Account login verification method and device, electronic equipment and storage medium
By obtaining the requirements information of the account to be logged in and determining its login type, and combining the zero-trust policy to authenticate the login credentials, the problem of low security in traditional user authentication methods is solved, and higher security and reliability are achieved.
Patent Information
- Application Number
- CN202510166958.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-14
AI Technical Summary
The traditional user authentication method is based on users and passwords, poses serious security risks and is vulnerable to cyber attacks and threats, resulting in low security of user authentication.
Provides a login verification method for an account, which can obtain the required information of the account to be logged in, determine its login type, and authenticate the login credentials based on the zero-trust policy to ensure that the login behavior of the account to be logged in is in a normal behavior state.
Improves the security of user authentication, reduces the risk of cyber attacks and threats, and ensures the reliability of user authentication.
Smart Images

Figure CN120017367A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to an account login verification method, device, electronic device and storage medium. Background Art
[0002] With the digitization of financial services and the continuous improvement of the network level, the security and reliability of user identity authentication have become particularly critical. The traditional user identity authentication method is based on user and password, but this method has serious security risks and is vulnerable to network attacks and threats, resulting in technical problems such as low security of user identity authentication.
[0003] Currently, no effective solution has been proposed for the technical problem of low security of user identity authentication in related technologies. Summary of the invention
[0004] The main purpose of the present application is to provide an account login verification method, device, electronic device and storage medium to solve the technical problem of low security of user identity authentication in related technologies.
[0005] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a method for login verification of an account is provided. The method comprises: obtaining the demand information of the account to be logged in, wherein the demand information is used to characterize the identity authentication demand of the account to be logged in; based on the demand information, obtaining the login type of the account to be logged in, wherein the login type is used to characterize the identity authentication method of the account to be logged in; based on the login type, determining the login credentials and initial session state of the account to be logged in, wherein the initial session state is used to characterize that the account to be logged in has not performed interactive operations on the management system of the account to be logged in; based on the initial session state, authenticating the login credentials according to the zero-trust policy, and obtaining the verification result of the account to be logged in, wherein the zero-trust policy is used to characterize the rules for authenticating the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state.
[0006] Optionally, based on the initial session state, the login credentials are authenticated in accordance with the zero trust policy to obtain a verification result of the account to be logged in, including: entering the login credentials in the terminal editor of the account to be logged in to obtain a login result of the account to be logged in; wherein the login result is used to characterize a successful login to the account to be logged in; based on the login result, the initial session state is switched to a target session state of the account to be logged in, wherein the target session state is used to characterize that the account to be logged in has not performed any interactive operations on the management system; based on the target session state, the login credentials are authenticated in accordance with the zero trust policy to obtain a verification result.
[0007] Optionally, based on the target session state, the login credentials are authenticated in accordance with the zero trust policy to obtain a verification result, including: based on the target session state, using the management system to obtain the target login credentials of the account to be logged in; in response to the target login credentials and the login credentials being the same, obtaining a verification result.
[0008] Optionally, after switching the initial session state to the target session state of the account to be logged in based on the login result, the method also includes: obtaining the permission level of the account to be logged in, wherein the permission level is used to characterize the permission level of the account to be logged in to access resources in the management system; based on the permission level, generating an access page for the account to be logged in.
[0009] Optionally, the method also includes: obtaining initial location information of the account to be logged in; monitoring the initial location information to obtain target location information of the account to be logged in, wherein the geographical location in the target location information is different from the geographical location in the initial location information; based on the target location information, triggering alarm information, wherein the alarm information is used to indicate that there is an abnormality in the login credentials of the account to be logged in.
[0010] Optionally, the login types include: a first login type, a second login type and a third login type, wherein the first login type is used to represent a login through the biometric information of the target object corresponding to the account to be logged in, the second login type is used to represent a login through a preset key of the account to be logged in, and the third login type is used to represent a login through a preset password of the terminal device of the account to be logged in.
[0011] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a login verification device for an account is provided. The device includes: a first acquisition unit, which is used to acquire the demand information of the account to be logged in, wherein the demand information is used to characterize the identity authentication demand of the account to be logged in; a second acquisition unit, which is used to acquire the login type of the account to be logged in based on the demand information, wherein the login type is used to characterize the identity authentication method of the account to be logged in; a determination unit, which is used to determine the login credentials and initial session state of the account to be logged in based on the login type, wherein the initial session state is used to characterize that the account to be logged in has not performed interactive operations with the management system of the account to be logged in; a third acquisition unit, which is used to authenticate the login credentials according to the zero-trust policy based on the initial session state, and obtain the verification result of the account to be logged in, wherein the zero-trust policy is used to characterize the rules for authenticating the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state.
[0012] Optionally, the third acquisition unit may include: a first acquisition module, used to enter login credentials in the terminal editor of the account to be logged in, and obtain a login result of the account to be logged in; wherein the login result is used to characterize a successful login to the account to be logged in; a switching module, used to switch the initial session state to a target session state of the account to be logged in based on the login result, wherein the target session state is used to characterize that the account to be logged in has not performed any interactive operations on the management system; a second acquisition module, used to authenticate the login credentials according to the zero trust policy based on the target session state, and obtain a verification result.
[0013] Optionally, the second acquisition module may include: a first acquisition submodule, used to obtain the target login credentials of the account to be logged in using the management system based on the target session state; and a second acquisition submodule, used to obtain a verification result in response to the target login credentials and the login credentials being the same.
[0014] Optionally, after the initial session state is switched to the target session state of the account to be logged in based on the login result, the third acquisition unit may also include: an acquisition module for acquiring the permission level of the account to be logged in, wherein the permission level is used to characterize the permission level of the account to be logged in to access resources in the management system; a generation module for generating an access page for the account to be logged in based on the permission level.
[0015] Optionally, the device also includes: a fourth acquisition unit, used to acquire the initial location information of the account to be logged in; a monitoring unit, used to monitor the initial location information to obtain the target location information of the account to be logged in, wherein the geographical location in the target location information is different from the geographical location in the initial location information; a triggering unit, used to trigger alarm information based on the target location information, wherein the alarm information is used to indicate that there is an abnormality in the login credentials of the account to be logged in.
[0016] Optionally, the login types include: a first login type, a second login type and a third login type, wherein the first login type is used to represent a login through the biometric information of the target object corresponding to the account to be logged in, the second login type is used to represent a login through a preset key of the account to be logged in, and the third login type is used to represent a login through a preset password of the terminal device of the account to be logged in.
[0017] In an embodiment of the present application, demand information of an account to be logged in is obtained, wherein the demand information is used to characterize the identity authentication requirement of the account to be logged in; based on the demand information, a login type of the account to be logged in is obtained, wherein the login type is used to characterize the identity authentication method of the account to be logged in; based on the login type, login credentials and an initial session state of the account to be logged in are determined, wherein the initial session state is used to characterize that the account to be logged in has not performed any interactive operations with the management system of the account to be logged in; based on the initial session state, the login credentials are authenticated according to a zero-trust policy to obtain a verification result of the account to be logged in, wherein the zero-trust policy is used to characterize the rules for performing identity authentication on the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state. That is to say, the present application can first obtain the demand information of the account to be logged in, and then according to the demand information obtained above, the login type of the account to be logged in can be obtained, and then according to the login type, the login credentials and initial session status of the account to be logged in can be determined, and finally according to the initial session status obtained above, the login credentials are authenticated according to the zero trust policy to achieve the purpose of obtaining the verification result of the account to be logged in. Considering that after obtaining the login type of the account to be logged in according to the demand information, the login credentials and initial session status of the account to be logged in can be determined according to the login type, and then the login credentials are authenticated according to the zero trust policy to obtain the verification result of the account to be logged in, and the account to be logged in corresponds to the user who needs to log in, that is, the above steps can be used to authenticate the user who needs to log in, so as to solve the technical problem of low security of user identity authentication, and achieve the technical effect of improving the security of user identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0019] Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a login verification method for an account is shown;
[0020] Figure 2 is a flowchart of a login verification method for an account according to an embodiment of the present application;
[0021] Figure 3 is a schematic diagram of an account login verification device according to an embodiment of the present application;
[0022] Figure 4 It is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0023] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0025] It is understandable that the collected information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data are in compliance with relevant laws, regulations and standards, necessary confidentiality measures are taken, and public order and good customs are not violated, and corresponding operation entrances are provided for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions to provide users with corresponding operation entrances for users to choose to agree or refuse the results of automated decision-making; if the user chooses to refuse, the expert decision-making process will be entered.
[0026] According to an embodiment of the present application, a method embodiment of a method for login verification of an account is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0027] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal (or mobile device) for implementing a login verification method for an account is shown. Figure 1As shown, the computer terminal 10 (or mobile device) may include one or more (102a, 102b, ..., 102n are used to illustrate) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.
[0028] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10 (or mobile device). As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0029] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the login verification method of the account in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, the login verification method of the account mentioned above is realized. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0030] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0031] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or mobile device).
[0032] Under the above operating environment, this application provides Figure 2 The login verification method for the account shown. Figure 2 It is a flowchart of a method for logging in and verifying an account according to an embodiment of the present application.
[0033] Step S201, obtaining the requirement information of the account to be logged in.
[0034] In step S201 of the embodiment of the application, the requirement information of the account to be logged in can be obtained, wherein the requirement information is used to characterize the identity authentication requirement of the account to be logged in. The account to be logged in corresponds to a user to be logged in. The account to be logged in can be called a user account to be logged in.
[0035] Optionally, the account to be logged in can be used to represent the account registered by the user on a specific website or application, such as a registered mobile phone number, email account, etc. It should be noted that this only provides examples for illustrating the account representation method of the account to be logged in, and does not specifically limit the account representation method of the account to be logged in.
[0036] For example, based on a user's non-logged-in account on a specific website or application, information required to log in to the account is obtained so that the account to be logged in can be successfully logged in.
[0037] Step S202, based on the requirement information, obtaining the login type of the account to be logged in;
[0038] In step S202 of the embodiment of the application, the login type of the account to be logged in can be obtained according to the obtained demand information, wherein the login type can include multiple preset login methods.
[0039] Optionally, the login type is used to characterize the identity authentication method of the account to be logged in, such as biometric login method, one-time password login method, and password login method. It should be noted that the login type is only illustrated here and is not specifically limited.
[0040] For example, based on the information about the requirements for logging into the account, the user can select a login type that suits his or her own login method so that his or her account can be logged in successfully and quickly.
[0041] It can be understood that this is only a preferred implementation method for obtaining the login type of the account to be logged in, and the process and method for obtaining the login type of the account to be logged in are not specifically limited. As long as the process and method for obtaining the login type of the account to be logged in are based on the demand information, they are within the protection scope of this application and are not listed here.
[0042] Step S203: Determine the login credentials and initial session status of the account to be logged in based on the login type.
[0043] In step S203 of the application embodiment, after obtaining the login type, the login credentials and initial session state of the account to be logged in can be determined, wherein the initial session state is used to indicate that the account to be logged in has not performed any interactive operation on the management system of the account to be logged in.
[0044] Optionally, the management system is used to manage and control user accounts, including creating, editing, deleting accounts, setting account permissions and access control, recording account operation logs, etc., wherein the management system may be referred to as the system. Through this system, administrators can effectively manage user accounts, thereby effectively ensuring the security and stability of the system.
[0045] Optionally, the interactive operation is used to represent the interaction process between the user corresponding to the account to be logged in and the system. That is, the user can send instructions, request information or control operations to the management system by performing interactive operations with the system. For example, the interactive operation may include clicking, dragging, inputting text, selecting a menu, etc.
[0046] For example, after selecting the login type that suits the user, the user can determine the login credentials of the account to be logged in, and determine that the session state at this time is a state of not interacting with the management system, thereby indicating that the account to be logged in at this time has not successfully logged in.
[0047] It should be noted that this is only a preferred implementation method for determining the login credentials and initial session status of the account to be logged in, and the process and method for determining the login credentials and initial session status of the account to be logged in are not specifically limited. As long as it is based on the login type, the process and method for determining the login credentials and initial session status of the account to be logged in are within the scope of protection of this application and are not listed here.
[0048] Step S204: Based on the initial session state, the login credentials are authenticated according to the zero trust policy to obtain a verification result of the account to be logged in.
[0049] In step S204 of the application embodiment, according to the initial session state obtained in the above steps, the login credentials can be authenticated according to the zero trust policy to obtain the verification result of the account to be logged in, wherein the zero trust policy is used to characterize the rules for authenticating the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state.
[0050] For example, when the user determines that the current session state is a state of not interacting with the management system, the login credentials can be authenticated according to the rules for authenticating the login account to achieve the purpose of obtaining the verification result, thereby ensuring that the user's identity is credible and that no abnormal behavior occurs after the user successfully logs in.
[0051] It should be noted that this is only a preferred implementation method for obtaining the verification result of the account to be logged in, and the process and method for obtaining the verification result of the account to be logged in are not specifically limited. As long as the login credentials are authenticated based on the initial session state in accordance with the zero trust policy, the process and method for obtaining the verification result of the account to be logged in are within the protection scope of this application and will not be repeated here.
[0052] In steps S201 to S204 of the embodiment of the present application, the demand information of the account to be logged in can be obtained first, and then the login type of the account to be logged in can be obtained based on the demand information obtained above, and then the login credentials and initial session status of the account to be logged in can be determined based on the login type, and finally the login credentials are authenticated according to the zero trust policy based on the initial session status obtained above, so as to achieve the purpose of obtaining the verification result of the account to be logged in. Considering that after the login type of the account to be logged in is obtained according to the demand information, the login credentials and initial session status of the account to be logged in can be determined according to the login type, and then the login credentials are authenticated according to the zero trust policy to obtain the verification result of the account to be logged in, and the account to be logged in corresponds to the user who needs to log in, the above steps are used to authenticate the user who needs to log in, so as to solve the technical problem of low security of user identity authentication, and achieve the technical effect of improving the security of user identity authentication.
[0053] In the account login verification method provided in the embodiment of the present application, based on the initial session state, the login credentials are authenticated in accordance with the zero trust policy to obtain a verification result of the account to be logged in, including: entering the login credentials in the terminal editor of the account to be logged in to obtain a login result of the account to be logged in; wherein the login result is used to characterize a successful login to the account to be logged in; based on the login result, the initial session state is switched to a target session state of the account to be logged in, wherein the target session state is used to characterize that the account to be logged in has not performed any interactive operations on the management system; based on the target session state, the login credentials are authenticated in accordance with the zero trust policy to obtain a verification result.
[0054] In this embodiment, the login credentials can be entered in the terminal editor of the account to be logged in to obtain the login result of the account to be logged in, and then according to the login result obtained above, the initial session state is switched to the target session state of the account to be logged in, so that the login credentials can be authenticated according to the zero trust policy based on the target session state, thereby achieving the purpose of obtaining the verification result.
[0055] Optionally, the terminal editor can be an editor displayed on the interface of the terminal used by the user, wherein the editor can be called a property editor, and the terminal can be various devices with computing and communication functions, such as personal computers, smart phones, tablet computers, and smart watches.
[0056] Optionally, the user can select a suitable login authentication method in the authentication area of the terminal. For example, the middle of the terminal screen contains a component for the user to select a login authentication method. After the user selects the corresponding login authentication method, different editors will be changed for the user to provide identity authentication related information. After the user selects the identity authentication method, the terminal screen will display an input area for the user to enter identity authentication related information. For example, after the user selects password authentication, an editor for entering the user password will be displayed. If the user selects SMS authentication, an editor for entering the SMS verification code will be displayed, so that the user can choose a suitable authentication method according to their own needs, achieving the technical effect of improving the authentication speed of the user's identity.
[0057] In the account login verification method provided in the embodiment of the present application, based on the target session state, the login credentials are authenticated in accordance with the zero trust policy to obtain a verification result, including: based on the target session state, using the management system to obtain the target login credentials of the account to be logged in; in response to the target login credentials and the login credentials being the same, obtaining a verification result.
[0058] In this embodiment, after obtaining the target session state, the target login credentials of the account to be logged in can be obtained by using the management system. If the target login credentials and the login credentials are the same, a verification result can be obtained. Among them, the zero trust strategy can be called the zero trust verification principle.
[0059] Optionally, the login credential may be referred to as login information, and may include an identity authentication credential and an authorization credential, wherein the identity authentication credential may be referred to as identity authentication information, and the authorization credential may be referred to as authorization information.
[0060] Furthermore, the target login credential may be a preset login credential, also referred to as preset login information, and may include a preset identity authentication credential and a preset authorization credential, wherein the preset identity authentication credential may be referred to as preset identity authentication information, and the preset authorization credential may be referred to as preset authorization information.
[0061] For example, the zero-trust authentication principle is used to require continuous authentication during the user session, not just at login. The management system uses real-time authentication information and authorization information to verify the user's login information to ensure that the user's identity is always authentic. By introducing zero-trust authentication, the management system will still monitor the user's behavior and identity even after the user logs in, so as to detect abnormal behavior in time and prevent potential risks.
[0062] In the account login verification method provided in the embodiment of the present application, after the initial session state is switched to the target session state of the account to be logged in based on the login result, the method also includes: obtaining the permission level of the account to be logged in, wherein the permission level is used to characterize the permission level of the account to be logged in to access resources in the management system; based on the permission level, generating an access page for the account to be logged in.
[0063] In this embodiment, after obtaining the target session state, the permission level of the account to be logged in can be obtained, and then the access page of the account to be logged in can be generated according to the permission level obtained above.
[0064] For example, after obtaining the target session status, it means that the user's identity authentication is successful. When the user's identity authentication is successful, the user will obtain the corresponding level of authority based on zero trust, and then jump to the page for obtaining the corresponding resources, thereby achieving the effect of improving user experience and page access efficiency.
[0065] It should be noted that this is only a preferred implementation method for generating an access page for the account to be logged in, and does not specifically limit the process and method of generating the access page for the account to be logged in. As long as it is based on the authority level, the process and method of generating the access page for the account to be logged in are within the protection scope of this application and will not be repeated here.
[0066] Optionally, when the account to be logged in is in the initial session state, it means that the user identity has not been verified successfully at this time. You can reselect the login type of the account to be logged in, and re-authenticate the login credentials of the account to be logged in based on the login type at this time. For example, if the user identity authentication fails, the user continues to stay in the current interface, and the user can choose to re-authenticate or change to other identity authentication methods.
[0067] In the account login verification method provided in the embodiment of the present application, the method also includes: obtaining initial location information of the account to be logged in; monitoring the initial location information to obtain target location information of the account to be logged in, wherein the geographical location in the target location information is different from the geographical location in the initial location information; based on the target location information, triggering alarm information, wherein the alarm information is used to indicate that there is an abnormality in the login credentials of the account to be logged in.
[0068] In this embodiment, the initial location information of the account to be logged in can be selected, and then the initial location information can be monitored to obtain the target location information of the account to be logged in. According to the target location information obtained above, an alarm information can be triggered.
[0069] Optionally, when the target location information is different from the initial location information, it means that the user has logged in from a different location or has changed the login location. In this case, an alarm message will be triggered, indicating that there is an abnormality in the login credentials of the account to be logged in.
[0070] Optionally, through artificial intelligence and machine learning technology, the management system can monitor the user's behavior patterns in real time. The management system can learn the user's normal behavior habits and be able to identify abnormal activities, such as logging in from a different location, frequently changing the login location, etc.
[0071] Furthermore, based on the intelligent risk analysis of the management system, the system can automatically trigger alarms, require additional verification, or even temporarily deactivate accounts to guard against potential security threats, thereby improving the security of user authentication.
[0072] In the account login verification method provided in the embodiment of the present application, the login types include: a first login type, a second login type and a third login type, wherein the first login type is used to represent a login through the biometric information of the target object corresponding to the account to be logged in, the second login type is used to represent a login through a preset key of the account to be logged in, and the third login type is used to represent a login through a preset password of the terminal device of the account to be logged in.
[0073] In this embodiment, the login types include: a first login type, a second login type and a third login type. The first login type can be a type of login through the biometric information of the target object corresponding to the account to be logged in, for example, logging in through fingerprints, facial recognition, or iris scanning.
[0074] Optionally, the second login type may be a type of logging in through a preset key or hardware token of the account to be logged in, for example, logging in through a preset security token or hardware key.
[0075] Optionally, the third login type can be a type of login through a preset password of the terminal device of the account to be logged in, wherein the account to be logged in sends authentication information to the terminal device, and after the terminal device receives the authentication information, it generates a dynamic password and sends the dynamic password to the response page of the account to be logged in, for example, logging in through a one-time password generated by a mobile phone application.
[0076] In the account login verification method provided in the embodiment of the present application, the demand information of the account to be logged in can be obtained first, and then the login type of the account to be logged in can be obtained based on the demand information obtained above, and then the login credentials and initial session status of the account to be logged in can be determined based on the login type, and finally the login credentials are authenticated according to the zero trust policy based on the initial session status obtained above, so as to achieve the purpose of obtaining the verification result of the account to be logged in. Considering that after the login type of the account to be logged in is obtained according to the demand information, the login credentials and initial session status of the account to be logged in can be determined according to the login type, and then the login credentials are authenticated according to the zero trust policy to obtain the verification result of the account to be logged in, and the account to be logged in corresponds to the user who needs to log in, that is, the above steps can be used to authenticate the user who needs to log in, so as to solve the technical problem of low security of user identity authentication, and achieve the technical effect of improving the security of user identity authentication.
[0077] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0078] The technical solution of the embodiment of the present application is illustrated below in conjunction with preferred implementation modes.
[0079] With the increasing digitalization and networking of financial services, the security and reliability of user identity authentication have become particularly critical, and the access authentication of massive Internet devices has brought severe challenges to the identity authentication platform. Traditional user identity authentication methods are based on users and passwords. These methods have serious security risks and are vulnerable to network attacks and threats, such as phishing and password cracking, which leads to technical problems such as low security of user identity authentication.
[0080] In order to solve the above problem, a login verification method for an account is proposed. The method can first obtain the demand information of the account to be logged in, and then obtain the login type of the account to be logged in according to the demand information obtained above, and then determine the login credentials and initial session status of the account to be logged in according to the login type, and finally authenticate the login credentials according to the zero trust policy based on the initial session status obtained above, so as to achieve the purpose of obtaining the verification result of the account to be logged in. Considering that after obtaining the login type of the account to be logged in according to the demand information, the login credentials and initial session status of the account to be logged in can be determined according to the login type, and then authenticate the login credentials according to the zero trust policy to obtain the verification result of the account to be logged in, and the account to be logged in corresponds to the user who needs to log in, that is, the above steps can be used to authenticate the user who needs to log in, so as to solve the technical problem of low security of user identity authentication, and achieve the technical effect of improving the security of user identity authentication.
[0081] In the embodiment of the present application, a graphical login authentication interface can be set, that is, the user does not need to pay attention to the logic of identity authentication, but only needs to select the authentication login method in the graphical authentication interface, and then perform the corresponding identity authentication. Among them, the implementation of the above-mentioned graphical login authentication interface can include graphical interface layout, security authentication technology and cross-platform support technology.
[0082] In this embodiment, the graphical interface layout requires the layout of the main interface, which may include: an authentication area, a property editor, and a real-time feedback component, wherein the authentication area is a component in the middle of the screen that contains a user selection of a login authentication method. When the user selects the corresponding login authentication method, different editors will change for the user to provide identity authentication related information.
[0083] Optionally, the main function of the attribute editor is to display an input editor after the user selects an authentication method, so that the user can enter authentication related information. For example, if the user selects password authentication, an editor for entering the user password will be displayed; if the user selects SMS authentication, an editor for entering the SMS verification code will be displayed.
[0084] Optionally, the main function of the real-time feedback component is to display the result of the identity authentication immediately on the interface after the user enters the corresponding authentication login information and clicks confirm.
[0085] Optionally, if the user authentication fails, the user continues to stay on the current interface and can choose to re-authenticate or change to other authentication methods; if the user authentication is successful, the user will obtain the corresponding level of permissions based on zero trust, and will jump to the page for obtaining the corresponding resources.
[0086] In an embodiment of the present application, security authentication technologies may include: multi-factor authentication technology, zero-trust verification technology, blockchain technology, intelligent risk analysis technology, unified identity management technology, and end-to-end encryption technology. Among them, multi-factor authentication technology: when a user logs in, the management system not only relies on the traditional username and password, but also requires the user to provide other factors for authentication. These factors may include biometrics (such as fingerprints, facial recognition, iris scanning), hardware tokens, dynamic passwords (one-time passwords generated by mobile phone applications), etc. This multi-factor authentication method greatly increases the difficulty of identity authentication. Even if one factor is threatened, other factors can still keep the user's identity secure.
[0087] Optionally, zero-trust authentication technology: Zero-trust authentication principles are used to require continuous authentication during the user session, not just at login. The management system uses real-time authentication information and authorization information to verify the user's login information to ensure that the user's identity is always trusted. By introducing zero-trust authentication, even after the user logs in, the management system will still monitor the user's behavior and identity to detect abnormal behavior in a timely manner in order to prevent potential risks.
[0088] Optionally, blockchain technology: Blockchain technology is introduced as the basis for identity authentication, and the user's identity information will be stored on a tamper-proof blockchain. This not only ensures the security of the user's identity information, but also realizes decentralized identity management. Each participant can verify the authenticity of the user's identity, and all identity authentication events will be stored in the form of a distributed ledger, preventing single point failure or malicious tampering.
[0089] Optionally, intelligent risk analysis technology: Through artificial intelligence and machine learning technology, the management system can monitor user behavior patterns in real time. The management system can learn the normal behavior habits of users and identify abnormal activities, such as logging in from a different location, frequently changing the login location, etc. Based on the management system's intelligent risk analysis, the system can automatically trigger alarms, require additional verification, or even temporarily deactivate accounts to prevent potential security threats, thereby improving the security of user authentication.
[0090] Optionally, unified identity management technology: A unified identity management system can be provided, so that users only need to authenticate once to achieve a single identity authentication across different financial institutions. This simplifies the user's identity authentication process and enhances the consistency of identity management. Financial institutions can share verified user identity information to improve efficiency while ensuring security.
[0091] Optionally, end-to-end encryption technology: End-to-end encryption technology can ensure the security of user information during data transmission and storage. Even if the data is intercepted during the data transmission process, it cannot be used maliciously, thus effectively preventing man-in-the-middle attacks and data leakage.
[0092] In an embodiment of the present application, cross-platform support technology may include: network standard support technology, mobile terminal support technology, preset application interface support technology, containerization support technology, adaptability design support technology and open standard support technology.
[0093] Optionally, web standards support technology: adopts identity authentication protocols and interfaces that comply with web standards to ensure cross-platform compatibility on various web browsers to ensure that it can run well on different web browsers and operating systems.
[0094] Optionally, mobile support technology: Provide native mobile applications and support mainstream mobile operating systems, such as Apple OS and Android OS. Improve user experience by optimizing the user interface and ensure consistent and friendly identity authentication on mobile phones and tablet devices.
[0095] Optionally, preset application interface support technology: adopt the design principle of preset application interface support technology to ensure cross-platform and cross-device data interaction and communication. In this way, other platforms and applications can communicate with the user's identity authentication platform through simple hypertext transfer protocol requests, thereby realizing integrated operations with various applications.
[0096] Optionally, containerization support technology: Use containerization technology to ensure consistency across different operating systems and cloud platforms. Containerization enables an application and its dependencies to be encapsulated in a self-contained, portable container, so that it behaves the same across environments.
[0097] Optionally, adaptive design support technology: focus on adaptability in user interface and interaction design to ensure good display effects on various screen sizes and resolutions. Use responsive design and adaptive layout to enable users to easily use the platform on different devices.
[0098] Optionally, open standards support technology: Use open standards to support integration with other identity providers and authentication systems. This way, users can log in through different identity providers without changing the authentication platform.
[0099] In an embodiment of the present application, a large-scale user security identity authentication login platform for the financial industry based on zero trust can be provided. The platform ensures the security of user identity authentication on different channels by integrating at the network, mobile application and interface levels; users can log in using the traditional username and password method, and the system will require users to perform multi-factor authentication, such as fingerprint recognition or mobile phone token verification, and zero trust verification ensures the security of users during the entire session; an enterprise can monitor user activities in real time through the management interface, use intelligent risk analysis technology to identify potential risks, and administrators can investigate abnormal activities, temporarily freeze accounts, or require users to perform additional identity authentication.
[0100] Furthermore, the platform can be applied in e-commerce, called an e-commerce platform, which is used to integrate the zero-trust identity authentication platform into various websites and mobile applications to provide secure user identity authentication services; users need to perform multi-factor identity authentication when making payments, viewing orders, etc. At the same time, the application of blockchain technology ensures the secure storage of user identity information; e-commerce platforms can analyze potential fraud through intelligent risk analysis and take timely measures to protect the security of users and platforms.
[0101] In addition, the internal enterprise system can integrate the zero-trust identity authentication platform into the single sign-on system to achieve highly secure authentication of employee identities; after employees log in through the internal enterprise system, the system will perform zero-trust verification to ensure the employee's identity security during the entire work session, and additional identity authentication is required for sensitive information and operations; enterprise administrators can use the unified identity management system to monitor the identity authentication status of employees in real time, promptly detect abnormal behavior and take corresponding measures.
[0102] The embodiment of the present application also provides a login verification device for an account. It should be noted that the login verification device for an account in the embodiment of the present application can be used to execute the login verification method for an account provided in the embodiment of the present application. The login verification device for an account provided in the embodiment of the present application is introduced below.
[0103] According to an embodiment of the present application, a device for implementing the above-mentioned account login verification method is also provided. Figure 3 is a schematic diagram of a login verification device for an account according to an embodiment of the present application, such as Figure 3 As shown, the device comprises:
[0104] The first acquisition unit 301 is used to acquire requirement information of an account to be logged in, wherein the requirement information is used to represent the identity authentication requirement of the account to be logged in.
[0105] The second acquisition unit 302 is used to acquire the login type of the account to be logged in based on the demand information, wherein the login type is used to represent the identity authentication method of the account to be logged in.
[0106] The determination unit 303 is used to determine the login credentials and initial session state of the account to be logged in based on the login type, wherein the initial session state is used to indicate that the account to be logged in has not performed any interactive operation on the management system of the account to be logged in.
[0107] The third acquisition unit 304 is used to authenticate the login credentials according to the zero trust policy based on the initial session state, and obtain the verification result of the account to be logged in, wherein the zero trust policy is used to characterize the rules for authenticating the identity of the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state.
[0108] The account login verification device provided in the embodiment of the present application obtains demand information of the account to be logged in through a first acquisition unit, wherein the demand information is used to characterize the identity authentication demand of the account to be logged in; obtains the login type of the account to be logged in based on the demand information through a second acquisition unit, wherein the login type is used to characterize the identity authentication method of the account to be logged in; determines the login credentials and initial session state of the account to be logged in based on the login type through a determination unit, wherein the initial session state is used to characterize that the account to be logged in has not performed any interactive operations with the management system of the account to be logged in; authenticates the login credentials according to the zero trust policy based on the initial session state through a third acquisition unit, to obtain a verification result of the account to be logged in, wherein the zero trust policy is used to characterize the rules for authenticating the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state, thereby solving the technical problem of low security of user identity authentication in related technologies, and thereby achieving the technical effect of improving the security of user identity authentication.
[0109] Optionally, in the account login verification device provided in the embodiment of the present application, the third acquisition unit 304 may include: a first acquisition module, used to enter the login credentials in the terminal editor of the account to be logged in, and obtain the login result of the account to be logged in; wherein the login result is used to characterize the successful login to the account to be logged in; a switching module, used to switch the initial session state to the target session state of the account to be logged in based on the login result, wherein the target session state is used to characterize that the account to be logged in has not performed any interactive operations on the management system; a second acquisition module, used to authenticate the login credentials according to the zero trust policy based on the target session state, and obtain a verification result.
[0110] Optionally, in the account login verification device provided in the embodiment of the present application, the second acquisition module may include: a first acquisition sub-module, used to obtain the target login credentials of the account to be logged in using the management system based on the target session state; and a second acquisition sub-module, used to obtain a verification result in response to the target login credentials and the login credentials being the same.
[0111] Optionally, in the account login verification device provided in the embodiment of the present application, after the initial session state is switched to the target session state of the account to be logged in based on the login result, the third acquisition unit 304 may also include: an acquisition module, used to obtain the permission level of the account to be logged in, wherein the permission level is used to characterize the permission level of the account to be logged in to access resources in the management system; a generation module, used to generate an access page for the account to be logged in based on the permission level.
[0112] Optionally, in the account login verification device provided in the embodiment of the present application, the device also includes: a fourth acquisition unit, used to obtain the initial location information of the account to be logged in; a monitoring unit, used to monitor the initial location information to obtain the target location information of the account to be logged in, wherein the geographical location in the target location information is different from the geographical location in the initial location information; a triggering unit, used to trigger alarm information based on the target location information, wherein the alarm information is used to indicate that there is an abnormality in the login credentials of the account to be logged in.
[0113] Optionally, in the account login verification device provided in the embodiment of the present application, the login types include: a first login type, a second login type and a third login type, wherein the first login type is used to characterize the login through the biometric information of the target object corresponding to the account to be logged in, the second login type is used to characterize the login through the preset key of the account to be logged in, and the third login type is used to characterize the login through the preset password of the terminal device of the account to be logged in.
[0114] It should be noted that the above-mentioned modules or units can be hardware components or software components stored in a memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n), and the above-mentioned modules can also be run as part of the device in the computer terminal 10 provided in Example 1.
[0115] An embodiment of the present application may provide an electronic device, Figure 4 is a structural block diagram of an electronic device according to an embodiment of the present application. Figure 4 As shown, the electronic device may include: one or more ( Figure 4 (only one is shown) processor 402, memory 404, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.
[0116] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application, and the processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0117] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: based on the initial session state, authenticate the login credentials according to the zero trust policy to obtain the verification result of the account to be logged in, including: entering the login credentials in the terminal editor of the account to be logged in to obtain the login result of the account to be logged in; wherein the login result is used to characterize the successful login to the account to be logged in; based on the login result, switch the initial session state to the target session state of the account to be logged in, wherein the target session state is used to characterize that the account to be logged in has not performed any interactive operations on the management system; based on the target session state, authenticate the login credentials according to the zero trust policy to obtain the verification result.
[0118] The processor can also call the information and applications stored in the memory through the transmission device to perform the following steps: based on the target session state, authenticate the login credentials in accordance with the zero trust policy to obtain a verification result, including: based on the target session state, using the management system to obtain the target login credentials of the account to be logged in; in response to the target login credentials and the login credentials being the same, obtain a verification result.
[0119] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: after switching the initial session state to the target session state of the account to be logged in based on the login result, the processor is also used to obtain the permission level of the account to be logged in, wherein the permission level is used to characterize the permission level of the account to be logged in to access resources in the management system; and is used to generate an access page for the account to be logged in based on the permission level.
[0120] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: obtain the initial location information of the account to be logged in; monitor the initial location information to obtain the target location information of the account to be logged in, wherein the geographical location in the target location information is different from the geographical location in the initial location information; based on the target location information, trigger an alarm message, wherein the alarm message is used to indicate that there is an abnormality in the login credentials of the account to be logged in.
[0121] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: the login types include: a first login type, a second login type and a third login type, wherein the first login type is used to represent the login through the biometric information of the target object corresponding to the account to be logged in, the second login type is used to represent the login through the preset key of the account to be logged in, and the third login type is used to represent the login through the preset password of the terminal device of the account to be logged in.
[0122] By adopting the embodiment of the present application, a login verification method for an account is provided. The requirement information of the account to be logged in can be obtained first, and then the login type of the account to be logged in can be obtained according to the requirement information obtained above, and then the login credentials and initial session state of the account to be logged in can be determined according to the login type, and finally the login credentials can be authenticated according to the zero-trust policy according to the initial session state obtained above, so as to achieve the purpose of obtaining the verification result of the account to be logged in. Considering that after obtaining the login type of the account to be logged in according to the requirement information, the login credentials and initial session state of the account to be logged in can be determined according to the login type, and then the login credentials can be authenticated according to the zero-trust policy to obtain the verification result of the account to be logged in, and the account to be logged in corresponds to the user who needs to log in, that is, the above steps can be used to authenticate the user who needs to log in, so as to solve the technical problem of low security of user identity authentication, and achieve the technical effect of improving the security of user identity authentication.
[0123] It can be understood by those skilled in the art that Figure 4 The structure shown is for illustration only, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, referred to as MID), a PAD, and other terminal devices. Figure 4 The structure of the electronic device is not limited. Figure 4 More or fewer components (such as network interfaces, display devices, etc.) shown in, or having Figure 4 Different configurations shown.
[0124] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.
[0125] The embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the account login verification method provided in the first embodiment.
[0126] Optionally, in this embodiment, the above storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0127] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing the steps of the account login verification method.
[0128] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0129] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0130] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0131] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0132] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0133] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.
[0134] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for verifying account login, characterized in that: include: Obtaining requirement information of the account to be logged in, wherein the requirement information is used to characterize the identity authentication requirement of the account to be logged in; Based on the requirement information, obtaining a login type of the account to be logged in, wherein the login type is used to characterize an identity authentication method of the account to be logged in; Based on the login type, determining the login credentials and initial session state of the account to be logged in, wherein the initial session state is used to indicate that the account to be logged in has not performed any interactive operation on the management system of the account to be logged in; Based on the initial session state, the login credentials are authenticated according to the zero trust policy to obtain a verification result of the account to be logged in, wherein the zero trust policy is used to characterize the rules for authenticating the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state.
2. The method according to claim 1, characterized in that Based on the initial session state, the login credentials are authenticated according to the zero trust policy to obtain a verification result of the account to be logged in, including: Entering the login credentials in the terminal editor of the account to be logged in, and obtaining a login result of the account to be logged in; wherein the login result is used to indicate a successful login to the account to be logged in; Based on the login result, the initial session state is switched to a target session state of the account to be logged in, wherein the target session state is used to indicate that the account to be logged in has not performed the interactive operation on the management system; Based on the target session state, the login credentials are authenticated according to the zero trust policy to obtain the verification result.
3. The method according to claim 2, characterized in that Based on the target session state, authenticating the login credentials according to the zero trust policy to obtain the verification result includes: Based on the target session state, using the management system to obtain the target login credentials of the account to be logged in; In response to the target login credential being identical to the login credential, obtaining the verification result.
4. The method according to claim 2, characterized in that: After switching the initial session state to the target session state of the account to be logged in based on the login result, the method further includes: Obtaining the permission level of the account to be logged in, wherein the permission level is used to represent the permission level of the account to be logged in to access resources in the management system; Based on the permission level, an access page for the account to be logged in is generated.
5. The method according to claim 1, characterized in that The method further comprises: Obtaining initial location information of the account to be logged in; The initial location information is monitored to obtain target location information of the account to be logged in, wherein the geographical location in the target location information is different from the geographical location in the initial location information; Based on the target location information, an alarm message is triggered, wherein the alarm message is used to indicate that the login credentials of the account to be logged in are abnormal.
6. The method according to claim 1, characterized in that The login types include: a first login type, a second login type and a third login type, wherein the first login type is used to represent a login through the biometric information of the target object corresponding to the account to be logged in, the second login type is used to represent a login through a preset key of the account to be logged in, and the third login type is used to represent a login through a preset password of the terminal device of the account to be logged in.
7. A login verification device for an account, characterized in that: include: A first acquisition unit is used to acquire requirement information of an account to be logged in, wherein the requirement information is used to represent the identity authentication requirement of the account to be logged in; A second acquisition unit, configured to acquire a login type of the account to be logged in based on the requirement information, wherein the login type is used to characterize an identity authentication method of the account to be logged in; A determination unit, configured to determine the login credentials and initial session state of the account to be logged in based on the login type, wherein the initial session state is used to indicate that the account to be logged in has not performed any interactive operation on the management system of the account to be logged in; The third acquisition unit is used to authenticate the login credentials according to the zero trust policy based on the initial session state, and obtain the verification result of the account to be logged in, wherein the zero trust policy is used to characterize the rules for authenticating the account to be logged in, and the verification result is used to characterize that the login behavior of the account to be logged in is in a normal behavior state.
8. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 6 when running.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 6.
10. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Password management method and system suitable for zero-trust network
CN112291071A
Data processing method and device based on zero trust model and electronic equipment
CN116244733A
Zero-trust user identity security detection method and system
CN117150459A
Inter-application authentication method and device and readable storage medium
CN118381626A
Zero trust authentication of secure systems with trusted platform modules
WO2024263557A1