Automatic website login method, system and device based on SIM (Subscriber Identity Module) card and medium
By encrypting and storing user accounts and passwords in SIM cards, and using SIM cards to develop gateways to verify login requests, the problem of users memorizing different passwords in multiple Internet applications is solved, and the user experience is improved and data security risks are reduced.
Patent Information
- Application Number
- CN202510000065.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-01
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, users need to remember different passwords in multiple Internet applications, resulting in an increase in the security risk of the application software.
The website automatic login method based on SIM card is adopted. By encrypting and storing the user account and password into the SIM card, the gateway for development of the SIM card is used to detect and verify the login request. If it is passed, the account password information stored in the SIM card is called for decryption and filling.
It realizes that users have no perception of password input of different Internet applications, improves user experience, and reduces data security risks through ciphertext transmission.
Smart Images

Figure CN119995849A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and relates to a website automatic login method, system, device and medium based on a SIM card. Background Art
[0002] Traditional account and password management applications such as one password, LastPassword, iCloud, Xiaomi Cloud, etc. are all stored in the cloud space and have great security risks. Once the application server is hacked or the user's application management password is hacked, the user's passwords for all websites or APPs will be at risk of being leaked, and users need to remember different passwords in multiple Internet applications. When the same account and password are used on different application software, the security risk of the application software will increase. Summary of the invention
[0003] The purpose of the present invention is to solve the problem in the prior art that users need to remember different passwords in multiple Internet applications. When the same account password is used on different application software, the security risk of the application software is increased. A method, system, device and medium for automatic website login based on a SIM card are provided.
[0004] In order to achieve the above object, the present invention adopts the following technical solutions: The website automatic login method based on SIM card includes: Encrypt user account and password and store them in the SIM card; Based on the Internet application, a login request is sent to the server to determine whether the login request passes the detection of the SIM card development gateway. If it passes, the account password information stored in the SIM card is called; Decrypt the called account password information and fill it into the account password field.
[0005] A further improvement of the present invention is: Furthermore, the user account and password are encrypted, specifically: the password is split into several segments, and the length of each password segment is not fixed; the split password segments are encrypted in turn using one or more of a one-way HASH algorithm, a symmetric encryption algorithm, and an asymmetric encryption algorithm, and the encryption method of each password segment is different, and the encrypted password segments are merged to form a final password; if a password segment is encrypted using multiple encryption methods, the password segment encrypted using one encryption method is randomly selected as the final password segment.
[0006] Furthermore, it is determined whether the login request has passed the detection of the SIM card development gateway. Specifically, when a login request sent by an Internet application is received, the server calls the operator's gateway verification interface to check whether the mobile phone number in the request is consistent with the mobile phone number currently used to access the Internet using the SIM card; if they are consistent, the fingerprint information in the request is continued to be verified. If the fingerprint information is different from the fingerprint information corresponding to the current SIM in the database, the login request is considered to have failed.
[0007] Furthermore, before the Internet application sends a login request to the server, it also includes: the Internet application applies to access the SIM card storage gateway, the SIM card storage gateway saves the basic information and application information of the Internet application for subsequent Internet application authentication; the SIM card storage gateway provides OpenApi for Internet application docking; Furthermore, the called account password information is decrypted, specifically: the password is reversely split into several password segments, and the split password segments are decrypted through a one-way HASH algorithm, a symmetric encryption algorithm, and an asymmetric encryption algorithm to obtain the final character segment.
[0008] Furthermore, when an Internet application sends a login request to a server, the login request is encrypted to form an encrypted login information data packet. After receiving the login information data packet, the server decrypts the login information data packet, extracts the digital certificate from the decrypted login information, and then verifies the digital certificate. If the digital certificate verification is successful, the server will consider the login request to be legal. If the digital certificate verification fails, the server will reject the login request and return a corresponding error message to the client.
[0009] Furthermore, the digital certificate is verified, specifically: checking the signature of the digital certificate authority to ensure that the digital certificate is issued by a trusted certificate authority; checking the validity period of the digital certificate to ensure that the digital certificate is within the validity period; checking whether the digital certificate has been revoked by querying the certificate revocation list or the online certificate status protocol; checking the digital certificate chain, if the digital certificate is issued by an intermediate certificate authority.
[0010] SIM card based website automatic login system, including: An encryption module, which encrypts the user account and password and stores them in the SIM card; A judgment module, wherein the judgment module sends a login request to the server based on the Internet application, and judges whether the login request passes the detection of the SIM card development gateway. If it passes, the account password information stored in the SIM card is called; The decryption module decrypts the called account password information and fills it into the account password column.
[0011] A terminal device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.
[0012] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0013] Compared with the prior art, the present invention has the following beneficial effects: The present invention stores the encrypted account number and password in the SIM card; based on the Internet application, a login request is sent to the server to determine whether the login request passes the detection of the SIM card development gateway. If it passes, the account password information stored in the SIM card is called; the called account password information is decrypted and filled into the account password column. The Internet application of the present invention performs unified access management, and the user password will be transmitted to the access website through ciphertext for authentication. The ciphertext password can only be verified once for login, which will reduce data security risks. The user will be authenticated without being aware of the password input, which greatly improves the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.
[0015] Figure 1 It is a flow chart of the method for automatic website login based on SIM card of the present invention; Figure 2 It is a structural schematic diagram of the website automatic login system based on SIM card of the present invention; Figure 3 It is a structural schematic diagram of the SIM card-based website automatic login device of the present invention. DETAILED DESCRIPTION
[0016] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.
[0017] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0018] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.
[0019] In the description of the embodiments of the present invention, it should be noted that if the terms "upper", "lower", "horizontal", "inner", etc. indicate an orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of the invention is usually placed when in use, it is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention. In addition, the terms "first", "second", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.
[0020] In addition, if the term "horizontal" appears, it does not mean that the component must be absolutely horizontal, but can be slightly tilted. For example, "horizontal" only means that its direction is more horizontal than "vertical", which does not mean that the structure must be completely horizontal, but can be slightly tilted.
[0021] In the description of the embodiments of the present invention, it is also necessary to explain that, unless otherwise clearly specified and limited, the terms "set", "install", "connect", and "connect" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal connection of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0022] The present invention is further described in detail below in conjunction with the accompanying drawings: The SIM card-based storage method refers to opening up a dedicated storage space in the SIM card to store passwords for third-party websites. This method can be widely used in various website and APP authentication scenarios. For example, when a user needs to log in to the Taobao APP, he or she can obtain the password stored in the SIM card through the built-in application of the mobile phone and automatically fill in the Taobao account and password to log in. This method can be used to quickly log in to a website or APP.
[0023] See also Figure 1The present invention discloses a website automatic login method based on a SIM card, comprising: S101: Encrypt the user account and password and store them in the SIM card; The password is split into several segments, and the length of each password segment is not fixed; the split password segments are encrypted in turn using one or more of the one-way HASH algorithm, symmetric encryption algorithm and asymmetric encryption algorithm, and the encryption method of each password segment is different, and the encrypted password segments are merged to form the final password; if a password segment is encrypted using multiple encryption methods, the password segment encrypted using one encryption method is randomly selected as the final password segment.
[0024] S102: Sending a login request to the server based on the Internet application, determining whether the login request passes the detection of the SIM card development gateway, and if so, calling the account password information stored in the SIM card; Determine whether the login request passes the detection of the SIM card development gateway. Specifically, when receiving a login request sent by an Internet application, the server calls the operator's gateway verification interface to check whether the mobile phone number in the request is consistent with the mobile phone number currently used to access the Internet using the SIM card; if they are consistent, continue to verify the fingerprint information in the request. If the fingerprint information is different from the fingerprint information corresponding to the current SIM in the database, the login request is considered to have failed.
[0025] Before the Internet application sends a login request to the server, it also includes: the Internet application applies to access the SIM card storage gateway, the SIM card storage gateway saves the basic information and application information of the Internet application for subsequent Internet application authentication; the SIM card storage gateway provides OpenApi for Internet application docking; When an Internet application sends a login request to a server, the login request is encrypted to form an encrypted login information data packet. When the server receives the login information data packet, it decrypts the login information data packet, extracts the digital certificate from the decrypted login information, and then verifies the digital certificate. If the digital certificate verification is successful, the server will consider the login request to be legal. If the digital certificate verification fails, the server will reject the login request and return a corresponding error message to the client.
[0026] Verify the digital certificate, specifically: check the signature of the digital certificate authority to ensure that the digital certificate is issued by a trusted certificate authority; check the validity period of the digital certificate to ensure that the digital certificate is within the validity period; check whether the digital certificate has been revoked by querying the certificate revocation list or the online certificate status protocol to check whether the certificate has been revoked; check the digital certificate chain if the digital certificate is issued by an intermediate certificate authority.
[0027] S103: Decrypt the called account password information and fill it into the account password field.
[0028] Decrypt the called account password information, specifically: reversely split the password into several password segments, decrypt the split password segments through a one-way HASH algorithm, a symmetric encryption algorithm, and an asymmetric encryption algorithm to obtain the final character segment.
[0029] See also Figure 2 The present invention discloses a website automatic login system based on a SIM card, which is characterized by comprising: An encryption module, which encrypts the user account and password and stores them in the SIM card; A judgment module, wherein the judgment module sends a login request to the server based on the Internet application, and judges whether the login request passes the detection of the SIM card development gateway. If it passes, the account password information stored in the SIM card is called; The decryption module decrypts the called account password information and fills it into the account password column.
[0030] Example: The present invention discloses a website automatic login device based on a SIM card. The login device can automatically fill in corresponding account passwords when a user accesses different applications, thereby improving user experience and security.
[0031] The entire login device is divided into three major modules: SIM card storage module, SIM card development gateway, and password automatic filling module.
[0032] SIM card storage module: uses encryption algorithm to store user account passwords, and uses Hash structure to facilitate data retrieval.
[0033] SIM Card Development Gateway: A Java-based development platform gateway that allows third-party Internet applications to connect and use the SIM card to store account passwords. The gateway will provide authentication and authorization mechanisms to ensure that only connected applications can access and use the account password information stored on the SIM card.
[0034] Password automatic filling module: After the Internet application is connected to the development gateway, the module will automatically identify the application and fill in the account password, and then log in automatically.
[0035] See also Figure 3 ,The present invention mainly includes: a SIM card storage gateway, a SIM card storage module, an automatic filling module and an Internet application authentication; The functions of the SIM card storage gateway are: providing OpenApi for Internet application docking; storing Internet application docking information and review information; Internet applications apply for access to the SIM card storage gateway, which saves the basic information of Internet applications and application information for subsequent storage module application authentication.
[0036] The function of the SIM card storage module is to communicate with the SIM card storage application to obtain whether the application has the permission to store the SIM card password. After the application authentication is passed, the SIM card storage module can automatically save the application account password.
[0037] The automatic filling module will call the SIM storage module in an encrypted manner to obtain the account password and then automatically fill in the account password for login.
[0038] The role of Internet application authentication is: after receiving a request to log in with a user account and password, if it is initiated by the SIM card auto-fill service, the Internet application authenticates with the SIM card storage gateway to obtain the encryption key for data decryption and login authentication.
[0039] The terminal device provided in an embodiment of the present invention. The terminal device of this embodiment includes: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above-mentioned method embodiments are implemented. Alternatively, when the processor executes the computer program, the functions of the modules / units in the above-mentioned device embodiments are implemented.
[0040] The computer program may be divided into one or more modules / units, and the one or more modules / units are stored in the memory and executed by the processor to accomplish the present invention.
[0041] The terminal device may be a computing device such as a desktop computer, a notebook, a PDA, a cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.
[0042] The processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0043] The memory may be used to store the computer programs and / or modules, and the processor implements various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory.
[0044] If the module / unit integrated in the terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0045] The above are only preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A website automatic login method based on a SIM card, characterized in that: include: Encrypt user account and password and store them in the SIM card; Based on the Internet application, a login request is sent to the server to determine whether the login request passes the detection of the SIM card development gateway. If it passes, the account password information stored in the SIM card is called; Decrypt the called account password information and fill it into the account password field.
2. The method for automatic website login based on SIM card according to claim 1, characterized in that: The encryption of the user account and password is specifically as follows: the password is split into several segments, and the length of each password segment is not fixed; the split password segments are encrypted in turn using one or more of a one-way HASH algorithm, a symmetric encryption algorithm, and an asymmetric encryption algorithm, and each password segment has a different encryption method, and the encrypted password segments are merged to form a final password; if a password segment is encrypted using multiple encryption methods, a password segment encrypted using one encryption method is randomly selected as the final password segment.
3. The method for automatic website login based on SIM card according to claim 2, characterized in that: The determination of whether the login request passes the detection of the SIM card development gateway is specifically as follows: when receiving a login request sent by an Internet application, the server calls the operator's gateway verification interface to check whether the mobile phone number in the request is consistent with the mobile phone number currently used to access the Internet using the SIM card; if consistent, continue to verify the fingerprint information in the request. If the fingerprint information is different from the fingerprint information corresponding to the current SIM in the database, it is considered that the login request has failed.
4. The method for automatic website login based on SIM card according to claim 3, characterized in that: Before the Internet application sends a login request to the server, it also includes: the Internet application applies to access the SIM card storage gateway, the SIM card storage gateway saves the basic information and application information of the Internet application for subsequent Internet application authentication; the SIM card storage gateway provides OpenApi for Internet application docking.
5. The method for automatic website login based on SIM card according to claim 4, characterized in that: The decryption of the called account password information is specifically as follows: the password is reversely split into a plurality of password segments, and the split password segments are decrypted by a one-way HASH algorithm, a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain a final character segment.
6. The method for automatic website login based on SIM card according to claim 5, characterized in that: When the Internet application sends a login request to the server, the login request is encrypted to form an encrypted login information data packet. When the server receives the login information data packet, it decrypts the login information data packet, extracts the digital certificate from the decrypted login information, and then verifies the digital certificate. If the digital certificate verification succeeds, the server will consider the login request to be legitimate; if the digital certificate verification fails, the server will reject the login request and return a corresponding error message to the client.
7. The method for automatic website login based on SIM card according to claim 6, characterized in that: The verification of the digital certificate is specifically as follows: checking the signature of the digital certificate issuing authority to ensure that the digital certificate is issued by a trusted certificate issuing authority; checking the validity period of the digital certificate to ensure that the digital certificate is within the validity period; checking whether the digital certificate has been revoked by querying the certificate revocation list or the online certificate status protocol; checking the digital certificate chain to check if the digital certificate is issued by an intermediate certificate issuing authority.
8. The website automatic login system based on SIM card is characterized by: include: An encryption module, which encrypts the user account and password and stores them in the SIM card; A judgment module, wherein the judgment module sends a login request to the server based on the Internet application, and judges whether the login request passes the detection of the SIM card development gateway. If it passes, the account password information stored in the SIM card is called; The decryption module decrypts the called account password information and fills it into the account password column.
9. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.