Secure login and verification method for network service system

By combining multiple security means of private key encryption, blockchain storage and dynamic verification code, the problem of user authentication security risks in existing network service systems is solved, and higher authentication security and system protection capabilities are achieved.

CN119945688AActive Publication Date: 2025-05-06BEIJING YUNCHENG FINANCIAL INFORMATION SERVICE CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510435622.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-05-06
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

User authentication methods in existing network service systems have security risks and are vulnerable to attacks, such as brute force cracking and man-in-the-middle attacks, and lack multiple encryption mechanisms and distributed storage means, and are vulnerable to single point of failure and data leakage.

Method used

By combining multiple security means such as private key encryption, blockchain storage and dynamic verification code, secure login and verification methods for identity verification are realized. The specific steps include the user terminal using the private key to determine the signature information, the server stores the user encryption key through the blockchain, and ensures the security of the login process through dynamic verification code and encrypted communication channel.

Benefits of technology

It significantly improves the authentication security of the network service system, prevents password leakage and forgery, ensures the security of key management, effectively prevents attacks by man in the middle and information leakage, and improves the overall protection capability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945688A_ABST
    Figure CN119945688A_ABST
Patent Text Reader

Abstract

The invention provides a secure login and verification method based on a network service system, and belongs to the technical field of network communication security, and the method comprises the steps: 1, transmitting a login request to a server based on a user terminal, generating a challenge code, and determining signature information; 2, sending the signature information and the public key to a server based on the user terminal, performing verification matching, generating a session token, and obtaining login information of the user terminal through a user login request; 3, confirming the existence of the user, and if the user exists, obtaining an encryption key preset by the user from the block chain storage so as to encrypt a login password of the user terminal; 4, verifying the correctness of the password, if the password is correct, generating a one-time dynamic verification code, and sending the one-time dynamic verification code to the user reserved device; and 5, obtaining the dynamic verification code of the user terminal, carrying out validity verification, and completing the login process after the verification is passed. Man-in-the-middle attack and information leakage are effectively prevented, and the overall protection capability of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network communication security, and in particular to a secure login and verification method for a network service system. Background Art

[0002] With the popularization of Internet applications, user identity authentication in network service systems has become increasingly important. The traditional username and password authentication method has certain security risks and is vulnerable to various attacks, such as brute force cracking and man-in-the-middle attacks.

[0003] Existing security verification technologies, such as SMS verification codes and OTP (one-time passwords), have improved security to a certain extent, but there are still risks of account theft and information leakage. Existing identity verification methods have the following technical defects: Password-based verification is vulnerable to attacks, especially in the case of password leakage or guessing. Traditional secondary verification methods (such as SMS verification codes) may face the risk of information theft and man-in-the-middle attacks. The lack of multiple encryption mechanisms and distributed storage methods makes the system vulnerable to single point failures and data leakage.

[0004] Therefore, the present invention provides a secure login and verification method for a network service system. Summary of the invention

[0005] The present invention provides a secure login and verification method for a network service system, which is used to significantly improve the identity authentication security of the network service system by combining multiple security means such as private key encryption, blockchain storage and dynamic verification codes. First, private key encryption and signature information are used to enhance the protection of identity authentication to prevent password leakage and forgery. Secondly, user encryption keys are stored in blockchain to ensure key management security. Finally, dynamic verification codes and encrypted communication channels further ensure the security of the login process, effectively prevent man-in-the-middle attacks and information leakage, and improve the overall protection capability of the system.

[0006] The present invention provides a secure login and verification method for a network service system, comprising: Step 1: A login request is sent from a user terminal to a server, and then a challenge code is generated by the server and the user terminal uses a private key to encrypt and determine the signature information, wherein the login request carries a user identifier; Step 2: Based on the user terminal, the signature information and public key are sent to the server for verification and matching, and then a session token is generated and returned to the user terminal, and the login information of the user terminal is obtained through the user login request; Step 3: Verify the login information, query the user basic information database based on the verified login information, and then confirm the existence of the user. If the user exists, obtain the user's preset encryption key from the blockchain storage and encrypt the login password of the user terminal; Step 4: Compare the encrypted login password with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel; Step 5: Obtain the dynamic verification code of the user terminal and verify the validity of the dynamic verification code of the user terminal. After the verification is passed, a secure login token is allocated to the user to complete the login process.

[0007] The present invention provides a secure login and verification method for a network service system, which is based on a user terminal sending a login request to a server, generating a challenge code based on the server, and the user terminal using a private key to encrypt and determine signature information, including: Acquire login-related data based on several preset data sources, wherein the login-related data includes: timestamp, high entropy random number, device feature hash value, behavior feature and key fragment; Combine the timestamp, high entropy random number, device feature hash value, behavior feature and key fragment into a string; Based on the user terminal sending a login request to the server, the server calls the smart contract to combine The string generates the initial challenge code; A validity period mark is added to the challenge code to generate a challenge code, and the user terminal encrypts the challenge code using a private key to determine the signature information.

[0008] The present invention provides a secure login and verification method for a network service system, which generates a session token, comprising: The time when the user terminal sends the login request to the server is determined as the session time, thereby generating a session timestamp; Combine the user ID and session timestamp to generate basic data, and sign the basic data based on the server private key; The signature and basic data are encapsulated into a session token, and the encapsulated session token is returned to the user terminal.

[0009] The present invention provides a safe login and verification method for a network service system, which verifies login information, including: performing whitelist check, preliminary information check and information check on the login information.

[0010] The present invention provides a secure login and verification method for a network service system, which queries a user basic information database based on verified login information to confirm the existence of the user. If the user exists, the user's preset encryption key is obtained from the blockchain storage to encrypt the login password of the user terminal, including: Determine the keyword based on the user ID of the verified login information, and then search for the user record in the main user table in the user basic information database, and determine the number of matching records in the main user table; If the user record is not found in the main user table, the historical record mark and the number of historical record marks corresponding to the user ID are determined based on the user basic information database; Performing type analysis on the historical record mark to determine the type of the historical record mark; Determine a number of association tables and the number of association tables corresponding to the user identifier in the user basic information database based on the type of the historical record mark; Determine a number of historical change identifiers and the number of historical change identifiers corresponding to the user identifier in all associated tables based on the keyword; Determine the user's existence coefficient based on the number of matching records in the main user table, the number of association tables corresponding to the user ID, the number of historical record marks, and the number of historical change marks of the user ID in each association table; The presence of the user is determined based on the user presence coefficient and a preset presence coefficient threshold.

[0011] The present invention provides a secure login and verification method for a network service system, which determines the user's existence coefficient based on the number of matching records in a main user table, the number of association tables corresponding to the user identifier, the number of historical record marks, and the number of historical change marks of the user identifier in each association table, including: The user's existence coefficient is determined based on the number of matching records in the main user table, the number of associated tables corresponding to the user ID, the number of historical record markers, and the number of historical change markers of the user ID in each associated table:

[0012] in, is the user's existence coefficient, The number of records that match the user ID in the main user table, For user identification The number of matching records in the associated table, is the total number of associated tables, The number of historical record marks corresponding to the user ID. The total number of preset history mark types. 1 is the conversion coefficient corresponding to the main user table match, Match the corresponding conversion coefficient to the association table, The conversion factor corresponding to the historical record mark.

[0013] The present invention provides a secure login and verification method for a network service system, which compares an encrypted login password with an encrypted password in a database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to a user reserved device through an encrypted communication channel, including: Compare the encrypted login password with the encrypted value of the user password stored in the database; If the encrypted login password is the same as the stored encrypted password, the password is considered correct; otherwise, the login fails and an error message is returned to the user terminal; When the password is correct, a one-time dynamic verification code is generated based on the server and the preset generator, and then sent to the user's reserved device through an encrypted communication channel.

[0014] The present invention provides a secure login and verification method for a network service system, which generates a one-time dynamic verification code based on a server and a preset generator, including: Get the security requirement related parameters to determine the length of the verification code:

[0015] in, is the length of the verification code, is the preset maximum number of verifications. The validity period of the verification code. is the preset maximum attempt frequency of the attacker, is the size coefficient of the verification code character set, is the rounding symbol; Generates a one-time dynamic verification code based on the server, preset generator, verification code length, and current timestamp.

[0016] Compared with the prior art, the beneficial effects of this application are as follows: By combining multiple security measures such as private key encryption, blockchain storage and dynamic verification codes, the identity authentication security of the network service system has been significantly improved. First, private key encryption and signature information are used to enhance identity authentication protection and prevent password leakage and forgery. Secondly, user encryption keys are stored on the blockchain to ensure key management security. Finally, dynamic verification codes and encrypted communication channels further ensure the security of the login process, effectively prevent man-in-the-middle attacks and information leakage, and enhance the overall protection capabilities of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0018] Figure 1 The present invention is a flowchart of a secure login and verification method for a network service system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0020] Embodiment 1: The embodiment of the present invention provides a secure login and verification method for a network service system, such as Figure 1 As shown, including: Step 1: A login request is sent from a user terminal to a server, and then a challenge code is generated by the server and the user terminal uses a private key to encrypt and determine the signature information, wherein the login request carries a user identifier; Step 2: Based on the user terminal, the signature information and public key are sent to the server for verification and matching, and then a session token is generated and returned to the user terminal, and the login information of the user terminal is obtained through the user login request; Step 3: Verify the login information, query the user basic information database based on the verified login information, and then confirm the existence of the user. If the user exists, obtain the user's preset encryption key from the blockchain storage and encrypt the login password of the user terminal; Step 4: Compare the encrypted login password with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel; Step 5: Obtain the dynamic verification code of the user terminal and verify the validity of the dynamic verification code of the user terminal. After the verification is passed, a secure login token is allocated to the user to complete the login process.

[0021] In this embodiment, the challenge code is a temporary information generated by the server to ensure that the user terminal can correctly respond and prove its identity during the login process. The challenge code is usually a randomly generated value or string, which is sent to the user terminal. The user terminal encrypts the challenge code with a private key to generate a signature to ensure the authenticity of the request.

[0022] In this embodiment, the user basic information database is a database that stores information related to user identity, usually including personal data such as username, password, contact information, etc. This database is used to confirm the identity of the user during the login verification process to ensure that the system can correctly identify legitimate users. For example, in a social network application, the user basic information database may contain the user's username "JohnDoe", password (encrypted) and mobile phone number "1234567890". When the user logs in, the system will query and verify from this database based on the provided login information.

[0023] In this embodiment, validity verification refers to checking the information submitted by the user (such as a verification code) to determine whether the information is valid, has not expired, and has not been tampered with. Usually in a multiple verification process, the server will verify whether the verification code entered by the user is correct and whether it is within the valid period. For example: when the user logs in, he receives a one-time dynamic verification code "382910". After entering the verification code, the system will verify its validity, check whether the verification code matches the one sent, and whether it is within the valid period. If it is valid, the operation is allowed to continue.

[0024] In this embodiment, the security login token is a token generated by the system after the user login verification is successful, which is used to indicate that the user has successfully logged in and is authorized to access resources. The token is usually an encrypted string and is used as a credential for the user's identity in subsequent requests to avoid the need to re-login for each request. For example: on an online shopping website, after the user successfully passes the verification, the system generates a security login token "abc123xyz", which will be saved in the user's browser. When the user subsequently visits the website, the system will verify the user's identity through the token without having to re-enter the username and password.

[0025] The beneficial effects of the above technical solution are as follows: by combining multiple security measures such as private key encryption, blockchain storage and dynamic verification codes, the identity authentication security of the network service system is significantly improved. First, private key encryption and signature information are used to enhance identity authentication protection and prevent password leakage and forgery. Secondly, user encryption keys are stored in blockchain to ensure key management security. Finally, dynamic verification codes and encrypted communication channels further ensure the security of the login process, effectively prevent man-in-the-middle attacks and information leakage, and enhance the overall protection capabilities of the system.

[0026] Embodiment 2: The embodiment of the present invention provides a secure login and verification method for a network service system, based on a user terminal sending a login request to a server, generating a challenge code based on the server and encrypting signature information using a private key by the user terminal, including: Acquire login-related data based on several preset data sources, wherein the login-related data includes: timestamp, high entropy random number, device feature hash value, behavior feature and key fragment; Combine the timestamp, high entropy random number, device feature hash value, behavior feature and key fragment into a string; Based on the user terminal sending a login request to the server, the server calls the smart contract to combine The string generates the initial challenge code; A validity period mark is added to the challenge code to generate a challenge code, and the user terminal encrypts the challenge code using a private key to determine the signature information.

[0027] In this embodiment, combining the timestamp, high entropy random number, device feature hash value, behavior feature and key fragment into a string is to combine multiple independent security data elements (such as timestamp, high entropy random number, etc.) into a complete string according to a predetermined format. The purpose of this is to generate a highly complex combination of data, making the generated challenge code more difficult to predict or forge. For example, assume that the user's login request contains the following information: Timestamp: "1674476730000" High entropy random number: "a7b2e9c4f8" Device feature hash value: "d34db33f7f9" Behavioral feature: "walking-pattern-xyz" Key fragment: "7ac9d2ef" Combine this information in sequence into a string: "1674476730000|a7b2e9c4f8|d34db33f7f9|walking-pattern-xyz|7ac9d2ef", which will then be used to generate the initial challenge code.

[0028] In this embodiment, the initial challenge code is the first encrypted value generated based on a set of preset data (timestamp, random number, device characteristics, etc. as described above). This challenge code is to verify the authenticity of the user's request, and it is one of the important credentials in the login process. The initial challenge code is usually affected by these data sources, making it different for each login. If the above combined string "1674476730000|a7b2e9c4f8|d34db33f7f9|walking-pattern-xyz|7ac9d2ef" is processed by a hash or encryption algorithm, the initial challenge code that may be generated is "9a3b4f5e2b4c1d3f2a4e".

[0029] In this embodiment, adding a validity period mark to the challenge code and then generating a challenge code is to add a validity period mark (such as an expiration timestamp) on the basis of the initial challenge code to ensure that the challenge code is valid within a certain time range. The addition of the validity period mark prevents attackers from using expired or old challenge codes to perform replay attacks. The validity period mark usually specifies the valid time range of the challenge code. Once expired, the challenge code will no longer be accepted. For example: assuming that the initial challenge code is "9a3b4f5e2b4c1d3f2a4e", the server may add a validity period mark at the end of this challenge code, such as "valid-until: 1674477930000" (indicating that the challenge code is valid before 13:45:30 on January 23, 2025). The complete challenge code generated in this way may be "9a3b4f5e2b4c1d3f2a4e|valid-until: 1674477930000". This challenge code can only be used by the user terminal within the validity period.

[0030] The beneficial effects of the above technical solution are as follows: by combining multiple login-related data sources (such as timestamps, high-entropy random numbers, device features, etc.) to generate an initial challenge code and adding an expiration mark, the security of identity authentication is enhanced. The user terminal uses a private key to encrypt the challenge code to generate signature information, thereby effectively preventing forgery and man-in-the-middle attacks, and improving the security and anti-attack capabilities of the system. This method can ensure the uniqueness and timeliness of data during each login process, and effectively prevent replay attacks.

[0031] Embodiment 3: The embodiment of the present invention provides a secure login and verification method for a network service system, generating a session token, including: The time when the user terminal sends the login request to the server is determined as the session time, thereby generating a session timestamp; Combine the user ID and session timestamp to generate basic data, and sign the basic data based on the server private key; The signature and basic data are encapsulated into a session token, and the encapsulated session token is returned to the user terminal.

[0032] In this embodiment, the session timestamp refers to a time identifier recorded during the user login request process. It is usually used to indicate the start time of the session, that is, the time when the user initiates the login request. The timestamp is a unique value generated based on the current time, usually in milliseconds or seconds, to ensure the timeliness of the session and avoid repeated session requests. Assuming that the user sends a login request to the server at 13:45:30 on January 23, 2025, the session timestamp generated by the server may be "1674476730000", indicating the exact time of 13:45:30 on January 23, 2025. This timestamp is used together with the user identifier to generate basic data and is used for subsequent session verification.

[0033] The beneficial effects of the above technical solution are as follows: by combining the user identification and session timestamp to generate basic data, and signing it with the server private key, the uniqueness and security of the session token are ensured. The signature and basic data are encapsulated into a session token and returned to the user terminal, which can effectively prevent session hijacking and forgery attacks, ensure the continued validity of the user identity, improve the security of the login process, and reduce the risk of man-in-the-middle attacks.

[0034] Embodiment 4: The embodiment of the present invention provides a secure login and verification method for a network service system, which verifies login information, including: performing whitelist check, preliminary information check and information check on the login information.

[0035] In this embodiment, the whitelist check includes: matching the extracted login information with the data in the whitelist one by one. First, check whether the user name is in the user list of the whitelist. If the user name does not exist in the whitelist, it may be directly determined as an illegal login attempt. Then check the login IP address to see if it matches the allowed login IP address range of the user recorded in the whitelist. For example, the whitelist stipulates that a user can only log in from a specific IP segment within the company. If the user initiates a login request from another IP address, the IP address matching fails. For device identification, similar matching will be performed to ensure that the user logs in from an authorized device. Multi-factor association check: In addition to matching single information, multi-factor association checks will also be performed. For example, check whether the association between the user name and the login IP address and device identification conforms to the whitelist setting. There may be a situation where a user name itself is in the whitelist and its login IP address also seems normal, but the IP address does not match the commonly used device recorded by the user name in the whitelist, which may also be regarded as abnormal login behavior. The system will comprehensively consider these factors and determine whether the login information fully meets the whitelist requirements according to the preset rules. Check result judgment: Based on the results of the above matching and inspection, the system will make a final judgment. If all the key data in the login information fully matches the records in the whitelist, and the multi-factor association also meets the requirements, then the whitelist check passes, and the system will allow the login process to continue and enter the next verification link. If any information does not match or the association is abnormal, the system will determine that the whitelist check has failed, reject the user's login request, and may record this abnormal login behavior. At the same time, it will feedback the reason for the login failure to the user and prompt the user of possible problems, such as "the user name or login address is not in the whitelist".

[0036] In this embodiment, the preliminary format check includes: checking whether the user name conforms to the specified character rules, determining whether the user name is valid, checking whether the password length is within the specified range, determining whether the password length is compliant, confirming whether the login information contains required fields, ensuring the integrity of the information, escaping special characters, and preventing injection attack risks; In this embodiment, the information check includes: legality check, account legality: checking whether the account entered by the user complies with the naming specifications specified by the system, such as whether it only contains letters, numbers and specific characters, whether the length is within the specified range, etc. To prevent malicious users from injecting attacks by entering special characters or overlong characters, etc. Password legitimacy: Verify whether the password meets the complexity requirements, such as whether it contains a combination of uppercase and lowercase letters, numbers and special characters, to improve the security of the password and reduce the risk of being cracked. Integrity check, mandatory item check: Make sure that all necessary login information fields are filled in, such as user name, password, verification code, etc., to prevent abnormal login process due to missing information. Integrity of related information: If the login information contains related content, such as the correspondence between the ID number and the name, the rationality of the email address and the username, etc., check whether these related information are complete and match each other. Authenticity check, email verification: Check whether the entered email address is real and valid. You can send a verification link or verification code to the email address and ask the user to confirm to ensure that the user is using his or her own valid email address, which is convenient for subsequent password retrieval operations. Mobile phone number verification: By sending a text message verification code, verify whether the mobile phone number entered by the user is correct and belongs to the user, increasing the security and traceability of the account. Risk assessment check, abnormal login check: Based on the user's login history, IP address and other information, determine whether the current login is abnormal, such as whether it is from an unfamiliar IP Behavioral feature check: Analyze the user's behavioral features when logging in, such as input speed, click frequency, etc., and compare them with the user's historical behavior data to determine whether the operation is performed by the user himself to prevent the account from being used by others.

[0037] The beneficial effects of the above technical solution are as follows: through the multiple verification processes of whitelist check, preliminary information verification and information check, the security of the system is effectively improved. The whitelist check ensures that only legitimate users can access, the preliminary information verification promptly excludes invalid information, and the information check further confirms the user's identity and data accuracy, effectively preventing forged login information, malicious attacks and data tampering, enhancing the security of the login process, and improving the protection capabilities of the network service system.

[0038] Embodiment 5: The embodiment of the present invention provides a secure login and verification method for a network service system, which queries a user basic information database based on the verified login information to confirm the existence of the user. If the user exists, the user's preset encryption key is obtained from the blockchain storage to encrypt the login password of the user terminal, including: Determine the keyword based on the user ID of the verified login information, and then search for the user record in the main user table in the user basic information database, and determine the number of matching records in the main user table; If the user record is not found in the main user table, the historical record mark and the number of historical record marks corresponding to the user ID are determined based on the user basic information database; Performing type analysis on the historical record mark to determine the type of the historical record mark; Determine a number of association tables and the number of association tables corresponding to the user identifier in the user basic information database based on the type of the historical record mark; Determine a number of historical change identifiers and the number of historical change identifiers corresponding to the user identifier in all associated tables based on the keyword; Determine the user's existence coefficient based on the number of matching records in the main user table, the number of association tables corresponding to the user ID, the number of historical record marks, and the number of historical change marks of the user ID in each association table; The presence of the user is determined based on the user presence coefficient and a preset presence coefficient threshold.

[0039] In this embodiment, the keyword is determined based on the user identifier in the verified login information, which is an important basis for performing query operations in the user basic information database. Usually, the keyword is the user identifier itself, such as user name, user ID, etc. Assuming that the user identifier in the verified login information is "user001", then "user001" will be used as a keyword for searching in the main user table and subsequent associated tables.

[0040] In this embodiment, the number of matching records in the main user table is the number of records that meet the conditions when performing a search operation in the main user table of the user basic information base based on the keyword. This number can reflect how many records in the main user table match the user ID. For example: when searching for the keyword "user001" in the main user table, if two records with the user ID "user001" are found, the number of matching records in the main user table is 2; if no matching record is found, the number is 0.

[0041] In this embodiment, a user record refers to a data record in the user basic information database that contains various relevant information of a certain user. This information may include basic information of the user (such as name, contact information, etc.), account information (such as password, account status, etc.). For example, there is a record in the main user table, whose content is user ID is "user001", name is "Zhang San", contact information is "1*********", and account status is "normal". This record is a user record.

[0042] In this embodiment, the type of historical record mark is that when the user record cannot be found in the main user table, it is necessary to find the historical record mark corresponding to the user identifier, and these marks have different types, and different types reflect the different changes that the user data has undergone. For example: Migration mark: indicates that the user's data has been migrated from one database to another. For example, due to system upgrades, the data of user "user001" has been migrated from the old database to the new database, and there will be a migration mark at this time. Merge mark: means that the user's account has been merged with other accounts. For example, users "user001" and "user002" are merged into a new account, and a merge mark will be left. Split mark: indicates that the user's account has been split into multiple accounts. Assuming that user "user001" is split into "user001_1" and "user001_2", there will be a split mark.

[0043] In this embodiment, the association table is a table related to the user identifier determined in the user basic information database based on the type of historical record mark. These tables may store the user's historical data, associated information, etc. The number of association tables is the number of determined association tables. For example: by analyzing the historical record mark, it is found that the user "user001" has migration and merger, and the related association tables are "migration_history" (migration history table) and "merge_record" (merge record table), then the association tables are "migration_history" and "merge_record", and the number of association tables is 2.

[0044] In this embodiment, the historical change identifier is an identifier related to the user identifier that can reflect the historical change of the user data, which is found in all associated tables based on the keyword. The number of historical change identifiers is the number of such identifiers found. For example: in the "migration_history" table, the historical change identifiers related to the keyword "user001" are "mig_001" and "mig_002"; in the "merge_record" table, "merge_001" is found, then the historical change identifiers are "mig_001", "mig_002" and "merge_001", and the number of historical change identifiers is 3.

[0045] The beneficial effects of the above technical solution are as follows: the system security is improved by verifying the user identity at multiple levels, and whether the user really exists is determined by verifying the login information, querying the user basic information database, analyzing the historical record marks and change marks, etc. The encryption key is stored in combination with blockchain technology to ensure the security of the login password. The calculation of the user existence coefficient further enhances the accuracy of identity authentication, effectively prevents illegal user access, improves the protection capability of the network service system, and reduces security risks.

[0046] Embodiment 6: The embodiment of the present invention provides a secure login and verification method for a network service system, which determines the existence coefficient of a user based on the number of matching records in a main user table, the number of association tables corresponding to a user identifier, the number of historical record marks, and the number of historical change marks of the user identifier in each association table, including: The user's existence coefficient is determined based on the number of matching records in the main user table, the number of associated tables corresponding to the user ID, the number of historical record markers, and the number of historical change markers of the user ID in each associated table:

[0047] in, is the user's existence coefficient, The number of records that match the user ID in the main user table, For user identification The number of matching records in the associated table, is the total number of associated tables, The number of historical record marks corresponding to the user ID. The total number of preset history mark types. 1 is the conversion coefficient corresponding to the main user table match, Match the corresponding conversion coefficient to the association table, The conversion factor corresponding to the historical record mark.

[0048] In this embodiment, If the user ID is directly matched to the main user table, use the logarithmic function to compress the calculation to avoid excessive The value dominates the results while ensuring its importance; In this embodiment, In all related tables, the number of matched historical change identifiers is square rooted to amplify the impact of low numbers and reduce the impact of high numbers; , balance the impact of history record marking on the final coefficient; In this embodiment, The more historical records are marked, the smaller the corresponding existence coefficient decays (the exponential function reflects the impact of long-term user activity). Normalization is performed to prevent historical markers from dominating the coefficients in extreme cases.

[0049] The beneficial effects of the above technical solution are as follows: by calculating the user existence coefficient and combining multi-dimensional information such as the main user table, the associated table, and the historical record mark, it is possible to accurately determine whether the user really exists. By setting the conversion coefficient for each table and mark type, the weights of different factors can be flexibly adjusted, thereby improving the accuracy and reliability of identity authentication, effectively reducing the risk of system attacks, avoiding false user logins, and improving the security and protection capabilities of the network service system.

[0050] Embodiment 7: The embodiment of the present invention provides a secure login and verification method for a network service system, which compares an encrypted login password with an encrypted password in a database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to a user reserved device through an encrypted communication channel, including: Compare the encrypted login password with the encrypted value of the user password stored in the database; If the encrypted login password is the same as the stored encrypted password, the password is considered correct; otherwise, the login fails and an error message is returned to the user terminal; When the password is correct, a one-time dynamic verification code is generated based on the server and the preset generator, and then sent to the user's reserved device through an encrypted communication channel.

[0051] In this embodiment, the encrypted value of the user password refers to the encrypted result after the user password is converted by the encryption algorithm before being stored in the database. This encrypted value is stored in the database to protect the security of the user password and prevent the password from being leaked in plain text. Assume that the user's original password is password123. In order to ensure the security of the password, the system uses an encryption algorithm (such as SHA-256) to encrypt the password to obtain an encrypted string of fixed length. This encrypted string is the encrypted value of the user password. For example: the original password: password123, the encrypted value obtained after encryption with SHA-256: ef92b778bafe771e89245b8d6b0f1d556e0d2ac622c487dfc3e3810f59782a6a, when the user logs in, the system encrypts the password entered by the user in the same way, and then compares it with the encrypted value stored in the database. If the two encrypted values ​​are the same, it means that the password is correct and the user can log in.

[0052] The beneficial effects of the above technical solution are: by encrypting the login password and comparing it with the encrypted password value in the database, the user password security is ensured, and the risk of plain text password leakage is avoided. Once the password verification is successful, the system generates a one-time dynamic verification code and sends it to the user's reserved device through an encrypted communication channel, further enhancing the security of identity authentication. This method effectively improves the security of the user login process, prevents password guessing and man-in-the-middle attacks, and ensures the protection of user data.

[0053] Embodiment 8: The embodiment of the present invention provides a secure login and verification method for a network service system, which generates a one-time dynamic verification code based on a server and a preset generator, including: Get the security requirement related parameters to determine the length of the verification code:

[0054] in, is the length of the verification code, is the preset maximum number of verifications. The validity period of the verification code. is the preset maximum attempt frequency of the attacker, is the size coefficient of the verification code character set, is the rounding symbol; Generates a one-time dynamic verification code based on the server, preset generator, verification code length, and current timestamp.

[0055] In this embodiment, the length of the verification code refers to the number of characters contained in the one-time dynamic verification code. It is calculated based on parameters related to security requirements. This length plays a key role in the security of the verification code. Longer verification codes are usually more difficult to crack, but may cause inconvenience to users in inputting. Although shorter verification codes are convenient for users to input, their security may be relatively low. By combining the verification code length calculated with multiple security factors, a balance can be found between security and user experience. For example: assuming that the length of the verification code calculated according to the above formula is 6, the generated one-time dynamic verification code will consist of 6 characters, such as "5A3x98"; In this embodiment, the preset maximum frequency of attempts by attackers is based on the estimation of possible attacks on the system, and is the maximum number of times an attacker can try to guess the verification code in a unit of time. This parameter reflects the system's assumption of the potential attack strength and is used to calculate the length of the verification code that can effectively resist the attack. If the system is expected to be subjected to more intense attacks, that is, the attacker's attempt frequency is high, then when calculating the verification code length, it will tend to generate longer and more complex verification codes to increase the difficulty of cracking; In this embodiment, the validity period of the verification code refers to the time interval from the moment the one-time dynamic verification code is generated to the time when the verification code loses its validity. During this validity period, the verification code entered by the user will be recognized by the system and used to verify the identity; once the validity period expires, even if the verification code entered is correct, the system will refuse verification and require the user to obtain the verification code again. This mechanism increases the security of the verification code and reduces the risk of the verification code being intercepted and used maliciously in the future. For example, if the validity period of the verification code is set to 5 minutes, then within 5 minutes after the verification code is generated, the user can use the verification code for operations such as login verification. For example, a verification code generated at 10:00 is valid if entered before 10:05, but will become invalid after 10:05, and the user needs to obtain a new verification code again.

[0056] The beneficial effects of the above technical solution are as follows: by generating a one-time dynamic verification code based on security requirement related parameters (such as verification code length, validity period, etc.), the security and effectiveness of the verification code are ensured. By presetting the maximum attacker attempt frequency and the verification code character size coefficient, brute force attacks are effectively prevented, and the system's protection capabilities are improved. At the same time, the generation of the verification code depends on the server and the preset generator, which makes the verification code highly random and unpredictable, enhancing the security of the network service system.

[0057] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A secure login and verification method for a network service system, characterized in that: include: Step 1: A login request is sent from a user terminal to a server, and then a challenge code is generated by the server and the user terminal uses a private key to encrypt and determine the signature information, wherein the login request carries a user identifier; Step 2: Based on the user terminal, the signature information and public key are sent to the server for verification and matching, and then a session token is generated and returned to the user terminal, and the login information of the user terminal is obtained through the user login request; Step 3: Verify the login information, query the user basic information database based on the verified login information, and then confirm the existence of the user. If the user exists, obtain the user's preset encryption key from the blockchain storage and encrypt the login password of the user terminal; Step 4: Compare the encrypted login password with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel; Step 5: Obtain the dynamic verification code of the user terminal and verify the validity of the dynamic verification code of the user terminal. After the verification is passed, a secure login token is allocated to the user to complete the login process.

2. A secure login and verification method for a network service system according to claim 1, characterized in that: The user terminal sends a login request to the server, generates a challenge code based on the server, and the user terminal uses the private key to encrypt and determine the signature information, including: Acquire login-related data based on several preset data sources, wherein the login-related data includes: timestamp, high entropy random number, device feature hash value, behavior feature and key fragment; Combine the timestamp, high entropy random number, device feature hash value, behavior feature and key fragment into a string; Based on the user terminal sending a login request to the server, the server calls the smart contract string to generate an initial challenge code; A validity period mark is added to the challenge code to generate a challenge code, and the user terminal encrypts the challenge code using a private key to determine the signature information.

3. A secure login and verification method for a network service system according to claim 1, characterized in that: Generate a session token, including: The time when the user terminal sends the login request to the server is determined as the session time, thereby generating a session timestamp; Combine the user ID and session timestamp to generate basic data, and sign the basic data based on the server private key; The signature and basic data are encapsulated into a session token, and the encapsulated session token is returned to the user terminal.

4. A secure login and verification method for a network service system according to claim 1, characterized in that: Verify the login information, including: whitelist check, preliminary information verification and information check.

5. A secure login and verification method for a network service system according to claim 1, characterized in that: Based on the verified login information, the user basic information database is queried to confirm the existence of the user. If the user exists, the user's preset encryption key is obtained from the blockchain storage to encrypt the login password of the user terminal, including: Determine the keyword based on the user ID of the verified login information, and then search for the user record in the main user table in the user basic information database, and determine the number of matching records in the main user table; If the user record is not found in the main user table, the historical record mark and the number of historical record marks corresponding to the user ID are determined based on the user basic information database; Performing type analysis on the historical record mark to determine the type of the historical record mark; Determine a number of association tables and the number of association tables corresponding to the user identifier in the user basic information database based on the type of the historical record mark; Determine a number of historical change identifiers and the number of historical change identifiers corresponding to the user identifier in all associated tables based on the keyword; Determine the user's existence coefficient based on the number of matching records in the main user table, the number of association tables corresponding to the user ID, the number of historical record marks, and the number of historical change marks of the user ID in each association table; The presence of the user is determined based on the user presence coefficient and a preset presence coefficient threshold.

6. A secure login and verification method for a network service system according to claim 5, characterized in that: The user's existence coefficient is determined based on the number of matching records in the main user table, the number of associated tables corresponding to the user ID, the number of historical record marks, and the number of historical change marks of the user ID in each associated table, including: The user's existence coefficient is determined based on the number of matching records in the main user table, the number of associated tables corresponding to the user ID, the number of historical record markers, and the number of historical change markers of the user ID in each associated table: in, is the user's existence coefficient, The number of records that match the user ID in the main user table, For user identification The number of matching records in the associated table, is the total number of associated tables, The number of historical record marks corresponding to the user ID. The total number of preset history mark types. 1 is the conversion coefficient corresponding to the main user table match, Match the corresponding conversion coefficient to the association table, The conversion factor corresponding to the historical record mark.

7. A secure login and verification method for a network service system according to claim 1, characterized in that: The encrypted login password is compared with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel, including: Compare the encrypted login password with the encrypted value of the user password stored in the database; If the encrypted login password is the same as the stored encrypted password, the password is considered correct; otherwise, the login fails and an error message is returned to the user terminal; When the password is correct, a one-time dynamic verification code is generated based on the server and the preset generator, and then sent to the user's reserved device through an encrypted communication channel.

8. A secure login and verification method for a network service system according to claim 7, characterized in that: Generate a one-time dynamic verification code based on the server and the preset generator, including: Get the security requirement related parameters to determine the length of the verification code: in, is the length of the verification code, is the preset maximum number of verifications. The validity period of the verification code. is the preset maximum attempt frequency of the attacker, is the size coefficient of the verification code character set, is the rounding symbol; Generates a one-time dynamic verification code based on the server, preset generator, verification code length, and current timestamp.

Citation Information

Patent Citations

  • Cross-application platform login method and system of block chain account

    CN114401100A

  • User security login method, system and device

    CN115174187A

  • Multi-authentication method based on code server

    CN117354032A

  • Block chain-based information authentication method and related equipment

    CN119652526A

  • Login authentication system, service provider and authentication server in login authentication system, and login authentication method and program for service provider, authentication server, computer and mobile terminal in login authentication system

    JP2018082244A