BS architecture system identity authentication method based on security control
By introducing security controls into the B/S architecture system, querying and encrypting the information of user terminal devices, the problem that existing systems cannot perform effective terminal device restrictions and identity authentication is solved, and higher identity authentication security and reliability are achieved.
Patent Information
- Application Number
- CN202510301387.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-05-16
AI Technical Summary
The existing B/S architecture system cannot obtain the unique identifier, IP address and MAC address of the user terminal device through the browser, resulting in the inability to perform effective terminal device restriction and identity authentication.
The security control-based method is adopted to provide the user login interface and login verification function through the identity authentication module. The security control queries the device unique identifier, IP address and MAC address of the terminal device when the user logs in request, and encrypts the login information and device information, and submits it to the back-end service of the identity authentication module for identity authentication.
It significantly improves the security and reliability of identity authentication, has strong flexibility, reduces the security risks of user identity information leakage, and provides more reliable information security guarantees.
Smart Images

Figure CN120017402A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a BS architecture system identity authentication method based on security controls. Background Art
[0002] Since the 1990s, the Internet has spread rapidly around the world, and people's work and life have become increasingly dependent on the Internet. With the deepening of network applications, people's lives and work have become increasingly dependent on the Internet. E-commerce activities such as online shopping and online payment have become part of people's daily lives; social media platforms allow people to share information and communicate anytime and anywhere; working from home has also quietly emerged in recent years. Along with this, network security issues have arisen, and identity authentication has become the basis for ensuring information security. Phishing websites, false advertisements and other fraud activities carried out through the Internet are emerging in an endless stream, and privacy and property losses caused by the leakage of user identity data are becoming more and more frequent. In this context, terminal device restrictions can prevent user identity leakage from causing identity authentication failure, and can also have the effect of restricting users to use specific terminal operating software systems.
[0003] The B / S architecture (Browser-Server architecture) system is a network architecture in which the client accesses and uses server-side applications through a browser. This architecture combines many advantages such as easy access and maintenance, cross-platform compatibility, centralized management, easy expansion, and consistent user interface. Currently, most software systems are developed based on this architecture. However, browsers do not provide methods to obtain local information due to security and privacy considerations. User terminal device restrictions are mainly limited by unique identifiers, IP addresses, and MAC addresses. This information cannot be directly obtained through the browser, resulting in the software system being unable to restrict user terminals.
[0004] Based on the above situation, the present invention proposes a BS architecture system identity authentication method based on security controls. Summary of the invention
[0005] In order to make up for the defects of the prior art, the present invention provides a simple and efficient BS architecture system identity authentication method based on security controls.
[0006] The present invention is achieved through the following technical solutions:
[0007] A BS architecture system identity authentication method based on security controls, characterized in that it includes the following steps:
[0008] Step S1: Provide a user login interface and login verification function through the identity authentication module. When the user clicks to log in on the client, the security control is automatically called to obtain the terminal device information;
[0009] Step S2: When the security control receives the user login request, it immediately queries the device unique identifier, IP address and MAC address of the current terminal to prevent the device information from being inconsistent;
[0010] Step S3: The security control encrypts the login information including the user and password and the terminal device information, and submits them to the identity authentication module backend service after encryption for identity authentication;
[0011] Step S4: The administrator customizes the user device security login restriction conditions through the identity authentication module according to actual needs;
[0012] When the device information of the login terminal device meets the user device security login restriction conditions, the security check passes and the user logs in normally. Otherwise, it fails and the user login request is rejected.
[0013] In step S2, the security control provides a terminal device information query service, which only monitors the 127.0.0.1 IP address and the user-specified port to prevent other terminals from accessing the security control to bypass terminal restrictions and ensure call security.
[0014] In step S2, when the user client queries the terminal device information, the current login user name is passed in; the steps for the security control to query the terminal device information are as follows:
[0015] Step S2.1: Query unique identifier
[0016] a) If the terminal device uses the mac operating system, then:
[0017] i. Get the terminal device hardware information through the command system_profiler SPHardwareDataType;
[0018] ii. Get the terminal device CPUID through the command sysctl-x machdep.cpu.signature;
[0019] iii. Concatenate the hardware identifier, hardware serial number and CPUID in the terminal device hardware information and encrypt them with base64 as a unique identifier;
[0020] b) If the terminal device uses Windows operating system, then:
[0021] i. Get the terminal device hardware identifier through the command wmic csproduct get uuid;
[0022] ii. Get the hardware serial number of the terminal device through the command wmic baseboard get serialnumber;
[0023] iii. Get the terminal device CPUID through the command wmic cpu get processorid;
[0024] iv. Concatenate the hardware identifier, hardware serial number and CPUID of the terminal device and encrypt them with base64 as a unique identifier;
[0025] c) If the terminal device uses the Linux operating system, then:
[0026] i. Get the terminal device hardware identifier through the command dmidecode –s system-uuid;
[0027] ii. Use the command dmidecode –s system-serial-number to obtain the hardware serial number of the terminal device;
[0028] iii. Get the terminal device CPUID through the command dmidecode –t processor;
[0029] iv. Concatenate the hardware identifier, hardware serial number and CPUID of the terminal device and encrypt them with base64 as a unique identifier;
[0030] Step S2.2: Query IP address and MAC address
[0031] Query all network interfaces of the terminal device and retain only the non-loopback global unicast IP address and the MAC address of its network card.
[0032] In step S3, the security control encrypts the requested user name by concatenating a segment of custom fixed characters to obtain the encrypted salt value (Salt), and uses the obtained salt value to encrypt the terminal device information.
[0033] In step S4, in the user device security login restriction conditions, three logical relationships of AND, OR, and NOT are set between the device information, and the corresponding security verification rules are as follows:
[0034] If the device identifier, device IP address and device MAC address are set in the user device security login restriction conditions, the above three types of device information must all be verified and passed, and the identity authentication module considers that the security verification has passed, otherwise it will fail;
[0035] If the device identifier or device IP address and device MAC address are set in the user device security login restriction conditions, if one or both of the device identifier or device IP address pass the verification, and the device MAC address pass the verification at the same time, the identity authentication module considers that the security verification has passed, otherwise it fails;
[0036] If the device identifier and non-device IP address and device MAC address are set in the user device security login restriction conditions, the device identifier verification passes, the device IP address verification fails, and the device MAC address verification passes, the identity authentication module considers that the security verification has passed, otherwise it has failed.
[0037] Unset device information does not participate in logical operations.
[0038] A BS architecture system identity authentication system based on security controls, including an identity authentication module and security controls;
[0039] The identity authentication module is divided into a front-end client and a back-end service in terms of architecture; the front-end client is used for interface display, and the back-end service performs data interaction and logic processing, and is responsible for providing login and logout, secure login management, login log viewing, login password management, security control management and user management functions;
[0040] The identity authentication module divides user roles into administrators and ordinary users, where administrators have all functional permissions and ordinary users only have login, logout and login password management functional permissions;
[0041] The security control is responsible for querying the unique device identifier, IP address and MAC address of the current terminal immediately after receiving the user login request, and encrypting the login information including the user and password and the terminal device information, and submitting them together to the identity authentication module backend service after encryption.
[0042] Login and logout are the core functions of the system. The identity authentication module provides the security device download address through the user login interface. The user downloads and installs the security control by clicking the download security device link;
[0043] Device verification is not performed when a user logs into the system for the first time.
[0044] Secure login management provides the ability to manage user secure login devices. Administrators can customize user device secure login restrictions based on actual needs. The specific setting rules are as follows:
[0045] a) The system only verifies the set device information, and does not verify other unset device information;
[0046] b) Device IP address supports entering specific IP address and IP segment;
[0047] c) Multiple device information are separated by separators. The device to be logged in satisfies one of the device information, that is, it passes the device information verification;
[0048] d) Set three logical relationships between multiple device information: AND, OR, and NOT:
[0049] Set the device identifier, device IP address and device MAC address. All three types of device information must be verified and passed. The identity authentication module considers the security verification to be passed, otherwise it is considered to be failed.
[0050] Set the device identifier or device IP address and device MAC address. If one or both of the device identifier or device IP address pass the verification and the device MAC address pass the verification, the identity authentication module considers that the security verification has passed, otherwise it fails;
[0051] Set the device identifier and non-device IP address and device MAC address. If the device identifier verification passes, the device IP address verification fails, and the device MAC address verification passes, the identity authentication module considers that the security verification has passed, otherwise it has failed.
[0052] A BS architecture system identity authentication device based on security controls, characterized in that it includes a memory and a processor; the memory is used to store a computer program, and the processor is used to implement the above method steps when executing the computer program.
[0053] A readable storage medium, characterized in that: a computer program is stored on the readable storage medium, and the computer program implements the above method steps when executed by a processor.
[0054] The beneficial effects of the present invention are as follows: the BS architecture system identity authentication method based on security controls significantly improves the security and reliability of identity authentication, has strong flexibility, reduces the security risk of user identity information leakage, and can provide more reliable information security protection for enterprises and users. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0056] Attached Figure 1 It is a schematic diagram of the BS architecture system identity authentication method based on security controls of the present invention.
[0057] Attached Figure 2A schematic diagram of a method for querying terminal device information by a security control of the present invention. DETAILED DESCRIPTION
[0058] In order to enable those skilled in the art to better understand the technical solutions in the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0059] In the field of information security technology, security controls provide unique identifiers, IP addresses, and MAC address information for user terminal devices. The identity authentication system combines the unique identifiers, IP addresses, and MAC addresses of user terminal devices with login information such as user names and passwords to perform identity authentication, thereby limiting login terminals and ensuring the security of the software system.
[0060] The BS architecture system identity authentication method based on security controls includes the following steps:
[0061] Step S1: Provide a user login interface and login verification function through the identity authentication module. When the user clicks to log in on the client, the security control is automatically called to obtain the terminal device information;
[0062] Step S2: When the security control receives the user login request, it immediately queries the device unique identifier, IP address and MAC address of the current terminal to prevent the device information from being inconsistent;
[0063] Step S3: The security control encrypts the login information including the user and password and the terminal device information, and submits them to the identity authentication module backend service after encryption for identity authentication;
[0064] Step S4: The administrator customizes the user device security login restriction conditions through the identity authentication module according to actual needs;
[0065] When the device information of the login terminal device meets the user device security login restriction conditions, the security check passes and the user logs in normally. Otherwise, it fails and the user login request is rejected.
[0066] In step S2, the security control provides a terminal device information query service, which only monitors the 127.0.0.1 IP address and the user-specified port to prevent other terminals from accessing the security control to bypass terminal restrictions and ensure call security.
[0067] In step S2, when the user client queries the terminal device information, the current login user name is passed in; the steps for the security control to query the terminal device information are as follows:
[0068] Step S2.1: Query unique identifier
[0069] a) If the terminal device uses the mac operating system, then:
[0070] i. Get the terminal device hardware information through the command system_profiler SPHardwareDataType;
[0071] ii. Get the terminal device CPUID through the command sysctl-x machdep.cpu.signature;
[0072] iii. Concatenate the hardware identifier, hardware serial number and CPUID in the terminal device hardware information and encrypt them with base64 as a unique identifier;
[0073] b) If the terminal device uses Windows operating system, then:
[0074] i. Get the terminal device hardware identifier through the command wmic csproduct get uuid;
[0075] ii. Use the command wmic baseboard get serialnumber to obtain the hardware serial number of the terminal device;
[0076] iii. Get the terminal device CPUID through the command wmic cpu get processorid;
[0077] iv. Concatenate the hardware identifier, hardware serial number and CPUID of the terminal device and encrypt them with base64 as a unique identifier;
[0078] c) If the terminal device uses the Linux operating system, then:
[0079] i. Get the terminal device hardware identifier through the command dmidecode –s system-uuid;
[0080] ii. Use the command dmidecode –s system-serial-number to obtain the hardware serial number of the terminal device;
[0081] iii. Get the terminal device CPUID through the command dmidecode –t processor;
[0082] iv. Concatenate the hardware identifier, hardware serial number and CPUID of the terminal device and encrypt them with base64 as a unique identifier;
[0083] Step S2.2: Query IP address and MAC address
[0084] Query all network interfaces of the terminal device and retain only the non-loopback global unicast IP address and the MAC address of its network card.
[0085] In step S3, the security control encrypts the requested user name by concatenating a segment of custom fixed characters to obtain the encrypted salt value (Salt), and uses the obtained salt value to encrypt the terminal device information.
[0086] In step S4, in the user device security login restriction conditions, three logical relationships of AND, OR, and NOT are set between the device information, and the corresponding security verification rules are as follows:
[0087] If the device identifier, device IP address and device MAC address are set in the user device security login restriction conditions, the above three types of device information must all be verified and passed, and the identity authentication module considers that the security verification has passed, otherwise it will fail;
[0088] If the device identifier or device IP address and device MAC address are set in the user device security login restriction conditions, if one or both of the device identifier or device IP address pass the verification, and the device MAC address pass the verification at the same time, the identity authentication module considers that the security verification has passed, otherwise it fails;
[0089] If the device identifier and non-device IP address and device MAC address are set in the user device security login restriction conditions, the device identifier verification passes, the device IP address verification fails, and the device MAC address verification passes, the identity authentication module considers that the security verification has passed, otherwise it has failed.
[0090] Unset device information does not participate in logical operations.
[0091] The BS architecture system identity authentication system based on security controls includes an identity authentication module and security controls;
[0092] The identity authentication module is divided into a front-end client and a back-end service in terms of architecture; the front-end client is used for interface display, and the back-end service performs data interaction and logic processing, and is responsible for providing login and logout, secure login management, login log viewing, login password management, security control management and user management functions;
[0093] The identity authentication module divides user roles into administrators and ordinary users, where administrators have all functional permissions and ordinary users only have login, logout and login password management functional permissions;
[0094] The security control is responsible for querying the unique device identifier, IP address and MAC address of the current terminal immediately after receiving the user login request, and encrypting the login information including the user and password and the terminal device information, and submitting them together to the identity authentication module backend service after encryption.
[0095] Login and logout are the core functions of the system. The identity authentication module provides the security device download address through the user login interface. The user downloads and installs the security control by clicking the download security device link;
[0096] Device verification is not performed when a user logs into the system for the first time.
[0097] Secure login management provides the ability to manage user secure login devices. Administrators can customize user device secure login restrictions based on actual needs. The specific setting rules are as follows:
[0098] a) The system only verifies the set device information, and does not verify other unset device information;
[0099] b) Device IP address supports entering specific IP address and IP segment;
[0100] c) Multiple device information are separated by separators. The device to be logged in satisfies one of the device information, that is, it passes the device information verification;
[0101] d) Set three logical relationships between multiple device information: AND, OR, and NOT:
[0102] Set the device identifier, device IP address and device MAC address. All three types of device information must be verified and passed. The identity authentication module considers the security verification to be passed, otherwise it is considered to be failed.
[0103] Set the device identifier or device IP address and device MAC address. If one or both of the device identifier or device IP address pass the verification and the device MAC address pass the verification, the identity authentication module considers that the security verification has passed, otherwise it fails;
[0104] Set the device identifier and non-device IP address and device MAC address. If the device identifier verification passes, the device IP address verification fails, and the device MAC address verification passes, the identity authentication module considers that the security verification has passed, otherwise it has failed.
[0105] Login log view provides the ability to view login logs, showing all user login log information, including login time, login user, login status, and device information. Administrator users can view the device information when users log in through login logs to maintain user security login device information.
[0106] Login password management provides users with the ability to modify their personal passwords. All users can reset their login passwords, and administrators can modify the passwords of ordinary users.
[0107] Security control management provides the ability to maintain security controls. Since security controls are strictly bound to the domain name of the identity authentication system and the fixed characters used to calculate the encryption salt value, the system provides this function module to facilitate administrators to modify security controls.
[0108] .User management provides the ability to manage system users. Administrator users can maintain user information of both administrative users and ordinary users through this function module, including adding, modifying, deleting, displaying user information in details, and modifying user passwords. When deleting a user, the current logged-in user cannot be deleted. At the same time, the system has a security policy to protect the default administrator when deleting a user to prevent all administrator users in the system from being deleted.
[0109] The BS architecture system identity authentication device based on security controls includes a memory and a processor; the memory is used to store a computer program, and the processor is used to implement the above method steps when executing the computer program.
[0110] The readable storage medium stores a computer program, and when the computer program is executed by a processor, the above method steps are implemented.
[0111] Compared with the existing technology, the BS architecture system identity authentication method based on security controls solves the current identity authentication problem that the software based on the B / S architecture cannot obtain the user terminal device number, IP address, and MAC address through the browser to restrict the device. It significantly improves the security and reliability of identity authentication, has strong flexibility, reduces the security risk of user identity information leakage, meets the compliance requirements for data security and privacy protection, and can provide enterprises and users with more reliable information security protection.
[0112] The embodiment described above is only one specific implementation of the present invention. Common changes and substitutions made by those skilled in the art within the scope of the technical solution of the present invention should be included in the protection scope of the present invention.
Claims
1. A BS architecture system identity authentication method based on security controls, characterized by: The following steps are involved: Step S1: Provide a user login interface and login verification function through the identity authentication module. When the user clicks to log in on the client, the security control is automatically called to obtain the terminal device information; Step S2: When the security control receives the user login request, it immediately queries the device unique identifier, IP address and MAC address of the current terminal to prevent the device information from being inconsistent; Step S3: The security control encrypts the login information including the user and password and the terminal device information, and submits them to the identity authentication module backend service after encryption for identity authentication; Step S4: The administrator customizes the user device security login restriction conditions through the identity authentication module according to actual needs; When the device information of the login terminal device meets the user device security login restriction conditions, the security check passes and the user logs in normally. Otherwise, it fails and the user login request is rejected.
2. The BS architecture system identity authentication method based on security controls according to claim 1 is characterized by: In step S2, the security control provides a terminal device information query service, which only monitors the 127.0.0.1 IP address and the user-specified port to prevent other terminals from accessing the security control to bypass terminal restrictions and ensure call security.
3. The BS architecture system identity authentication method based on security controls according to claim 1 is characterized by: In step S2, when the user client queries the terminal device information, the current login user name is passed in; the steps for the security control to query the terminal device information are as follows: Step S2.1: Query unique identifier a) If the terminal device uses the mac operating system, then: i. Get the terminal device hardware information through the command system_profiler SPHardwareDataType; ii. Get the terminal device CPUID through the command sysctl-x machdep.cpu.signature; iii. Concatenate the hardware identifier, hardware serial number and CPUID in the terminal device hardware information and encrypt them with base64 as a unique identifier; b) If the terminal device uses Windows operating system, then: i. Get the terminal device hardware identifier through the command wmic csproduct get uuid; ii. Use the command wmic baseboard get serialnumber to obtain the hardware serial number of the terminal device; iii. Get the terminal device CPUID through the command wmic cpu get processorid; iv. Concatenate the hardware identifier, hardware serial number and CPUID of the terminal device and encrypt them with base64 as a unique identifier; c) If the terminal device uses the Linux operating system, then: i. Get the terminal device hardware identifier through the command dmidecode –s system-uuid; ii. Use the command dmidecode –s system-serial-number to obtain the hardware serial number of the terminal device; iii. Get the terminal device CPUID through the command dmidecode –t processor; iv. Concatenate the hardware identifier, hardware serial number and CPUID of the terminal device and encrypt them with base64 as a unique identifier; Step S2.2: Query IP address and MAC address Query all network interfaces of the terminal device and retain only the non-loopback global unicast IP address and the MAC address of its network card.
4. The BS architecture system identity authentication method based on security controls according to claim 1 is characterized by: In step S3, the security control encrypts the requested user name by concatenating a segment of custom fixed characters to obtain a salt value for this encryption, and uses the obtained salt value to encrypt the terminal device information.
5. The BS architecture system identity authentication method based on security controls according to claim 1 is characterized by: In step S4, in the user device security login restriction conditions, three logical relationships of AND, OR, and NOT are set between the device information, and the corresponding security verification rules are as follows: If the device identifier, device IP address and device MAC address are set in the user device security login restriction conditions, the above three types of device information must all be verified and passed, and the identity authentication module considers that the security verification has passed, otherwise it will fail; If the device identifier or device IP address and device MAC address are set in the user device security login restriction conditions, if one or both of the device identifier or device IP address pass the verification, and the device MAC address pass the verification at the same time, the identity authentication module considers that the security verification has passed, otherwise it fails; If the device identifier and non-device IP address and device MAC address are set in the user device security login restriction conditions, the device identifier verification passes, the device IP address verification fails, and the device MAC address verification passes, the identity authentication module considers that the security verification has passed, otherwise it has failed.
6. A BS architecture system identity authentication system based on security controls, characterized by: Includes identity authentication module and security controls; The identity authentication module is divided into a front-end client and a back-end service in terms of architecture; the front-end client is used for interface display, and the back-end service performs data interaction and logic processing, and is responsible for providing login and logout, secure login management, login log viewing, login password management, security control management and user management functions; The identity authentication module divides user roles into administrators and ordinary users, where administrators have all functional permissions and ordinary users only have login, logout and login password management functional permissions; The security control is responsible for querying the unique device identifier, IP address and MAC address of the current terminal immediately after receiving the user login request, and encrypting the login information including the user and password and the terminal device information, and submitting them together to the identity authentication module backend service after encryption.
7. The BS architecture system identity authentication system based on security controls according to claim 6 is characterized by: The identity authentication module provides a security device download address through the user login interface, and the user downloads and installs the security control by clicking the download security device link; Device verification is not performed when a user logs into the system for the first time.
8. The BS architecture system identity authentication trap based on security controls according to claim 6 is characterized by: Administrators can customize user device security login restrictions based on actual needs. The specific setting rules are as follows: a) The system only verifies the set device information, and does not verify other unset device information; b) Device IP address supports entering specific IP address and IP segment; c) Multiple device information are separated by separators. The device to be logged in satisfies one of the device information, that is, it passes the device information verification; d) Set three logical relationships between multiple device information: AND, OR, and NOT: Set the device identifier, device IP address and device MAC address. All three types of device information must be verified and passed. The identity authentication module considers the security verification to be passed, otherwise it is considered to be failed. Set the device identifier or device IP address and device MAC address. If one or both of the device identifier or device IP address pass the verification and the device MAC address pass the verification, the identity authentication module considers that the security verification has passed, otherwise it fails; Set the device identifier and non-device IP address and device MAC address. If the device identifier verification passes, the device IP address verification fails, and the device MAC address verification passes, the identity authentication module considers that the security verification passes, otherwise it fails.
9. A BS architecture system identity authentication device based on security controls, characterized in that: The method comprises a memory and a processor; the memory is used to store a computer program, and the processor is used to implement the method steps as claimed in any one of claims 1 to 5 when executing the computer program.
10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps according to any one of claims 1 to 5 are implemented.