Information processing method

By generating and encrypting character verification code prototype information through the SIM card, and combining it with the interactive verification between the terminal and the authentication platform, the problems of QR code interception and network dependence are solved, achieving a more secure and stable QR code authentication.

CN119624447BActive Publication Date: 2026-04-07CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In existing QR code transaction and authentication solutions, QR codes are easily intercepted by malicious third parties, resulting in insufficient identity verification security. Furthermore, relying on the APP to generate QR codes leads to large memory consumption, and transactions and authentication are difficult to complete when the network signal is poor.

Method used

The system generates a target random number using a SIM card and encrypts it into a character verification code prototype. It then uses a preset public key and a target key to interact between the terminal and the authentication platform. The terminal displays the character verification code, and the authentication platform performs the verification. This avoids generating traditional QR codes and enhances security and network independence.

Benefits of technology

It improves the security and stability of QR code authentication, reduces the risk of verification code leakage, adapts to transaction authentication needs in various environments, and reduces dependence on data networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119624447B_ABST
    Figure CN119624447B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses an information processing method. The information processing method is applied to a SIM card of a first terminal, and the method comprises the following steps: in response to a target transaction instruction, a target random number corresponding to the target transaction instruction is generated; the target random number is sent to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information comprises a user identity information identification code and a security environment identifier corresponding to the SIM card of the first terminal; the target random number is encrypted by using the preset public key to obtain a target key; the user identity information identification code and the security environment identifier are encrypted by using the target key to obtain character verification code prototype information; and the character verification code prototype information is sent to the first terminal, so that the first terminal displays a first character verification code corresponding to the character verification code prototype information. The embodiment of the application can improve the security of code brushing authentication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of secure communication, and particularly relates to an information processing method. BACKGROUND

[0002] With the development of smart phones, more and more people use application programs (APPs) on smart phones to conduct code brushing transactions and code brushing authentication, such as payment platform payment and collection codes and supermarket application member codes. In current code brushing transaction and code brushing authentication schemes, an APP is mostly used to provide a two-dimensional code for identity authentication. When transaction authentication is required, a two-dimensional code is generated by the APP and displayed through a user terminal. A scanning terminal can conduct authentication by scanning the two-dimensional code displayed by the user terminal APP.

[0003] However, in the case of a social engineering attack, the two-dimensional code is easy to be maliciously intercepted by a third party. For example, the third party can obtain the two-dimensional code displayed by the user terminal APP through network monitoring, packet capture, and the like, thereby impersonating the user identity by using the two-dimensional code to conduct identity authorization or payment transactions, and endangering the property safety of the user. Therefore, it is urgent to strengthen the security of code brushing authentication. SUMMARY

[0004] Embodiments of the application provide an information processing method, device, equipment, computer storage medium and computer program product, which can improve the security of code brushing authentication.

[0005] In a first aspect, embodiments of the application provide an information processing method applied to a Subscriber Identity Module (SIM) card of a first terminal, and the method comprises:

[0006] In response to a target transaction instruction, a target random number corresponding to the target transaction instruction is generated;

[0007] The target random number is sent to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information comprises a user identity information identification code corresponding to the SIM card of the first terminal and a security environment identifier;

[0008] The target random number is encrypted using the preset public key to obtain a target key;

[0009] The user identity information identification code and the security environment identifier are encrypted using the target key to obtain character verification code prototype information;

[0010] The character verification code prototype information is sent to the first terminal, so as to display a first character verification code corresponding to the character verification code prototype information by the first terminal.

[0011] In an alternative implementation, before the user identity information identifier and the security environment identifier are encrypted using the target key to obtain the character verification code prototype information, the method further comprises:

[0012] The preset identity information is encrypted using the session key to obtain the user identity information identifier, and the preset identity information includes the security environment identifier and / or the biometric information.

[0013] In an alternative implementation, sending the target random number to the authentication platform comprises:

[0014] The target random number encrypted by the preset public key is sent to the authentication platform, so that the authentication platform decrypts the target random number encrypted by the preset public key using the preset private key to obtain the target random number.

[0015] In an alternative implementation, before the target random number is sent to the authentication platform, the method further comprises:

[0016] The preset public key, the preset private key corresponding to the preset public key, and the user identity information identifier are sent to the authentication platform, so that the authentication platform stores the preset public key, the preset private key, and the user identity information identifier.

[0017] In an alternative implementation, after the character verification code prototype information is sent to the first terminal, so that the first terminal displays the first character verification code corresponding to the character verification code prototype information, the method further comprises:

[0018] The verification result sent by the authentication platform is received, the verification result being obtained by the authentication platform receiving the second character verification code sent by the second terminal, and verifying the character verification code prototype information in the second character verification code; the second character verification code being obtained by the second terminal scanning the first character verification code displayed by the first terminal;

[0019] The target random number is deleted.

[0020] In an alternative implementation, after the authentication platform receives the verification result of the character verification code prototype information, the method further comprises:

[0021] The verification result is sent to the first terminal, so that the first terminal displays the character corresponding to the verification result.

[0022] In an alternative implementation, before the target random number corresponding to the transaction instruction is generated, the method further comprises:

[0023] The personal identity code input by the user at the first terminal is obtained;

[0024] The personal identity code is verified.

[0025] In a case where the personal identification code is verified, a target random number corresponding to a transaction instruction is generated.

[0026] In a second aspect, the embodiments of the present application provide an information processing method, applied to an authentication platform, comprising:

[0027] receiving a target random number sent by a SIM card of the first terminal, the target random number being generated by the first terminal in response to a target transaction instruction;

[0028] receiving a second character verification code sent by the second terminal, the second character verification code being generated by the second terminal by scanning a first character verification code displayed by the first terminal, the first character verification code corresponding to character verification code prototype information, the character verification code prototype information being obtained by encrypting a user identity information identifier and a secure environment identifier based on a target key by the first terminal, the target key being obtained by encrypting the target random number using a preset public key, and the second character verification code comprising the character verification code prototype information;

[0029] encrypting the target random number using a preset public key stored in advance to obtain a target key;

[0030] decrypting the character verification code prototype information using the target key to obtain the user identity information identifier and the secure environment identifier;

[0031] verifying the user identity information identifier and the secure environment identifier based on authentication information stored in advance to obtain a verification result, the authentication information comprising a user identity information identifier and a secure environment identifier corresponding to the SIM card of the first terminal.

[0032] In an optional implementation, verifying the user identity information identifier and the secure environment identifier based on the authentication information stored in advance to obtain the verification result comprises:

[0033] comparing the user identity information identifier and the secure environment identifier with a user identity information identifier and a secure environment identifier in the authentication information;

[0034] in a case where the user identity information identifier and the secure environment identifier are consistent with the user identity information identifier and the secure environment identifier in the authentication information, determining that the verification is passed;

[0035] in a case where the user identity information identifier and the secure environment identifier are inconsistent with the user identity information identifier and the secure environment identifier in the authentication information, determining that the verification is failed.

[0036] In an optional implementation, after verifying the user identity information identifier and the secure environment identifier based on the authentication information stored in advance to obtain the verification result, the method further comprises:

[0037] send the verification result to the second terminal and the SIM card of the first terminal respectively;

[0038] delete the target random number.

[0039] In a third aspect, an embodiment of the present application provides an information processing device applied to a SIM card of a first terminal, and the device comprises:

[0040] a generation module configured to generate a target random number corresponding to a target transaction instruction in response to the target transaction instruction;

[0041] a sending module configured to send the target random number to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information comprises a user identity information identifier and a secure environment identifier corresponding to the SIM card of the first terminal;

[0042] an encryption module configured to encrypt the target random number using the preset public key to obtain a target key;

[0043] The encryption module is further configured to encrypt the user identity information identifier and the secure environment identifier using the target key to obtain character verification code prototype information.

[0044] The sending module is further configured to send the character verification code prototype information to the first terminal, so that the first terminal displays a first character verification code corresponding to the character verification code prototype information.

[0045] In a fourth aspect, an embodiment of the present application provides an information processing device applied to an authentication platform, and the device comprises:

[0046] a receiving module configured to receive a target random number sent by a SIM card of a first terminal, wherein the target random number is generated by the first terminal in response to a target transaction instruction;

[0047] The receiving module is further configured to receive a second character verification code sent by a second terminal, wherein the second character verification code is generated by the second terminal by scanning a first character verification code displayed by the first terminal, the first character verification code corresponds to the character verification code prototype information, the character verification code prototype information is obtained by encrypting the user identity information identifier and the secure environment identifier based on the target key, the target key is obtained by encrypting the target random number using the preset public key, and the second character verification code comprises the character verification code prototype information.

[0048] an encryption module configured to encrypt the target random number using the preset public key pre-stored to obtain the target key;

[0049] a decryption module configured to decrypt the character verification code prototype information using the target key to obtain the user identity information identifier and the secure environment identifier;

[0050] The verification module is configured to verify the user identity information identifier and the secure environment identifier according to pre-stored authentication information to obtain a verification result, and the authentication information includes the user identity information identifier and the secure environment identifier corresponding to the SIM card of the first terminal.

[0051] In a fifth aspect, an embodiment of the present application provides an electronic device, the device comprising: a processor and a memory storing computer program instructions.

[0052] The processor executes the computer program instructions to implement the information processing method of any of the optional implementation manners of the first aspect of the present application, or the information processing method of any of the optional implementation manners of the second aspect of the present application.

[0053] In a sixth aspect, an embodiment of the present application provides a computer readable storage medium, the computer readable storage medium storing computer program instructions, and the computer program instructions are executed by a processor to implement the information processing method of any of the optional implementation manners of the first aspect of the present application, or the information processing method of any of the optional implementation manners of the second aspect of the present application.

[0054] In a seventh aspect, an embodiment of the present application provides a computer program product, instructions in the computer program product are executed by a processor of an electronic device to enable the electronic device to execute the information processing method of any of the optional implementation manners of the first aspect of the present application, or the information processing method of any of the optional implementation manners of the second aspect of the present application.

[0055] The information processing method, device, equipment, computer storage medium and computer program product provided by the embodiments of the present application are applied to a SIM card of a first terminal, can generate a target random number corresponding to a target transaction instruction in response to the target transaction instruction, and send the target random number to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information includes a user identity information identifier and a security environment identifier corresponding to the SIM card of the first terminal. Then, the target random number is encrypted using the preset public key to obtain a target key. In this way, a target key corresponding to a single transaction can be generated. Correspondingly, the authentication platform can also generate the target key by using the pre-stored preset public key and the received target random number for subsequent authentication. In this way, the encryption key corresponding to each transaction is different, so that even if the encryption key corresponding to a certain transaction is cracked, the encryption key of other transactions cannot be obtained through the cracked key, thereby improving the security of authentication. Then, the user identity information identifier and the security environment identifier can be encrypted using the target key to obtain character verification code prototype information. The character verification code prototype information contains authentication information of multiple dimensions and has high credibility, which can improve the effectiveness of user identity authentication. Then, the character verification code prototype information can be sent to the first terminal to display a first character verification code corresponding to the character verification code prototype information. In this way, the character verification code prototype information can be generated by the SIM card in the case that the SIM card cannot generate a traditional two-dimensional code, and then the character verification code can be displayed by the terminal where the SIM card is located. The character verification code can be scanned by a code scanning terminal and sent to the authentication platform for verification of the character verification code prototype information by the authentication platform. In this way, the code scanning authentication can be realized through the interaction of the SIM card, the terminal and the platform, the risk of code leakage is reduced, and the security of the code scanning authentication can be further improved. BRIEF DESCRIPTION OF DRAWINGS

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced. Other drawings can also be obtained by those skilled in the art without creative labor on the premise of not paying creative labor.

[0057] Figure 1 is a flowchart of an information processing method provided by an embodiment of the present application;

[0058] Figure 2 is a flowchart of an information processing method provided by another embodiment of the present application;

[0059] Figure 3 is a flowchart of an information processing method provided by another embodiment of the present application;

[0060] Figure 4 is a flowchart of an information processing method according to another embodiment of the present application;

[0061] Figure 5 is a schematic diagram of a character verification code according to another embodiment of the present application;

[0062] Figure 6 is a flowchart of an information processing method according to another embodiment of the present application;

[0063] Figure 7 is a structural diagram of an information processing apparatus according to another embodiment of the present application;

[0064] Figure 8 is a structural diagram of an information processing apparatus according to another embodiment of the present application;

[0065] Figure 9 is a structural diagram of an electronic device according to yet another embodiment of the present application. DETAILED DESCRIPTION

[0066] The features and exemplary embodiments of the various aspects of the present application will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely intended to explain the present application, and are not intended to limit the present application. The present application can be implemented without some of the specific details described below. The following description of the embodiments is merely provided to give a better understanding of the present application by showing examples of the present application.

[0067] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one entity or action from another, without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without more limitations, an element defined by an "comprising" statement is not excluded from a process, method, article, or apparatus that includes the element, even if the same process, method, article, or apparatus also includes other identical elements not expressly defined.

[0068] With the development of smart phones, more and more people use application programs (APPs) on smart phones to conduct code brushing transactions and code brushing authentication, such as payment platform payment and collection codes and supermarket application member codes. In the current code brushing transaction and code brushing authentication scheme, the APP is mostly used to provide a two-dimensional code for identity verification. When transaction authentication is required, a two-dimensional code is generated by the APP and displayed through a user terminal. Scanning the two-dimensional code displayed by the user terminal APP through a code scanning terminal can perform authentication.

[0069] However, in the case of a social engineering attack, the two-dimensional code is easy to be maliciously intercepted by a third party. For example, a third party can obtain the two-dimensional code displayed by the user terminal APP through network monitoring, packet capture, etc., thereby impersonating the user identity using the two-dimensional code to perform identity authorization or payment transactions, etc., endangering the user's property safety.

[0070] In addition, since the two-dimensional code is generated based on the APP, different APPs need to be used for code brushing authentication in different transaction scenarios. Therefore, the user terminal needs to download multiple APPs, resulting in excessive memory occupation. Moreover, the APP-based two-dimensional code generation authentication method also depends on the data network, and if the user terminal is in a location with poor network signal such as an underground garage or a supermarket, it is difficult to complete the transaction and authentication.

[0071] In view of this, the inventors have ingeniously proposed an information processing method, device, equipment, computer storage medium and computer program product.

[0072] In the embodiments of the present application, the information processing method can be implemented based on an information processing system. First, the information processing system is briefly introduced.

[0073] The information processing system can include a first terminal, a SIM card, a second terminal and an authentication platform.

[0074] The first terminal can be a user terminal, such as a mobile terminal such as a mobile phone. The first terminal can be used to receive and display data transmitted by the SIM card.

[0075] The SIM card can be installed in the first terminal. In an embodiment, the SIM card can be a super SIM card. The SIM card can execute an Application Protocol Data Unit (APDU) instruction and store data through a card application of the SIM card. The SIM card can pre-store a Security Environment Identifier (SEID). In an embodiment, after the card application is installed, the SIM card can generate a pair of public and private keys and a user identity information identifier. The pair of public and private keys can be used for encryption and decryption when data is transmitted, and the user identity information identifier can be used for transaction authentication.

[0076] The second terminal can be a code scanning terminal. In an embodiment of the present application, the second terminal can scan the character verification code and send the character verification code to the authentication platform for the authentication platform to verify the character verification code.

[0077] The authentication platform can be a server end for judging a transaction authentication result. In an embodiment of the present application, the authentication platform can verify the character verification code to obtain a verification result.

[0078] For example, the SIM card can generate character verification code prototype information based on the SEID and the user identity information identifier. The first terminal can convert the character verification code prototype information into meaningless character verification codes through a DISPLAY TEXT (DT) module. Correspondingly, the second terminal can scan the character verification code displayed by the first terminal and send the character verification code to the authentication platform. The authentication platform can verify the character verification code prototype information carried by the character verification code to obtain a verification result. In this way, to overcome the defect that the SIM card cannot generate a two-dimensional code, the information processing system provided in the embodiment of the present application can generate a character verification code through the functions of the SIM card and the first terminal, scan the character verification code through the second terminal, and verify the character verification code scanned by the second terminal through the authentication platform. In this way, the code authentication can be performed through the verification code generated by the SIM card.

[0079] The information processing method provided in the embodiment of the present application will be described in detail below in combination with the drawings, specific embodiments, and application scenarios. The device that executes the information processing method provided in the embodiment of the present application can be an information processing device or a part of the information processing device that is used to execute the information processing method. In the embodiment of the present application, the information processing device is taken as an example to execute the information processing method, and the information processing method provided in the embodiment of the present application is described in detail.

[0080] The information processing method provided in the embodiment of the present application will be described in detail below in combination with the drawings, specific embodiments, and application scenarios. The device that executes the information processing method provided in the embodiment of the present application can be an information processing device or a part of the information processing device that is used to execute the information processing method. In the embodiment of the present application, the information processing device is taken as an example to execute the information processing method, and the information processing method provided in the embodiment of the present application is described in detail. Figure 1 The information processing method provided in the embodiment of the present application will be described in detail below in combination with the drawings, specific embodiments, and application scenarios. The device that executes the information processing method provided in the embodiment of the present application can be an information processing device or a part of the information processing device that is used to execute the information processing method. In the embodiment of the present application, the information processing device is taken as an example to execute the information processing method, and the information processing method provided in the embodiment of the present application is described in detail.

[0081] Figure 1 A flowchart of an information processing method provided by an embodiment of the present application is shown. As shown in the figure, the information processing method can specifically include the following steps S101-S111. Figure 1

[0082] S101, the SIM card of the first terminal generates a target random number corresponding to a target transaction instruction in response to the target transaction instruction.

[0083] In step S101, the target transaction instruction can be a transaction instruction generated based on the selection input of the user on the first terminal. The target random number can be generated by a method known in the art, for example, it can be generated by a SecureRandom class. Exemplarily, the target random number can be a 16-byte random number. After the SIM card of the first terminal generates the target random number, the target random number can be stored in the card application for subsequent encryption operations.

[0084] S102, the SIM card of the first terminal sends the target random number to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information includes a user identity information identification code and a secure environment identifier corresponding to the SIM card of the first terminal.

[0085] In step S102, the preset public key can include a public key generated by the card application of the SIM card. The user identity information identification code can include an identification code generated by the identity information corresponding to the user. In some embodiments, the authentication information can be stored in the authentication platform when the information processing system is initialized. For example, the authentication platform can authenticate the transaction authentication results of a plurality of first terminals. When the information processing system is initialized, each first terminal can process the authentication information corresponding to itself to the authentication platform for the authentication platform to store the authentication information corresponding to each first terminal.

[0086] Correspondingly, the authentication platform can receive the target random number sent by the SIM card of the first terminal.

[0087] Exemplarily, after the authentication platform receives the target random number, the target random number can be stored for subsequent decryption operations.

[0088] S103, the SIM card of the first terminal encrypts the target random number using the preset public key to obtain a target key.

[0089] S104, the SIM card of the first terminal encrypts the user identity information identification code and the secure environment identifier using the target key to obtain character verification code prototype information.

[0090] ​S105, the SIM card of the first terminal sends character verification code prototype information to the first terminal for the first terminal to display a first character verification code corresponding to the character verification code prototype information.

[0091] Correspondingly, the first terminal can receive the character verification code prototype information.

[0092] The first terminal can also convert the character verification code prototype information into the first character verification code according to the display rule.

[0093] In one example, the first character verification code can be a Chinese verification code. The Chinese verification code can effectively compress the display length.

[0094] It can be understood that the SIM card of the first terminal generates a corresponding target random number each time the first terminal initiates a transaction instruction, and each target random number is only valid for the corresponding transaction instruction. The target key generated using the target random number encrypts the user identity information identifier and the secure environment identifier to generate the character verification code prototype information. In this way, the first character verification code corresponding to each transaction instruction is different, thereby improving the security of transaction authentication.

[0095] S106, the first terminal displays the first character verification code corresponding to the character verification code prototype information.

[0096] Illustratively, after the first terminal generates and displays the first character verification code, the user can show the first terminal interface to the corresponding second terminal.

[0097] S107, the second terminal scans the first character verification code displayed by the first terminal, generates a second character verification code, and the second character verification code includes the character verification code prototype information.

[0098] S108, the second terminal sends the second character verification code to the authentication platform.

[0099] Correspondingly, the authentication platform can receive the second character verification code sent by the second terminal.

[0100] S109, the authentication platform encrypts the target random number using a pre-stored preset public key to obtain a target key.

[0101] S110, the authentication platform decrypts the character verification code prototype information using the target key to obtain the user identity information identifier and the secure environment identifier.

[0102] S111, the authentication platform verifies the user identity information identifier and the secure environment identifier according to pre-stored authentication information to obtain a verification result.

[0103] In the information processing method of the embodiments of the present application, the SIM card of the first terminal can generate a target random number corresponding to the target transaction instruction in response to the target transaction instruction, and send the target random number to the authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information includes a user identity information identifier corresponding to the SIM card of the first terminal and a secure environment identifier. Then the target random number is encrypted using the preset public key to obtain a target key. In this way, a target key corresponding to a single transaction can be generated. Correspondingly, the authentication platform can also generate the target key by using the pre-stored preset public key and the received target random number for subsequent authentication. In this way, the encryption key corresponding to each transaction is different, so even if the encryption key corresponding to a certain transaction is cracked, it is impossible to obtain the encryption key of other transactions through the cracked key, thereby improving the security of authentication. Then, the SIM card of the first terminal can encrypt the user identity information identifier and the secure environment identifier using the target key to obtain character verification code prototype information. The character verification code prototype information contains authentication information of multiple dimensions and has high credibility, which can improve the effectiveness of user identity authentication. Then, the character verification code prototype information can be sent to the first terminal for the first terminal to display a first character verification code corresponding to the character verification code prototype information. Correspondingly, the first terminal can display the first character verification code corresponding to the character verification code prototype information. In this way, the character verification code prototype information can be generated by the SIM card in the case that the SIM card cannot generate a traditional two-dimensional code, and then the character verification code can be displayed by the terminal where the SIM card is located.

[0104] In the embodiments of the present application, the second terminal can scan the first character verification code, generate a second character verification code, and send the second character verification code to the authentication platform for the authentication platform to verify the character verification code prototype information. The authentication platform can encrypt the target random number using the pre-stored preset public key to obtain the target key, and then decrypt the character verification code prototype information using the target key to obtain the user identity information identifier and the secure environment identifier. Subsequently, the authentication platform can verify the user identity information identifier and the secure environment identifier according to the pre-stored authentication information to obtain a verification result. In this way, the code scanning authentication can be realized through the interaction of the SIM card, the terminal and the platform, the risk of verification code leakage is reduced, and the security of the code scanning authentication can be further improved.

[0105] In addition, according to the information processing method in the embodiment of the present application, the SIM card of the first terminal can interact with a software development kit (SDK) through a machine card channel, and then communicate with the first terminal. The SIM card of the first terminal and the authentication platform, and the second terminal and the authentication platform can communicate through a communication network. Compared with the authentication method based on the APP generated two-dimensional code in the related art, the embodiment of the present application does not need to rely on a data network, has higher stability, and can meet the code authentication needs in various environments.

[0106] The encryption and decryption method of the character verification code prototype information is not specifically limited in the embodiment of the present application, and a suitable encryption algorithm can be selected according to actual needs. For example, the SIM card of the first terminal can use a target key to encrypt the user identity information identifier and the security environment identifier through a triple data encryption algorithm (3DES) to obtain the character verification code prototype information. Correspondingly, the authentication platform can use the target key to decrypt the character verification code prototype information through the 3DES algorithm to obtain the user identity information identifier and the security environment identifier. For example, the encryption algorithm can also be a private algorithm, and a message authentication code (MAC) of the private algorithm can be added for encryption and decryption authentication.

[0107] In one embodiment, the SIM card of the first terminal uses a target key to encrypt the user identity information identifier and the security environment identifier to obtain the character verification code prototype information, which can specifically include:

[0108] The SIM card of the first terminal adds corresponding identification tags to the user identity information identifier and the security environment identifier respectively to obtain original data.

[0109] The SIM card of the first terminal uses a target key to encrypt the original data to obtain the character verification code prototype information.

[0110] Correspondingly, in one embodiment, the authentication platform uses a target key to decrypt the character verification code prototype information to obtain the user identity information identifier and the security environment identifier, which can specifically include:

[0111] The authentication platform uses a target key to decrypt the character verification code prototype information to obtain original data.

[0112] The original data is split according to the identification tags of the user identity information identifier and the security environment identifier to obtain the user identity information identifier and the security environment identifier.

[0113] According to the above-mentioned embodiments, the corresponding identification tags are added to the user identity information identifier and the security environment identifier, which facilitates the authentication platform to quickly extract the user identity information identifier and the security environment identifier from the character verification code prototype information in the verification process. In this way, the efficiency of the code brushing authentication can be improved.

[0114] In one embodiment, before the SIM card of the first terminal encrypts the user identity information identifier and the security environment identifier using the target key to obtain the character verification code prototype information, the method can further include:

[0115] The SIM card of the first terminal encrypts the preset identity information using the session key to obtain the user identity information identifier, and the preset identity information includes the security environment identifier and / or the biometric information.

[0116] In the above-mentioned embodiments, the encryption of the preset identity information using the session key can be implemented by methods known in the art. For example, the preset identity information can be encrypted by the encSessionKey of the secure copy protocol (scp02).

[0117] In the above-mentioned embodiments, the biometric information can include, but is not limited to, face authentication information or fingerprint authentication information.

[0118] According to the above-mentioned embodiments, the encryption of the preset identity information using the session key to obtain the user identity identifier can reduce the risk of tampering with the user identity identifier, make the user identity identifier unique, and thus improve the security of the code brushing authentication. In addition, the SEID can be used as a unique identifier of the SIM card, and the biometric information directly corresponds to the biological characteristics of the user. By using the SEID and / or the biometric information as the preset identity information, the user identity identifier obtained by encryption has high credibility, and can be used to identify the user identity in transaction authentication, thereby improving the effectiveness of the user identity authentication. In this way, the security of the code brushing authentication and the transaction can be improved.

[0119] In one embodiment, the SIM card of the first terminal sends the target random number to the authentication platform, which can specifically include:

[0120] The SIM card of the first terminal sends the target random number encrypted by the preset public key to the authentication platform, so that the authentication platform decrypts the target random number encrypted by the preset public key using the preset private key to obtain the target random number.

[0121] Correspondingly, in one embodiment, the authentication platform receives the target random number sent by the SIM card of the first terminal, which can specifically include:

[0122] The authentication platform receives the target random number sent by the SIM card of the first terminal and encrypted by the preset public key.

[0123] The method can further include, after the authentication platform receives the target random number sent by the SIM card of the first terminal:

[0124] The authentication platform decrypts the target random number encrypted by the preset public key using a preset private key stored in advance to obtain the target random number.

[0125] The authentication platform stores the target random number.

[0126] In the above embodiment, the preset private key can be a private key corresponding to the preset public key.

[0127] According to the above embodiment, after the SIM card of the first terminal generates the target random number corresponding to the target transaction instruction, the target random number can be encrypted using the preset public key and then sent to the authentication platform. Correspondingly, after the authentication platform receives the target random number encrypted by the preset public key, the target random number can be decrypted using the preset private key, and the target random number can be stored. In this way, the risk of the target random number being stolen during transmission can be reduced, thereby improving the security of the target key. In this way, the security of the code brushing authentication can be improved.

[0128] In one embodiment, before the SIM card of the first terminal sends the target random number to the authentication platform, the method can further include:

[0129] The SIM card of the first terminal sends the preset public key, the preset private key corresponding to the preset public key, and the user identity information identifier to the authentication platform, so that the authentication platform stores the preset public key, the preset private key, and the user identity information identifier.

[0130] Correspondingly, in one embodiment, before the authentication platform receives the target random number sent by the SIM card of the first terminal, the method can further include:

[0131] The authentication platform receives the preset public key, the preset private key, and the user identity information identifier sent by the SIM card of the first terminal.

[0132] The authentication platform stores the preset public key, the preset private key, and the user identity information identifier.

[0133] In the above embodiment, the preset public key and the preset private key can be a public-private key pair generated by the SIM card of the first terminal in a card application initialization process. The authentication platform can synchronize the SEID of the SIM card in advance.

[0134] According to the above-mentioned embodiments, the SIM card of the first terminal can send the preset public key, the preset private key, and the user identity information identifier to the authentication platform for storage. The preset public key and the preset private key are a public-private key pair generated by the card application, have high privacy, and can be used when the SIM card of the first terminal and the authentication platform perform data transmission, thereby improving the security of the interaction between the SIM card of the first terminal and the authentication platform. The user identity information identifier is generated by encrypting the preset identity information by using the session key, has high reliability, and after being synchronized to the authentication platform, the authentication platform can verify the character verification code prototype information based on the user identity information identifier. In this way, the security and effectiveness of the code brushing authentication can be improved.

[0135] As an example, after the card application is installed, the SIM card can generate a public-private key pair and store the public key in the card application. The SIM card can also read the preset identity information in the card, encrypt the preset identity information by using the session key to obtain the user identity information identifier of the SIM card, and store the user identity information identifier in the card application. The SIM card can send the public-private key pair and the user identity information identifier to the authentication platform for storage. In this way, the public key, the SEID, and the user identity information identifier are all stored in the SIM card instead of being stored in the first terminal. Even if the user loses the first terminal, the SIM card can be invalidated by the SIM card loss reporting. In this way, the risk of the keys, the SEID, and the user identity information identifier being leaked due to the attack or theft of the first terminal can be reduced, thereby improving the security of the authentication. In an example, the SIM card can send the public-private key pair and the user identity information identifier to the authentication platform by using the encrypted transmission. In this way, the risk of the public-private key pair and the user identity information identifier being leaked can be reduced, thereby further improving the security of the authentication.

[0136] In an embodiment, after the authentication platform verifies the user identity information identifier and the secure environment identifier based on the pre-stored authentication information and obtains the verification result, the method can further include:

[0137] The authentication platform sends the verification result to the second terminal and the SIM card of the first terminal, respectively.

[0138] The authentication platform deletes the target random number.

[0139] According to the above-mentioned embodiments, after obtaining the verification result, the authentication platform can notify the code scanning terminal and the SIM card of the first terminal, respectively, so that both parties can obtain the authentication result in time. In this way, the efficiency of the authentication and the transaction can be improved, thereby improving the user experience. After the transaction authentication is completed, the authentication platform can delete the target random number in time, so that each generated random number is only used for a single transaction, thereby improving the security of the code brushing authentication.

[0140] In one embodiment, after the SIM card of the first terminal sends the character verification code prototype information to the first terminal for the first terminal to display the first character verification code corresponding to the character verification code prototype information, the method can further include:

[0141] The SIM card of the first terminal receives the verification result sent by the authentication platform, the verification result being a verification result obtained by the authentication platform receiving the second character verification code sent by the second terminal and verifying the character verification code prototype information in the second character verification code; the second character verification code being obtained by the second terminal scanning the first character verification code displayed by the first terminal.

[0142] The SIM card of the first terminal deletes the target random number.

[0143] According to the above embodiment, after receiving the verification result, the SIM card of the first terminal can clear the random number in time, so that the random number used in each transaction authentication is different, and thus the character verification code generated each time is only valid for a single transaction. In addition, clearing the random number in time after each authentication is completed can also reduce the risk of malicious use of the character verification code after being photographed. In this way, the security of the code authentication can be improved.

[0144] In one embodiment, after the SIM card of the first terminal receives the verification result of the authentication platform on the character verification code prototype information, the method can further include:

[0145] The SIM card of the first terminal sends the verification result to the first terminal for the first terminal to display the character corresponding to the verification result.

[0146] For example, after receiving the verification result, the SIM card of the first terminal can send a DISPLAY TXT command to the first terminal and carry the verification result. The first terminal can convert the verification result into characters through the DISPLAY TXT module and display them.

[0147] According to the above embodiment, the verification result can be displayed through the first terminal. In this way, the user can directly obtain the verification result through the screen of the first terminal, thereby improving the user experience.

[0148] In one embodiment, before the SIM card of the first terminal generates the target random number corresponding to the transaction instruction, the method can further include:

[0149] The SIM card of the first terminal obtains the personal identification number input by the user on the first terminal.

[0150] The SIM card of the first terminal verifies the personal identification number.

[0151] The SIM card of the first terminal generates a target random number corresponding to the transaction instruction when the personal identification number is verified.

[0152] The personal identification number (PIN code) can be used to confirm the correctness of the user and to authenticate the user of the SIM card. In the embodiments of the present application, the user information related to authentication is stored in the SIM card. Before transaction authentication, the user is authenticated through the PIN code, which can protect the data of the SIM card and reduce the risk of information theft in the SIM card. In this way, the security of the code authentication can be improved.

[0153] In one embodiment, the authentication platform verifies the user identity information identifier and the security environment identifier according to the pre-stored authentication information, and obtains a verification result, which can specifically include:

[0154] The authentication platform compares the user identity information identifier and the security environment identifier in the character verification code prototype information with the user identity information identifier and the security environment identifier in the authentication information.

[0155] The authentication platform determines that the verification is passed when the user identity information identifier and the security environment identifier in the character verification code prototype information are consistent with the user identity information identifier and the security environment identifier in the authentication information.

[0156] The authentication platform determines that the verification is not passed when the user identity information identifier and the security environment identifier in the character verification code prototype information are inconsistent with the user identity information identifier and the security environment identifier in the authentication information.

[0157] According to the above embodiments, the corresponding verification result can be determined according to the comparison result of the user identity information identifier and the security environment identifier in the character verification code prototype information and the authentication information. In this way, the risk of user identity impersonation can be reduced, and the security of the code authentication can be improved.

[0158] The information processing method provided by the embodiments of the present application will be introduced below in combination with the drawings, specific embodiments and application scenarios. The information processing method provided by the embodiments of the present application can be executed by an information processing device or a part of the information processing device for executing the information processing method. In the embodiments of the present application, the information processing device is taken as an example to execute the information processing method, and the information processing method provided by the embodiments of the present application is described in detail.

[0159] In the above embodiments, the PIN code can be used to authenticate the user identity.

[0160] In order to better describe the whole scheme, based on the above embodiments, an example is given to describe the information processing method and the information processing method of the embodiments of the present application. The following is explained in detail. It should be noted that the following examples are only for explaining the embodiments of the present application, and do not limit the embodiments of the present application.

[0161] Exemplarily, the information processing method of the embodiments of the present application can be implemented based on an information processing system. The following describes an example of the information processing method in conjunction with the accompanying drawings.

[0162] Exemplarily, the information processing method can include steps S210 to S260.

[0163] S210, the SIM card of the first terminal generates a public-private key pair and a user identity information identifier through a card application, and synchronizes to an authentication platform.

[0164] In step S210, after the card application of the SIM card of the first terminal is installed, a public-private key pair and a user identity information identifier can be generated, and the public key and the user identity information identifier are stored in the card application, and the public-private key pair and the user identity information identifier are sent to the platform. The public-private key pair is used for encryption and decryption when transmitting data later, and the user identity information identifier is used for transaction authentication.

[0165] In one example, as shown in Figure 2 S210 can specifically include steps S211 to S214.

[0166] S211, the SIM card of the first terminal generates a public-private key pair through a card application, and stores the public key in the card application.

[0167] S212, the SIM card of the first terminal reads the SEID value in the card, encrypts the SEID through the scp02 encSessionKey, and the encrypted value is used as the user identity information identifier of the SIM card of the first terminal.

[0168] S213, the SIM card of the first terminal stores the public key in the public-private key pair and the user identity information identifier through the card application.

[0169] S214, the SIM card of the first terminal sends the public-private key pair and the user identity information identifier to the authentication platform, so that the platform stores the public-private key pair and the user identity information identifier.

[0170] Correspondingly, the authentication platform can receive and store the public-private key pair and the user identity information identifier. It can be understood that the authentication platform can pre-synchronize the SEID of the SIM card, so that the SEID does not need to be sent to the authentication platform when the card application is initialized.

[0171] According to steps S211 to S214, the card application generates the public-private key pair during initialization, so that the public-private key pair has high privacy in subsequent transmission processes. Moreover, the user identity information identification code does not directly use the SEID, but uses the value encrypted by the SEID using the encSessionKey as the identity information identification code, so that the user identity information identification code has uniqueness and high security.

[0172] S220, the card application of the SIM card of the first terminal generates a random number and sends it to the authentication platform each time the transaction authentication requirement is triggered.

[0173] In step S220, when the first terminal issues a transaction authentication requirement to the SIM card, the card application can generate a 16-byte random number and store it, and then send the random number to the authentication platform, which is used to generate the target key for the encryption operation of the current transaction.

[0174] In one example, as shown in Figure 3 step S220 can include the following S221 to S226.

[0175] S221, the SIM card of the first terminal generates a 16-byte random number through the card application.

[0176] S222, the SIM card of the first terminal stores the random number in the card application.

[0177] S223, the SIM card of the first terminal encrypts the random number using the public key generated during initialization of the card application.

[0178] S224, the SIM card of the first terminal sends the encrypted random number to the authentication platform.

[0179] S225, after receiving the encrypted random number, the authentication platform decrypts it using the stored private key.

[0180] S226, the authentication platform stores the decrypted random number.

[0181] According to the above steps S221 to S226, the identity information identification code is not directly encrypted and displayed using the public-private key pair, but a random number is generated each time a transaction is initiated, and each random number is only valid for the transaction. Moreover, the random number is encrypted to generate a character verification code, which ensures that the character verification code is different each time, further ensuring the security of transaction authentication.

[0182] S230, the SIM card of the first terminal generates character verification code prototype information through the card application and sends it to the first terminal.

[0183] In step S230, the user can initiate a transaction at the first terminal, and the SIM card receives the transaction instruction and generates the character verification code prototype information and sends it to the first terminal.

[0184] In one example, as shown in Figure 4 step S230 can include the following S231-S235.

[0185] S231, the SIM card of the first terminal encrypts the random number using the public key generated when the card application is initialized, to obtain a target key.

[0186] S232, the SIM card of the first terminal adds an identification tag (tag) to the user identity information identification code and the SEID respectively, to obtain original data.

[0187] For example, the tag of the user identity information identification code can be "41", and the tag of the SEID can be "42".

[0188] S233, the SIM card of the first terminal encrypts the original data using the target key through the 3DES algorithm, to obtain the character verification code prototype information.

[0189] S234, the SIM card of the first terminal sends the character verification code prototype information to the first terminal.

[0190] S235, the first terminal displays the character verification code prototype information as a character verification code according to the display rule.

[0191] In one example, the character verification code prototype information can be a hexadecimal number. The character verification code can be a Chinese verification code, and a specific example can be as shown in Figure 5 .

[0192] The first terminal is usually a mobile terminal, such as a mobile phone. Taking the mobile phone screen as an example, the information it can display is limited. Converting the hexadecimal returned by the SIM card into Chinese can effectively compress the display length. In addition, a random number is used in the process of encrypting the user identity information identification code and the SEID, which can make the Chinese verification code prototype generated each time the transaction is authenticated different, thereby improving the security of transaction authentication.

[0193] S240, the second terminal scans the character verification code and sends the recognized information to the authentication platform.

[0194] Specifically, after the first terminal displays the Chinese character verification code, the user can show it to the verification party. The verification party can scan the character verification code through the second terminal and send the recognized character verification code to the authentication platform.

[0195] S250, after the authentication platform receives the Chinese verification code, it performs verification and sends the verification result to the SIM card.

[0196] In one example, as shown in FIG. 25, step S250 can include steps S251-S258. Figure 6

[0197] S251, the authentication platform converts the received character verification code into a 16 hexadecimal number.

[0198] S252, the authentication platform encrypts the random number with the pre-stored public key to obtain a target key.

[0199] S253, the authentication platform decrypts the 16 hexadecimal number converted from the character verification code using the target key through the 3Des algorithm to obtain the original data.

[0200] S254, the authentication platform splits the original data through the tag of the user identity information identification code and the tag of the SEID to obtain the user identity information identification code and the SEID.

[0201] For example, the tag of the user identity information identification code can be "41", and the tag of the SEID can be "42". The user identity information identification code and the SEID can be obtained by splitting the "41" and "42" tags.

[0202] S255, the authentication platform compares the user identity information identification code and the SEID obtained by splitting with the user identity information identification code and the SEID stored in the platform. If they are the same, the verification is passed, and if they are different, the verification fails.

[0203] S256, the authentication platform sends the verification result to the SIM card of the first terminal.

[0204] S257, the authentication platform clears the random number of this transaction authentication.

[0205] S258, the SIM card of the first terminal clears the random number of this transaction authentication.

[0206] In this way, the random number is only valid for a single transaction, and clearing the random number after each transaction can also prevent the character verification code from being maliciously used after being photographed.

[0207] S260, the SIM card of the first terminal sends the received verification result to the first terminal for display.

[0208] In step S260, after receiving the verification result, the SIM card of the first terminal can send a DISPLAYTXT command to the first terminal, and the first terminal converts the generated verification result into Chinese and displays it to the user.

[0209] ​Based on the same inventive concept as the information processing method, the embodiments of the present application further provide an information processing device applied to a SIM card of a first terminal.

[0210] As shown in Figure 7 The information processing device 300 can include a generation module 301, a sending module 302, and an encryption module 303.

[0211] The generation module 301 is configured to generate a target random number corresponding to the target transaction instruction in response to the target transaction instruction.

[0212] The sending module 302 is configured to send the target random number to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information includes a user identity information identification code and a secure environment identifier corresponding to the SIM card of the first terminal.

[0213] The encryption module 303 is configured to encrypt the target random number using the preset public key to obtain a target key.

[0214] The encryption module 303 is further configured to encrypt the user identity information identification code and the secure environment identifier using the target key to obtain character verification code prototype information.

[0215] The sending module 302 is further configured to send the character verification code prototype information to the first terminal, so as to display a first character verification code corresponding to the character verification code prototype information by the first terminal.

[0216] The information processing device of the embodiment of the present application is applied to a SIM card of a first terminal, can generate a target random number corresponding to a target transaction instruction in response to the target transaction instruction, and send the target random number to an authentication platform, wherein the authentication platform pre-stores a preset public key and authentication information, and the authentication information includes a user identity information identifier corresponding to the SIM card of the first terminal and a security environment identifier. Then the target random number is encrypted using the preset public key to obtain a target key. In this way, a target key corresponding to a single transaction can be generated. Correspondingly, the authentication platform can also generate the target key by using the pre-stored preset public key and the received target random number for subsequent authentication. In this way, the encryption key corresponding to each transaction is different, so that even if the encryption key corresponding to a certain transaction is cracked, it is impossible to obtain the encryption key of other transactions through the cracked key, thereby improving the security of authentication. Then, the user identity information identifier and the security environment identifier can be encrypted using the target key to obtain character verification code prototype information. The character verification code prototype information contains authentication information of multiple dimensions and has high credibility, which can improve the effectiveness of user identity authentication. Then, the character verification code prototype information can be sent to the first terminal to display a first character verification code corresponding to the character verification code prototype information. In this way, the character verification code prototype information can be generated by the SIM card when the SIM card cannot generate a traditional two-dimensional code, and then the character verification code can be displayed by the terminal where the SIM card is located. The code scanning terminal can scan the character verification code and send the character verification code to the authentication platform for the authentication platform to verify the character verification code prototype information. In this way, the code scanning authentication can be realized through the interaction of the SIM card, the terminal and the platform, the risk of code leakage is reduced, and the security of the code scanning authentication can be further improved.

[0217] In one embodiment, the encryption module can also be used to encrypt the preset identity information using the session key to obtain the user identity information identifier before encrypting the user identity information identifier and the security environment identifier using the target key to obtain the character verification code prototype information, and the preset identity information includes the security environment identifier and / or the biometric information.

[0218] In one embodiment, the sending module can be specifically used for:

[0219] sending the target random number encrypted by the preset public key to the authentication platform, so that the authentication platform decrypts the target random number encrypted by the preset public key using a preset private key to obtain the target random number.

[0220] In an embodiment, the sending module can be further configured to send, to the authentication platform, a preset public key, a preset private key corresponding to the preset public key, and a user identity information identifier before sending the target random number to the authentication platform, so that the authentication platform stores the preset public key, the preset private key, and the user identity information identifier.

[0221] In an embodiment, the apparatus can further include:

[0222] The receiving module is configured to receive a verification result sent by the authentication platform after sending the character verification code prototype information to the first terminal for the first terminal to display a first character verification code corresponding to the character verification code prototype information, the verification result being obtained by the authentication platform receiving a second character verification code sent by the second terminal and verifying the character verification code prototype information in the second character verification code; the second character verification code being obtained by the second terminal scanning the first character verification code displayed by the first terminal.

[0223] The deleting module is configured to delete the target random number.

[0224] In an embodiment, the sending module can be further configured to send, to the authentication platform, a preset public key, a preset private key corresponding to the preset public key, and a user identity information identifier before sending the target random number to the authentication platform, so that the authentication platform stores the preset public key, the preset private key, and the user identity information identifier.

[0225] In an embodiment, the apparatus can further include:

[0226] The obtaining module is configured to obtain a personal identity identifier input by a user on the first terminal before generating the target random number corresponding to the transaction instruction.

[0227] The checking module is configured to check the personal identity identifier.

[0228] The generating module is configured to generate the target random number corresponding to the transaction instruction if the personal identity identifier passes the check.

[0229] The information processing apparatus provided by the embodiments of the present application can implement the various processes of the method embodiments, and thus repeated descriptions are omitted here. Figure 1

[0230] Based on the same inventive concept as the information processing method, the embodiments of the present application further provide an information processing apparatus applied to an authentication platform.

[0231] As shown in Figure 8 , the information processing apparatus 400 can include a receiving module 401, an encryption module 402, a decryption module 403, and a verification module 404.

[0232] ​The receiving module 401 is configured to receive a target random number sent by a SIM card of the first terminal, the target random number being generated by the first terminal in response to the target transaction instruction.

[0233] The receiving module 401 is further configured to receive a second character verification code sent by the second terminal, the second character verification code being generated by the second terminal by scanning the first character verification code displayed by the first terminal, the first character verification code corresponding to character verification code prototype information, the character verification code prototype information being obtained by encrypting a user identity information identifier and a secure environment identifier based on a target key by the first terminal, the target key being obtained by encrypting the target random number using a preset public key, and the second character verification code including the character verification code prototype information.

[0234] The encryption module 402 is configured to encrypt the target random number using a preset public key stored in advance to obtain a target key.

[0235] The decryption module 403 is configured to decrypt the character verification code prototype information using the target key to obtain the user identity information identifier and the secure environment identifier.

[0236] The verification module 404 is configured to verify the user identity information identifier and the secure environment identifier according to authentication information stored in advance to obtain a verification result, the authentication information including the user identity information identifier and the secure environment identifier corresponding to the SIM card of the first terminal.

[0237] The information processing device of the embodiment of the application is applied to an authentication platform, and can receive a target random number sent by a SIM card of a first terminal, the target random number being generated by the first terminal in response to a target transaction instruction. Then, a second character verification code sent by a second terminal can be received, the second character verification code being generated by the second terminal by scanning a first character verification code displayed by the first terminal, the first character verification code corresponding to character verification code prototype information, the character verification code prototype information being obtained by encrypting a user identity information identifier and a secure environment identifier based on a target key by the first terminal, the target key being obtained by encrypting the target random number using a preset public key, and the second character verification code including the character verification code prototype information. The character verification code prototype information contains authentication information of multiple dimensions and has high credibility, and thus the effectiveness of user identity authentication can be improved. Subsequently, the authentication platform can encrypt the target random number using a preset public key stored in advance to obtain the target key. In this way, the target key corresponding to a single transaction can be generated. In this way, the encryption key corresponding to each transaction is different, and even if the encryption key corresponding to a transaction is cracked, the encryption key of other transactions cannot be obtained through the cracked key, and the security of authentication is improved. Then, the character verification code prototype information can be decrypted using the target key to obtain the user identity information identifier and the secure environment identifier. The user identity information identifier and the secure environment identifier are verified according to pre-stored authentication information to obtain a verification result. The authentication information includes the user identity information identifier and the secure environment identifier corresponding to the SIM card of the first terminal. In this way, code brushing authentication can be realized through the interaction of the SIM card, the terminal and the platform, the risk of verification code leakage is reduced, and thus the security of code brushing authentication can be further improved.

[0238] In one embodiment, the verification module can be specifically configured to:

[0239] compare the user identity information identifier and the secure environment identifier with the user identity information identifier and the secure environment identifier in the authentication information.

[0240] in a case where the user identity information identifier and the secure environment identifier are consistent with the user identity information identifier and the secure environment identifier in the authentication information, determine that the verification is passed.

[0241] in a case where the user identity information identifier and the secure environment identifier are inconsistent with the user identity information identifier and the secure environment identifier in the authentication information, determine that the verification is not passed.

[0242] In one embodiment, the device can further include:

[0243] The sending module is configured to send the verification result to the second terminal and the SIM card of the first terminal respectively after verifying the user identity information identification code and the security environment identifier according to the pre-stored authentication information and obtaining a verification result.

[0244] The deleting module is configured to delete the target random number.

[0245] The information processing device provided by the embodiment of the application can realize Figure 1 The method embodiment realizes various processes, and thus details are not repeated here.

[0246] Figure 9 A hardware structure schematic diagram of an electronic device provided by the embodiment of the application is shown.

[0247] The electronic device can include a processor 501 and a memory 502 storing computer program instructions.

[0248] Specifically, the processor 501 can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of the embodiment of the application.

[0249] The memory 502 can include a mass storage for data or instructions. For example, but not limited to, the memory 502 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of the above. In appropriate cases, the memory 502 can include removable or non-removable (or fixed) media. In appropriate cases, the memory 502 can be internal or external to the integrated gateway disaster recovery device. In a specific embodiment, the memory 502 is a non-volatile solid state memory.

[0250] The memory can include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Therefore, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions and, when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.

[0251] The processor 501 implements the information processing or the information processing method in any of the above-described embodiments by reading and executing computer program instructions stored in the memory 502.

[0252] As an example, the electronic device can further include a communication interface 503 and the bus 510. As shown in the figure, the processor 501, the memory 502, and the communication interface 503 are connected through the bus 510 and complete communication with each other. Figure 9

[0253] The communication interface 503 is mainly used to realize the communication between the modules, devices, units and / or equipment in the embodiments of the present application.

[0254] The bus 510 includes hardware, software or both to couple components of the information processing device to each other. By way of example, and not limitation, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand (IB) interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or another suitable bus or a combination of two or more of these. Where appropriate, the bus 510 can include one or more buses. Although the present application describes and illustrates a particular bus, the present application contemplates any suitable bus or interconnect.

[0255] The electronic device can execute the information processing method in the embodiments of the present application, thereby realizing the information processing method and device described in combination with Figure 1 and Figures 7-8

[0256] In addition, in combination with the information processing method in the above-described embodiments, the embodiments of the present application can provide a computer storage medium to realize. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by the processor to realize any of the information processing methods in the above-described embodiments.

[0257] It needs to be clear that the present application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above-described embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between steps, after understanding the spirit of the present application.

[0258] ​​The functions noted in the description of the structural block diagrams above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, and the like. When implemented in software, the elements of the present application are program or code segments that are used to perform the required tasks. The program or code segments can be stored in a machine-readable medium, or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. A "machine-readable medium" includes any medium that can store or transport information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and the like. The code segments can be downloaded via computer networks such as the Internet, intranets, and the like.

[0259] It is also important to note that the examples mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the steps mentioned above, that is, the steps can be performed in the order mentioned in the examples, or in an order different from the examples, or several steps can be performed simultaneously.

[0260] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer program instructions can also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other processing device to operate in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks. The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer program instructions can also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other processing device to operate in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.

[0261] The above merely describes a specific implementation of the present application. Those skilled in the art can clearly understand the specific working processes of the system, modules and units described above for the convenience and brevity of description, and can refer to the corresponding processes in the foregoing method embodiments, which will not be described herein again. It should be understood that the protection scope of the present application is not limited to this, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application.

Claims

1. An information processing method, characterized in that, The method, applied to a user identification SIM card in a first terminal, includes: In response to a target transaction instruction, the system obtains the personal identification code input by the user on the first terminal; verifies the personal identification code; and generates a target random number corresponding to the target transaction instruction if the personal identification code passes the verification. The target random number is sent to the authentication platform, wherein the authentication platform has a preset public key and authentication information stored in advance, and the authentication information includes the user identity information identification code and security environment identifier corresponding to the SIM card of the first terminal; The target random number is encrypted using a preset public key to obtain the target key; The target key is used to encrypt the user identity information identification code and the security environment identifier to obtain the character verification code prototype information; The character verification code prototype information is sent to the first terminal so that the first terminal can display the first character verification code corresponding to the character verification code prototype information.

2. The method according to claim 1, characterized in that, Before encrypting the user identity information identification code and security environment identifier using the target key to obtain the character verification code prototype information, the method further includes: The preset identity information is encrypted using a session key to obtain the user identity information identification code, wherein the preset identity information includes a security environment identifier and / or biometric information.

3. The method according to claim 1 or 2, characterized in that, Sending the target random number to the authentication platform includes: The target random number encrypted with the preset public key is sent to the authentication platform, so that the authentication platform can use the preset private key to decrypt the target random number encrypted with the preset public key to obtain the target random number.

4. The method according to claim 1, characterized in that, Before sending the target random number to the authentication platform, the method further includes: The system sends the preset public key, the preset private key corresponding to the preset public key, and the user identity information identification code to the authentication platform for the authentication platform to store the preset public key, the preset private key, and the user identity information identification code.

5. The method according to claim 1, characterized in that, After sending the character verification code prototype information to the first terminal for the first terminal to display the first character verification code corresponding to the character verification code prototype information, the method further includes: The authentication platform receives a verification result sent by the authentication platform. The verification result is obtained by the authentication platform receiving a second character verification code sent by the second terminal and verifying the character verification code prototype information in the second character verification code. The second character verification code is obtained by the second terminal scanning the first character verification code displayed by the first terminal. Delete the target random number.

6. The method according to claim 5, characterized in that, After receiving the verification result of the character verification code prototype information from the authentication platform, the method further includes: The verification result is sent to the first terminal so that the first terminal can display the character corresponding to the verification result.

7. An information processing method, characterized in that, Applied to an authentication platform, the method includes: The system receives a target random number sent by the SIM card of the first terminal, wherein the target random number is generated by the first terminal in response to a target transaction instruction, obtaining a personal identification code input by the user on the first terminal; verifying the personal identification code; and generating the random number if the personal identification code passes the verification. The system receives a second character verification code sent by a second terminal. The second character verification code is generated by the second terminal scanning the first character verification code displayed by the first terminal. The first character verification code corresponds to the character verification code prototype information. The character verification code prototype information is obtained by the first terminal encrypting the user identity information identification code and the security environment identifier based on the target key. The target key is obtained by encrypting the target random number using a preset public key. The second character verification code includes the character verification code prototype information. The target random number is encrypted using the pre-stored preset public key to obtain the target key; The target key is used to decrypt the character verification code prototype information to obtain the user identity information identification code and security environment identifier. The user identity information identification code and security environment identifier are verified based on the pre-stored authentication information to obtain the verification result. The authentication information includes the user identity information identification code and security environment identifier corresponding to the SIM card of the first terminal.

8. The method according to claim 7, characterized in that, The step of verifying the user identity information identification code and security environment identifier based on pre-stored authentication information to obtain a verification result includes: The user identity information identification code and security environment identifier are compared with the user identity information identification code and security environment identifier in the authentication information; If the user identity information identification code and security environment identifier are consistent with the user identity information identification code and security environment identifier in the authentication information, the verification is deemed successful. If the user identity information identification code and security environment identifier are inconsistent with the user identity information identification code and security environment identifier in the authentication information, the verification is determined to be unsuccessful.

9. The method according to claim 7 or 8, characterized in that, After verifying the user identity information identification code and security environment identifier based on pre-stored authentication information and obtaining the verification result, the method further includes: The verification results are sent to the second terminal and the SIM card of the first terminal, respectively. Delete the target random number.

Citation Information

Patent Citations

  • Data interaction method, verifying terminal, server and system

    CN104836780A

  • Two-dimensional code generation method and device and two-dimensional code verification method and device

    CN109766979A