this invention also discloses a software login device applied to a communication system. The communication system includes a terminal device and a portable authentication device. The terminal device and the portable authentication device can be connected via short-range wireless communication. The terminal device pre-stores the target device identifier of the portable authentication device. See also... Figure 2 As shown, the software login device of this embodiment may include: a detection module 201, an establishment module 202, a receiving module 203, a first judgment module 204 and a login module 205 located in a terminal device; and a first sending module 206, a second sending module 207 and a third sending module 208 located in a portable authentication device.
[0173] The detection module 201 is used to periodically detect short-range wireless communication signals;
[0174] The first transmitting module 206 is used to transmit a short-range wireless communication signal carrying the identifier of the target device;
[0175] The establishment module 202 is used to establish a short-range wireless communication connection with the portable authentication device after detecting a short-range wireless communication signal carrying a pre-stored target device identifier;
[0176] The second sending module 207 is used to send authorized login information to the terminal device;
[0177] The receiving module 202 is used to receive the authorized login information sent by the portable authentication device, and to verify the authorized login information using the public key in the digital certificate of the portable authentication device that is stored in advance; wherein, the authorized login information is obtained by the portable authentication device signing the user login information;
[0178] The third transmitting module 208 is used to send a connection-keeping signal to the terminal device;
[0179] The first judgment module 204 is used to determine whether the signal strength of the received keep-connect signal sent by the portable authentication device is greater than or equal to a first preset strength threshold.
[0180] The login module 205 is used to input user login information into the login port of the preset software in the terminal device when the signal strength of the connection signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, so as to log in to the preset software.
[0181] The software login device provided in this embodiment of the invention uses a digital certificate mechanism to authenticate the portable authentication device. The terminal device only logs into the preset software using user login information when it determines that the signal strength of the keep-alive signal sent by the portable authentication device is greater than or equal to a first preset strength threshold. Therefore, the technical solution of this embodiment of the invention prevents direct login to the preset software based on user login information without the participation of a portable authentication device, thus avoiding security and liability risks caused by the leakage of user accounts and passwords.
[0182] Optionally, in some embodiments of the present invention, user login information is pre-stored in a portable authentication device. The software login device of the present invention further includes: a fourth sending module located in the terminal device; and a first signature module located in the portable authentication device.
[0183] The fourth sending module is used to send a login information acquisition request to the portable authentication device while maintaining the signal strength of the connection signal greater than or equal to the first preset strength threshold.
[0184] The first signature module is used to sign the user's login information after receiving a login information retrieval request, thereby obtaining authorized login information.
[0185] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a fifth sending module located in the terminal device; and a second signature module located in the portable authentication device;
[0186] The fifth sending module is used to send the user login information entered by the user to the portable authentication device;
[0187] The second signature module is used to sign the user's login information to obtain authorized login information.
[0188] Optionally, in some embodiments of the present invention, the establishment module 202 is specifically used for:
[0189] When a short-range wireless communication signal carrying a pre-stored target device identifier is detected and the signal strength of the short-range wireless communication signal is greater than or equal to a second preset strength threshold, a short-range wireless communication connection with the portable authentication device is established.
[0190] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a first identity authentication module located in the portable authentication device;
[0191] The first identity authentication module is used to authenticate the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through the biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device;
[0192] The second sending module 207 is used to send authorized login information to the terminal device after user authentication has been completed.
[0193] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a second identity authentication module located in the portable authentication device;
[0194] The second identity authentication module is used to authenticate the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through the biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device;
[0195] The first transmitting module 206 is used to transmit a short-range wireless communication signal carrying the target device identifier after user authentication has been completed.
[0196] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a mode switching module;
[0197] The mode switching module is used to enter passive mode after receiving the user's first operation;
[0198] The second sending module 207 is used to send authorized login information to the terminal device when it receives the user's second operation in passive mode.
[0199] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: an exit module located in a terminal device;
[0200] The exit module is used to exit the preset software login when the signal strength is less than the first preset strength threshold.
[0201] Optionally, in some embodiments of the present invention, the exit module is specifically used for:
[0202] If the signal strength is less than the first preset strength threshold for more than the first preset duration, and the signal strength is greater than or equal to the third preset strength threshold, log out of the preset software.
[0203] Log out of the preset software when the signal strength is less than the third preset strength threshold.
[0204] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a positioning module and a second judgment module located in the portable authentication device;
[0205] The positioning module acquires the location information of the portable authentication device;
[0206] The second judgment module is used to determine whether the portable authentication device is within a preset geographical range based on the location information;
[0207] The second sending module 207 is used to send authorized login information to the terminal device when the portable authentication device is within a preset geographical range.
[0208] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a sixth sending module located in the portable authentication device; a control module and a seventh sending module located in the terminal device;
[0209] The sixth sending module is used to send emergency instruction information to the terminal device when the portable authentication device is not within the preset geographical range and receives a third operation from the user;
[0210] The control module is used to control the preset software to enter emergency mode when it receives emergency instruction information;
[0211] The seventh sending module is used to send a temporary login request to the backend management server via the Internet in emergency mode;
[0212] The receiving module 203 is used to receive temporary login information from the backend management server based on the temporary login request;
[0213] The login module 205 is used to log in to the preset software within a second preset time period using temporary login information.
[0214] Optionally, in some embodiments of the present invention, the software login device of the present invention further includes: a third judgment module located in the terminal device;
[0215] The third judgment module is used to determine whether the user's login information is in the login information list;
[0216] The login module 205 is used to input the user login information into the login port of the preset software in the terminal device when the user login information is in the login information list, so as to log in to the preset software.
[0217] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments of the present invention.
[0218] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Where there is no conflict, the embodiments and features of the present invention can be combined with each other. Each embodiment focuses on describing the differences from other embodiments. In particular, the system and device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the description of the method embodiments.
[0219] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0220] The embodiments of the present invention described above do not constitute a limitation on the scope of protection of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A software login method, characterized in that, The method is applied to a communication system, which includes a terminal device and a portable authentication device, wherein the terminal device and the portable authentication device are connected via short-range wireless communication, and the terminal device pre-stores a target device identifier of the portable authentication device; the method includes: The terminal device periodically detects short-range wireless communication signals; After detecting a short-range wireless communication signal carrying a pre-stored target device identifier, the terminal device establishes a short-range wireless communication connection with the portable authentication device. The terminal device receives the authorized login information sent by the portable authentication device and verifies the authorized login information using the public key in the digital certificate of the portable authentication device that is stored in advance; wherein, the authorized login information is obtained by the portable authentication device signing the user login information; The terminal device determines whether the signal strength of the keep-connect signal received by the portable authentication device is greater than or equal to a first preset strength threshold. When the signal strength of the connection-keeping signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, the terminal device inputs the user login information into the login port of the preset software in the terminal device to log in to the preset software.
2. The method according to claim 1, characterized in that, The user login information is pre-stored in the portable authentication device, and the method further includes: When the signal strength of the connection-keeping signal is greater than or equal to the first preset strength threshold, the terminal device sends a login information acquisition request to the portable authentication device; After receiving the login information acquisition request, the portable authentication device signs the user login information to obtain the authorized login information; The portable authentication device sends the authorized login information to the terminal device; Alternatively, the method may further include: The terminal device sends the user login information entered by the user to the portable authentication device; The portable authentication device signs the user login information to obtain the authorized login information; The portable authentication device sends the authorized login information to the terminal device.
3. The method according to claim 1, characterized in that, After detecting a short-range wireless communication signal carrying a pre-stored target device identifier, the terminal device establishes a short-range wireless communication connection with the portable authentication device, including: When the terminal device detects a short-range wireless communication signal carrying a pre-stored target device identifier and the signal strength of the short-range wireless communication signal is greater than or equal to a second preset strength threshold, it establishes a short-range wireless communication connection with the portable authentication device.
4. The method according to claim 1, characterized in that, The method further includes: The portable authentication device authenticates the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through a biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device; Once the user's identity has been authenticated, the portable authentication device sends the authorized login information to the terminal device.
5. The method according to claim 1, characterized in that, The method further includes: The portable authentication device authenticates the user's identity based on the user's biometric information; wherein, the portable authentication device collects the user's biometric information through a biometric sensor configured on it, or the portable authentication device receives the user's biometric information sent by the terminal device; Once the user's identity has been authenticated, the portable authentication device sends a short-range wireless communication signal carrying the identifier of the target device.
6. The method according to claim 1, characterized in that, The method further includes: Upon receiving the user's first operation, the portable authentication device enters passive mode; When the portable authentication device receives the user's second operation in the passive mode, it sends the authorized login information to the terminal device.
7. The method according to claim 1, characterized in that, The method further includes: When the duration during which the signal strength is less than the first preset strength threshold exceeds the first preset duration, and the signal strength is greater than or equal to the third preset strength threshold, the terminal device logs out of the preset software. When the signal strength is less than the third preset strength threshold, the terminal device logs out of the preset software.
8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: The portable authentication device acquires its own location information; The portable authentication device determines whether it is within a preset geographical range based on the location information; When the portable authentication device is within a preset geographical range, it sends the authorized login information to the terminal device.
9. The method according to claim 8, characterized in that, The method further includes: When the portable authentication device is not within the preset geographical range and receives a third operation from the user, the portable authentication device sends an emergency instruction message to the terminal device. When the terminal device receives the emergency instruction information, it controls the preset software to enter emergency mode; In the emergency mode, the terminal device sends a temporary login request to the backend management server via the Internet. The terminal device receives temporary login information from the backend management server based on the temporary login request, and uses the temporary login information to log in to the preset software within a second preset time period.
10. A software login device, characterized in that, The device is applied to a communication system, which includes a terminal device and a portable authentication device. The terminal device and the portable authentication device can be connected via short-range wireless communication. The terminal device pre-stores the target device identifier of the portable authentication device. The device includes: a detection module, an establishment module, a receiving module, a first judgment module, and a login module located in the terminal device; and a first sending module, a second sending module, and a third sending module located in the portable authentication device. The detection module is used to periodically detect short-range wireless communication signals; The first transmitting module is used to transmit a short-range wireless communication signal carrying a target device identifier; The establishment module is used to establish a short-range wireless communication connection with the portable authentication device after detecting a short-range wireless communication signal carrying a pre-stored target device identifier. The second sending module is used to send authorized login information to the terminal device; The receiving module is used to receive the authorized login information sent by the portable authentication device, and to verify the authorized login information using the public key in the digital certificate of the portable authentication device that is stored in advance; wherein, the authorized login information is obtained by the portable authentication device signing the user login information; The third sending module is used to send a keep-connection signal to the terminal device; The first determination module is used to determine whether the signal strength of the keep-connect signal received by the portable authentication device is greater than or equal to a first preset strength threshold. The login module is used to input the user login information into the login port of the preset software in the terminal device when the signal strength of the connection signal is greater than or equal to the first preset strength threshold and the authorized login information verification is successful, so as to log in to the preset software.
Citation Information
Patent Citations
Identity authentication method, terminal device, authentication server, and electronic device
CN107079034A
Login method for web sight in mobile telecommunicationterminal equipment
KR1020060025480A