Cloud-based application login authentication methods, devices and electronic equipment

By generating and verifying random strings and random codes on a cloud phone platform, the problem of having to enter authentication information multiple times in cloud applications is solved, enabling a secure and fast login process and improving the user experience.

CN119853977BActive Publication Date: 2025-10-31CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411915831.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-10-31
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

Users need to enter authentication information multiple times in cloud-based applications, which affects the user experience.

Method used

The cloud phone platform generates the first verification information, which includes a random string and a random code. This information is then sent to the SIM card authentication center and the terminal for verification. The terminal interacts with the SIM card authentication center to ensure the legitimacy and security of the login object and avoid repeated input of authentication information.

Benefits of technology

It enables quick login for cloud-based applications, improves user experience, and ensures the security and legitimacy of login.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119853977B_ABST
    Figure CN119853977B_ABST
Patent Text Reader

Abstract

This application discloses a cloud application login authentication method, apparatus, and electronic device, belonging to the field of cloud application login technology. The method includes: receiving a first login request from a terminal to log in to a cloud application; generating first verification information based on the first login request; sending the first verification information to a SIM card authentication center and the terminal, so that the SIM card authentication center verifies second verification information sent by the cloud application platform based on the first verification information; receiving an interactive authentication request from the terminal; verifying the interactive data; and sending the verification result to the terminal, so that the terminal sends the verification result to the SIM card authentication center for verification, wherein the verification result includes a first random code and a first request identifier. Through the above method, quick login to cloud applications can be achieved, solving the user experience problem caused by the need to repeatedly enter authentication information when logging into cloud applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of cloud application login technology, specifically relating to a cloud application login authentication method, device, and electronic device. Background Technology

[0002] Cloud phones are virtual phones implemented in the cloud based on virtualization technology. When a user accesses a cloud phone through a client installed on a real device, the server will designate one of the cloud machines to connect with the client, allowing the user to experience the cloud phone just like operating a real device.

[0003] In related technologies, when a user logs into a cloud application by entering authentication information on a real device, they need to enter the authentication information again to log in to the same cloud application when opening it on a cloud device, which affects the user experience. Summary of the Invention

[0004] The purpose of this application is to provide a cloud application login authentication method, device, and electronic device that can solve the user experience problem caused by the need to enter authentication information multiple times when logging into cloud applications.

[0005] In a first aspect, embodiments of this application provide a cloud application login authentication method applied to a cloud phone platform. The method includes: receiving a first login request from a terminal to log in to a cloud application, wherein the first login request carries a second identifier of the cloud machine the terminal is logging into and a first application identifier of the cloud application; generating first verification information based on the first login request, wherein the first verification information includes a first random string, the first random string including a first identifier of the login object, a second identifier, the first application identifier, a first random code, and a first request identifier corresponding to the first login request; and sending the first verification information to a SIM card authentication center and the terminal, so that the SIM card authentication center can authenticate the user based on the first verification information. The system verifies the user's identity using second verification information sent by the cloud application platform. This second verification information includes a second random string, which comprises: a third identifier of the login object, a fourth identifier of the cloud machine the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. The system also receives an interactive authentication request sent by the terminal, which includes interactive data. The system verifies the interactive data and sends the verification result to the terminal, enabling the terminal to send the verification result to the SIM card authentication center for verification. The verification result includes the first random code and the first request identifier.

[0006] Secondly, this application provides a cloud application login authentication method applied to a SIM card authentication center. The method includes: receiving first verification information sent by a cloud mobile phone platform, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier of the cloud machine the terminal is logging into, a first application identifier of the cloud application the terminal requests to log into, a first random code, and a first request identifier corresponding to the first login request received by the cloud mobile phone platform; receiving second verification information sent by the cloud application platform, wherein the second verification information includes a second random string, the second random string including: a third identifier of the login object, a second random code, and a third random code. The authentication process includes: a fourth identifier for the cloud machine to log in; a second application identifier for the cloud application requesting login; a second random code; and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. Based on the first verification information, the second verification information is verified, and an authentication message is sent to the terminal. A login authentication request is received from the terminal, wherein the login authentication request carries a third random code and a third request identifier. If the first random code matches the third random code, an authentication result is sent to the cloud application platform, so that the cloud application can learn that the terminal is allowed to log in to the cloud application by polling the cloud application platform.

[0007] Thirdly, embodiments of this application provide a cloud application login method applied to a terminal. The method includes: responding to a login operation initiated by a login object on a cloud application, sending a first login request to a cloud phone platform, wherein the first login request carries a second identifier of the cloud machine the terminal is logging into and a first application identifier of the cloud application; receiving first verification information sent by the cloud phone platform, wherein the first verification information includes a first random string, which includes a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; sending the first verification information to the cloud application, causing the cloud application to send second verification information to the cloud application platform based on the first verification information, and the cloud application platform sending the second verification information to a SIM card authentication center for verification; sending an interactive authentication request to the cloud phone platform; receiving an authentication result sent by the cloud phone platform, wherein the authentication result includes a third random code and a third request identifier; and sending a login authentication request carrying the third random code and the third request identifier to the SIM card authentication center, causing the SIM card authentication center to verify the third random code based on the first random code.

[0008] Fourthly, this application provides a cloud application login authentication device applied to a cloud phone platform. The device includes: a first receiving module for receiving a first login request from a terminal to log in to a cloud application, wherein the first login request carries a second identifier of the cloud machine the terminal is logging into and a first application identifier of the cloud application; a generating module for generating first verification information based on the first login request, wherein the first verification information includes a first random string, which includes a first identifier of the login object, a second identifier, the first application identifier, a first random code, and a first request identifier corresponding to the first login request; and a first sending module for sending the first verification information to a SIM card authentication center and the terminal, so that the SIM card authentication center can, based on the first verification... The system verifies the second verification information sent by the cloud application platform. The second verification information includes a second random string, which comprises: a third identifier of the login object, a fourth identifier of the cloud machine the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. A second receiving module receives an interactive authentication request sent by the terminal, which includes interactive data. A second sending module verifies the interactive data and sends the verification result to the terminal, so that the terminal sends the verification result to the SIM card authentication center for verification. The verification result includes the first random code and the first request identifier.

[0009] Fifthly, this application provides a cloud-based application login authentication device applied to a SIM card authentication center. The device includes: a first receiving module for receiving first verification information sent by a cloud mobile phone platform, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier of the cloud machine the terminal is logging into, a first application identifier of the cloud application the terminal requests to log into, a first random code, and a first request identifier corresponding to the first login request received by the cloud mobile phone platform; and a second receiving module for receiving second verification information sent by the cloud application platform, wherein the second verification information includes a second random string, the second random string including: a third identifier of the login object, a first application identifier of the cloud application the login object is logging into, a first random code, and a first request identifier corresponding to the first login request received by the cloud mobile phone platform; and a second receiving module for receiving second verification information sent by the cloud application platform, wherein the second verification information includes a second random string, the second random string including: a third identifier of the login object, a first application identifier of the cloud application the login object is logging into, and a first application identifier of the cloud application the terminal is logging into. The cloud application includes a fourth identifier for the cloud machine, a second application identifier for the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. A first sending module is used to verify the second verification information based on the first verification information and send an authentication message to the terminal. A third receiving module is used to receive a login authentication request sent by the terminal, wherein the login authentication request carries a third random code and a third request identifier. A second sending module is used to send an authentication result to the cloud application platform when the first random code matches the third random code, so that the cloud application can learn that the terminal is allowed to log in to the cloud application by polling the cloud application platform.

[0010] Sixthly, this application provides a cloud application login device applied to a terminal. The device includes: a first sending module, configured to send a first login request to a cloud phone platform in response to a login operation initiated by a login object for a cloud application, wherein the first login request carries a second identifier of the cloud machine the terminal is logging into and a first application identifier of the cloud application; a first receiving module, configured to receive first verification information sent by the cloud phone platform, wherein the first verification information includes a first random string, the first random string including a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; and a second sending module. The system comprises four modules: a first module for sending the first verification information to the cloud application, which in turn sends the second verification information to the cloud application platform based on the first verification information; a second module for sending the second verification information to the SIM card authentication center for verification; a third module for sending an interactive authentication request to the cloud phone platform; a second module for receiving the authentication result sent by the cloud phone platform, wherein the authentication result includes a third random code and a third request identifier; and a fourth module for sending a login authentication request carrying the third random code and the third request identifier to the SIM card authentication center, which in turn verifies the third random code based on the first random code.

[0011] In a seventh aspect, embodiments of this application provide an electronic device including a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions, when executed by the processor, implementing the steps of the methods described in the first, second, or third aspects.

[0012] Eighthly, embodiments of this application provide a computer-readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first, second, or third aspect.

[0013] Ninthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the methods described in the first, second, or third aspects.

[0014] In a tenth aspect, embodiments of this application provide a computer program product, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the method as described in the first aspect, the second aspect, or the third aspect.

[0015] In this embodiment, the cloud phone platform can receive a first login request from the terminal to log in to a cloud-based application. Based on the first login request, it can generate first verification information including a first random string. This first verification information is then sent to the SIM card authentication center and the terminal. The SIM card authentication center then verifies the second verification information sent by the cloud-based application platform based on the first verification information. Finally, based on an interactive authentication request, it sends a first random code and a first request identifier to the terminal, which then forwards them to the SIM card authentication center for verification. By verifying the first random string and the first random code in the first verification information, the security and legitimacy of the login to the cloud-based application can be guaranteed, enabling quick login to the cloud-based application, avoiding repeated input of usernames and passwords, and improving user experience. Attached Figure Description

[0016] Figure 1 The sequence diagram of login authentication for cloud-based applications in related technologies is shown;

[0017] Figure 2 This illustration shows a flowchart of a cloud application login authentication method provided in an embodiment of this application;

[0018] Figure 3 This diagram illustrates the data structure of random strings and random encrypted strings provided in the embodiments of this application.

[0019] Figure 4 This illustration shows a flowchart of another cloud-based application login authentication method provided in an embodiment of this application;

[0020] Figure 5 This diagram illustrates a timing diagram of cloud application registration provided in an embodiment of this application.

[0021] Figure 6 This illustration shows a flowchart of a cloud application login method provided in an embodiment of this application;

[0022] Figure 7 A schematic diagram of the graphical verification code provided in the embodiments of this application is shown;

[0023] Figure 8 This diagram illustrates the interaction between the various modules provided in the embodiments of this application.

[0024] Figure 9 This diagram illustrates the timing of random string generation by the cloud mobile phone platform provided in an embodiment of this application.

[0025] Figure 10 This diagram illustrates a timing sequence of a cloud-based application displaying a mobile phone number, as provided in an embodiment of this application.

[0026] Figure 11This shows a timing diagram of the SIM card authentication center comparing random encrypted strings according to an embodiment of this application;

[0027] Figure 12 A timing diagram illustrating user interaction provided in an embodiment of this application is shown;

[0028] Figure 13 This document illustrates a timing diagram of the SIM card authentication center comparing random codes according to an embodiment of this application.

[0029] Figure 14 This diagram illustrates the structure of a cloud-based application login authentication device according to an embodiment of this application.

[0030] Figure 15 This diagram illustrates the structure of another cloud-based application login authentication device provided in an embodiment of this application.

[0031] Figure 16 This diagram illustrates the structure of a cloud-based application login device according to an embodiment of this application.

[0032] Figure 17 This illustration shows a structural block diagram of an electronic device provided by an exemplary embodiment of this application. Detailed Implementation

[0033] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0034] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0035] Cloud phones are virtual phones implemented in the cloud based on virtualization technology. A cloud server manages multiple virtualized containers, each running a customized Android operating system. Each container is a cloud machine, and combined with hardware emulation capabilities, the cloud machine's functionality is essentially the same as a real device. Users access the cloud phone through a client installed on their real device. The server then designates one of the cloud machines to connect with the client, allowing users to experience the cloud phone just like operating a real device.

[0036] In related technologies, users enter authentication information on a cloud phone client and successfully log in to the cloud machine. When opening applications within the cloud machine, they need to enter authentication information again to access the application's account system and obtain user information. Each application requiring login in the cloud machine necessitates additional authentication information input, impacting user experience. A specific timing diagram is shown below. Figure 1 As shown.

[0037] Because cloud servers are virtual environments, current quick login methods, such as one-click login with a mobile phone number, require the hardware capabilities of a physical machine. Currently, there is a lack of relevant technologies to enable quick login on cloud servers.

[0038] The cloud-based application login authentication scheme provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0039] Figure 2 This illustration shows a flowchart of a cloud application login authentication method provided in an exemplary embodiment of this application. (As shown...) Figure 2 As shown, the method mainly includes the following steps:

[0040] S201: Receive the first login request sent by the terminal to log in to the cloud application.

[0041] The first login request includes: the second identifier of the cloud machine to which the terminal is logging in, and the first application identifier of the cloud application.

[0042] In this embodiment, the cloud phone platform can receive a first login request sent by the terminal. The first login request instructs the login target to log in to the cloud application through the terminal. The first login request carries a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application. The first identifier can be used to identify the login target; in practical applications, it can be the user's mobile phone number. The second identifier can be used to identify the cloud machine to which the terminal is logging in; in practical applications, it can be the cloud machine's identity document (ID). The first application identifier can be used to identify the cloud application; in practical applications, it can be the application (App) ID. In this embodiment, the APP ID is generated by the SIM card authentication center based on the cloud application's package name information, etc., during cloud application registration.

[0043] In an optional implementation, before the cloud phone platform receives the first login request from the terminal to log in to the cloud-based application, the method further includes:

[0044] The cloud phone platform receives a second login request sent by the terminal to log in to the cloud phone platform, wherein the second login request carries a first identifier and authentication information of the login object;

[0045] If the first identifier and the authentication information are successfully authenticated, the cloud mobile platform returns a login success response to the terminal.

[0046] In this embodiment, the cloud phone platform can receive a second login request sent by the terminal for logging into the cloud phone platform. The second login request carries a first identifier and authentication information of the login object. If the first identifier and authentication information are successfully authenticated, the cloud phone platform can return a login success response to the terminal. This can verify the login object's login to the cloud phone platform, help confirm the legitimacy of the login object, and ensure the security of privacy data.

[0047] S202: Generate first verification information based on the first login request.

[0048] The first verification information includes a first random string, which includes a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request.

[0049] In this embodiment, the cloud phone platform can generate first verification information based on a first login request. The first verification information includes a first random string, which comprises: a first identifier (which may be a mobile phone number), a second identifier (which may be a cloud machine ID), a first application identifier (which may be an APP ID), a first random code, and a first request identifier corresponding to the first login request. In this embodiment, the first random code is a randomly generated set of characters, which may consist of numbers, special characters, and uppercase and lowercase letters, and can be used for authentication verification. The first request identifier is an identifier for the terminal to obtain the first verification information once. In practical applications, the first random string may also include a timestamp and a verification code. The timestamp is a digital identifier generated from the current time and can be used to verify the timeliness of the first random string. The verification code is a digest generated by concatenating the first identifier, the second identifier, the first application identifier, the first random code, the first request identifier, and the timestamp, and can be used to verify the first random string. The first verification information can be used to verify the login object, the terminal, and the cloud application, ensuring the security of the login object logging into the cloud application through the cloud machine connected to the terminal.

[0050] In one optional implementation, the cloud phone platform generates first verification information based on the first login request, including:

[0051] Based on the first login request, obtain the first identifier of the login object;

[0052] Obtain the public key corresponding to the SIM card authentication center;

[0053] The first random string is generated based on the first login request;

[0054] The first random string generated is encrypted using the public key to obtain the first verification information.

[0055] In this embodiment, the cloud phone platform can obtain the first identifier of the login object based on the first login request, and then obtain the public key corresponding to the SIM card authentication center. This public key can be a pre-set, publicly available public key of the SIM card authentication center. Then, based on the public key, the first random string is encrypted using asymmetric encryption to generate the first random encrypted string corresponding to the first random string, i.e., the first verification information. The data structures of the random string and the random encrypted string are as follows: Figure 3 As shown. Encryption ensures the security of the first random string.

[0056] S203: The first verification information is sent to the SIM card authentication center and the terminal, so that the SIM card authentication center verifies the second verification information sent by the cloud application platform based on the first verification information. The second verification information includes a second random string, which includes: a third identifier of the login object, a fourth identifier of the cloud machine the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform.

[0057] In this embodiment, the cloud phone platform can send the first verification information to the SIM card authentication center and the terminal, so that the SIM card authentication center can verify the second verification information sent by the cloud application platform based on the first verification information. The second verification information includes a second random string, the data structure of which is consistent with the first random string. The second random string is received from the terminal and sent to the cloud application platform by the cloud application. This allows the transmission of the first verification information, which helps verify the legitimacy of the login object's login to the cloud application.

[0058] In an optional implementation, sending the first verification information to the SIM card authentication center and the terminal includes:

[0059] The first verification information is sent to the SIM card authentication center so that the SIM card authentication center can verify the first random string in the first verification information;

[0060] Receive the verification result sent by the SIM card authentication center;

[0061] If the verification result is that the verification is passed, the first verification information is sent to the terminal, wherein the first verification information also includes interactive information.

[0062] In this embodiment, the first verification information can be sent to the SIM card authentication center, allowing the SIM card authentication center to verify the first random string in the first verification information; then, the verification result sent by the SIM card authentication center is received; if the verification result is successful, the first verification information is sent to the terminal, wherein the first verification information also includes interactive information. This ensures the integrity and validity of the first verification information.

[0063] S204: Receive the interactive authentication request sent by the terminal.

[0064] The interactive authentication request includes interactive data.

[0065] In this embodiment of the application, the cloud phone platform can receive an interactive authentication request carrying interactive data sent by the terminal.

[0066] S205: Verify the interactive data and send the verification result to the terminal so that the terminal sends the verification result to the SIM card authentication center for verification.

[0067] The verification result includes the first random code and the first request identifier.

[0068] In this embodiment, the first verification information may further include interactive information, such as a graphical verification code, a slider confirmation, or the selection of a certain type of image. This embodiment does not impose specific limitations. When the interactive information is a graphical verification code, the cloud phone platform can concatenate the phone number, APP ID, and cloud machine ID with colons, process them using the MD5 algorithm to generate M, and randomly generate a string S composed of alphanumeric characters. EasyCaptcha is then used to convert S into an image object, simultaneously establishing a mapping relationship between M and S. Subsequently, the base64 string of the image is sent to the cloud phone client as interactive information.

[0069] After sending the initial verification information to the terminal, the cloud phone platform can receive interactive authentication requests from the terminal. These requests include interactive data. The cloud phone platform then verifies the interactive data based on the corresponding interactive verification information and sends the authentication result back to the terminal. The authentication result includes a first random code from a pre-generated first random string and a first request identifier, facilitating the terminal's transmission of this result to the SIM card authentication center for verification. This not only ensures the legitimacy of the login object through interaction but also further guarantees the security of logging into cloud-based applications.

[0070] In this embodiment, the cloud phone platform can receive a first login request from a terminal to log in to a cloud-based application. Based on the first login request, it can generate first verification information including a first random string. This first verification information is then sent to the SIM card authentication center and the terminal. The SIM card authentication center then verifies the second verification information sent by the cloud application platform based on the first verification information. Finally, based on the terminal's interactive authentication request, the platform sends a first random code and a first request identifier to the terminal, which then forwards them to the SIM card authentication center for verification. This method, by verifying various aspects of the information through the first random string in the first verification information and verifying the first random code, ensures the security and legitimacy of the login to the cloud application, avoids repeated input of usernames and passwords, enables quick login to the cloud application, and improves the user experience.

[0071] Figure 4 This illustration shows a flowchart of another cloud-based application login authentication method provided by an exemplary embodiment of this application, applied to a SIM card authentication center, such as... Figure 4 As shown, the method mainly includes the following steps:

[0072] S401: Receives the first verification information sent by the cloud phone platform.

[0073] The first verification information includes a first random string, which includes: a first identifier of the login object, a second identifier of the cloud machine to which the terminal is logging in, a first application identifier of the cloud application to which the terminal requests login, a first random code, and a first request identifier corresponding to the first login request received by the cloud mobile platform.

[0074] In this embodiment, the SIM card authentication center can provide a unified login authentication service for cloud-based applications. The SIM card authentication center can receive first verification information sent by the cloud phone platform. This first verification information includes a first random string, which comprises: a first identifier of the login object, a second identifier of the cloud machine the terminal is logging into, a first application identifier of the cloud application the terminal is requesting to log into, a first random code, and a first request identifier corresponding to the first login request received by the cloud phone platform. Receiving the first verification information sent by the cloud phone platform can be used to confirm the legitimacy of the login object's login to the cloud-based application.

[0075] Figure 5 This diagram illustrates a sequence of events for cloud application registration provided in this embodiment. In response to an application registration request from a cloud phone platform, the SIM card authentication center generates an application APPID and key based on information such as the package name, and returns the generated APPID and key to the cloud phone platform. In practical applications, cloud application developers apply to the cloud phone platform to cloudify their applications, submitting information such as the application installation package, application package name, and application signature. The cloud phone platform pushes the application installation package to a cloud machine, which then installs the application. The cloud phone platform then registers the application with the SIM card authentication center. The SIM card authentication center generates an application APPID and key based on information such as the package name and returns the generated APPID and key to the cloud phone platform, which then provides the APPID and key to the cloud application vendor. It is important to note that the key issued to the application is used by the cloud application platform to request the SIM card authentication center; their previous requests need to be protected and are different from the encryption and decryption keys used in subsequent login processes. In an optional implementation, the first random string further includes a first verification code; after the SIM card authentication center receives the first verification information sent by the cloud phone platform, the method further includes:

[0076] The SIM card authentication center verifies the integrity of the first random string based on the first verification code, and saves the first verification information after the verification is successful.

[0077] In this embodiment, the SIM card authentication center can establish a mapping relationship between the first request identifier and the first random string. By verifying the first random string, the validity of the first random string can be guaranteed, erroneous first verification information can be avoided, and transmission efficiency and security can be improved.

[0078] S402: Receive the second verification information sent by the cloud application platform.

[0079] The second verification information includes a second random string, which includes: the third identifier of the login object, the fourth identifier of the cloud machine that the login object is logging into, the second application identifier of the cloud application requesting login, the second random code, and the second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform.

[0080] In this embodiment, the SIM card authentication center can receive second verification information sent by the cloud application platform. The second verification information includes a second random string, which comprises: a third identifier of the login object, a fourth identifier of the cloud machine the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. The second verification information received by the SIM card authentication center from the cloud application platform can be used to further confirm the legitimacy of the login object's login to the cloud application.

[0081] S403: Verify the second verification information based on the first verification information, and send an authentication message to the terminal.

[0082] In an optional implementation, verifying the second verification information based on the first verification information and sending an authentication message to the terminal may include the following steps:

[0083] Step 1: If the second request identifier matches the first request identifier, the SIM card authentication center obtains the first random string corresponding to the first request identifier.

[0084] In this embodiment, after receiving the second verification information sent by the cloud application platform, the SIM card authentication center can decrypt the second verification information using a private key. First, it verifies whether the cloud application platform matches the APPID in the second random string. Then, it checks whether a first request identifier is stored that matches the second request identifier in the second random string. If the second request identifier matches the first request identifier, the SIM card authentication center can obtain the first random string corresponding to the first request identifier.

[0085] Step 2: If the first random string matches the second random string, the SIM card authentication center sends an authentication message to the terminal corresponding to the first identifier.

[0086] The authentication message includes the second identifier and the first application identifier.

[0087] In this embodiment, if the first random string matches the second random string, the SIM card authentication center can send an authentication message to the terminal corresponding to the first identifier. The authentication message includes the second identifier (cloud machine ID) and the first application identifier (APP ID). If the first random string does not match the second random string, it indicates that the login process may have errors, be under attack, or be insecure. In this case, no authentication message can be sent, preventing login to the cloud application. The authentication message facilitates further interaction by the terminal, improving the efficiency of quick login.

[0088] S404: Receive the login authentication request sent by the terminal.

[0089] The login authentication request includes a third random code and a third request identifier.

[0090] S405: If the first random code matches the third random code, send the authentication result to the cloud application platform so that the cloud application can learn by polling the cloud application platform that the terminal is allowed to log in to the cloud application.

[0091] In this embodiment, the SIM card authentication center can receive a login authentication request sent by a terminal. The login authentication request carries a third random code and a third request identifier. If the first random code in the first random string corresponding to the third request identifier matches the third random code, the SIM card authentication center can send an authentication result to the cloud application platform. This allows the cloud application to learn that the terminal is allowed to log in by polling the cloud application platform. The SIM card authentication center can decrypt the request ID and random code using its private key. It can then find the random code stored by the SIM card authentication center using the request ID and compare this random code with the random code returned by the terminal's SIM module. If the comparison is successful, authentication is successful, and the cloud application platform is notified of the authentication result. After each comparison, the SIM card authentication center needs to delete the relevant information of the stored first random string to avoid information leakage and to save storage resources.

[0092] In this embodiment, the SIM card authentication center can receive first verification information sent by the cloud phone platform, then receive second verification information sent by the cloud application platform, verify the second verification information based on the first verification information, send an authentication message to the terminal, and then receive a login authentication request sent by the terminal. The login authentication request carries a third random code and a third request identifier. If the first random code matches the third random code, an authentication result is sent to the cloud application platform, allowing the cloud application to learn that the terminal is allowed to log in to the cloud application by polling the cloud application platform. This verifies the security and validity of the terminal's login to the cloud application, improving the user experience.

[0093] Figure 6 This illustration shows a flowchart of a cloud application login method provided in an exemplary embodiment of this application, applied to a terminal. The terminal can be an electronic device such as a mobile phone. Figure 6 As shown, the method mainly includes the following steps:

[0094] S601: In response to the login operation initiated by the login object to the cloud application, a first login request is sent to the cloud phone platform. The first login request carries: a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application.

[0095] In this embodiment, in response to a login operation initiated by the login object to a cloud application, the terminal can send a first login request to the cloud phone platform. The first login request carries: a first identifier of the login object (which may be the login object's mobile phone number), a second identifier of the cloud machine the terminal is logging into (which may be the cloud machine ID), and a first application identifier of the cloud application (which may be the APP ID). This eliminates the need for the login object to input authentication information, facilitating quick login to the cloud application.

[0096] S602: Receive the first verification information sent by the cloud mobile phone platform.

[0097] The first verification information includes a first random string, which includes a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request.

[0098] In this embodiment, the terminal can receive first verification information sent by the cloud phone platform based on the first login request.

[0099] In an optional implementation, after receiving the first verification information sent by the cloud phone platform, the method further includes:

[0100] Send the first identifier to the cloud application so that the cloud application displays the first identifier;

[0101] In response to the confirmation operation of the first identifier displayed by the cloud application, a confirmation message is sent to the cloud application to trigger the cloud application to send the second verification message to the cloud application platform.

[0102] In this embodiment, after receiving the first verification information sent by the cloud phone platform, the terminal can send a first identifier (the login target's mobile phone number) to the cloud application, causing the cloud application to display the first identifier. Then, in response to the confirmation operation of the first identifier displayed by the cloud application, the terminal sends confirmation information to the cloud application, triggering the cloud application to send second verification information to the cloud application platform. This allows the login target to confirm their mobile phone number without needing to enter additional authentication information, thus improving the user experience.

[0103] S603: Send the first verification information to the cloud application, so that the cloud application sends the second verification information to the cloud application platform based on the first verification information, and the cloud application platform sends the second verification information to the SIM card authentication center for verification.

[0104] In this embodiment, the terminal can send a first random string to the cloud application, which then sends second verification information to the cloud application platform based on the first random string. The cloud application platform then sends the second verification information to the SIM card authentication center for verification. This verifies the legitimacy of the terminal's login to the cloud application, helps avoid repeated input of verification information, and improves the user experience.

[0105] S604: Send an interactive authentication request to the cloud phone platform.

[0106] S605: Receive the authentication result sent by the cloud mobile phone platform.

[0107] The authentication result includes: a third random code and a third request identifier.

[0108] S606: Send a login authentication request carrying a third random code and a third request identifier to the SIM card authentication center, so that the SIM card authentication center can verify the third random code based on the first random code.

[0109] In this embodiment, the terminal can receive an authentication message sent by the SIM card authentication center, wherein the authentication message includes a second identifier and a first application identifier. In practical applications, after receiving the first verification information sent by the cloud phone platform, the terminal can notify the Subscriber Identification Module (SIM) Software Development Kit (SDK) to start polling to query the message issued by the SIM card authentication center. After sending the first random string to the cloud application, it can receive the authentication message sent by the SIM card authentication center, which helps to quickly receive the authentication message. The authentication message allows for further operations, improving login efficiency.

[0110] In an optional implementation, the first verification information further includes: interaction information; sending an interaction authentication request to the cloud phone platform includes:

[0111] Based on the interactive information, an interactive page is displayed;

[0112] In response to an input operation on the interactive page, an interaction authentication request is sent to the cloud phone platform, wherein the interaction authentication request includes interaction data; in this embodiment, the first verification information further includes: interaction information, which in this embodiment can be a graphic verification code, a slider confirmation, or selection of a certain type of image. A schematic diagram of the graphic verification code is shown below. Figure 7 As shown, the terminal can display an interactive page based on the interactive information; then, in response to input operations on the interactive page, it sends an interactive authentication request to the cloud phone platform, where the interactive authentication request includes interactive information and interactive information to be authenticated; then, it receives the authentication result sent by the cloud phone platform, where the authentication result includes a third random code and a third request identifier; finally, it can send the third random code and the third request identifier to the SIM card authentication center so that the SIM card authentication center can verify the third random code and the third request identifier. Through interaction, the legality of the random string can be guaranteed.

[0113] In this embodiment, the terminal can respond to a login operation initiated by the login object on a cloud application by sending a first login message to the cloud phone platform; then receiving first verification information sent by the cloud phone platform; finally sending a first random string to the cloud application, so that the cloud application sends second verification information to the cloud application platform based on the first random string. The cloud application platform then sends the second verification information to the SIM card authentication center for verification. The terminal can then send an interactive authentication request to the cloud phone platform; receive the authentication result sent by the cloud phone platform, wherein the authentication result includes a third random code and a third request identifier; finally, sending a login authentication request carrying the third random code and the third request identifier to the SIM card authentication center, so that the SIM card authentication center verifies the third random code based on the first random code. This avoids repeatedly entering authentication information, enabling the login object to quickly log in to the cloud application and improving the user experience.

[0114] Figure 8 This illustration shows a schematic diagram of module interaction provided in an embodiment of this application, which includes five modules: a cloud phone platform, a SIM card authentication center, a cloud application platform, a cloud device, and a physical device (terminal). The physical device is equipped with a cloud phone client and a system SIM module. The cloud phone client includes a client-side SDK and a SIM SDK. The cloud device is equipped with cloud applications, a cloud-side proxy, and a cloud-side SDK.

[0115] In this embodiment, the cloud phone platform can process cloud phone operation data and business data, and also connect with third-party partners to perform actions such as... Figure 2 The cloud application login authentication method shown has the following main functions: (1) providing an application cloud application application entry and returning the application ID and application key issued by the SIM card authentication center to the application provider; (2) pushing the cloud application installation package to the cloud machine; (3) registering application information and sending a random password to the SIM card authentication center; (4) creating a random password and completing the user authentication interaction with the cloud mobile client.

[0116] In this embodiment of the application, the SIM card authentication center can provide unified login authentication services for cloud-based applications, and can perform actions such as... Figure 4 The cloud application login authentication method shown has the following main functions: (1) It is responsible for sending SIM authentication messages to the SIM module of the real device system and obtaining the random code and request ID sent by the SIM module; (2) It is responsible for verifying the validity of the random password sent by the cloud mobile phone platform; (3) It is responsible for comparing and verifying the random password of the cloud mobile phone platform with the random password of the cloud application platform; (4) It is responsible for comparing and verifying the random code fed back by the SIM module with the random code of the cloud application platform; (5) It is responsible for notifying the cloud application platform of the login authentication result.

[0117] In this embodiment of the application, the real device can perform the following: Figure 6The cloud-based application login authentication method includes a cloud phone client on the real device. Users can complete identity authentication through the cloud phone client, enter the cloud device, and operate it. Its main functions include: receiving user-input authentication information and initiating a login authentication request to the cloud phone platform; interacting with the client-side SDK to transmit the phone number and random password information; interacting with the SIM SDK to transmit random codes, request IDs, etc.; and rendering the user interface after receiving SIM card authentication information. The real device may also include a client-side SDK: an SDK embedded in the cloud phone client, responsible for communicating with the cloud-side SDK and building a communication bridge between the cloud phone client and the cloud device. The real device may also include a SIM SDK: an SDK embedded in the cloud phone client, responsible for interacting with the system SIM module and transmitting data between the cloud phone platform and the SIM card authentication center. The real device may also include a SIM card module, a system-integrated module responsible for receiving SIM card messages from the SIM card authentication center.

[0118] In this embodiment, the cloud machine is a virtual mobile phone as seen by the user, running an Android operating system and containing various applications, including system applications and third-party cloud-based applications. The cloud-side SDK is responsible for communicating with the client-side SDK within the cloud machine, transmitting data between the cloud phone client and the cloud machine. The cloud-side proxy is a system application installed within the cloud machine, responsible for building a communication bridge between the cloud-side SDK and the cloud-based applications.

[0119] And cloud-based applications: These are applications provided by third-party partners that run on cloud machines. Their main functions include: (1) calling the cloud-side agent to obtain the real mobile phone number and random password; (2) sending login authentication requests to the cloud-based application platform; and (3) sending polling requests to the cloud-based application platform to query quick login results.

[0120] In this embodiment of the application, the cloud application platform can process login authentication request data sent by the cloud application client. Its main functions are: (1) to process login authentication requests sent by the cloud application; (2) to send SIM card login authentication requests to the SIM card authentication center; and (3) to receive login result information from the SIM card authentication center.

[0121] Figures 9 to 13 This is a timing diagram for implementing quick login for cloud applications provided in an embodiment of this application. Figure 9 This diagram illustrates the timing of random string generation by the cloud mobile phone platform provided in an embodiment of this application. Figure 10 This diagram illustrates a timing sequence of a cloud-based application displaying a mobile phone number, as provided in an embodiment of this application. Figure 11 This shows a timing diagram of the SIM card authentication center comparing random encrypted strings according to an embodiment of this application; Figure 12 A timing diagram illustrating user interaction provided in an embodiment of this application is shown; Figure 13 This diagram illustrates the timing of the SIM card authentication center comparing random codes according to an embodiment of this application.

[0122] Figure 14 This illustration shows a schematic diagram of the structure of a cloud application login authentication device provided in an exemplary embodiment of this application. This cloud application login authentication device can achieve the following: Figure 2 The cloud application login authentication device, as shown in all or part of the embodiments, includes: a first receiving module 1401, a generating module 1402, a first sending module 1403, a second receiving module 1404, and a second sending module 1405.

[0123] In this embodiment, the first receiving module 1401 is used to receive a first login request from a terminal to log in to a cloud application, wherein the first login request carries a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application; the generating module 1402 is used to generate first verification information based on the first login request, wherein the first verification information includes a first random string, the first random string including a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; the first sending module 1403 is used to send the first verification information to the SIM card authentication center and the terminal, so that the SIM card authentication center sends a second login request to the cloud application platform based on the first verification information. The verification information is verified, wherein the second verification information includes a second random string, which includes: a third identifier of the login object, a fourth identifier of the cloud machine logged in by the login object, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. The second receiving module 1404 is used to receive the interactive authentication request sent by the terminal, wherein the interactive authentication request includes interactive data. The second sending module 1405 is used to verify the interactive data and send the verification result to the terminal, so that the terminal sends the verification result to the SIM card authentication center for verification, wherein the verification result includes the first random code and the first request identifier. In an optional implementation, when the first sending module 1403 is used to send the first verification information to the SIM card authentication center and the terminal, it is specifically used for:

[0124] The first verification information is sent to the SIM card authentication center so that the SIM card authentication center can verify the first random string in the first verification information;

[0125] Receive the verification result sent by the SIM card authentication center;

[0126] If the verification result is that the verification is passed, the first verification information is sent to the terminal, wherein the first verification information also includes interactive information.

[0127] In an optional implementation, when generating the first verification information based on the first login request, the generation module 1402 is specifically used for:

[0128] Based on the first login request, obtain the first identifier of the login object;

[0129] Obtain the public key corresponding to the SIM card authentication center;

[0130] The first random string is generated based on the first login request;

[0131] The first random string generated is encrypted using the public key to obtain the first verification information.

[0132] In an alternative implementation, the first receiving module 1401 is further configured to:

[0133] The terminal sends a second login request to log in to the cloud mobile platform, wherein the second login request carries a first identifier and authentication information of the login object;

[0134] If the first identifier and the authentication information are successfully authenticated, a login success response is returned to the terminal.

[0135] The cloud-based application login authentication device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the device.

[0136] The cloud-based application login authentication device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.

[0137] The cloud application login authentication device provided in this application embodiment can achieve... Figure 2 To avoid repetition, the various processes implemented in the method embodiment shown will not be described again here.

[0138] Figure 15 This illustration shows a schematic diagram of the structure of a cloud application login authentication device provided in an exemplary embodiment of this application. This cloud application login authentication device can achieve the following: Figure 4 As shown in all or part of the embodiments, the cloud application login authentication device includes: a first receiving module 1501, a second receiving module 1502, a first sending module 1503, a third receiving module 1504, and a second sending module 1505.

[0139] In this embodiment, the first receiving module 1501 is used to receive first verification information sent by the cloud phone platform, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier of the cloud machine logged in by the terminal, a first application identifier of the cloud application requested by the terminal, a first random code, and a first request identifier corresponding to the first login request received by the cloud phone platform; the second receiving module 1502 is used to receive second verification information sent by the cloud application platform, wherein the second verification information includes a second random string, the second random string including: a third identifier of the login object, a fourth identifier of the cloud machine logged in by the login object, and a first application identifier of the cloud application requested by the terminal. The system comprises three components: a second application identifier, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. A first sending module 1503 is used to verify the second verification information based on the first verification information and send an authentication message to the terminal. A third receiving module 1504 is used to receive a login authentication request sent by the terminal, wherein the login authentication request carries a third random code and a third request identifier. A second sending module 1505 is used to send an authentication result to the cloud application platform when the first random code matches the third random code, so that the cloud application can learn that the terminal is allowed to log in to the cloud application by polling the cloud application platform.

[0140] In an optional implementation, when the first sending module 1503 verifies the second verification information based on the first verification information and sends an authentication message to the terminal, it is specifically used for:

[0141] If the second request identifier matches the first request identifier, the SIM card authentication center obtains the first random string corresponding to the first request identifier;

[0142] If the first random string matches the second random string, the SIM card authentication center sends an authentication message to the terminal, wherein the authentication message includes the second identifier and the first application identifier.

[0143] In an optional implementation, the first random string further includes a first checksum; the first receiving module 1501 is further configured to:

[0144] The SIM card authentication center verifies the integrity of the first random string based on the first verification code, and saves the first verification information after the verification is successful.

[0145] Establish a mapping relationship between the first random string and the first request identifier.

[0146] In an optional implementation, the second receiving module 1502 is further configured to establish a mapping relationship between the second request identifier and the second random code.

[0147] The cloud-based application login authentication device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the device.

[0148] The cloud-based application login authentication device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.

[0149] The cloud application login authentication device provided in this application embodiment can achieve... Figure 4 To avoid repetition, the various processes implemented in the method embodiment shown will not be described again here.

[0150] Figure 16 This illustration shows a schematic diagram of the structure of a cloud application login device provided in an exemplary embodiment of this application. This cloud application login device can achieve the following: Figure 6 As shown in all or part of the embodiments, the cloud application login device includes: a first sending module 1601, a first receiving module 1602, a second sending module 1603, a third sending module 1604, a second receiving module 1605, and a fourth sending module 1606.

[0151] In this embodiment, the first sending module 1601 is used to send a first login request to the cloud phone platform in response to a login operation initiated by the login object to the cloud application. The first login request carries a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application. The first receiving module 1602 is used to receive first verification information sent by the cloud phone platform. The first verification information includes a first random string, which includes a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request. The second sending module 1603 is used to send a... The system comprises: a first verification information module 1604, a second receiving module 1605, and a fourth sending module 1606, which sends a login authentication request carrying the third random code and the third request identifier to the SIM card authentication center. The first verification information is used to enable the cloud application to send a second verification information to the cloud application platform, and the cloud application platform then sends the second verification information to the SIM card authentication center for verification.

[0152] In an optional implementation, the second sending module 1603 is further configured to:

[0153] Send the first identifier to the cloud application so that the cloud application displays the first identifier;

[0154] In response to the confirmation operation of the first identifier displayed by the cloud application, a confirmation message is sent to the cloud application to trigger the cloud application to send the second verification message to the cloud application platform.

[0155] In an optional implementation, the second receiving module 1605 is further configured to:

[0156] The system receives an authentication message sent by the SIM card authentication center, wherein the authentication message includes the second identifier and the first application identifier.

[0157] In an optional implementation, the first verification information further includes: interaction information; when the third sending module 1604 sends an interaction authentication request to the cloud phone platform, it is specifically used for:

[0158] Based on the interactive information, an interactive page is displayed;

[0159] In response to an input operation on the interactive page, an interaction authentication request is sent to the cloud phone platform, wherein the interaction authentication request includes the interaction information and the interaction information to be authenticated;

[0160] The cloud application login device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the device.

[0161] The cloud-based application login authentication device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.

[0162] The cloud application login device provided in this application embodiment can achieve... Figure 6 To avoid repetition, the various processes implemented in the method embodiment shown will not be described again here.

[0163] Optionally, such as Figure 17 As shown, this application embodiment also provides an electronic device 1700, including a processor 1701 and a memory 1702. The memory 1702 stores a program or instructions that can run on the processor 1701. When the program or instructions are executed by the processor 1701, they implement the various steps of the above method embodiments and can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0164] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.

[0165] This application also provides a computer-readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described method embodiments and achieve the same technical effects. To avoid repetition, these will not be described again here.

[0166] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0167] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above method embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0168] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0169] This application provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, which, when executed by a computer, cause the computer to perform the various processes described in the above method embodiments and achieve the same technical effect. To avoid repetition, these will not be repeated here.

[0170] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples. Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, hardware is also possible, but in many cases the former is a preferred implementation. Based on this understanding, the technical solution of this application, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0171] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. A cloud-based application login authentication method, applied to a cloud mobile phone platform, characterized in that, include: The receiving terminal sends a first login request to log in to a cloud application, wherein the first login request carries a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application; Based on the first login request, first verification information is generated, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; The first verification information is sent to the SIM card authentication center and the terminal, so that the SIM card authentication center can verify the second verification information sent by the cloud application platform based on the first verification information. The second verification information includes a second random string, which includes: a third identifier of the login object, a fourth identifier of the cloud machine that the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. Receive an interactive authentication request sent by the terminal, wherein the interactive authentication request includes interactive data; The interactive data is verified, and the verification result is sent to the terminal so that the terminal sends the verification result to the SIM card authentication center for verification. The verification result includes the first random code and the first request identifier.

2. The method according to claim 1, characterized in that, Before the first login request for the cloud application sent by the receiving terminal, the method further includes: The terminal sends a second login request to log in to the cloud mobile platform, wherein the second login request carries a first identifier and authentication information of the login object; If the first identifier and the authentication information are successfully authenticated, a login success response is returned to the terminal.

3. The method according to claim 2, characterized in that, The step of generating first verification information based on the first login request includes: Based on the first login request, obtain the first identifier of the login object; Obtain the public key corresponding to the SIM card authentication center; The first random string is generated based on the first login request; The first random string generated is encrypted using the public key to obtain the first verification information.

4. The method according to claim 1, characterized in that, Sending the first verification information to the SIM card authentication center and the terminal includes: The first verification information is sent to the SIM card authentication center so that the SIM card authentication center can verify the first random string in the first verification information; Receive the verification result sent by the SIM card authentication center; If the verification result is that the verification is passed, the first verification information is sent to the terminal, wherein the first verification information also includes interactive information.

5. A cloud-based application login authentication method, applied to a SIM card authentication center, characterized in that, include: The system receives first verification information sent by a cloud phone platform, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier of the cloud machine to which the terminal is logging in, a first application identifier of the cloud application to which the terminal requests login, a first random code, and a first request identifier corresponding to the first login request received by the cloud phone platform; The system receives second verification information sent by a cloud application platform. The second verification information includes a second random string, which includes: a third identifier of the login object, a fourth identifier of the cloud machine that the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. The second verification information is verified based on the first verification information, and an authentication message is sent to the terminal. Receive a login authentication request sent by the terminal, wherein the login authentication request carries a third random code and a third request identifier; If the first random code matches the third random code, an authentication result is sent to the cloud application platform so that the cloud application can learn that the terminal is allowed to log in to the cloud application by polling the cloud application platform.

6. The method according to claim 5, characterized in that, The step of verifying the second verification information based on the first verification information and sending an authentication message to the terminal includes: If the second request identifier matches the first request identifier, obtain the first random string corresponding to the first request identifier; If the first random string matches the second random string, an authentication message is sent to the terminal, wherein the authentication message includes the second identifier and the first application identifier.

7. The method according to claim 5, characterized in that, The first random string further includes a first checksum; after receiving the first verification information sent by the cloud phone platform, the method further includes: The integrity of the first random string is verified based on the first check code. After the verification is successful, the first verification information is saved. Establish a mapping relationship between the first random string and the first request identifier.

8. The method according to claim 5, characterized in that, After receiving the second verification information sent by the cloud application platform, the method further includes: Establish a mapping relationship between the second request identifier and the second random code.

9. A cloud-based application login method, applied to a terminal, characterized in that, include: In response to a login operation initiated by the login object to a cloud application, a first login request is sent to the cloud phone platform, wherein the first login request carries a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application. The system receives first verification information sent by the cloud phone platform, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; The first verification information is sent to the cloud application, so that the cloud application sends the second verification information to the cloud application platform based on the first verification information, and the cloud application platform sends the second verification information to the SIM card authentication center for verification. Send an interactive authentication request to the cloud phone platform; Receive the authentication result sent by the cloud phone platform, wherein the authentication result includes: a third random code and a third request identifier; Send a login authentication request carrying a third random code and a third request identifier to the SIM card authentication center, so that the SIM card authentication center can verify the third random code based on the first random code.

10. The method according to claim 8, characterized in that, The method further includes: Send the first identifier to the cloud application so that the cloud application displays the first identifier; In response to the confirmation operation of the first identifier displayed by the cloud application, a confirmation message is sent to the cloud application to trigger the cloud application to send the second verification message to the cloud application platform.

11. The method according to claim 9, characterized in that, After sending the first random string to the cloud application, the method further includes: The system receives an authentication message sent by the SIM card authentication center, wherein the authentication message includes the second identifier and the first application identifier.

12. The method according to claim 10, characterized in that, The first verification information also includes: interaction information; sending an interaction authentication request to the cloud phone platform, including: Based on the interactive information, an interactive page is displayed; In response to an input operation on the interactive page, an interaction authentication request is sent to the cloud phone platform, wherein the interaction authentication request includes interaction data.

13. A cloud-based application login authentication device, applied to a cloud mobile phone platform, characterized in that, include: The first receiving module is used to receive a first login request sent by the terminal to log in to the cloud application, wherein the first login request carries a second identifier of the cloud machine to which the terminal logs in, and a first application identifier of the cloud application. The generation module is used to generate first verification information based on the first login request, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; The first sending module is used to send the first verification information to the SIM card authentication center and the terminal, so that the SIM card authentication center can verify the second verification information sent by the cloud application platform based on the first verification information. The second verification information includes a second random string, which includes: a third identifier of the login object, a fourth identifier of the cloud machine that the login object is logging into, a second application identifier of the cloud application requesting login, a second random code, and a second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. The second receiving module is used to receive the interactive authentication request sent by the terminal, wherein the interactive authentication request includes interactive data; The second sending module is used to verify the interactive data and send the verification result to the terminal, so that the terminal sends the verification result to the SIM card authentication center for verification. The verification result includes the first random code and the first request identifier.

14. A cloud-based application login authentication device, applied to a SIM card authentication center, characterized in that, include: The first receiving module is used to receive the first verification information sent by the cloud phone platform. The first verification information includes: a first random string, which includes: a first identifier of the login object, a second identifier of the cloud machine that the terminal is logging into, a first application identifier of the cloud application that the terminal requests to log in, a first random code, and a first request identifier corresponding to the first login request received by the cloud phone platform. The second receiving module is used to receive the second verification information sent by the cloud application platform. The second verification information includes a second random string, which includes: the third identifier of the login object, the fourth identifier of the cloud machine that the login object is logging into, the second application identifier of the cloud application requesting login, the second random code, and the second request identifier. The second random string is received by the cloud application from the terminal and sent to the cloud application platform. The first sending module is used to verify the second verification information based on the first verification information and send an authentication message to the terminal; The third receiving module is used to receive the login authentication request sent by the terminal, wherein the login authentication request carries a third random code and a third request identifier; The second sending module is used to send an authentication result to the cloud application platform when the first random code matches the third random code, so that the cloud application can learn that the terminal is allowed to log in to the cloud application by polling the cloud application platform.

15. A cloud-based application login device, applied to a terminal, characterized in that, include: The first sending module is used to send a first login request to the cloud phone platform in response to the login operation initiated by the login object to the cloud application. The first login request carries the following: a second identifier of the cloud machine to which the terminal is logging in, and a first application identifier of the cloud application. The first receiving module is configured to receive first verification information sent by the cloud phone platform, wherein the first verification information includes: a first random string, the first random string including: a first identifier of the login object, a second identifier, a first application identifier, a first random code, and a first request identifier corresponding to the first login request; The second sending module is used to send the first verification information to the cloud application, so that the cloud application sends the second verification information to the cloud application platform based on the first verification information, and the cloud application platform sends the second verification information to the SIM card authentication center for verification. The third sending module is used to send an interactive authentication request to the cloud phone platform; The second receiving module is used to receive the authentication result sent by the cloud phone platform, wherein the authentication result includes: a third random code and a third request identifier; The fourth sending module is used to send a login authentication request carrying a third random code and a third request identifier to the SIM card authentication center, so that the SIM card authentication center can verify the third random code based on the first random code.

16. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory storing programs or instructions that can run on the processor, the programs or instructions being executed by the processor to implement the steps of the method as claimed in any one of claims 1 to 12.

17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 12.

18. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the steps of the method as described in any one of claims 1 to 12.

Citation Information

Patent Citations

  • Cloud mobile phone internal application one-key login system

    CN118301608A

  • Payment Method and System Based on Cloud Application Instance, and Related Device

    US20230056518A1