Security verification method, system and equipment for code scanning behavior of interactive code user and medium
By synchronously extracting and parallel processing of code encoding information and user authentication information in the interactive code in the target code scanning interface, the problem of long operation time in traditional verification methods is solved, and verification efficiency and user experience are improved.
Patent Information
- Application Number
- CN202510494757.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-06-10
AI Technical Summary
In the traditional interactive code user code scanning behavior security verification method, the extraction and verification of encoded information and user authentication information are carried out in serial, resulting in a long operation time and poor user experience.
By setting a first area for accommodating the target interaction code and a second area for inputting user authentication information in the target code scanning interface, synchronous extraction and parallel processing of the encoded information and user authentication information are realized.
It shortens the operation time required for security verification of scanning code behavior on user equipment, improves the operation efficiency of the verification process, and enhances the user experience.
Smart Images

Figure CN120124031A_ABST
Abstract
Description
Technical Field
[0001] This application relates to data processing technologies, and in particular, to a method, system, device, and medium for securely verifying the scanning behavior of interactive code users. Background Art
[0002] With the rapid development of the mobile Internet, interactive code applications such as scanning code payment, scanning code unlocking, and scanning code signing have become an indispensable part of people's daily lives. These applications quickly realize functions such as information recognition, identity verification, and permission granting by scanning interactive codes, greatly improving the efficiency of life and work.
[0003] However, there are some problems with traditional methods for securely verifying the scanning behavior of interactive code users, which limit the improvement of their operating efficiency. In traditional verification processes, the system usually first requires users to scan the interactive code to extract the encoded information, and then requires users to enter authentication information for verification. These two steps are often sequential, that is, the next step must wait until the previous step is completed. This method results in a relatively long overall operation time and poor user experience. Summary of the Invention
[0004] This application provides a method, system, device, and medium for securely verifying the scanning behavior of interactive code users, which realizes the synchronous extraction and parallel processing of encoded information and user authentication information, thereby effectively improving the operating efficiency of the verification process.
[0005] In a first aspect, this application provides a method for securely verifying the scanning behavior of interactive code users, including: In response to a scanning code authentication instruction, display a target scanning code interface, where the target scanning code interface includes a first area for accommodating a target interactive code and a second area for entering user authentication information; Extract target encoded information from the target interactive code through the first area, and obtain the user authentication information through the second area; Perform a secure verification of the scanning behavior on the user authentication information according to the target encoded information.
[0006] In the above solution, when the system receives a scanning code authentication instruction, it immediately responds and displays the target scanning code interface, which contains two core areas: the first area is used to accommodate the target interactive code for easy user scanning; the second area is used to enter user authentication information for easy input of user identity information, so that while the user scans the target interactive code, the authentication information entered by the user is obtained through the second area, realizing the synchronous extraction of encoded information and user authentication information, shortening the operation time required for securely verifying the scanning behavior on the user device, and improving the efficiency of securely verifying the scanning behavior.
[0007] Optionally, the security verification of the code scanning behavior for the user authentication information according to the target coding information includes: Inputting the user authentication information into the security verification object called by the target coding information for security verification of the code scanning behavior.
[0008] In the above solution, after calling the security verification object, the user authentication information is input into the object for verification to effectively perform security verification on the code scanning behavior and enhance the security of the verification process.
[0009] Optionally, if the duration of extracting the target coding information is less than the duration of obtaining the user authentication information, correspondingly, the security verification of the code scanning behavior by inputting the user authentication information into the security verification object linked by the target coding information includes: At the first time node, complete the access call to the security verification object to form a security authentication link for the code scanning behavior; At the second time node, transmit the user authentication information through the security authentication link for the code scanning behavior to the security verification object for the security verification of the code scanning behavior, and the second time node is after the first time node.
[0010] In the code scanning behavior of the above solution, if the speed of extracting the target coding information is fast, that is, the user quickly completes the scanning of the interactive code, the system will quickly respond at the first time node, complete the access call to the security verification object, and quickly establish a security authentication link for the code scanning behavior, providing a stable channel for the transmission and verification of the user authentication information. After completing the access call to the security verification object at the first time node, since the duration of obtaining the user authentication information is long, at a later second time node, the authentication information input by the user through the second area will be transmitted through the established security authentication link for the code scanning behavior to the security verification object for verification. The entire verification process takes into account the acquisition speed and time difference between extracting the target coding information and obtaining the user authentication information. By reasonably arranging the time nodes for accessing and calling the security verification object and transmitting the user authentication information, parallel processing of extracting the target coding information and obtaining the user authentication information is achieved, effectively improving the operation efficiency of the verification process.
[0011] Optionally, if the duration of extracting the target coding information is greater than the duration of obtaining the user authentication information, correspondingly, the security verification of the code scanning behavior by inputting the user authentication information into the security verification object linked by the target coding information includes: At the third time node, complete the acquisition of the user authentication information and cache the user authentication information in the memory of the user device; At the fourth time node, an access call to the security verification object is completed to form a security authentication link for the code scanning behavior, and the user authentication information is called from the memory of the user device, so as to transmit the user authentication information through the security authentication link for the code scanning behavior to the security verification object for the security verification of the code scanning behavior. The fourth time node is after the third time node.
[0012] In the above solution, when the user starts the code scanning behavior, if the duration of extracting the target code information is relatively long while the duration of obtaining the user authentication information is relatively short. To prevent the user from interrupting the operation due to waiting for the completion of the extraction of the target code information, the system caches the obtained user authentication information in the memory of the user device to ensure the integrity and availability of the user authentication information and the convenience of subsequent calls. After completing the access call to the security verification object at the fourth time node to form a security authentication link for the code scanning behavior, the user authentication information is retrieved from the cache and transmitted through the established security authentication link for the code scanning behavior to the security verification object for verification, enabling more efficient processing of the user's code scanning request and behavior security verification, and improving the overall performance and operation efficiency.
[0013] Optionally, the first area is an interface for calling one side camera of the user device to scan the target interactive code; The second area is an interface for calling the other side camera of the user device to scan the user's face, and the user authentication information includes the scanned user face information.
[0014] In the above solution, by setting the first area and the second area to call the two side cameras of the user device respectively, the coordinated operation of the dual cameras is realized, making full use of the hardware resources of the user device and improving the efficiency and accuracy of the code scanning behavior. On the one hand, one side camera focuses on scanning the target interactive code to ensure the accurate extraction of the code information; on the other hand, the other side camera focuses on scanning the user's face to obtain the user authentication information. The two are independent of each other and closely cooperate to realize the parallel processing of extracting the target code information and obtaining the user authentication information, effectively improving the operation efficiency of the verification process.
[0015] Optionally, the one side camera corresponding to the first area is the rear camera of the user device; The other side camera corresponding to the second area is the front camera of the user device.
[0016] Optionally, the first area is an interface for calling the rear camera of the user device to scan the target interactive code; The second area is an interface for invoking the fingerprint authentication module of the user device to scan the user's fingerprint, and the user authentication information includes the user fingerprint information obtained by scanning.
[0017] In the above solution, by using the rear camera of the user device to scan the target interaction code and the fingerprint authentication module to scan the user fingerprint information, the two are independent and closely cooperate with each other, realizing the parallel processing of extracting the target code information and obtaining the user authentication information, effectively improving the operation efficiency of the verification process.
[0018] In a second aspect, the present application provides an interactive code user scanning behavior security verification system, including: A display module, configured to respond to a scanning authentication instruction and display a target scanning interface, where the target scanning interface includes a first area for accommodating the target interaction code and a second area for inputting user authentication information; An acquisition module, configured to extract target code information from the target interaction code through the first area and obtain the user authentication information through the second area; A processing module, configured to perform a scanning behavior security verification on the user authentication information according to the target code information.
[0019] Optionally, the processing module is specifically configured to: Input the user authentication information into a security verification object called by the target code information for scanning behavior security verification.
[0020] Optionally, the processing module is specifically configured to: At a first time node, complete the access call to the security verification object to form a scanning behavior security authentication link; At a second time node, transmit the user authentication information to the security verification object through the scanning behavior security authentication link for the scanning behavior security verification, and the second time node is after the first time node.
[0021] Optionally, the processing module is specifically configured to: At a third time node, complete the acquisition of the user authentication information and cache the user authentication information in the memory of the user device; At a fourth time node, complete the access call to the security verification object to form a scanning behavior security authentication link, and call the user authentication information from the memory of the user device to transmit the user authentication information to the security verification object through the scanning behavior security authentication link for the scanning behavior security verification, and the fourth time node is after the third time node.
[0022] Optionally, the first area is an interface for invoking a camera on one side of the user device to scan the target interaction code; The second area is an interface for invoking a camera on the other side of the user device to scan the user's face, and the user authentication information includes the user's face information obtained by scanning.
[0023] Optionally, the camera on the one side corresponding to the first area is the rear camera of the user device; The camera on the other side corresponding to the second area is the front camera of the user device.
[0024] Optionally, the first area is an interface for invoking the rear camera of the user device to scan the target interaction code; The second area is an interface for invoking the fingerprint authentication module of the user device to scan the user's fingerprint, and the user authentication information includes the user's fingerprint information obtained by scanning.
[0025] In a third aspect, the present application provides an electronic device, including: A processor; and, A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute any of the possible methods described in the first aspect by executing the executable instructions.
[0026] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement any of the possible methods described in the first aspect.
[0027] The interaction code user scanning behavior security verification method, system, device and medium provided by the present application, in response to a scanning authentication instruction, display a target scanning interface, and then, the first area in the target scanning interface extracts the target coding information in the target interaction code, and obtains user authentication information through the second area, so as to perform scanning behavior security verification on the user authentication information according to the target coding information, thereby realizing the synchronous extraction and parallel processing of the coding information and the user authentication information, and effectively improving the operation efficiency of the verification process. Description of the Drawings
[0028] The drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0029] Figure 1 It is a schematic flowchart of an interaction code user scanning behavior security verification method shown according to an exemplary embodiment of the present application; Figure 2 It is a schematic flowchart of a method for securely verifying the behavior of a user scanning an interactive code according to another exemplary embodiment of the present application; Figure 3 It is an interactive diagram of a security verification interface for the behavior of a user scanning an interactive code according to an exemplary embodiment of the present application; Figure 4 It is an interactive diagram of a security verification interface for the behavior of a user scanning an interactive code according to another exemplary embodiment of the present application; Figure 5 It is a schematic structural diagram of a system for securely verifying the behavior of a user scanning an interactive code according to an exemplary embodiment of the present application; Figure 6 It is a schematic structural diagram of an electronic device according to an exemplary embodiment of the present application.
[0030] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and written descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Description of Specific Embodiments
[0031] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0032] To solve the above problems, the embodiments provided by the present application have the main inventive concepts reflected in the following aspects: Synchronous extraction and parallel processing: Realize the synchronous extraction and parallel processing of encoded information and user authentication information. By setting a first area for accommodating the target interactive code and a second area for inputting user authentication information in the same target scanning code interface, the system can simultaneously extract the encoded information and obtain the user authentication information, thus effectively shortening the operation duration required for the verification process.
[0033] Dynamically adjust the verification process: Can dynamically adjust the verification process according to the acquisition speeds of the encoded information and the user authentication information. Specifically, when the duration of extracting the encoded information is less than the duration of obtaining the user authentication information, the system will give priority to completing the access call to the security verification object and establish a security authentication link for the scanning code behavior; while when the duration of extracting the encoded information is greater than the duration of obtaining the user authentication information, the system will first cache the user authentication information and then perform transmission and verification after the access call to the security verification object is completed.
[0034] Support for multiple authentication methods: The system supports multiple user authentication methods, including but not limited to face recognition, fingerprint recognition, etc. By invoking different hardware resources of the user device (such as front and rear cameras, fingerprint authentication modules, etc.), the system can flexibly implement different forms of user authentication, improving the convenience and security of verification.
[0035] To facilitate the understanding of relevant terms in this application, the definitions of some key terms are as follows: Interactive code: An interactive code is a graphical code used to quickly implement functions such as information recognition, identity verification, and permission granting. It is usually presented in the form of QR codes, barcodes, etc. Users can complete operations such as payment, unlocking, and signing in by scanning the interactive code. By scanning the interactive code, users can quickly access relevant digital services or information. The application scope of interactive codes is extensive, including but not limited to fields such as mobile payment, smart door locks, and conference sign-in.
[0036] Scanning code authentication instruction: It is a signal or command that triggers the system to perform security verification of the scanning code behavior. When the user can trigger it through a control in the application software on the user device, the system will receive the scanning code authentication instruction and respond to this instruction to start the security verification process of the scanning code behavior. The scanning code authentication instruction is the starting point for initiating the security verification process of the scanning code behavior. It may be generated by the user by clicking a button in the application, triggering a specific event (such as approaching an electronic lock), etc. After receiving the scanning code authentication instruction, the system will immediately respond and display the target scanning code interface.
[0037] Target scanning code interface: It is the main interface for the user to perform the scanning code behavior. It includes a first area for accommodating the target interactive code and a second area for inputting user authentication information. The user needs to align the interactive code and place it in the first area for scanning, and at the same time input user authentication information (such as face, fingerprint, etc.) in the second area. The system will perform security verification based on the extracted coding information and the obtained user authentication information.
[0038] Coding information: It is the key information contained in the interactive code for verifying the user's identity or performing specific operations. It is usually processed by a specific coding algorithm and presented in the form of a graphical code. The coding information is the core part of the interactive code. It contains all the necessary links for the system to verify the user's identity or perform operations, such as a link to the cloud identity authentication system.
[0039] User authentication information: It is the information input by the user for verifying their identity during the scanning code behavior. It may include the user's biometric information (such as face, fingerprint, etc.), password, etc. By inputting user authentication information, the user can prove their identity and permissions, thus ensuring that only legitimate users can perform corresponding operations. The system will compare and verify the extracted coding information and the obtained user authentication information.
[0040] Security verification object: It is an entity or program used to perform security verification for the QR code scanning behavior. It may be a remote server, cloud service, or local security module, responsible for receiving user authentication information and performing verification. It will call the corresponding security verification object according to the extracted encoded information and transmit the user authentication information to this object for verification. The security verification object will perform comprehensive security verification on the user authentication information according to the preset security verification rules or algorithms and return the verification result.
[0041] Security authentication link for QR code scanning behavior: It is a secure communication link established between the user device and the security verification object. It is used to transmit user authentication information and ensure the confidentiality, integrity, and availability during the data transmission process. By establishing a secure communication link, the user device can encrypt and transmit the user authentication information to the security verification object for verification. During the transmission process, the link will ensure that the data is not intercepted, tampered with, or lost, thus guaranteeing the security of the QR code scanning behavior.
[0042] Figure 1 It is a schematic flowchart of the security verification method for the interactive code user's QR code scanning behavior shown according to an exemplary embodiment of the present application. As Figure 1 shown, the security verification method for the interactive code user's QR code scanning behavior provided in this embodiment includes: S101. In response to the QR code scanning authentication instruction, display the target QR code scanning interface.
[0043] Specifically, when the QR code scanning authentication instruction is received, the response mechanism will be immediately triggered, and a target QR code scanning interface will be displayed. This interface is the main interface for the user to perform the QR code scanning behavior, facilitating the user's operation.
[0044] In the target QR code scanning interface, there are two core areas: the first area and the second area. The first area is used to accommodate the target interactive code, usually a rectangular or circular frame, which is used to guide the user to align and place the interactive code in it for scanning. The second area is used to input the user authentication information, which can be an input box, fingerprint recognition area, face recognition area, etc., and the specific form depends on the user authentication methods supported by the system.
[0045] S102. Extract the target encoded information in the target interactive code through the first area.
[0046] Specifically, when the user places the interactive code in the first area, the scanning program will be immediately started, and the camera of the user device (such as a smart phone, tablet computer, etc.) will be used to scan the interactive code. During the scanning process, image processing algorithms will be used to analyze the interactive code and extract the target encoded information.
[0047] Among them, the target encoding information is the core part of the interaction code, which contains the key information required to verify the user's identity or perform specific operations. For example, in a payment scenario, the target encoding information may contain key payment information such as the user's payment account and payment amount.
[0048] S103. Obtain the user authentication information through the second area.
[0049] Specifically, while scanning the target interaction code, the user will be guided to input the user authentication information in the second area. The user authentication information can be the user's fingerprint, face, password, etc., depending on the supported user authentication methods.
[0050] For example, if face recognition is supported, the second area will activate the face recognition algorithm to scan and recognize the user's face using the front camera of the user's device. If the system supports fingerprint recognition, the second area will call the fingerprint authentication module of the user's device to guide the user to place their finger on the fingerprint recognition area for scanning.
[0051] S104. Perform a security verification of the scanning behavior on the user authentication information according to the target encoding information.
[0052] It should be noted that the above process of performing a security verification of the scanning behavior on the user authentication information can be in the form of face verification, iris authentication, fingerprint authentication, voiceprint authentication, etc. The specific method is not specifically limited in this embodiment.
[0053] In a possible case, if the duration of extracting the target encoding information is less than the duration of obtaining the user authentication information. Then at the first time node, the access call to the security verification object is completed to form a security authentication link for the scanning behavior. At the second time node, the user authentication information is transmitted through the security authentication link for the scanning behavior to the security verification object for security verification of the scanning behavior, and the second time node is after the first time node.
[0054] Specifically, when it is detected that the duration of extracting the target encoding information is less than the duration of obtaining the user authentication information, the access call process to the security verification object will be preferentially initiated. Specifically, first, an access request is sent to the security verification object through a preset interface or application programming interface. This request may contain credentials for identity verification, such as tokens, key pairs, or other authentication information, to ensure the legitimacy and security of the access.
[0055] After receiving the access request, the security verification object will verify the authentication information in the request. If the verification is successful, the security verification object will return a successful access response and establish a secure communication link with the requester (where this method is located). This link is the scanning behavior security authentication link, which will be used for the subsequent transmission of user authentication information for security verification of scanning behavior.
[0056] After the scanning behavior security authentication link is successfully established at the first time node, it will enter a waiting state until the complete user authentication information is obtained. User authentication information may include but is not limited to the user's identity, device information, geographic location, scanning time, etc. This information will be used in the subsequent security verification process.
[0057] When the user authentication information is obtained, it will be immediately encrypted and transmitted to the security verification object at the second time node (which is after the first time node) through the previously established scanning behavior security authentication link. In order to ensure the security of data during transmission, HTTPS (Hypertext Transfer Protocol Security), TLS (Transport Layer Security) or other secure transmission protocols may be used to encrypt data.
[0058] After receiving the encrypted user authentication information, the security verification object will first decrypt it, and then perform a comprehensive security verification on the user authentication information according to the preset security verification rules or algorithms. The verification content may include the legitimacy of the user identity, the authenticity of the device information, the rationality of the geographical location, and the validity of the scanning time.
[0059] If the security verification object passes the verification, a successful verification response will be returned, indicating that the scanning behavior is safe; if the verification fails, a failed verification response will be returned, and may be accompanied by corresponding error prompts or suggestions so that further measures can be taken, such as refusing service, requiring users to re-authenticate, etc.
[0060] In another possible case, if the time length for extracting the target coded information is longer than the time length for acquiring the user authentication information, then at the third time node, the acquisition of the user authentication information is completed, and the user authentication information is cached in the user device memory. At the fourth time node, the access call to the security verification object is completed to form a scanning behavior security authentication link, and the user authentication information is called from the user device memory to transmit the user authentication information to the security verification object through the scanning behavior security authentication link for scanning behavior security verification. The fourth time node is after the third time node.
[0061] Specifically, at the third time node, the scanning device successfully obtains the user authentication information, which may include user identity information, authentication method, authentication timestamp, etc. The obtained user authentication information is temporarily stored in the memory of the scanning device for subsequent use. Among them, the caching mechanism can be implemented using an in-memory database, temporary files, or an in-memory caching framework to ensure fast access to information. Moreover, the cached user authentication information should be set with an expiration date or access rights to prevent information leakage or abuse.
[0062] At the fourth time node, an access call to the security verification object is completed to form a security authentication link for the scanning behavior, and the user authentication information is called from the user device memory to transmit the user authentication information through the security authentication link for the scanning behavior to the security verification object for security verification of the scanning behavior. At the fourth time node, the scanning device starts to access and call the security verification object. The security verification object may be a remote server, cloud service, or local security module responsible for performing the security verification of the scanning behavior. The access call process may involve network requests, API calls, or local interface calls, depending on the implementation method of the security verification object.
[0063] Through the access call, a secure communication link, that is, the security authentication link for the scanning behavior, is established between the scanning device and the security verification object. This link should ensure the confidentiality, integrity, and availability of data transmission, preventing data from being intercepted, tampered with, or lost during transmission. The scanning device calls the cached user authentication information from the memory. The called user authentication information is transmitted through the security authentication link for the scanning behavior to the security verification object. During the transmission process, the user authentication information may be encrypted to ensure data security. After receiving the user authentication information, the security verification object starts to perform the security verification of the scanning behavior. The verification process may include user identity verification, authentication method verification, timestamp check, etc., to ensure the legality and effectiveness of the scanning behavior. The verification result may be returned to the scanning device in the form of success or failure, and the scanning device performs corresponding subsequent operations according to the verification result, such as displaying a verification success message, jumping to a specific page, or prompting the user to re-authenticate, etc.
[0064] Among them, in a possible application scenario, if the target interaction code is a payment code, the caching time of the user authentication information in the memory of the user device is less than the preset secure payment time threshold. Specifically, when the user scans the payment code for payment, the user authentication information is only cached in the memory within this time threshold. Once this time is exceeded, the authentication information will be automatically cleared or invalidated. By restricting the caching time of the user authentication information, the risk of leakage of the user authentication information caused by device theft or malware attacks is effectively reduced. Even if an attacker can obtain the access right to the user device within a short period of time, due to the time-limited caching of the authentication information, it is very difficult to use this information to complete unauthorized payment operations within the validity period. While ensuring security, this strategy also takes into account the user experience. The preset secure payment time threshold is usually sufficient to cover the normal payment process, ensuring that the user will not be interrupted due to the expiration of the authentication information during the legal payment process. Through this design that balances security and efficiency, the user can enjoy the convenient payment service without worrying about payment failure or delay caused by overly strict security verification. It is worth noting that the above-mentioned preset secure payment time threshold can also be set according to the difference between the average duration of extracting the target coding information on the user device and the average duration of obtaining the user authentication information.
[0065] In another possible application scenario, the above-mentioned target interaction code can also be a check-in code. Among them, the check-in code can be a two-dimensional code set on the check-in board at the meeting site. The participants can scan the check-in code for electronic check-in and authentication of identity information, so as to effectively avoid the situation of proxy check-in. At the same time, since the scanning of the check-in code information and the acquisition of the identity information are processed in parallel, it can also effectively save the time for check-in of a large number of meeting participants.
[0066] In addition, the above-mentioned check-in code can also be used as a clock-in code for enterprises and institutions. When the employee scans the check-in code, the employee's face information is scanned at the same time, and the face information is authenticated in the cloud. In this scenario, compared with the clock-in device with a camera usually set by enterprises, only a two-dimensional code needs to be set at a specific location. The employee can scan the check-in code with his own mobile phone and scan the face information at the same time to complete the clock-in authentication of himself, thus effectively saving the hardware cost of the enterprise for clock-in.
[0067] In this embodiment, in response to the code scanning authentication instruction, the target code scanning interface is displayed. Then, the first area in the target code scanning interface extracts the target coding information in the target interaction code, and the user authentication information is obtained through the second area, so as to perform security verification of the code scanning behavior on the user authentication information according to the target coding information, thereby realizing the synchronous extraction and parallel processing of the coding information and the user authentication information, and effectively improving the operation efficiency of the verification process.
[0068] Specifically, during the process of extracting the target encoding information and obtaining the user authentication information, these two tasks can be processed in parallel to shorten the overall operation duration. For example, while scanning the interactive code, the face recognition algorithm can be started to pre-recognize the user's face. To improve the verification speed, a caching mechanism can also be introduced. During the security verification process of the code scanning behavior, various error situations may also need to be handled. For example, if the camera fails to recognize the interactive code or the user's face, corresponding error prompts need to be given and the user needs to be guided to perform the correct operations.
[0069] Figure 2 is a flowchart showing the method for security verification of the interactive code user's code scanning behavior according to an exemplary embodiment of the present application. As Figure 2 shown, the method for security verification of the interactive code user's code scanning behavior provided in this embodiment includes: S201. In response to the code scanning authentication instruction, display the target code scanning interface.
[0070] When the code scanning authentication instruction is received, the response mechanism will be immediately triggered, and a target code scanning interface will be displayed.
[0071] Figure 3 is an interface interaction diagram showing the security verification of the interactive code user's code scanning behavior according to an exemplary embodiment of the present application. As Figure 3 shown, the first area 310 is the interface for calling the camera on one side of the user device to scan the target interactive code. The second area 320 is the interface for calling the camera on the other side of the user device to scan the user's face, and the user authentication information includes the user's face information obtained by scanning. Optionally, the camera on one side corresponding to the first area 310 is the rear camera of the user device. The camera on the other side corresponding to the second area 320 is the front camera of the user device.
[0072] Figure 4 is an interface interaction diagram showing the security verification of the interactive code user's code scanning behavior according to another exemplary embodiment of the present application. As Figure 4 shown, the first area 410 is the interface for calling the rear camera of the user device to scan the target interactive code. The second area 420 is the interface for calling the fingerprint authentication module of the user device to scan the user's fingerprint, and the user authentication information includes the user's fingerprint information obtained by scanning.
[0073] S202. Extract the target encoding information in the target interactive code through the first area.
[0074] Specifically, when the user places the interactive code in the first area, the scanning program will be immediately started, and the rear camera of the user device (such as a smart phone, a tablet computer, etc.) will be used to scan the interactive code. During the scanning process, the image processing algorithm will be used to analyze the interactive code and extract the target encoding information therein.
[0075] S203. Obtain user authentication information through the second area.
[0076] Specifically, while scanning the target interaction code, the user will be guided to input user authentication information in the second area. The user authentication information can be the user's fingerprint, face, password, etc., depending on the supported user authentication methods.
[0077] For example, if face recognition is supported, the second area will activate the face recognition algorithm and use the front camera of the user device to scan and recognize the user's face. If the system supports fingerprint recognition, the second area will call the fingerprint authentication module of the user device and guide the user to place their finger on the fingerprint recognition area for scanning.
[0078] S204. Perform a security verification of the scanning behavior on the user authentication information according to the target coding information.
[0079] Specifically, the user authentication information can be input into the security verification object called by the target coding information for the security verification of the scanning behavior. This verification process generally includes the following steps: Call the security verification object: According to the information contained in the target coding information, the corresponding security verification object will be called. The security verification object can be a verification program on the server, a user information table in the database, etc., depending on the system's security verification mechanism.
[0080] Input the user authentication information for verification: After calling the security verification object, the user authentication information will be input into the object for verification. The verification process will check whether the user authentication information is consistent with the user information stored in the system and whether it meets specific security verification conditions (such as password complexity, fingerprint recognition rate, etc.).
[0081] Return the verification result: According to the verification result, a corresponding prompt message will be returned to the user device. If the verification is passed, the user can continue to perform subsequent operations (such as payment, unlocking, etc.). If the verification fails, the system will prompt the user to re-enter the authentication information or perform other security verification operations.
[0082] S205. Receive the authentication passed instruction for the security verification of the scanning behavior through the security authentication link of the scanning behavior.
[0083] If the target interaction code is the unlocking code on the electronic lock, it should be noted that the electronic lock is equipped with a near-field communication module and not equipped with a network data communication module. Specifically, the electronic lock is only equipped with a Bluetooth communication module and cannot be connected to the external network, thus ensuring the security of the electronic lock. The electronic lock internally presets encrypted unlocking information, which is the unlocking key processed by a specific encryption algorithm and is used to verify the validity of the unlocking code. In addition, the electronic lock is also equipped with a unique identification information, such as a serial number or a device ID, which is used to uniquely identify the electronic lock in the system.
[0084] In this step, after the security verification of the user's code scanning behavior is passed, it can be through the code scanning behavior security authentication link to receive the authentication passed instruction of the code scanning behavior security verification. The unlocking code is configured with the identification information of the electronic lock, and the authentication passed instruction includes the decoding information corresponding to the identification information. That is, the user uses the code scanning software or a dedicated unlocking application on the mobile device to scan the unlocking two-dimensional code on the electronic lock. The code scanning software or application identifies the information in the unlocking code and sends it to the server or locally for security verification. The server (such as the hotel room registration server) searches for the corresponding electronic lock record according to the identification information in the unlocking code. The verification system decrypts the unlocking code or verifies its integrity to ensure that it has not been tampered with and comes from a legitimate source. If the verification is passed, the system generates an authentication passed instruction, which contains the decoding information corresponding to the electronic lock identification information.
[0085] S206. Send the decoding information to the electronic lock through the near-field communication module.
[0086] Specifically, the user's mobile device receives the authentication passed instruction sent by the server or the local verification system through the code scanning behavior security authentication link. The authentication passed instruction contains the decoding information used to decrypt the encrypted unlocking information in the electronic lock. The user's mobile device sends the decoding information to the electronic lock through the near-field communication module. The near-field communication module ensures that the decoding information is transmitted within a safe short distance range to prevent interception or eavesdropping. After receiving the decoding information, the electronic lock uses its internal decryption algorithm to decrypt the preset encrypted unlocking information. After successful decryption, the electronic lock generates an unlocking instruction, which is used to control the unlocking mechanism of the electronic lock. The electronic lock can also send a feedback message of successful unlocking to the user's mobile device through the near-field communication module to confirm that the unlocking operation has been completed. At the same time, the electronic lock can also record information such as the time of the unlocking event and the user identity for subsequent auditing or tracking.
[0087] In the above embodiment, when the target interaction code is the unlocking code on the electronic lock and the electronic lock is equipped with a near-field communication module but not equipped with a network data communication module, this embodiment has the following specific technical effects: Realize secure unlocking in an offline environment: Since the electronic lock is not equipped with a network data communication module, it is impossible to directly perform remote unlocking or verification through the network. The above embodiments realize the local interaction between the unlocking code and the electronic lock through the near-field communication module, so as to complete the unlocking operation within a limited range (such as close contact), effectively solving the unlocking requirement in the offline environment.
[0088] Ensure the uniqueness and security of the unlocking code: The unlocking code is configured with the identification information of the electronic lock, so that each unlocking code is bound to a specific electronic lock, ensuring the uniqueness of the unlocking code. At the same time, as a type of interactive code, the generation, distribution, and verification processes of the unlocking code all follow strict security mechanisms, effectively preventing the unlocking code from being forged or tampered with.
[0089] Realize the close connection between the code scanning behavior and the security verification: When the user scans the unlocking code, the system will perform security verification on the user authentication information according to the target coding information during the code scanning behavior. This verification process ensures the legitimacy of the user's identity and the authenticity of the code scanning behavior, providing a reliable security guarantee for the subsequent unlocking operation.
[0090] Transmit the decoding information through the authentication passed instruction: After the security verification of the code scanning behavior is passed, the system will send an authentication passed instruction through the security authentication link of the code scanning behavior. This instruction contains the decoding information corresponding to the identification information of the electronic lock, which is used to decrypt the encrypted unlocking information preset in the electronic lock. This design ensures the accurate transmission and confidentiality of the decoding information.
[0091] Utilize the near-field communication module to achieve fast transmission of the decoding information: The near-field communication module has the characteristics of fast transmission speed, short distance, and high security. The above embodiments utilize the near-field communication module to quickly and securely send the decoding information to the electronic lock, realizing the instant communication between the decoding information and the electronic lock.
[0092] Ensure the accurate generation and execution of the unlocking instruction: After receiving the decoding information, the electronic lock will decrypt the preset encrypted unlocking information and generate an unlocking instruction. This decryption process ensures the accuracy of the unlocking instruction and prevents unauthorized unlocking operations.
[0093] In summary, in the case where the electronic lock does not have a network data communication module, the above embodiments achieve local interaction between the unlocking code and the electronic lock through the near-field communication module, ensuring the security, reliability, and convenience of the unlocking process. At the same time, the above embodiments realize the effective control and management of the electronic lock through steps such as secure verification of the scanning behavior, transmission of the authentication passed instruction, rapid transmission of the decoded information, and accurate generation and execution of the unlocking instruction. In addition, during the process of verifying and unlocking the electronic lock, all the information transmitted is decoded information, without transmitting specific decoding instructions or decoding passwords, which can effectively avoid the security risks that may be brought by network transmission and the leakage of the unlocking password.
[0094] In addition, it is worth noting that in another possible implementation, it can also be to receive the authentication passed instruction of the scanning behavior security verification through the scanning behavior security authentication link. The unlocking code is configured with the identification information of the electronic lock and the encrypted unlocking information, and the authentication passed instruction includes the decoded information corresponding to the identification information. Then, the encrypted unlocking information is decrypted using the decoded information to obtain the unlocking instruction corresponding to the electronic lock, and the unlocking instruction is sent to the electronic lock through the near-field communication module to unlock the electronic lock.
[0095] The above unlocking code is not only configured with the identification information of the electronic lock, but also includes encrypted unlocking information. When the scanning behavior security verification passes, the system sends an authentication passed instruction through the scanning behavior security authentication link. This instruction contains the decoded information corresponding to the identification information of the electronic lock, which is the key to decrypting the encrypted unlocking information. The encrypted unlocking information in the unlocking code is decrypted using the decoded information in the authentication passed instruction to obtain the unlocking instruction corresponding to the electronic lock. This decryption process is completed locally, effectively avoiding the security risks that may be brought by network transmission and the leakage of the unlocking password. At the same time, the accuracy and security of the decryption algorithm are guaranteed, ensuring that only the correct decoded information can decrypt a valid unlocking instruction. After receiving the unlocking instruction, the electronic lock immediately performs an unlocking operation. Since the unlocking instruction is quickly transmitted through the near-field communication module and the decryption process is completed locally, the electronic lock can quickly respond to the unlocking request and provide a convenient user experience.
[0096] Figure 5 It is a schematic structural diagram of an interactive code user scanning behavior security verification system shown according to an exemplary embodiment of the present application. As Figure 5 shown, the interactive code user scanning behavior security verification system 500 provided in this embodiment includes: A display module 510, configured to respond to a scanning authentication instruction and display a target scanning interface, where the target scanning interface includes a first area for accommodating a target interactive code and a second area for inputting user authentication information; An acquisition module 520, configured to extract target coding information in the target interaction code through the first area, and acquire the user authentication information through the second area; A processing module 530, configured to perform a security verification of the scanning behavior on the user authentication information according to the target coding information.
[0097] Optionally, the processing module 530 is specifically configured to: Input the user authentication information into a security verification object called by the target coding information to perform a security verification of the scanning behavior.
[0098] Optionally, the processing module 530 is specifically configured to: At a first time node, complete an access call to the security verification object to form a security authentication link for the scanning behavior; At a second time node, transmit the user authentication information to the security verification object through the security authentication link for the scanning behavior security verification, and the second time node is after the first time node.
[0099] Optionally, the processing module 530 is specifically configured to: At a third time node, complete the acquisition of the user authentication information and cache the user authentication information in the user device memory; At a fourth time node, complete an access call to the security verification object to form a security authentication link for the scanning behavior, and call the user authentication information from the user device memory to transmit the user authentication information to the security verification object through the security authentication link for the scanning behavior security verification, and the fourth time node is after the third time node.
[0100] Optionally, the first area is an interface for calling a side camera of the user device to scan the target interaction code; The second area is an interface for calling the other side camera of the user device to scan the user's face, and the user authentication information includes the scanned user face information.
[0101] Optionally, the side camera corresponding to the first area is the rear camera of the user device; The other side camera corresponding to the second area is the front camera of the user device.
[0102] Optionally, the first area is an interface for calling the rear camera of the user device to scan the target interaction code; The second region is an interface for invoking the fingerprint authentication module of the user device to scan the user's fingerprint, and the user authentication information includes the user fingerprint information obtained by scanning.
[0103] Figure 6 is a schematic structural diagram of an electronic device shown according to an exemplary embodiment of the present application. As Figure 6 shown, an electronic device 600 provided in this embodiment includes: a processor 601 and a memory 602; wherein: The memory 602 is used to store a computer program, and this memory can also be flash (flash memory).
[0104] The processor 601 is used to execute the execution instructions stored in the memory to implement each step in the above method. Specifically, reference can be made to the relevant descriptions in the foregoing method embodiments.
[0105] Optionally, the memory 602 can be either independent or integrated with the processor 601.
[0106] When the memory 602 is a device independent of the processor 601, the electronic device 600 may further include: A bus 603 for connecting the memory 602 and the processor 601.
[0107] This embodiment also provides a readable storage medium, in which a computer program is stored. When at least one processor of the electronic device executes this computer program, the electronic device executes the methods provided by the above various embodiments.
[0108] This embodiment also provides a program product, which includes a computer program stored in a readable storage medium. At least one processor of the electronic device can read this computer program from the readable storage medium, and at least one processor executes this computer program to enable the electronic device to implement the methods provided by the above various embodiments.
[0109] Those skilled in the art will readily think of other implementation schemes of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the claims.
[0110] It should be understood that the present application is not limited to the exact structure already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A security verification method for interactive code user scanning behavior, characterized in that: include: In response to the code scanning authentication instruction, displaying a target code scanning interface, the target code scanning interface including a first area for accommodating a target interactive code and a second area for inputting user authentication information; Extracting target coding information in the target interactive code through the first area, and acquiring the user authentication information through the second area; The scanning behavior of the user authentication information is securely verified according to the target coding information.
2. The interactive code user scanning behavior security verification method according to claim 1 is characterized in that: The scanning code security verification of the user authentication information according to the target code information includes: The user authentication information is input into the security verification object called by the target coding information to perform security verification of the code scanning behavior.
3. The interactive code user scanning behavior security verification method according to claim 2 is characterized in that: If the time duration for extracting the target coded information is shorter than the time duration for acquiring the user authentication information, correspondingly, inputting the user authentication information into the security verification object linked to the target coded information for scanning code security verification includes: At the first time point, completing the access call to the security verification object to form a code scanning behavior security authentication link; At a second time node, the user authentication information is transmitted to the security verification object through the code scanning behavior security authentication link to perform the code scanning behavior security verification, and the second time node is after the first time node.
4. The interactive code user scanning behavior security verification method according to claim 2 is characterized in that: If the time length for extracting the target coded information is longer than the time length for acquiring the user authentication information, then correspondingly, inputting the user authentication information into the security verification object linked to the target coded information for scanning code security verification includes: At a third time point, completing the acquisition of the user authentication information, and caching the user authentication information in a memory of the user device; At a fourth time node, an access call to the security verification object is completed to form a scanning behavior security authentication link, and the user authentication information is called from the user device memory to transmit the user authentication information through the scanning behavior security authentication link to the security verification object for the scanning behavior security verification. The fourth time node is after the third time node.
5. The method for security verification of interactive code user scanning behavior according to any one of claims 1 to 4, characterized in that: The first area is an interface for calling a camera on one side of the user device to scan the target interaction code; The second area is an interface for calling the camera on the other side of the user device to scan the user's face, and the user authentication information includes the user's face information obtained by scanning.
6. The interactive code user scanning behavior security verification method according to claim 5 is characterized in that: The side camera corresponding to the first area is a rear camera of the user equipment; The other side camera corresponding to the second area is the front camera of the user equipment.
7. The method for security verification of interactive code user scanning behavior according to any one of claims 1 to 4, characterized in that: The first area is an interface for calling a rear camera of a user device to scan the target interaction code; The second area is an interface for calling the fingerprint authentication module of the user device to scan the user's fingerprint, and the user authentication information includes the user's fingerprint information obtained by scanning.
8. An interactive code user scanning behavior security verification system, characterized in that: include: A display module, for responding to a code scanning authentication instruction and displaying a target code scanning interface, wherein the target code scanning interface includes a first area for accommodating a target interactive code and a second area for inputting user authentication information; an acquisition module, configured to extract target coding information in the target interactive code through the first area, and to acquire the user authentication information through the second area; A processing module is used to perform a scanning behavior security verification on the user authentication information according to the target coding information.
9. An electronic device, characterized in that: include: processor; as well as, A memory, configured to store executable instructions of the processor; The processor is configured to perform the method of any one of claims 1 to 7 by executing the executable instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.