A secure login and verification method for a network service system

By combining multiple security means such as private key encryption, blockchain storage and dynamic verification code, the problem of the existing network service system's identity verification security risks is solved, and higher authentication security and system protection capabilities are achieved.

CN119945688BActive Publication Date: 2025-06-10BEIJING YUNCHENG FINANCIAL INFORMATION SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510435622.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-06-10
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

The authentication methods of existing network service systems pose security risks, are vulnerable to attacks, and lack multiple encryption mechanisms and distributed storage means, and are vulnerable to single point of failure and data leakage.

Method used

By combining multiple security means such as private key encryption, blockchain storage and dynamic verification code, secure login and verification of identity verification can be achieved. The specific steps include using the private key to encrypt and sign information, storing the user encryption keys on the blockchain, and ensuring the security of the login process through dynamic verification codes and encrypted communication channels.

Benefits of technology

It significantly improves the authentication security of the network service system, prevents password leakage and forgery, ensures the security of key management, effectively prevents attacks by man in the middle and information leakage, and improves the overall protection capability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945688B_ABST
    Figure CN119945688B_ABST
Patent Text Reader

Abstract

The present invention provides a secure login and verification method for a network service system, belonging to the technical field of network communication security, including: Step 1: Based on the user terminal sending a login request to the server, generating a challenge code and determining signature information; Step 2: Based on the user terminal sending the signature information and the public key to the server for verification and matching, generating a session token, passing the user login request and obtaining the login information of the user terminal; Step 3: Confirming the existence of the user, if the user exists, obtaining the encryption key preset by the user from the blockchain storage to encrypt the login password of the user terminal; Step 4: Verifying the correctness of the password, if the password is correct, generating a one-time dynamic verification code and sending it to the user's reserved device; Step 5: Obtaining the dynamic verification code of the user terminal and performing validity verification, and after passing the verification, completing the login process. It effectively prevents man-in-the-middle attacks and information leakage, and improves the overall protection ability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network communication security, and particularly to a secure login and verification method for a network service system. Background Art

[0002] With the popularization of Internet applications, the problem of user authentication in network service systems has become increasingly important. Traditional username and password verification methods have certain security risks and are vulnerable to various attacks, such as brute-force cracking and man-in-the-middle attacks.

[0003] Existing security verification technologies, such as methods based on SMS verification codes, OTP (one-time passwords), etc., although improving security to a certain extent, still have risks such as account theft and information leakage. The existing authentication methods have the following technical defects: Password-based verification is vulnerable to attacks, especially in the case of password leakage or guessing. Traditional secondary verification means (such as SMS verification codes) may face risks of information theft and man-in-the-middle attacks. There is a lack of multiple encryption mechanisms and distributed storage means, which easily makes the system vulnerable to single-point failures and data leakage threats.

[0004] Therefore, the present invention provides a secure login and verification method for a network service system. Summary of the Invention

[0005] The present invention provides a secure login and verification method for a network service system, which significantly improves the authentication security of the network service system by combining multiple security means such as private key encryption, blockchain storage, and dynamic verification codes. First, private key encryption and signature information are used to enhance the protection of authentication and prevent password leakage and forgery. Second, the user's encryption key is stored through the blockchain to ensure the security of key management. Finally, dynamic verification codes and encrypted communication channels further guarantee the security of the login process, effectively preventing man-in-the-middle attacks and information leakage, and enhancing the overall protection ability of the system.

[0006] The present invention provides a secure login and verification method for a network service system, including:

[0007] Step 1: Based on the user terminal sending a login request to the server, and then the server generates a challenge code and the user terminal uses the private key to encrypt and determine the signature information, where the login request carries the user identifier;

[0008] Step 2: Based on the user terminal sending the signature information and the public key to the server for verification and matching, and then generating a session token and returning it to the user terminal, passing the user login request and obtaining the login information of the user terminal;

[0009] Step 3: Verify the login information, query the user basic information database based on the verified login information, and then confirm the existence of the user. If the user exists, obtain the preset encryption key of the user from the blockchain storage and then encrypt the login password of the user terminal.

[0010] Step 4: Compare the encrypted login password with the encrypted password in the database, and then verify the correctness of the password. If the password is correct, generate a one-time dynamic verification code and send it to the user's reserved device through an encrypted communication channel.

[0011] Step 5: Obtain the dynamic verification code of the user terminal and verify the validity of the dynamic verification code of the user terminal. After the verification passes, assign a secure login token to the user, and then complete the login process.

[0012] The present invention provides a secure login and verification method for a network service system. Based on the user terminal sending a login request to the server, a challenge code is generated by the server and the signature information is determined by the user terminal encrypting it with a private key, including:

[0013] Obtain login-related data based on a number of preset data sources. Among them, the login-related data includes: timestamp, high-entropy random number, device feature hash value, behavior feature, and key fragment.

[0014] Combine the timestamp, high-entropy random number, device feature hash value, behavior feature, and key fragment into a string.

[0015] Based on the user terminal sending a login request to the server, the server calls a smart contract and combines

[0016] the string to generate an initial challenge code.

[0017] Add a validity period mark to the challenge code to generate a challenge code, and the user terminal encrypts the challenge code with a private key to determine the signature information.

[0018] The present invention provides a secure login and verification method for a network service system, generating a session token, including:

[0019] Determine the time when the user terminal sends a login request to the server as the session time, and then generate a session timestamp.

[0020] Combine the user identification and the session timestamp to generate basic data, and sign the basic data based on the server private key.

[0021] Package the signature and the basic data into a session token, and return the packaged session token to the user terminal.

[0022] The present invention provides a secure login and verification method for a network service system, which verifies login information, including: performing a whitelist check on the login information, performing a preliminary information verification, and performing an information check.

[0023] The present invention provides a secure login and verification method for a network service system. Based on the verified login information, the user basic information database is queried to confirm the existence of the user. If the user exists, the preset encryption key of the user is obtained from the blockchain storage to encrypt the login password of the user terminal, including:

[0024] Determine a keyword based on the user identifier of the verified login information, and then search for user records in the main user table in the user basic information database and determine the number of matching records in the main user table;

[0025] If no user record is found in the main user table, determine the historical record mark and the number of historical record marks corresponding to the user identifier based on the user basic information database;

[0026] Perform a type analysis on the historical record mark to determine the type of the historical record mark;

[0027] Based on the type of the historical record mark, determine several associated tables and the number of associated tables corresponding to the user identifier in the user basic information database;

[0028] Based on the keyword, determine several historical change identifiers and the number of historical change identifiers corresponding to the user identifier in all associated tables;

[0029] Determine the existence coefficient of the user based on the number of matching records in the main user table, the number of associated tables corresponding to the user identifier, the number of historical record marks, and the number of historical change identifiers of the user identifier in each associated table;

[0030] Determine the existence of the user based on the user existence coefficient and a preset existence coefficient threshold.

[0031] The present invention provides a secure login and verification method for a network service system. Determine the existence coefficient of the user based on the number of matching records in the main user table, the number of associated tables corresponding to the user identifier, the number of historical record marks, and the number of historical change identifiers of the user identifier in each associated table, including:

[0032] Determine the existence coefficient of the user based on the number of matching records in the main user table, the number of associated tables corresponding to the user identifier, the number of historical record marks, and the number of historical change identifiers of the user identifier in each associated table:

[0033]

[0034] Wherein, is the existence coefficient of the user, The number of records matched for the user identifier in the main user table, For the user identifier in the number of matching records in the associated table, is the total number of associated tables, is the number of historical record marks corresponding to the user identifier, is the total number of preset historical record mark types, 1 is the conversion coefficient corresponding to the main user table match, is the conversion coefficient corresponding to the associated table match, is the conversion coefficient corresponding to the historical record mark.

[0035] The present invention provides a secure login and verification method for a network service system, which compares the encrypted login password with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel, including:

[0036] Compare the encrypted login password with the encrypted value of the user password stored in the database;

[0037] If the encrypted login password is the same as the stored encrypted password, the password is considered correct; otherwise, the login fails and an error message is returned to the user terminal.

[0038] When the password is correct, a one-time dynamic verification code is generated based on the server and a preset generator, and then sent to the user's reserved device through an encrypted communication channel.

[0039] The present invention provides a secure login and verification method for a network service system, which generates a one-time dynamic verification code based on the server and a preset generator, including:

[0040] Obtain the parameters related to the security requirements, and then determine the length of the verification code:

[0041]

[0042] Among them, is the length of the verification code, is the preset maximum number of verification attempts, is the validity period of the verification code, is the maximum attempt frequency of the preset attacker, is the size coefficient of the verification code character set, is the ceiling symbol;

[0043] Generate a one-time dynamic verification code based on the server, the preset generator, the verification code length, and the current timestamp.

[0044] Compared with the prior art, the beneficial effects of the present application are as follows:

[0045] By combining multiple security means such as private key encryption, blockchain storage, and dynamic verification codes, the authentication security of the network service system is significantly improved. First, the use of private key encryption and signature information enhances the protection of authentication, preventing password leakage and forgery. Second, storing the user's encrypted key through the blockchain ensures the security of key management. Finally, dynamic verification codes and encrypted communication channels further safeguard the security of the login process, effectively preventing man-in-the-middle attacks and information leakage, and enhancing the overall protection ability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0047] Figure 1 It is a schematic flowchart of a secure login and verification method for a network service system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0049] Embodiment 1:

[0050] An embodiment of the present invention provides a secure login and verification method for a network service system, as Figure 1 shown, including:

[0051] Step 1: Based on the user terminal sending a login request to the server, and then based on the server generating a challenge code and the user terminal using the private key to encrypt and determine the signature information, where the login request carries the user identifier;

[0052] Step 2: Based on the user terminal sending the signature information and the public key to the server for verification and matching, and then generating a session token and returning it to the user terminal, passing the user login request and obtaining the login information of the user terminal;

[0053] Step 3: Verify the login information, query the user basic information database based on the verified login information, and then confirm the existence of the user. If the user exists, obtain the user's preset encryption key from the blockchain storage and then encrypt the login password of the user terminal;

[0054] Step 4: Compare the encrypted login password with the encrypted password in the database, and then verify the correctness of the password. If the password is correct, generate a one-time dynamic verification code and send it to the user's reserved device through an encrypted communication channel;

[0055] Step 5: Obtain the dynamic verification code of the user terminal and verify the validity of the dynamic verification code of the user terminal. After the verification passes, allocate a secure login token to the user, and then complete the login process.

[0056] In this embodiment, the challenge code is a temporary information generated by the server to ensure that the user terminal can respond correctly and prove its identity during the login process. The challenge code is usually a randomly generated numerical value or string, which is sent to the user terminal. The user terminal encrypts the challenge code with the private key to generate a signature to ensure the authenticity of the request.

[0057] In this embodiment, the user basic information database is a database that stores information related to user identities, usually including personal data such as usernames, passwords, and contact information. This database is used to confirm the identity of the user during the login verification process to ensure that the system can correctly identify legitimate users. For example, in a social network application, the user basic information database may contain the username "JohnDoe", the password (encrypted), and the mobile phone number "1234567890" of the user. When the user logs in, the system will query and verify according to the provided login information from this database.

[0058] In this embodiment, the validity verification refers to checking the information (such as the verification code) submitted by the user to determine whether the information is valid, not expired, and not tampered with. Usually in the multi-verification process, the server will verify whether the verification code entered by the user is correct and within the valid time. For example: when the user receives a one-time dynamic verification code "382910" during login, after entering this verification code, the system will perform a validity verification on it, check whether the verification code matches the sent one and whether it is within the validity period. If it is valid, the user is allowed to continue the operation.

[0059] In this embodiment, the secure login token is a token generated by the system after the user's login verification is successful, which is used to indicate that the user has successfully logged in and is authorized to access resources. The token is usually an encrypted string and is used as a credential for the user's identity in subsequent requests, avoiding the need to log in again for each request. For example, on an online shopping website, after the user successfully passes the verification, the system generates a secure login token "abc123xyz", which is saved in the user's browser. When the user accesses the website later, the system will verify the user's identity through this token without the need to re-enter the username and password.

[0060] Advantages of the above technical solution: By combining multiple security means such as private key encryption, blockchain storage, and dynamic verification codes, the identity verification security of the network service system is significantly improved. First, the use of private key encryption and signature information enhances the protection of identity verification, preventing password leakage and forgery. Second, storing the user's encrypted key through the blockchain ensures the security of key management. Finally, the dynamic verification code and the encrypted communication channel further guarantee the security of the login process, effectively preventing man-in-the-middle attacks and information leakage, and enhancing the overall protection ability of the system.

[0061] Embodiment 2:

[0062] The embodiment of the present invention provides a secure login and verification method for a network service system. Based on the user terminal sending a login request to the server, and the server generating a challenge code and the user terminal using a private key to encrypt and determine the signature information, it includes:

[0063] Obtaining login-related data based on several preset data sources. Among them, the login-related data includes: timestamp, high-entropy random number, device feature hash value, behavior feature, and key fragment;

[0064] Combining the timestamp, high-entropy random number, device feature hash value, behavior feature, and key fragment into a string;

[0065] Based on the user terminal sending a login request to the server, the server calls a smart contract to combine

[0066] the string to generate an initial challenge code;

[0067] Adding a validity period mark to the challenge code to generate a challenge code, and the user terminal uses a private key to encrypt the challenge code to determine the signature information.

[0068] In this embodiment, combining the timestamp, high-entropy random number, device feature hash value, behavior feature, and key fragment into a string means combining multiple independent security data elements (such as the timestamp, high-entropy random number, etc.) into a complete string according to a certain predetermined format. The purpose of doing this is to generate a combined data with high complexity, making the generated challenge code more difficult to predict or forge. For example, assume that the user's login request contains the following information:

[0069] Timestamp: "1674476730000" High-entropy random number: "a7b2e9c4f8" Device feature hash value: "d34db33f7f9" Behavior feature: "walking-pattern-xyz" Key fragment: "7ac9d2ef" Combine these information in order into a string: "1674476730000|a7b2e9c4f8|d34db33f7f9|walking-pattern-xyz|7ac9d2ef", and this string will then be used to generate the initial challenge code.

[0070] In this embodiment, the initial challenge code is the first encrypted value generated based on a set of preset data (such as the timestamp, random number, device features, etc. mentioned above). This challenge code is used to verify the authenticity of the user request, and it is one of the important credentials in the login process. The initial challenge code is usually affected by these data sources, making it different for each login. If the above combined string "1674476730000|a7b2e9c4f8|d34db33f7f9|walking-pattern-xyz|7ac9d2ef" is processed by a hash or encryption algorithm, the possible initial challenge code may be "9a3b4f5e2b4c1d3f2a4e".

[0071] In this embodiment, adding a validity period marker to the challenge code to generate the challenge code is based on the initial challenge code, and adding a validity period marker (such as an expiration timestamp) to ensure that the challenge code is valid within a certain time range. The addition of the validity period marker prevents attackers from using expired or old challenge codes for replay attacks. The validity period marker usually specifies the valid time range of the challenge code. Once expired, the challenge code is no longer accepted. For example, assume the initial challenge code is "9a3b4f5e2b4c1d3f2a4e", and the server may add a validity period marker at the end of this challenge code, such as "valid-until: 1674477930000" (indicating that the challenge code is valid before January 23, 2025, 13:45:30). The complete challenge code generated in this way may be "9a3b4f5e2b4c1d3f2a4e|valid-until: 1674477930000". This challenge code can only be used by the user terminal within the validity period.

[0072] Beneficial effects of the above technical solution: By combining multiple login-related data sources (such as timestamps, high-entropy random numbers, device characteristics, etc.) to generate the initial challenge code and adding a validity period marker, the security of authentication is enhanced. The user terminal encrypts the challenge code with the private key to generate the signature information, thereby effectively preventing forgery and man-in-the-middle attacks, and improving the security and anti-attack ability of the system. This method can ensure the uniqueness and timeliness of data during each login process, and effectively prevent replay attacks.

[0073] Embodiment 3:

[0074] The embodiment of the present invention provides a secure login and verification method for a network service system, which generates a session token, including:

[0075] Determine the time when the user terminal sends a login request to the server as the session time, and then generate a session timestamp;

[0076] Combine the user identifier and the session timestamp to generate basic data, and sign the basic data based on the server's private key;

[0077] Package the signature and the basic data into a session token, and return the packaged session token to the user terminal.

[0078] In this embodiment, the session timestamp refers to a time identifier recorded during the user login request process. It is usually used to indicate the start time of the session, that is, the time when the user initiates the login request. The timestamp is a unique value generated based on the current time, usually in milliseconds or seconds, to ensure the timeliness of the session and avoid duplicate session requests. Suppose the user sends a login request to the server at 13:45:30 on January 23, 2025. The session timestamp generated by the server may be "1674476730000", indicating the exact time at 13:45:30 on January 23, 2025. This timestamp, together with the user identifier, generates the basic data and is used for subsequent session verification.

[0079] Advantages of the above technical solution: By combining the user identifier and the session timestamp to generate the basic data and using the server private key to sign it, the uniqueness and security of the session token are ensured. Encapsulating the signature and the basic data into a session token and returning it to the user terminal can effectively prevent session hijacking and forgery attacks, ensure the continuous validity of the user identity, improve the security of the login process, and reduce the risk of man-in-the-middle attacks.

[0080] Embodiment 4:

[0081] The embodiment of the present invention provides a secure login and verification method for a network service system, which verifies the login information, including: performing a whitelist check, a preliminary information verification, and an information check on the login information.

[0082] In this embodiment, the whitelist check includes: comparing the extracted login information with the data in the whitelist one by one. First, check whether the username is in the user list of the whitelist. If the username does not exist in the whitelist, it may be directly determined as an illegal login attempt. Then, check the login IP address to see if it matches the range of allowed login IP addresses of this user recorded in the whitelist. For example, if the whitelist stipulates that a certain user can only log in from a specific IP segment within the company, and this user initiates a login request from other IP addresses, the IP address match fails. Similar matching is also performed for the device identifier to ensure that the user logs in from an authorized device. Multi-factor correlation check: In addition to matching individual information, a multi-factor correlation check is also performed. For example, check whether the association relationship between the username, login IP address, and device identifier conforms to the whitelist settings. There may be a situation where a certain username itself is in the whitelist and its login IP address seems normal, but the IP address does not match the commonly used device recorded for this username in the whitelist, which may also be regarded as an abnormal login behavior. The system will comprehensively consider these factors and judge whether the login information fully meets the whitelist requirements according to the preset rules. Check result determination: Based on the results of the above matching and checks, the system will make a final determination. If all the key data in the login information completely match the records in the whitelist and the multi-factor correlation also meets the requirements, then the whitelist check passes, and the system will allow the login process to continue and enter the next verification link. If any piece of information does not match or the association relationship is abnormal, the system determines that the whitelist check fails, rejects the user's login request, may record this abnormal login behavior, and at the same time feedback the reason for the login failure to the user, prompting the possible problems, such as "the username or login address is not in the whitelist", etc.

[0083] In this embodiment, the preliminary format verification includes: checking whether the username conforms to the specified character rules, judging whether the username is valid, checking whether the password length is within the specified range, judging whether the password length is compliant, confirming whether the login information contains required fields to ensure information integrity, performing escape processing on special characters to prevent the risk of injection attacks;

[0084] In this embodiment, the information check includes: Legality check, account legality: Check whether the account entered by the user complies with the naming specifications stipulated by the system, such as whether it only contains letters, numbers, and specific characters, and whether the length is within the specified range, etc., to prevent malicious users from performing injection attacks by entering special characters or overly long characters, etc.; password legality: Verify whether the password meets the complexity requirements, such as whether it contains a combination of uppercase and lowercase letters, numbers, and special characters, to improve the security of the password and reduce the risk of being cracked; Integrity check, mandatory item check: Ensure that all necessary login information fields have been filled, such as username, password, verification code, etc., to prevent abnormal login processes due to missing information; associated information integrity: If the login information contains associated content, such as the correspondence between the ID number and name, the rationality of the email and username, etc., check whether this associated information is complete and mutually matching; Authenticity check, email verification: Check whether the entered email address is real and valid, which can be done by sending a verification link or verification code to this email and asking the user to confirm, to ensure that the user is using their own valid email for subsequent password recovery and other operations; mobile phone number verification: Verify whether the mobile phone number entered by the user is correct and belongs to the user by sending a text message verification code, increasing the security and traceability of the account; Risk assessment check, abnormal login check: Based on information such as the user's login history and IP address, determine whether the current login is abnormal, such as whether it is logged in from a strange IP address or during abnormal time periods, etc., to prevent the risk of account theft; behavior characteristic check: Analyze the behavior characteristics when the user logs in, such as input speed, click frequency, etc., and compare them with the user's historical behavior data to determine whether it is an operation by the user himself, preventing the account from being misused by others.

[0085] The beneficial effects of the above technical solution: Through the multiple verification processes of whitelist check, preliminary information verification, and information check, the security of the system is effectively improved. The whitelist check ensures that only legitimate users can access. The preliminary information verification promptly eliminates invalid information. The information check further confirms the user's identity and data accuracy, effectively preventing forged login information, malicious attacks, and data tampering, enhancing the security of the login process and improving the protection ability of the network service system.

[0086] Embodiment 5:

[0087] The embodiment of the present invention provides a secure login and verification method for a network service system. Based on the verified login information, query the user basic information database to further confirm the existence of the user. If the user exists, obtain the preset encryption key of the user from the blockchain storage and then encrypt the login password of the user terminal, including:

[0088] Determine keywords based on the user identifier in the verified login information, and then search for user records in the main user table of the user basic information database, and determine the number of matching records in the main user table;

[0089] If no user record is found in the main user table, determine the historical record mark and the number of historical record marks corresponding to the user identifier based on the user basic information database;

[0090] Conduct type analysis on the historical record mark, and then determine the type of the historical record mark;

[0091] Based on the type of the historical record mark, determine several associated tables and the number of associated tables corresponding to the user identifier in the user basic information database;

[0092] Based on the keyword, determine several historical change identifiers and the number of historical change identifiers corresponding to the user identifier in all associated tables;

[0093] Determine the existence coefficient of the user based on the number of matching records in the main user table, the number of associated tables corresponding to the user identifier, the number of historical record marks, and the number of historical change identifiers of the user identifier in each associated table;

[0094] Determine the existence of the user based on the user existence coefficient and a preset existence coefficient threshold.

[0095] In this embodiment, the keyword is determined based on the user identifier in the verified login information, and it is an important basis for performing query operations in the user basic information database. Usually, the keyword is the user identifier itself, such as information like username and user ID. Assuming the user identifier in the verified login information is "user001", then "user001" will be used as the keyword to search in the main user table and subsequent associated tables.

[0096] In this embodiment, the number of matching records in the main user table is the number of records that meet the conditions when searching in the main user table of the user basic information database based on the keyword. This number can reflect how many records in the main user table match the user identifier. For example, when searching for the keyword "user001" in the main user table, if the user identifiers of 2 records found are both "user001", then the number of matching records in the main user table is 2; if no matching records are found, the number is 0.

[0097] In this embodiment, a user record refers to a data record in the user basic information database that contains various relevant information of a certain user. Such information may cover the user's basic information (such as name, contact information, etc.), account information (such as password, account status, etc.). For example, there is a record in the main user table with the content that the user ID is "user001", the name is "Zhang San", the contact information is "1*********", and the account status is "normal". This record is a user record.

[0098] In this embodiment, the type of the historical record mark is that when a user record cannot be found in the main user table, it is necessary to search for the historical record mark corresponding to the user identifier, and these marks have different types. Different types reflect different change situations experienced by the user data. For example, the migration mark: indicates that the user's data has been migrated from one database to another. For example, because of system upgrade, the data of user "user001" has been migrated from the old database to the new database, and there will be a migration mark at this time. The merge mark: means that the user's account has been merged with other accounts. For example, when users "user001" and "user002" are merged into a new account, a merge mark will be left. The split mark: indicates that the user's account has been split into multiple accounts. Suppose user "user001" is split into "user001_1" and "user001_2", there will be a split mark.

[0099] In this embodiment, the associated table is a table related to the user identifier determined in the user basic information database based on the type of the historical record mark. These tables may store the user's historical data, associated information, etc. The number of associated tables is the number of determined associated tables. For example, by analyzing the historical record mark, it is found that user "user001" has migration and merge situations, and the associated tables related to it are "migration_history" (migration history table) and "merge_record" (merge record table). Then the associated tables are "migration_history" and "merge_record", and the number of associated tables is 2.

[0100] In this embodiment, the historical change identifier is found in all associated tables based on keywords, and it is an identifier related to the user identifier that can reflect the historical changes of user data. The number of historical change identifiers is the number of such identifiers found. For example, in the "migration_history" table, the historical change identifiers related to the keyword "user001" are "mig_001" and "mig_002"; in the "merge_record" table, "merge_001" is found, so the historical change identifiers are "mig_001", "mig_002", and "merge_001", and the number of historical change identifiers is 3.

[0101] The beneficial effects of the above technical solution: By verifying the user identity at multiple levels, the system security is improved. By steps such as verifying the login information, querying the user basic information library, analyzing the historical record marks and change identifiers, it is judged whether the user really exists. Combining with the blockchain technology to store the encryption key, the security of the login password is ensured. The calculation of the user existence coefficient further strengthens the accuracy of identity verification, effectively prevents illegal users from accessing, improves the protection ability of the network service system, and reduces the security risk.

[0102] Embodiment 6:

[0103] The embodiment of the present invention provides a secure login and verification method for a network service system. Based on the number of matching records in the main user table, the number of associated tables corresponding to the user identifier, the number of historical record marks, and the number of historical change identifiers of the user identifier in each associated table, the user existence coefficient is determined, including:

[0104] Based on the number of matching records in the main user table, the number of associated tables corresponding to the user identifier, the number of historical record marks, and the number of historical change identifiers of the user identifier in each associated table, the user existence coefficient is determined:

[0105]

[0106] Wherein, is the user existence coefficient, is the number of records matched by the user identifier in the main user table, is the number of records matched by the user identifier in the th associated table, is the total number of associated tables, is the number of historical record marks corresponding to the user identifier, is the total number of preset historical record mark types, 1 is the conversion coefficient corresponding to the main user table match, is the conversion coefficient corresponding to the associated table match, Is the conversion coefficient corresponding to the historical record mark.

[0107] In this embodiment, If the user identifier directly matches the main user table, a logarithmic function is used for compression calculation to avoid excessive values from dominating the result while ensuring its importance;

[0108] In this embodiment, Among all associated tables, the number of matching historical change identifiers is square-rooted to amplify the impact of low numbers and reduce the impact of high numbers; a is added to the denominator to balance the impact of historical record marks on the final coefficient;

[0109] In this embodiment, The more historical record marks there are, the smaller the corresponding attenuation of the existence coefficient (the exponential function reflects the impact of the user's long-term activity). is used for normalization to prevent historical marks from dominating the coefficient in extreme cases.

[0110] Beneficial effects of the above technical solution: By calculating the user existence coefficient and combining multi-dimensional information such as the main user table, associated tables, and historical record marks, it can accurately determine whether a user truly exists. By setting conversion coefficients for each table and mark type, the weights of different factors can be flexibly adjusted, thereby improving the accuracy and reliability of identity verification, effectively reducing the risk of system attacks, avoiding false user logins, and enhancing the security and protection capabilities of the network service system.

[0111] Embodiment 7:

[0112] The embodiment of the present invention provides a secure login and verification method for a network service system. The encrypted login password is compared with the encrypted password in the database to verify the password correctness. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel, including:

[0113] Compare the encrypted login password with the encrypted value of the user password stored in the database;

[0114] If the encrypted login password is the same as the stored encrypted password, the password is considered correct; otherwise, the login fails and an error message is returned to the user terminal;

[0115] When the password is correct, a one-time dynamic verification code is generated based on the server and a preset generator and then sent to the user's reserved device through an encrypted communication channel.

[0116] In this embodiment, the encrypted value of the user password refers to the encrypted result obtained by converting the user password through an encryption algorithm before it is stored in the database. This encrypted value is stored in the database to protect the security of the user password and prevent the password from being leaked in plain text. Assume the original password of the user is password123. To ensure password security, the system uses an encryption algorithm (such as SHA-256) to encrypt this password, obtaining an encrypted string of a fixed length. This encrypted string is the encrypted value of the user password. For example: original password: password123, encrypted value obtained by using SHA-256 encryption: ef92b778bafe771e89245b8d6b0f1d556e0d2ac622c487dfc3e3810f59782a6a. When the user logs in, the system encrypts the password entered by the user in the same way and then compares it with the encrypted value stored in the database. If the two encrypted values are the same, it means the password is correct and the user can log in.

[0117] The beneficial effects of the above technical solution: By encrypting the login password and comparing it with the encrypted password value in the database, the security of the user password is ensured, avoiding the risk of plain text password leakage. Once the password verification is successful, the system generates a one-time dynamic verification code and sends it to the user's reserved device through an encrypted communication channel, further enhancing the security of identity verification. This method effectively improves the security of the user login process, prevents password guessing and man-in-the-middle attacks, and ensures the protection of user data.

[0118] Embodiment 8:

[0119] The embodiment of the present invention provides a secure login and verification method for a network service system, which generates a one-time dynamic verification code based on a server and a preset generator, including:

[0120] Obtain parameters related to security requirements, and then determine the length of the verification code:

[0121]

[0122] Wherein, is the length of the verification code, is the preset maximum number of verification attempts, is the validity period of the verification code, is the maximum attempt frequency of the preset attacker, is the size coefficient of the verification code character set, is the ceiling symbol;

[0123] Generate a one-time dynamic verification code based on the server, the preset generator, the verification code length, and the current timestamp.

[0124] In this embodiment, the length of the verification code refers to the number of characters contained in the one-time dynamic verification code. It is calculated based on parameters related to security requirements. This length plays a crucial role in the security of the verification code. A longer verification code is usually more difficult to crack, but it may cause inconvenience to users when entering; a shorter verification code is convenient for users to enter, but its security may be relatively low. The length of the verification code calculated by combining multiple security factors can find a balance between security and user experience. For example, assuming that the length of the verification code calculated according to the above formula is 6, then the generated one-time dynamic verification code will consist of 6 characters, such as "5A3x98".

[0125] In this embodiment, the preset maximum attempt frequency of the attacker is a pre-set maximum number of times that the attacker can attempt to guess the verification code within a unit time based on the estimation of the possible attack situation of the system. This parameter reflects an assumption of the intensity of potential attacks on the system and is used to calculate the length of the verification code that can effectively resist attacks. If the system expects to be subjected to relatively fierce attacks, that is, the attacker's attempt frequency is high, then when calculating the length of the verification code, it will tend to generate longer and more complex verification codes to increase the difficulty of cracking.

[0126] In this embodiment, the validity period of the verification code refers to the time interval from the moment when the one-time dynamic verification code is generated to the moment when the verification code loses its validity. Within this validity period, the verification code entered by the user will be recognized by the system and used for identity verification; once it exceeds the validity period, even if the entered verification code is correct, the system will reject the verification and require the user to obtain a new verification code. This mechanism increases the security of the verification code and reduces the risk of the verification code being intercepted and maliciously used subsequently. For example, if the validity period of the verification code is set to 5 minutes, then within 5 minutes after the verification code is generated, the user can use this verification code for login verification and other operations. For example, the verification code generated at 10:00 is valid when entered before 10:05 and will become invalid after 10:05, and the user needs to obtain a new verification code.

[0127] The beneficial effects of the above technical solutions: By generating one-time dynamic verification codes based on parameters related to security requirements (such as the length and validity period of the verification code), the security and effectiveness of the verification code are ensured. Through the preset maximum attempt frequency of the attacker and the verification code character size coefficient, brute-force cracking attacks are effectively prevented, and the protection ability of the system is improved. At the same time, the generation of the verification code depends on the server and the preset generator, making the verification code highly random and unpredictable, enhancing the security of the network service system.

[0128] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A secure login and verification method for a network service system, characterized in that: include: Step 1: A login request is sent from a user terminal to a server, and then a challenge code is generated by the server and the user terminal uses a private key to encrypt and determine the signature information, wherein the login request carries a user identifier; Step 2: Based on the user terminal, the signature information and public key are sent to the server for verification and matching, and then a session token is generated and returned to the user terminal, and the login information of the user terminal is obtained through the user login request; Step 3: Verify the login information, query the user basic information database based on the verified login information, and then confirm the existence of the user. If the user exists, obtain the user's preset encryption key from the blockchain storage and encrypt the login password of the user terminal; Step 4: Compare the encrypted login password with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel; Step 5: Obtain the dynamic verification code of the user terminal and verify the validity of the dynamic verification code of the user terminal. After the verification is passed, a secure login token is allocated to the user to complete the login process.

2. A secure login and verification method for a network service system according to claim 1, characterized in that: The user terminal sends a login request to the server, generates a challenge code based on the server, and the user terminal uses the private key to encrypt and determine the signature information, including: Acquire login-related data based on several preset data sources, wherein the login-related data includes: timestamp, high entropy random number, device feature hash value, behavior feature and key fragment; Combine the timestamp, high entropy random number, device feature hash value, behavior feature and key fragment into a string; Based on the user terminal sending a login request to the server, the server calls the smart contract string to generate an initial challenge code; A validity period mark is added to the challenge code to generate a challenge code, and the user terminal encrypts the challenge code using a private key to determine the signature information.

3. A secure login and verification method for a network service system according to claim 1, characterized in that: Generate a session token, including: The time when the user terminal sends the login request to the server is determined as the session time, thereby generating a session timestamp; Combine the user ID and session timestamp to generate basic data, and sign the basic data based on the server private key; The signature and basic data are encapsulated into a session token, and the encapsulated session token is returned to the user terminal.

4. A secure login and verification method for a network service system according to claim 1, characterized in that: Verify the login information, including: whitelist check, preliminary information verification and information check.

5. A secure login and verification method for a network service system according to claim 1, characterized in that: Based on the verified login information, the user basic information database is queried to confirm the existence of the user. If the user exists, the user's preset encryption key is obtained from the blockchain storage to encrypt the login password of the user terminal, including: Determine the keyword based on the user ID of the verified login information, and then search for the user record in the main user table in the user basic information database, and determine the number of matching records in the main user table; If the user record is not found in the main user table, the historical record mark and the number of historical record marks corresponding to the user ID are determined based on the user basic information database; Performing type analysis on the historical record mark to determine the type of the historical record mark; Determine a number of association tables and the number of association tables corresponding to the user identifier in the user basic information database based on the type of the historical record mark; Determine a number of historical change identifiers and the number of historical change identifiers corresponding to the user identifier in all associated tables based on the keyword; Determine the user's existence coefficient based on the number of matching records in the main user table, the number of association tables corresponding to the user ID, the number of historical record marks, and the number of historical change marks of the user ID in each association table; The presence of the user is determined based on the user presence coefficient and a preset presence coefficient threshold.

6. A secure login and verification method for a network service system according to claim 5, characterized in that: The user's existence coefficient is determined based on the number of matching records in the main user table, the number of associated tables corresponding to the user ID, the number of historical record marks, and the number of historical change marks of the user ID in each associated table, including: The user's existence coefficient is determined based on the number of matching records in the main user table, the number of associated tables corresponding to the user ID, the number of historical record markers, and the number of historical change markers of the user ID in each associated table: in, is the user's existence coefficient, The number of records that match the user ID in the main user table, For user identification The number of matching records in the associated table, is the total number of associated tables, The number of historical record marks corresponding to the user ID. The total number of preset history mark types. 1 is the conversion coefficient corresponding to the main user table match, Match the corresponding conversion coefficient to the association table, The conversion factor corresponding to the historical record mark.

7. A secure login and verification method for a network service system according to claim 1, characterized in that: The encrypted login password is compared with the encrypted password in the database to verify the correctness of the password. If the password is correct, a one-time dynamic verification code is generated and sent to the user's reserved device through an encrypted communication channel, including: Compare the encrypted login password with the encrypted value of the user password stored in the database; If the encrypted login password is the same as the stored encrypted password, the password is considered correct; otherwise, the login fails and an error message is returned to the user terminal; When the password is correct, a one-time dynamic verification code is generated based on the server and the preset generator, and then sent to the user's reserved device through an encrypted communication channel.

8. A secure login and verification method for a network service system according to claim 7, characterized in that: Generate a one-time dynamic verification code based on the server and the preset generator, including: Get the security requirement related parameters to determine the length of the verification code: in, is the length of the verification code, is the preset maximum number of verifications. The validity period of the verification code. is the preset maximum attempt frequency of the attacker, is the size coefficient of the verification code character set, is the rounding symbol; Generates a one-time dynamic verification code based on the server, preset generator, verification code length, and current timestamp.

Citation Information

Patent Citations

  • Multi-authentication method based on code server

    CN117354032A

  • Block chain-based information authentication method and related equipment

    CN119652526A