Two-factor security verification method and system, terminal equipment and medium

By recording the verification key in the user association table of the SaaS platform and encrypting the two-factor authentication seed data, data leakage and bypassing verification vulnerabilities in the existing two-factor security verification methods are solved, and higher security and simplified user experience are achieved.

CN120151004APending Publication Date: 2025-06-13SHENZHEN COOCAA NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510262061.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing two-factor security verification methods have problems such as data leakage, bypassing verification vulnerabilities, users are vulnerable to social engineering attacks, cumbersome login processes and complex device migration.

Method used

By recording the verification key in the user association table of the SaaS platform, two-factor authentication is performed, and the two-factor authentication seed data is encrypted and stored to ensure data confidentiality. At the same time, the device migration process is simplified by storing the two-factor authentication data locally.

Benefits of technology

It solves the problems of data leakage caused by unencrypted cloud backup seed data, bypassing verification vulnerabilities, user vulnerability, cumbersome login process and complex device migration caused by two-factor verification applications, improving security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151004A_ABST
    Figure CN120151004A_ABST
Patent Text Reader

Abstract

The invention discloses a two-factor security verification method and system, terminal equipment and a medium, and the method comprises the steps: obtaining first identity verification information of a user, verifying the first identity verification information, and obtaining verification result information of the first identity verification information; querying a user association table to obtain a verification key of the user; acquiring second identity verification information generated by the authenticator; and based on the verification key and the current timestamp, generating expected identity verification information, and performing comparison verification on the expected identity verification information and the second identity verification information to obtain verification result information of the second identity verification information. Two-factor authentication is carried out on the user through the verification key related information recorded in the user association table on the SaaS platform, encryption storage is carried out on the two-factor authentication seed data in the authentication mode, the confidentiality of the data is ensured, and meanwhile, the authentication efficiency is improved by locally storing the two-factor authentication data. And the two-factor authentication setting can be quickly recovered when the user replaces the equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of two-factor security verification, and in particular to a two-factor security verification method, system, terminal device and medium applied to a SaaS platform. Background Art

[0002] In the field of security verification, the single-factor verification method based on passwords has security risks.

[0003] To enhance security, a two-factor verification mechanism is introduced. Based on the traditional username and password verification, it adds a dynamic verification code generated by an authentication server as the second identity verification information. When a user logs in, they first enter the correct username and password. After successful verification, the system sends the verification code to the bound device, and the user needs to enter it within a specified time. Only after re-verification and being correct can the user log in.

[0004] Current two-factor security verification methods still have many problems. In terms of security, if the seed data backed up in the cloud is not encrypted in the application of two-factor verification, it is easy to cause data leakage, and attackers can use this to generate correct verification codes; there are also vulnerabilities to bypass the verification disabling function, and attackers can use cached information to extract passwords; in addition, users are vulnerable to social engineering attacks and provide verification codes after being phished, allowing attackers to bypass the verification. In terms of user experience, the login operation process is cumbersome, with more input information and steps, reducing the user's willingness to use; when migrating devices, the process of re-setting two-factor security verification is complex, bringing inconvenience to users.

[0005] Therefore, the existing two-factor verification technology has deficiencies in both security and experience, and the existing technology needs to be improved. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a two-factor security verification method, system, terminal device and medium in view of the above-mentioned defects of the existing technology, aiming to solve the problems that existing two-factor verification applications are prone to data leakage if the seed data backed up in the cloud is not encrypted, attackers can bypass the verification disabling function and use cached information to extract passwords, users are easily phished and provide verification codes, the login operation process is cumbersome and the increased input information and steps lead to a decrease in the user's willingness to use, and the process of re-setting two-factor security verification when migrating devices is complex.

[0007] To solve the above technical problems, the technical solutions adopted by the present invention are as follows:

[0008] In a first aspect, the present invention provides a two-factor security verification method applied to a SaaS platform, and the method includes:

[0009] Obtain the user's first authentication information and verify the first authentication information to obtain the verification result information of the first authentication information;

[0010] Query the user association table to obtain the verification key of the user;

[0011] Obtain the second authentication information generated by the authenticator;

[0012] Generate the expected authentication information based on the verification key and the current timestamp, and compare and verify the expected authentication information with the second authentication information to obtain the verification result information of the second authentication information.

[0013] In one implementation, the method further includes:

[0014] If the verification result information of the second authentication information is verification failure, generate a prompt message for guiding the user to re-verify the second authentication information, and re-record the verification result of the second authentication information;

[0015] When the number of verification failures of the second authentication information exceeds a preset number, take security measures.

[0016] In one implementation, the taking security measures when the number of verification failures of the second authentication information exceeds a preset number includes:

[0017] Set a verification failure times threshold for the second authentication information. When the number of verification failures of the second authentication information exceeds the verification failure times threshold, take security measures;

[0018] The security measures include temporarily restricting login, marking the user in the user association table, and sending a security warning notice to the user using a preset communication method.

[0019] In one implementation, the method further includes:

[0020] If the user association table does not store the verification key of the user, generate a unique verification key corresponding to the user and store it in the user association table;

[0021] Combine the user's account information with the verification key and generate a binding code;

[0022] Bind the user's account to the authenticator through the binding code.

[0023] In one implementation, the combining the user's account information with the verification key and generating a binding code includes:

[0024] Combine the user's account information with the verification key to obtain combined information;

[0025] Encrypt the combined information to obtain encrypted combined information;

[0026] Generate a preset-validity-period verification code based on the encrypted combined information, and the binding code is the preset-validity-period verification code.

[0027] In one implementation, the binding of the user's account to the authenticator through the binding code includes:

[0028] Input the binding code into the authenticator and record the binding code based on the authenticator;

[0029] Obtain the binding authentication information generated by the authenticator through the time synchronization algorithm of the verification key in the binding code and the authenticator;

[0030] Generate expected authentication information through the verification key and the current timestamp, compare and verify the expected authentication information with the binding authentication information to obtain the verification result information of the binding authentication information, and write the binding success flag into the user association table.

[0031] In one implementation, the binding of the user's account to the authenticator through the binding code further includes:

[0032] If the result of the binding authentication is verification failure, generate prompt information for guiding the user to re-bind and verify, and record the verification result of the re-bind and verify;

[0033] When the number of times of failed binding verification exceeds the preset number, take security measures.

[0034] In a second aspect, an embodiment of the present invention further provides a two-factor security verification system, and the system includes:

[0035] A first authentication information verification module, configured to obtain the user's first authentication information and verify the first authentication information to obtain the verification result information of the first authentication information;

[0036] A verification key acquisition module, configured to query the user association table to obtain the verification key of the user;

[0037] A second authentication information acquisition module, configured to obtain the second authentication information generated by the authenticator;

[0038] The second authentication information verification module is used to generate expected authentication information based on the verification key and the current timestamp, and compare and verify the expected authentication information with the second authentication information to obtain the verification result information of the second authentication information.

[0039] In a third aspect, an embodiment of the present invention further provides a terminal device, which includes a memory, a processor, and a two-factor security verification program stored in the memory and executable on the processor. When the processor executes the two-factor security verification program, the steps of the two-factor security verification method in any one of the above solutions are implemented.

[0040] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a two-factor security verification program is stored. When the two-factor security verification program is executed by a processor, the steps of the two-factor security verification method in any one of the above solutions are implemented.

[0041] Beneficial effects: The present invention discloses a two-factor security verification method, system, terminal device, and medium. The method first obtains the first authentication information of a user, and verifies the first authentication information to obtain the verification result information of the first authentication information. Then, it queries the user association table to obtain the verification key of the user. Next, it obtains the second authentication information generated by the authenticator. Finally, based on the verification key and the current timestamp, it generates expected authentication information, and compares and verifies it with the second authentication information to obtain the verification result information of the second authentication information. The present invention performs two-factor authentication on the user by recording verification key-related information in the user association table on the SaaS platform. This authentication method encrypts and stores the two-factor authentication seed data to ensure data confidentiality. At the same time, by locally storing the two-factor authentication data, the user can quickly restore the two-factor authentication settings when changing devices. In this way, the problems in the prior art can be solved, including that if the two-factor verification application does not encrypt the seed data backed up in the cloud, it is easy to cause data leakage, attackers can bypass the verification disabling function and use cached information to extract passwords, users are easily phished and provide verification codes, the login operation process is cumbersome and the input information steps are numerous, resulting in a decrease in user willingness to use, and the process of re-setting two-factor security verification during device migration is complex. Description of the Drawings

[0042] Figure 1 It is a flowchart of the specific implementation manner of the two-factor security verification method provided by the embodiment of the present invention.

[0043] Figure 2 It is a principle block diagram of the two-factor security verification device provided by the embodiment of the present invention.

[0044] Figure 3 It is the flowchart of two-factor security verification provided by the embodiments of the present invention.

[0045] Figure 4 It is the block diagram of the internal structure principle of the intelligent terminal provided by the embodiments of the present invention. Detailed implementation manners

[0046] To make the objectives, technical solutions and effects of the present invention clearer and more explicit, the following further describes the present invention in detail with reference to the accompanying drawings and by way of examples. It should be understood that the specific examples described herein are only used to explain the present invention and are not used to limit the present invention.

[0047] The flowchart shown in the accompanying drawings is only an illustrative example, and does not necessarily include all the contents, operations or steps, nor does it necessarily execute in the described order. For example, some operations or steps can also be decomposed, combined or partially merged, so the actual execution order may be changed according to the actual situation.

[0048] It should be understood that the terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.

[0049] It should be understood that, in order to facilitate the clear description of the technical solutions of the embodiments of the present invention, in the embodiments of the present invention, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and effects. For example, the first control information and the second control information are only used to distinguish different control information, and do not limit their sequence.

[0050] Those skilled in the art can understand that the terms "first", "second", etc. do not limit the quantity and execution order, and the terms "first", "second", etc. do not necessarily mean different.

[0051] It should also be understood that the term "and / or" used in the specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the related listed items, and includes these combinations.

[0052] In the prior art in the field of security verification, there are security risks in the single-factor verification method based on passwords. To enhance security, a two-factor verification mechanism has been introduced. Based on the traditional username and password verification, it adds a dynamic verification code generated by the authentication server as the second identity verification information. When a user logs in, they first enter the correct username and password. After successful verification, the system sends the verification code to the bound device, and the user needs to enter it within the specified time. Only after successful re-verification can the user log in. However, there are still many problems in the current two-factor security verification method. At the security level, if the two-factor verification application does not encrypt the seed data backed up in the cloud, it is easy to cause data leakage, and attackers can use this to generate the correct verification code. There is also a vulnerability to bypass the verification disabling function, and attackers can use cached information to extract passwords. In addition, users are vulnerable to social engineering attacks. After being phished, they provide the verification code, allowing attackers to bypass the verification. In terms of user experience, the login operation process is cumbersome, with more input information and steps, reducing the user's willingness to use. When migrating devices, the process of re-setting two-factor security verification is complex, causing inconvenience to users.

[0053] To solve the problems of the prior art, the present invention provides a two-factor security verification method, system, terminal device, and medium. Compared with the prior art, the method first obtains the user's first identity verification information and verifies the first identity verification information to obtain the verification result information of the first identity verification information. Then, it queries the user association table to obtain the verification key of the user. Immediately afterwards, it obtains the second identity verification information generated by the authenticator. Finally, based on the verification key and the current timestamp, it generates the expected identity verification information and compares it with the second identity verification information for verification to obtain the verification result information of the second identity verification information. The present invention performs two-factor authentication on the user by recording verification key-related information in the user association table on the SaaS platform. This authentication method encrypts and stores the two-factor authentication seed data to ensure data confidentiality. At the same time, by locally storing the two-factor authentication data, the user can quickly restore the two-factor authentication settings when changing devices. In this way, the problems existing in the prior art can be solved, including data leakage easily caused by the failure to encrypt the seed data backed up in the cloud in the two-factor verification application, attackers bypassing the verification disabling function to extract passwords using cached information, users being phished and providing verification codes, the cumbersome login operation process and the large number of input information steps resulting in a decrease in the user's willingness to use, and the complex process of re-setting two-factor security verification when migrating devices.

[0054] A two-factor security verification method provided in this embodiment is as Figure 1 shown, and specifically includes the following steps:

[0055] Step S100: Obtain the user's first identity verification information and verify the first identity verification information to obtain the verification result information of the first identity verification information.

[0056] In this embodiment, the first authentication information may be the user's account and static password. Among them, the user's account and the corresponding static password are stored in the platform database after being encrypted. As Figure 3 shown, the user inputs the static password through the interaction interface of the platform to perform a login operation. After the platform decrypts the static password stored in the platform using the corresponding decryption algorithm, it compares it with the static password input by the user, or encrypts the static password input by the user using the same encryption algorithm and then compares it with the encrypted password stored in the platform. The result of the above comparison is obtained and recorded in the database.

[0057] Step S200: Query the user association table to obtain the verification key of the user.

[0058] In this embodiment, a user association table is set up in the platform. The user association table records the user account, user-related identity information, and verification key. Further, the user association table may also store data such as user login situation log information and user static password. Integrating the above data into the user association table can reduce the number of data tables in the database. Of course, the user association table can also only record the user account and the corresponding verification key to reduce the storage size of the user association table and improve the speed of querying the user association table. Among them, before the verification key is stored in the user association table, it can be encrypted to increase security. By querying the user association table, the platform obtains the verification key of the user performing the login operation. The verification key is used to verify the second authentication information later.

[0059] Step S300: Obtain the second authentication information generated by the authenticator.

[0060] In this embodiment, since the verification key of the user performing the login operation has been queried from the user association table, it indicates that the user is not logging in for the first time and has already been bound to an authenticator. Therefore, as Figure 3 shown, the user can directly obtain the second authentication information through the authenticator. The authenticator can be Google Authenticator, Microsoft Authenticator, or other open-source or closed-source authentication tools, and these authentication tools all implement the function of providing the second authentication information in the two-factor authentication method. Preferably, in this embodiment, Google Authenticator is used. The user opens the authenticator, and the authentication code is displayed in the authenticator interface. In Google Authenticator, the authentication code is a six-digit authentication code.

[0061] Step S400: Generate the expected authentication information based on the verification key and the current timestamp, and compare and verify the expected authentication information with the second authentication information to obtain the verification result information of the second authentication information.

[0062] In this embodiment, the platform generates expected authentication information using the verification key of the user who performs the login behavior obtained by querying in the user association table. Specifically, the time-based one-time password algorithm (TOTP, Time-based One-Time Password Algorithm) is used, and the verification key of the user and the current timestamp are combined to generate a dynamic authentication code. The TOTP algorithm uses a hash function. Preferably, the HMAC-SHA1 (Hash Message Authentication Code-Secure Hash Algorithm 1) hash function is used to calculate the verification key and the current timestamp as input parameters to obtain a hash value. Then, a preset specific part is extracted from the hash value and undergoes a preset conversion process to finally generate a six-digit authentication code, which is the expected authentication information and corresponds to the six-digit authentication code displayed in the Google Authenticator interface.

[0063] The user inputs the six-digit authentication code displayed in the authenticator, that is, the second authentication information, into the platform interface. The platform compares the six-digit authentication code input by the user with the six-digit authentication code generated by the platform. If the comparison is successful, it indicates that the second authentication information is successfully verified, and the platform records the verification success information in the platform's login log table, and the user logs in successfully.

[0064] In one implementation, the method further includes the following steps:

[0065] Step S500: If the verification result information of the second authentication information is verification failure, generate prompt information for guiding the user to re-verify the second authentication information, and re-record the verification result of the second authentication information.

[0066] In this embodiment, when the authentication code generated by the authenticator input by the user is different from the expected authentication information, that is, the authentication code generated by the platform, the second authentication information is verified as failed. At this time, the platform prompts through the interface that the verification fails and needs to be re-entered. The platform records the relevant information of the user's verification failure, including the timestamp of the verification failure and the number of verification failures within a preset time period.

[0067] Step S600: When the number of verification failures of the second authentication information exceeds the preset number, take security measures.

[0068] In this embodiment, in the platform, there is a limit on the number of verification failures of the user's second authentication information. When the user exceeds the verification times, relevant security measures will be taken to protect the user account.

[0069] In one implementation, when the number of verification failures of the second authentication information exceeds the preset number and security measures are taken, it specifically includes the following steps:

[0070] Step S610: Set the threshold for the number of verification failures of the second authentication information. When the number of verification failures of the second authentication information exceeds the threshold for the number of verification failures, take security measures.

[0071] Step S620: The security measures include temporarily restricting login, marking the user in the user association table, and sending a security warning notice to the user using a preset communication method.

[0072] In this embodiment, the platform sets a threshold for the number of verification failures, and the threshold can be specifically set according to requirements. Preferably, it can be specifically set for each user's situation. For example, the platform sets a table of the threshold for the number of user verification failures, which records the corresponding thresholds for all users or users that need special handling. The threshold for the number of failures can be configured according to the characteristics of the user. For example, if the user's login IP often changes, the user is marked as a high-risk user, and the threshold for the number of failures is set to a lower value.

[0073] When the number of user verification failures exceeds the corresponding threshold of the user, the platform protects the user account with security measures. The security measures can be to restrict the user from logging in within a preset time period. The security measures can also be to mark the user as high-risk in the user association table or other user information tables and adjust the corresponding threshold for the number of verification failures of the user. The security measures can also be to send a warning notice to the user through a preset communication method, such as the mobile phone number or email filled in by the user in the user information table, notifying the user that their account has failed verification multiple times.

[0074] In one implementation, the method further includes the following steps:

[0075] Step S700: If the user association table does not store the verification key of the user, generate a unique verification key corresponding to the user and store it in the user association table.

[0076] In this embodiment, after the verification of the first authentication information of the user is successful, as Figure 3 shown, if the platform does not query the verification key corresponding to the user in the user association table, it indicates that the user has not bound the corresponding authenticator and needs to perform the first authentication process. First, the platform generates a unique verification key corresponding to the user through an algorithm. Among them, the generation of the verification key can be generated by a random algorithm, generated by an encrypted hash function through user information, or generated by a symmetric key algorithm using the master key of the platform and user information. Store the generated verification key in the user association table.

[0077] Step S800: Combine the user's account information with the verification key and generate a binding code.

[0078] In this embodiment, the verification key is used to uniquely represent the base key of the user's second authentication information. The binding code is used for the authenticator to record the base key required for the user to verify the second authentication information.

[0079] In one implementation manner, the combination of the user's account information and the verification key and the generation of the binding code specifically include the following steps:

[0080] Step S810: Combine the user's account information and the verification key to obtain combined information;

[0081] Step S820: Encrypt the combined information to obtain encrypted combined information;

[0082] Step S830: Generate a verification code with a preset validity period based on the encrypted combined information, and the binding code is the verification code with the preset validity period.

[0083] In this embodiment, obtaining the binding code specifically includes the following steps. First, combine the user account information with the verification key. Preferably, direct data splicing is used, for example, separated by a delimiter such as a semicolon to form combined information in string form. Specifically, the user's account information may include user identification information such as a username, identity information such as a registration time, a registration IP, etc. Then, symmetrically encrypt the combined information in string form. Preferably, the AES algorithm is used to encrypt the combined information to obtain encrypted combined information. Finally, through a verification code generation tool, convert the encrypted combined information into a verification code with a short validity period, which is provided as the binding code for subsequent binding. Preferably, the verification code can be a QR code, and the preset validity period of the QR code is 5 minutes.

[0084] Step S900: Bind the user's account to the authenticator through the binding code.

[0085] In this embodiment, after the platform generates the binding code, the authenticator inputs and recognizes the binding code, obtains the relevant information of the user, and performs a binding operation.

[0086] In one implementation manner, the binding of the user's account to the authenticator through the binding code specifically includes the following steps:

[0087] Step S910: Input the binding code into the authenticator and record the binding code based on the authenticator;

[0088] Step S920: Obtain the binding authentication information generated by the authenticator through the verification key in the binding code and the time synchronization algorithm of the authenticator;

[0089] Step S930: Generate expected authentication information using the verification key and the current timestamp, compare and verify the expected authentication information with the bound authentication information to obtain the verification result information of the bound authentication information, and write the binding success flag into the user association table.

[0090] In this embodiment, the authenticator obtains the binding code through input recognition. Preferably, when the authenticator is Google Authenticator and the binding code is a QR code, as Figure 3 shown, the authenticator scans the QR code to obtain the QR code, and uses the QR code decoding algorithm to obtain the encrypted combined information recorded in the QR code. Decrypt the encrypted combined information to obtain the combined information, and extract the verification key corresponding to the user in the combined information through the delimiter. Further, the authenticator stores the binding code and the verification key therein. Generate a six-digit dynamic authentication code with a preset update validity period using the time synchronization algorithm and the verification key provided by the authenticator. The six-digit dynamic authentication code is the bound authentication information. Preferably, the preset update validity period is 30 seconds, that is, a new six-digit dynamic authentication code is refreshed every 30 seconds. The platform generates expected authentication information based on the verification key and the current timestamp. At the same time, the platform obtains the six-digit dynamic authentication code generated by the authenticator input by the user and compares the two. When the comparison is successful, write the binding success flag into the user association table, indicating that the user has completed the first authentication, and subsequent verification can be performed using the corresponding second authentication information generated by the authenticator.

[0091] In one implementation, the step of binding the user's account to the authenticator using the binding code specifically further includes the following steps:

[0092] Step S940: If the result of the binding authentication fails, generate a prompt message for guiding the user to re-bind and verify, and record the verification result of the re-bind and verify.

[0093] Step S950: When the number of times of failed binding verification exceeds the preset number of times, take security measures.

[0094] In this embodiment, when the bound authentication information input by the user is not the same as the expected authentication information, that is, the authentication code generated by the platform, the bound authentication information verification fails. At this time, the platform prompts through the interface that the verification fails and needs to be re-entered. The platform records the relevant information of the user's failed binding verification, including the timestamp of the failed binding verification and the number of times of failed binding verification within the preset time period.

[0095] In the platform, there is a limit on the number of verification failures of the user's bound authentication information. When the user's verification exceeds the limit, relevant security measures will be taken to protect the user account.

[0096] In summary, under the technical solution of the above embodiments, the user is authenticated by two factors by recording the verification key-related information in the user association table on the SaaS platform. This authentication method encrypts and stores the two-factor authentication seed data to ensure data confidentiality. At the same time, by locally storing the two-factor authentication data, the two-factor authentication settings can be quickly restored when the user changes the device. In this way, the problems existing in the prior art can be solved, including that if the seed data backed up in the cloud is not encrypted in the two-factor verification application, it is easy to cause data leakage, attackers can bypass the verification disabling function and use the cached information to extract the password, users are easily phished and provide verification codes, the login operation process is cumbersome and the number of input information steps is large, resulting in a decrease in the user's willingness to use, and the process of re-setting the two-factor security verification during device migration is complex.

[0097] As Figure 2 shown in, the embodiment of the present invention provides a two-factor security verification system, which includes: a first authentication information verification module 10, a verification key acquisition module 20, a second authentication information acquisition module 30, and a second authentication information verification module 40.

[0098] Specifically, the first authentication information verification module 10 is used to obtain the user's first authentication information and verify the first authentication information to obtain the verification result information of the first authentication information; the verification key acquisition module 20 is used to query the user association table to obtain the verification key of the user; the second authentication information acquisition module 30 is used to obtain the second authentication information generated by the authenticator; the second authentication information verification module 40 is used to generate the expected authentication information based on the verification key and the current timestamp, and compare and verify the expected authentication information with the second authentication information to obtain the verification result information of the second authentication information.

[0099] In one implementation, the system further includes:

[0100] A second authentication information re-verification module, which is used to generate a prompt message for guiding the user to re-verify the second authentication information if the verification result information of the second authentication information is verification failure, and re-record the verification result of the second authentication information;

[0101] A verification failure over-limit defense module, which is used to take security measures when the number of verification failures of the second authentication information exceeds a preset number.

[0102] In one implementation, the verification failure over - times defense module includes:

[0103] A verification failure times threshold setting unit, configured to set a verification failure times threshold for the second authentication information. When the verification failure times of the second authentication information exceed the verification failure times threshold, security measures are taken.

[0104] A security measure execution unit, where the security measures include temporarily restricting logins, marking the user in the user association table, and using a preset communication method to send a security warning notice to the user.

[0105] In one implementation, the system further includes:

[0106] A verification key generation module, configured to generate a unique verification key corresponding to the user if the user association table does not store the verification key of the user, and store it in the user association table.

[0107] A binding code generation module, configured to combine the user's account information with the verification key and generate a binding code.

[0108] An authenticator binding module, configured to bind the user's account to the authenticator through the binding code.

[0109] In one implementation, the binding code generation module includes:

[0110] A combined information acquisition unit, configured to combine the user's account information with the verification key to obtain combined information.

[0111] A combined information encryption unit, configured to encrypt the combined information to obtain encrypted combined information.

[0112] A verification code generation unit, configured to generate a verification code with a preset validity period based on the encrypted combined information, and the binding code is the verification code with the preset validity period.

[0113] In one implementation, the authenticator binding module includes:

[0114] A binding code input to authenticator unit, configured to input the binding code into the authenticator and record the binding code based on the authenticator.

[0115] A bound identity authentication information generation unit, configured to obtain the bound identity authentication information generated by the authenticator through the time synchronization algorithm of the verification key in the binding code and the authenticator.

[0116] The bound authentication information verification unit is used to generate expected authentication information through the verification key and the current timestamp, compare and verify the expected authentication information with the bound authentication information, obtain the verification result information of the bound authentication information, and write the bound success flag into the user association table.

[0117] In one implementation, the authenticator binding module further includes:

[0118] The bound authentication information re-verification module unit is used to generate prompt information for guiding the user to re-bind and verify if the result of the bound authentication fails, and record the verification result of the re-bind and verify;

[0119] The bound verification failure over-limit defense module unit is used to take security measures when the number of times of the bound verification failure exceeds the preset number of times.

[0120] Based on the above embodiments, the present invention further provides an intelligent terminal, and its principle block diagram can be as Figure 4 shown. The intelligent terminal includes a processor, a memory, a network interface, a display screen, and a temperature sensor connected through a system bus. Among them, the processor of the intelligent terminal is used to provide computing and control capabilities. The memory of the intelligent terminal includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the intelligent terminal is used to communicate with an external terminal through a network connection. The computer program, when executed by the processor, implements a two-factor security verification method. The display screen of the intelligent terminal can be a liquid crystal display screen or an electronic ink display screen, and the temperature sensor of the intelligent terminal is pre-set inside the intelligent terminal for detecting the operating temperature of the internal device.

[0121] Those skilled in the art can understand that Figure 4 the principle block diagram shown in is only a block diagram of some structures related to the solution of the present invention, and does not constitute a limitation on the intelligent terminal to which the solution of the present invention is applied. The specific intelligent terminal may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0122] In one embodiment, an intelligent terminal is provided, including a memory, and one or more programs, where one or more programs are stored in the memory and are configured to be executed by one or more processors. The one or more programs include instructions for performing the following operations:

[0123] Obtain the first authentication information of the user, and verify the first authentication information to obtain the verification result information of the first authentication information;

[0124] Query the user association table to obtain the verification key of the user;

[0125] Obtain the second authentication information generated by the authenticator;

[0126] Generate the expected authentication information based on the verification key and the current timestamp, and compare and verify the expected authentication information with the second authentication information to obtain the verification result information of the second authentication information.

[0127] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to memory, storage, database or other media used in the various embodiments provided by the present invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchl ink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0128] In summary, the present invention provides a two-factor security verification method, system, terminal device and medium. Compared with the prior art, the method first obtains the user's first authentication information and verifies the first authentication information to obtain the verification result information of the first authentication information. Then, it queries the user association table to obtain the verification key of the user. Immediately afterwards, it obtains the second authentication information generated by the authenticator. Finally, based on the verification key and the current timestamp, it generates the expected authentication information and compares it with the second authentication information for verification to obtain the verification result information of the second authentication information. The present invention performs two-factor authentication on the user by recording the verification key-related information in the user association table on the SaaS platform. This authentication method encrypts and stores the two-factor authentication seed data to ensure the confidentiality of the data. At the same time, by locally storing the two-factor authentication data, the user can quickly restore the two-factor authentication settings when changing devices. In this way, it can solve the problems existing in the prior art, including that if the two-factor verification application does not encrypt the seed data backed up in the cloud, it is easy to cause data leakage, attackers can bypass the verification disabling function and use the cached information to extract the password, users are easily phished and provide verification codes, the login operation process is cumbersome and the number of input information steps is large, resulting in a decrease in the user's willingness to use, and the process of re-setting the two-factor security verification during device migration is complex.

[0129] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0130] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A two-factor security verification method, characterized in that: Applied in a SaaS platform, the method includes: Acquire first identity authentication information of the user, and verify the first identity authentication information to obtain verification result information of the first identity authentication information; Query the user association table to obtain the verification key of the user; Obtaining second identity verification information generated by the authenticator; Based on the verification key and the current timestamp, expected identity authentication information is generated, and the expected identity authentication information is compared and verified with the second identity authentication information to obtain verification result information of the second identity authentication information.

2. The two-factor security verification method according to claim 1, characterized in that: The method further comprises: If the verification result information of the second identity authentication information indicates that the verification has failed, generating prompt information for guiding the user to re-verify the second identity authentication information, and re-recording the verification result of the second identity authentication information; When the number of verification failures of the second identity verification information exceeds a preset number, security measures are taken.

3. The two-factor security verification method according to claim 2, characterized in that: When the number of verification failures of the second identity verification information exceeds a preset number, taking security measures includes: Setting a verification failure number threshold for the second identity authentication information, and taking security measures when the verification failure number of the second identity authentication information exceeds the verification failure number threshold; The security measures include temporarily restricting login, marking users in a user association table, and using a preset communication method to issue security warning notifications to users.

4. The two-factor security verification method according to claim 1, characterized in that: The method further comprises: If the user association table does not store the verification key of the user, generating a unique verification key corresponding to the user and storing it in the user association table; Combining the user's account information with the verification key to generate a binding code; The user's account is bound to the authenticator through the binding code.

5. The two-factor security verification method according to claim 4, characterized in that: The combining the user's account information with the verification key to generate a binding code includes: Combining the user's account information with the verification key to obtain combined information; encrypting the combined information to obtain encrypted combined information; Based on the encrypted combined information, a preset validity period verification code is generated, and the binding code is the preset validity period verification code.

6. The two-factor security verification method according to claim 4, characterized in that: The step of binding the user's account to the authenticator through the binding code includes: inputting the binding code into the authenticator, and recording the binding code based on the authenticator; Obtaining binding identity authentication information generated by the authenticator through the verification key in the binding code and the time synchronization algorithm of the authenticator; The expected identity authentication information is generated by using the verification key and the current timestamp, and the expected identity authentication information is compared and verified with the binding identity authentication information to obtain the verification result information of the binding identity authentication information, and a binding success mark is written into the user association table.

7. The two-factor security verification method according to claim 4, characterized in that: The step of binding the user's account to the authenticator through the binding code further comprises: If the result of the binding authentication is verification failure, a prompt message for guiding the user to re-bind verification is generated, and the verification result of the re-binding verification is recorded; When the number of binding verification failures exceeds a preset number, security measures are taken.

8. A two-factor security authentication system, characterized in that: The system comprises: A first identity authentication information verification module, used to obtain the first identity authentication information of the user, and verify the first identity authentication information to obtain verification result information of the first identity authentication information; A verification key acquisition module, used to query the user association table to obtain the verification key of the user; A second identity authentication information acquisition module, used to acquire the second identity authentication information generated by the authenticator; The second identity authentication information verification module is used to generate expected identity authentication information based on the verification key and the current timestamp, and compare and verify the expected identity authentication information with the second identity authentication information to obtain verification result information of the second identity authentication information.

9. A terminal device, characterized in that: The terminal device includes a memory, a processor, and a two-factor security verification program stored in the memory and executable on the processor. When the processor executes the two-factor security verification program, the steps of the two-factor security verification method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a two-factor security verification program, and when the two-factor security verification program is executed by the processor, the steps of the two-factor security verification method according to any one of claims 1 to 7 are implemented.