Business authentication method, device, platform, storage medium and program product

By updating the challenge word combination and verifying it during the business client authentication process, the problems caused by the leakage of the encryption and decryption key and the update of the single challenge word in the prior art are solved, and the security and stability of the business client authentication are achieved.

CN120223374APending Publication Date: 2025-06-27E-SURFING DIGITAL LIFE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510309151.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the prior art, when authenticating the business client, user information and terminal information are easily leaked due to the disclosure of the decryption key, and the single challenge word update rule may lead to user activation and authentication failure.

Method used

Provide a business authentication method, by updating the challenge word combination between two adjacent authentications, ensures that the service client receives the latest challenge word and performs challenge word verification during the subsequent authentication, ensuring the matching and security of the authentication parameters.

Benefits of technology

It effectively avoids the leakage of user information and terminal information, ensures the security of the authentication process, and reduces the risk of authentication failure caused by single challenge word updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223374A_ABST
    Figure CN120223374A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of internet application development, provides a service authentication method, device and platform, a storage medium and a program product, and can reduce the risk that user information and terminal information are leaked. According to the application, after the previous authentication is passed, the corresponding challenge word is issued to the service client; according to a subsequent authentication request initiated by the service client, obtaining the encrypted subsequent authentication parameter and the latest challenge word obtained when the service client is subjected to subsequent authentication; after the subsequent authentication parameter verification is completed, if challenge word verification is needed, analyzing the latest challenge word obtained by the service client after the subsequent authentication; and if the subsequent authentication parameter analysis result is matched with the challenge word analysis result, determining that the subsequent authentication is passed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of Internet application development, and particularly to a service authentication method, device, service platform, storage medium, and computer program product. Background Art

[0002] With the expansion and development of Internet services, people have paid increasing attention to the security of authentication and authorization of service clients. Usually, a mode of encrypting request and return parameters is adopted to ensure security. When the encryption and decryption keys are leaked, the basic user information and terminal basic information may be exposed on the public network, which may lead to problems such as the leakage of user information and terminal information. Summary of the Invention

[0003] Based on this, it is necessary to provide a service authentication method, device, service platform, storage medium, and computer program product for the above technical problems.

[0004] This application provides a service authentication method, and the method includes:

[0005] For the previous authentication in two adjacent authentications, after the previous authentication passes, if the latest challenge word obtained by the service client as of the previous authentication matches the latest challenge word in the challenge word combination, the newly generated challenge word is sent to the service client;

[0006] After the previous authentication passes, if the latest challenge word obtained by the service client as of the previous authentication matches a non-latest challenge word in the challenge word combination, the latest challenge word in the challenge word combination is sent to the service client;

[0007] For the subsequent authentication in the two adjacent authentications, according to the subsequent authentication request initiated by the service client after user login, the encrypted subsequent authentication parameters and the latest challenge word obtained by the service client as of the subsequent authentication are obtained;

[0008] After the parsing result of the subsequent authentication parameters obtained from the encrypted subsequent authentication parameters passes the verification, if challenge word verification is required, the latest challenge word obtained by the service client as of the subsequent authentication is parsed to obtain a challenge word parsing result;

[0009] If the parsing result of the subsequent authentication parameters matches the challenge word parsing result, it is determined that the subsequent authentication for the service client passes.

[0010] In one embodiment, the non-latest challenge word in the challenge word combination is the challenge word generated last time of the latest challenge word in the challenge word combination.

[0011] In one embodiment, after generating the new challenge word, the method further includes:

[0012] Update the non-latest challenge words in the challenge word combination to the latest challenge words, and update the latest challenge words in the challenge word combination to the newly generated challenge words.

[0013] In one embodiment, the method further includes:

[0014] Obtain the secret key agreed upon by the service client and the local end;

[0015] According to the secret key, decrypt the encrypted secondary authentication parameter to obtain the plaintext secondary authentication parameter;

[0016] Parse the plaintext secondary authentication parameter to obtain the parsing result of the secondary authentication parameter; the parsing result of the secondary authentication parameter includes the unique identifier of the terminal where the service client is located and the access address of the user.

[0017] In one embodiment, the method further includes:

[0018] Determine whether the service client is a client of a third-party institution outside the institution where the local end is located;

[0019] If so, determine that challenge word verification is required.

[0020] In one embodiment, after the parsing result of the secondary authentication parameter obtained according to the encrypted secondary authentication parameter passes the verification, the method further includes:

[0021] If challenge word verification is not required, determine that the secondary authentication for the service client passes.

[0022] This application provides a service authentication device, and the device includes:

[0023] A challenge word processing module, which is used for the previous authentication in two adjacent authentications. After the previous authentication passes, if the latest challenge word obtained by the service client as of the previous authentication matches the latest challenge word in the challenge word combination, the newly generated challenge word is sent to the service client;

[0024] The challenge word processing module is further used for, after the previous authentication passes, if the latest challenge word obtained by the service client as of the previous authentication matches the non-latest challenge word in the challenge word combination, the latest challenge word in the challenge word combination is sent to the service client;

[0025] An authentication request processing module, which is used for the secondary authentication in the two adjacent authentications. According to the secondary authentication request initiated by the service client after user login, the encrypted secondary authentication parameter and the latest challenge word obtained by the service client as of the secondary authentication are obtained;

[0026] The challenge word verification module is used to, after the verification of the post-authentication parameter parsing result obtained according to the encrypted post-authentication parameter passes, if challenge word verification is required, parse the latest challenge word obtained by the service client as of the post-authentication to obtain a challenge word parsing result;

[0027] The authentication result processing module is used to determine that the post-authentication for the service client passes if the post-authentication parameter parsing result matches the challenge word parsing result.

[0028] This application provides a service platform, including a memory and a processor. The memory stores a computer program, and the processor executes the above method.

[0029] This application provides a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by the processor to execute the above method.

[0030] This application provides a computer program product, on which a computer program is stored, and the computer program is executed by the processor to execute the above method.

[0031] In the above service authentication method, device, service platform, storage medium and computer program product, for the previous authentication in two adjacent authentications, after the previous authentication passes, if the latest challenge word obtained by the service client as of the previous authentication matches the latest challenge word in the challenge word combination, the newly generated challenge word is sent to the service client; after the previous authentication passes, if the latest challenge word obtained by the service client as of the previous authentication matches a non-latest challenge word in the challenge word combination, the latest challenge word in the challenge word combination is sent to the service client; for the post-authentication in two adjacent authentications, according to the post-authentication request initiated by the service client after user login, the encrypted post-authentication parameter and the latest challenge word obtained by the service client as of the post-authentication are obtained; after the verification of the post-authentication parameter parsing result obtained according to the encrypted post-authentication parameter passes, if challenge word verification is required, the latest challenge word obtained by the service client as of the post-authentication is parsed to obtain a challenge word parsing result; if the post-authentication parameter parsing result matches the challenge word parsing result, it is determined that the post-authentication for the service client passes. In the solution provided by this application, when the service client initiates authentication through the user's terminal, the authentication parameter is encrypted to avoid the leakage of user information and terminal information; when the service client initiates authentication, a challenge word can also be sent, and when the challenge word parsing result matches the authentication parameter parsing result, it is determined that the authentication passes, ensuring security; moreover, the maintained challenge word combination includes the latest challenge word and non-latest challenge words, which can avoid the situation where user activation and authentication fail due to the problem of a single challenge word. Description of the Drawings

[0032] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0033] Figure 1 It is a schematic flowchart of a service authentication method in an embodiment;

[0034] Figure 2 It is a timing diagram of an authentication process in an embodiment;

[0035] Figure 3 It is a flowchart of the (N + 1)-th authentication method in an embodiment;

[0036] Figure 4 It is a schematic flowchart of verifying a challenge word in an embodiment;

[0037] Figure 5 It is a structural block diagram of a service authentication device in an embodiment;

[0038] Figure 6 It is an internal structure diagram of a service platform in an embodiment. Detailed implementation manners

[0039] In order to make the objectives, technical solutions and advantages of the present application clearer, the following further details the present application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0040] The service authentication method provided by the present application includes Figure 1 The steps shown. The steps included in this method can be executed by a service platform.

[0041] Step S101. For the previous authentication in two adjacent authentications, after the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches the latest challenge word in the challenge word combination, the newly generated challenge word is sent to the service client.

[0042] The service client can include, but is not limited to, a music playback client and a video playback client. A terminal (such as a set-top box) can download the installation package of the service client and install the service client on the terminal through the installation package of the service client. Some installation packages are applicable to the Android system, and such installation packages can be called Android installation packages (APK, Android PackageKit).

[0043] After the user logs in to the service client on the terminal, the service client can initiate an authentication request to the service platform through the terminal to authenticate and authorize the user's identity.

[0044] The challenge word combinations maintained by the service platform include the latest challenge word and non-latest challenge words. The latest challenge word is the challenge word newly generated by the service platform. In some scenarios, the non-latest challenge word in the challenge word combination is the challenge word generated in the previous time of the latest challenge word in the challenge word combination. At this time, the challenge word combination includes the challenge words generated in the most recent two times.

[0045] Taking the Nth authentication and the (N + 1)th authentication as an example for introduction. The Nth authentication and the (N + 1)th authentication are two adjacent authentications. The Nth authentication is the previous authentication, and the (N + 1)th authentication is the subsequent authentication.

[0046] After the user logs in to the service client on the terminal for the Nth time, the service client can initiate the Nth authentication request to the service platform through the terminal. The Nth authentication request carries the encrypted Nth authentication parameters and the latest challenge word obtained by the service client as of the Nth authentication.

[0047] The service platform can parse the Nth authentication request to obtain the encrypted Nth authentication parameters and the latest challenge word obtained by the service client as of the Nth authentication. After obtaining the encrypted Nth authentication parameters, the service platform can decrypt and parse the encrypted Nth authentication parameters to obtain the parsing result of the Nth authentication parameters. The parsing result of the Nth authentication parameters includes user basic information such as the user account and password. The service platform can verify the user basic information included in the parsing result of the Nth authentication parameters. If the verification passes (that is, the parsing result of the Nth authentication parameters passes the verification), the service platform can determine whether challenge word verification is required. If challenge word verification is required, the service platform can parse the latest challenge word obtained by the service client as of the Nth authentication obtained from the encrypted Nth authentication parameters to obtain the challenge word parsing result. The challenge word parsing result includes user basic information such as the user account and password.

[0048] The service platform can compare whether the user basic information included in the parsing result of the Nth authentication parameters matches the user basic information included in the challenge word parsing result. If they match, it can be determined that the Nth authentication passes.

[0049] After the Nth authentication passes, the service platform can compare the latest challenge word obtained by the service client as of the Nth authentication with the challenge word combination maintained. If the latest challenge word obtained by the service client as of the Nth authentication matches the latest challenge word in the challenge word combination, it indicates that the service client has normally obtained the latest challenge word newly generated by the service platform. At this time, the service platform can generate a new challenge word and send it to the service client.

[0050] In addition, after the business platform generates a new challenge word, it can update the non-latest challenge words in the challenge word combination to the latest challenge words, and update the latest challenge word in the challenge word combination to the newly generated challenge word. Through this step, the update and maintenance of the challenge word combination can be achieved.

[0051] Step S102, after the previous authentication is passed, if the latest challenge word obtained by the business client as of the previous authentication matches the non-latest challenge word in the challenge word combination, then the latest challenge word in the challenge word combination is sent to the business client.

[0052] As introduced before, after the Nth authentication is passed, the business platform can compare the latest challenge word obtained by the business client as of the Nth authentication with the maintained challenge word combination. If the latest challenge word obtained by the business client as of the Nth authentication matches the non-latest challenge word in the challenge word combination, it means that the business client has not received the latest challenge word newly generated by the business platform. At this time, the business platform can continue to send the latest challenge word in the challenge word combination to the business client.

[0053] Exemplarily, the challenge word combination maintained by the business platform is the challenge words generated in the most recent two times: (b, a), where b represents the latest challenge word generated by the business platform, and a represents the challenge word generated by the business platform the previous time (compared with the latest generation).

[0054] If the latest challenge word obtained by the business client as of the Nth authentication is b, then the latest challenge word obtained by the business client as of the Nth authentication matches the latest challenge word in the challenge word combination. At this time, it means that the business client has normally obtained the latest challenge word newly generated by the business platform. At this time, the business platform can generate a new challenge word (denoted as c) and send it to the business client. At this time, the business platform can update the maintained challenge word combination and update the challenge word combination to: (c, b), where c represents the latest challenge word generated by the business platform, and b represents the challenge word generated by the business platform the previous time (compared with the latest generation).

[0055] If the latest challenge word obtained by the business client as of the Nth authentication is a, then the latest challenge word obtained by the business client as of the Nth authentication matches the non-latest challenge word in the challenge word combination, which means that the business client has not received the latest challenge word b newly generated by the business platform. At this time, the business platform can continue to send the latest challenge word b in the challenge word combination to the business client.

[0056] Step S103, for the subsequent authentication in two adjacent authentications, according to the subsequent authentication request initiated by the business client after the user logs in, obtain the encrypted subsequent authentication parameter and the latest challenge word obtained by the business client as of the subsequent authentication.

[0057] After the user logs in to the service client for the (N + 1)-th time on the terminal, the service client can initiate a (N + 1)-th authentication request to the service platform through the terminal. The (N + 1)-th authentication request carries the encrypted (N + 1)-th authentication parameter and the latest challenge word obtained by the service client as of the (N + 1)-th authentication.

[0058] The service platform can parse the (N + 1)-th authentication request to obtain the encrypted (N + 1)-th authentication parameter and the latest challenge word obtained by the service client as of the (N + 1)-th authentication.

[0059] Step S104, after the parsing result of the subsequent authentication parameter obtained according to the encrypted subsequent authentication parameter passes the verification, if challenge word verification is required, parse the latest challenge word obtained by the service client as of the subsequent authentication to obtain the challenge word parsing result.

[0060] After obtaining the encrypted (N + 1)-th authentication parameter, the service platform can decrypt and parse the encrypted (N + 1)-th authentication parameter to obtain the parsing result of the (N + 1)-th authentication parameter. The parsing result of the (N + 1)-th authentication parameter includes user basic information such as the user account and password. The service platform can verify the user basic information included in the parsing result of the (N + 1)-th authentication parameter. If the verification passes (that is, the parsing result of the (N + 1)-th authentication parameter passes the verification), the service platform can determine whether challenge word verification is required. If challenge word verification is required, the service platform can parse the latest challenge word obtained by the service client as of the (N + 1)-th authentication obtained from the encrypted (N + 1)-th authentication parameter to obtain the challenge word parsing result, and the challenge word parsing result includes user basic information such as the user account and password.

[0061] Step S105, if the parsing result of the subsequent authentication parameter matches the challenge word parsing result, it is determined that the subsequent authentication for the service client passes.

[0062] The service platform can compare whether the user basic information included in the parsing result of the (N + 1)-th authentication parameter matches the user basic information included in the challenge word parsing result. If they match, it can be determined that the (N + 1)-th authentication passes. If they do not match, it is determined that the (N + 1)-th authentication fails.

[0063] After the (N + 1)-th authentication passes, the service platform can compare the latest challenge word obtained by the service client as of the (N + 1)-th authentication with the maintained challenge word combination.

[0064] If the latest challenge word obtained by the service client as of the (N + 1)-th authentication matches the latest challenge word in the challenge word combination, it indicates that the service client has normally obtained the latest challenge word newly generated by the service platform. At this time, the service platform can generate a new challenge word and send it to the service client. After generating the new challenge word, the service platform can also update the non-latest challenge word in the challenge word combination to the latest challenge word, and update the latest challenge word in the challenge word combination to the newly generated challenge word. Through this step, the update and maintenance of the challenge word combination can be achieved.

[0065] If the latest challenge word obtained by the service client as of the (N + 1)-th authentication matches the non-latest challenge word in the challenge word combination, it indicates that the service client has not received the latest challenge word newly generated by the service platform. At this time, the service platform can continue to send the latest challenge word in the challenge word combination to the service client.

[0066] In the above service authentication method, for the previous authentication in two adjacent authentications, after the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches the latest challenge word in the challenge word combination, the newly generated challenge word is sent to the service client; after the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches the non-latest challenge word in the challenge word combination, the latest challenge word in the challenge word combination is sent to the service client; for the subsequent authentication in two adjacent authentications, according to the subsequent authentication request initiated by the service client after the user logs in, the encrypted subsequent authentication parameter and the latest challenge word obtained by the service client as of the subsequent authentication are obtained; after the parsing result of the subsequent authentication parameter obtained according to the encrypted subsequent authentication parameter passes the verification, if challenge word verification is required, the latest challenge word obtained by the service client as of the subsequent authentication is parsed to obtain the challenge word parsing result; if the parsing result of the subsequent authentication parameter matches the challenge word parsing result, it is determined that the subsequent authentication for the service client is passed. In the solution provided by this application, when the service client initiates authentication through the user's terminal, the authentication parameter is encrypted to avoid the leakage of user information and terminal information; when the service client initiates authentication, it can also send a challenge word. When the challenge word parsing result matches the authentication parameter parsing result, it is determined that the authentication is passed, ensuring security; and, the maintained challenge word combination includes the latest challenge word and the non-latest challenge word, which can avoid the situation of user activation and authentication failure caused by the problem of a single challenge word.

[0067] In one embodiment, the method provided by this application further includes:

[0068] Obtain the secret key agreed upon by the service client and the local end; according to the secret key, decrypt the encrypted secondary authentication parameters to obtain the plaintext secondary authentication parameters; parse the plaintext secondary authentication parameters to obtain the parsing result of the secondary authentication parameters; the parsing result of the secondary authentication parameters includes the unique identifier of the terminal where the service client is located and the access address of the user.

[0069] Take the (N + 1)-th authentication as an example for introduction.

[0070] After the user logs in to the service client for the (N + 1)-th time on the terminal, the service client can generate a (N + 1)-th authentication request and initiate a (N + 1)-th authentication request to the service platform through the terminal.

[0071] When generating the (N + 1)-th authentication request, the service client can perform the following steps: take the unique identifier of the terminal and the access address (Internet Protocol, IP) of the user as one of the encryption elements, and encrypt the encryption elements according to the secret key agreed upon by both the service client and the service platform and the AES (Advanced Encryption) algorithm to obtain the encrypted (N + 1)-th authentication parameters; the service platform can also obtain the latest challenge word obtained up to the (N + 1)-th authentication, and generate a (N + 1)-th authentication request according to the encrypted (N + 1)-th authentication parameters and the latest challenge word obtained up to the (N + 1)-th authentication.

[0072] Correspondingly, after receiving the (N + 1)-th authentication request, the service platform can parse the (N + 1)-th authentication request to obtain the encrypted (N + 1)-th authentication parameters and the latest challenge word obtained up to the (N + 1)-th authentication. The service platform can decrypt the encrypted (N + 1)-th authentication parameters according to the secret key agreed upon by both the service client and the service platform and the AES algorithm to obtain the plaintext (N + 1)-th authentication parameters; parse the plaintext (N + 1)-th authentication parameters to obtain the parsing result of the (N + 1)-th authentication parameters; the parsing result of the (N + 1)-th authentication parameters includes the unique identifier of the terminal where the service client is located and the access address of the user.

[0073] The service platform can verify the unique identifier of the terminal where the service client is located and the access address of the user included in the parsing result of the (N + 1)-th authentication parameters. If the verification passes, the service platform can determine whether challenge word verification is required.

[0074] In this embodiment, encryption is performed through the secret key agreed upon by the service client and the local end, avoiding the leakage of user information and terminal information, and taking the unique identifier of the terminal and the access address of the user as one of the encryption elements, ensuring that this authentication request is from the current user's current terminal, and thus ensuring the security of the request data.

[0075] In one of the embodiments, the method provided by the present application further includes: determining whether the service client is a client of a third-party organization other than the organization where the client is located; if so, determining that a challenge word check is required.

[0076] The business platform can determine whether the business client is a client of a third-party organization outside the organization where the terminal is located. If the business client is a client of a third-party organization outside the organization where the terminal is located, it indicates that the business client and the business platform belong to different organizations. At this time, the business platform can determine that a challenge word check is required to ensure the security of the requested data. If the business client is a client of the organization where the terminal is located, it indicates that the business client and the business platform belong to the same organization. At this time, the business platform can determine that a challenge word check is not required, thereby improving the efficiency of data requests.

[0077] In one of the embodiments, after the subsequent authentication parameter parsing result obtained based on the encrypted subsequent authentication parameter is verified, the method provided by the present application further includes: if no challenge word verification is required, determining that the subsequent authentication for the service client is passed.

[0078] The following example is used to describe the next authentication as the N+1 authentication. The business platform can verify the unique terminal identifier of the business client and the user's access address included in the N+1 authentication parameter parsing result. After the N+1 authentication parameter parsing result is verified, if the business platform determines that the challenge word verification is not required, it can be determined that the N+1 authentication is passed.

[0079] In order to better understand the above method, an application embodiment of the service authentication method of the present application is described in detail below. When the service client has different requirements for user authentication and authorization of complex services, the service platform can adapt the challenge word information of different levels.

[0080] The method proposed in this embodiment belongs to an authentication method based on the multi-level challenge word update of the improved AES algorithm. When the service client initiates an authentication request through the terminal, in order to ensure the security of user information and terminal information, with the help of the improved AES algorithm challenge word update method, a combination of multi-level challenge words is performed to verify the authentication request initiated by the service client, thereby reducing the risk of leakage of user information and terminal information.

[0081] In view of the authentication process in a public network environment, there is a risk of leakage of user information and terminal information. This embodiment considers multiple dimensions and proposes an improved AES encryption algorithm multi-level challenge word update method without affecting the system stability and response speed. The security of authentication is ensured by comparing the most recent multiple levels of challenge words. Secondly, the challenge words are encrypted and verified by the AES algorithm to reduce the risk of leakage of user information and terminal information.

[0082] Reference Figure 2 , Figure 2 is the timing diagram of the authentication process in this embodiment.

[0083] Specifically, when the user opens the terminal and initiates a login for the first time on the business client; after the login is completed, the business client can send a first challenge word acquisition request to the business platform through the authentication API (Application Programming Interface) provided by the business platform to request the first challenge word; the business platform can verify the information used to generate the first challenge word. After the verification passes, the business platform can generate the first challenge word and return it to the business client, and the business client can store the first challenge word in the terminal. When the business platform returns the first challenge word, the encryption method of the challenge word can include: encrypting the first challenge word with the secret key agreed upon by both the business client and the business platform, and adding the terminal unique identifier and the user's access address to the encryption elements, so as to ensure that this request is from the terminal bound to the current user to ensure the security of the request data.

[0084] After the user's first login is completed, the business client can initiate the first authentication based on the first challenge word returned by the business platform. The business client can send a first authentication request to the business platform through the terminal. The first authentication request carries the encrypted first authentication parameters and the latest challenge word (i.e., the first challenge word) obtained by the business client as of the first authentication. The encrypted first authentication parameters are formed by encrypting the first authentication parameters through the AES encryption algorithm. The first authentication parameters include the terminal unique identifier and the user's access address. The security of the request parameters and the user information is ensured through the method of encrypting multiple elements.

[0085] The business platform can parse the first authentication request to obtain the encrypted first authentication parameters and the latest challenge word obtained by the business client as of the first authentication. After obtaining the encrypted first authentication parameters, the business platform can decrypt and parse the encrypted first authentication parameters to obtain the first authentication parameter parsing result. The business platform can verify the information included in the first authentication parameter parsing result. If the verification passes (i.e., the first authentication parameter parsing result verification passes), the business platform can determine whether challenge word verification is required.

[0086] If challenge word verification is not required, the business platform can determine that the first authentication is passed and feedback the terminal information and user information unknown to the business client to the business client.

[0087] If challenge word verification is required, the business platform can parse the latest challenge word obtained by the business client as of the first authentication obtained from the encrypted first authentication parameters to obtain the challenge word parsing result.

[0088] The service platform can compare whether the user basic information included in the first authentication parameter parsing result matches the user basic information included in the challenge word parsing result. If they match, it can be determined that the first authentication is passed, and the terminal information and user information unknown to the service client are fed back to the service client.

[0089] After the first authentication is passed, the service platform can compare the latest challenge word obtained by the service client as of the first authentication with the challenge word combination maintained by it. It can be understood that at the first authentication, among the challenge word combinations maintained by the service platform, the latest challenge word is the first challenge word, and the non-latest challenge words are empty. If the latest challenge word obtained by the service client as of the first authentication matches the latest challenge word in the challenge word combination, it means that the service client has normally obtained the latest challenge word newly generated by the service platform. At this time, the service platform can generate a new challenge word and send it to the service client. After receiving the new challenge word, the service client can store it in the terminal.

[0090] Refer to Figure 3 , Figure 3 which is the flowchart of the (N + 1)-th authentication method provided in this embodiment, and is introduced by taking the (N + 1)-th authentication as an example.

[0091] After the (N + 1)-th login, the service client can initiate an (N + 1)-th authentication request to the service platform. The (N + 1)-th authentication request carries the encrypted (N + 1)-th authentication parameter and the latest challenge word obtained by the service client as of the (N + 1)-th authentication.

[0092] The service platform can parse the (N + 1)-th authentication request to obtain the encrypted (N + 1)-th authentication parameter and the latest challenge word obtained by the service client as of the (N + 1)-th authentication.

[0093] After obtaining the encrypted (N + 1)-th authentication parameter, the service platform can decrypt and parse the encrypted (N + 1)-th authentication parameter to obtain the (N + 1)-th authentication parameter parsing result. The service platform can verify the user basic information included in the (N + 1)-th authentication parameter parsing result. If the verification passes (that is, the (N + 1)-th authentication parameter parsing result passes the verification), the service platform can determine whether challenge word verification is required. If challenge word verification is required, the service platform can parse the latest challenge word obtained by the service client as of the (N + 1)-th authentication obtained from the encrypted (N + 1)-th authentication parameter to obtain the challenge word parsing result.

[0094] The service platform can compare whether the user basic information included in the (N + 1)-th authentication parameter parsing result matches the user basic information included in the challenge word parsing result. If they match, it can be determined that the (N + 1)-th authentication is passed. If they do not match, it is determined that the (N + 1)-th authentication fails.

[0095] After the (N + 1)-th authentication is passed, the service platform can compare the latest challenge word obtained by the service client as of the (N + 1)-th authentication with the challenge word combination it maintains.

[0096] If the latest challenge word obtained by the service client as of the (N + 1)-th authentication matches the latest challenge word in the challenge word combination, it indicates that the service client has normally obtained the latest challenge word newly generated by the service platform. At this time, the service platform can generate a new challenge word and send it to the service client. After generating the new challenge word, the service platform can also update the non-latest challenge word in the challenge word combination to the latest challenge word, and update the latest challenge word in the challenge word combination to the newly generated challenge word. At this time, the (N + 1)-th authentication can be regarded as completed.

[0097] If the latest challenge word obtained by the service client as of the (N + 1)-th authentication matches the non-latest challenge word in the challenge word combination, it indicates that the service client has not received the latest challenge word newly generated by the service platform. At this time, the service platform can continue to send the latest challenge word in the challenge word combination to the service client. At this time, the (N + 1)-th authentication can be regarded as completed.

[0098] Refer to Figure 4 , Figure 4It is a schematic diagram of the process for verifying challenge words. After the business platform obtains the parsing results of the (N + 1)-th authentication parameters and the challenge word parsing results, it can perform an existence check on the parameters to determine whether the parsing results of the (N + 1)-th authentication parameters and the challenge word parsing results include all the specified parameters. If one of the parsing results does not include a certain specified parameter, an error result of "91000" can be returned. If both parsing results include all the specified parameters, an existence check on the terminal can be performed to determine whether the terminal unique identifier included in the parsing result of the (N + 1)-th authentication parameters is the same as the terminal unique identifier included in the challenge word parsing result. If the terminal unique identifiers are not the same, an error result of "91021" can be returned. If the terminal unique identifiers are the same, a card number existence check can be performed to determine whether the card number included in the parsing result of the (N + 1)-th authentication parameters is the same as the card number included in the challenge word parsing result. If the card numbers are not the same, an error result of "91042" can be returned. If the card numbers are the same, a card batch existence check can be performed to determine whether the card batch included in the parsing result of the (N + 1)-th authentication parameters is the same as the card batch included in the challenge word parsing result. If the card batches are not the same, an error result of "91055" can be returned. If the card batches are the same, a card password correctness check can be performed to determine whether the card password included in the parsing result of the (N + 1)-th authentication parameters is the same as the card password included in the challenge word parsing result. If the card passwords are not the same, an error result of "91042" can be returned. If the card passwords are the same, an existence check on the terminal activation record can be performed to determine whether the terminal activation record information included in the parsing result of the (N + 1)-th authentication parameters is the same as the terminal activation record information included in the challenge word parsing result. If the terminal activation record information is not the same, an error result of "91042" can be returned. If the terminal activation record information is the same, the verification passes, and it is determined that the user basic information included in the parsing result of the (N + 1)-th authentication parameters matches the user basic information included in the challenge word parsing result. It can be understood that when the above error result is returned, the user basic information included in the parsing result of the (N + 1)-th authentication parameters does not match the user basic information included in the challenge word parsing result.

[0099] This embodiment adopts an improved AES encryption algorithm and a multi-level challenge word update authentication method. It is encrypted by a secret key agreed upon by both the client and the business platform, and the terminal unique identifier and the user's access address are added to the encryption element to ensure that the authentication request is the terminal bound to the current user, so as to ensure the security of the request data, improve the security of user information and terminal information in a public network environment, and prevent user and terminal information leakage due to interface secret key leakage; at the same time, the stability of the authentication API is maintained through multi-level challenge word updates to avoid user activation and authentication failures due to problems with a single challenge word. By updating the challenge word generated at multiple levels and utilizing the security of challenge word information verification, the stability and security of the system during the authentication process are guaranteed, and the scenario of user and terminal information leakage due to business platform problems is avoided.

[0100] This embodiment has the following advantages:

[0101] (1) When the business client initiates an authentication request, the corresponding challenge word can be sent to the business platform. The business platform determines whether challenge word verification is required. If challenge word verification is not required, the business platform directly encrypts and returns the unknown terminal information and user information to the business client. If challenge word verification is required, the information in the authentication parameters and the information in the challenge word are compared according to the challenge word rules determined by both parties. If the information is inconsistent, the challenge word verification failure is directly returned, thereby ensuring the security of user information and account information.

[0102] (2) Use a multi-level verification method to avoid scenarios where activation fails due to mismatched challenge words. By retaining the challenge words generated for the last two times, the consistency of the challenge words obtained by both the business platform and the business client is ensured in all cases.

[0103] (3) By adding multi-level challenge word update rules, when the business platform detects that the challenge word brought by the business client is inconsistent with the local one, the business platform will regenerate and return a new challenge word to the business client according to the rules for generating challenge words. As a result, there will be no situation where the two challenge words are inconsistent when the business client initiates an authentication request next time. This not only reduces the overhead in the network, but also does not affect the stability and response speed of the system due to the challenge word update problem.

[0104] (4) The security of user information and challenge words is improved through the improved AES encryption algorithm. The terminal unique identifier and the user's access address are added to the traditional AES encryption method. The legitimacy of user access is guaranteed by verifying the user's access address and terminal unique identifier, thereby ensuring the security of user information. This not only ensures that user information is not exposed on the public Internet, but also ensures the legitimacy of user access.

[0105] This embodiment can solve the problem that when the requested secret key is leaked, user information and terminal information will be exposed on the public network, resulting in the leakage of user information and terminal information; it can also solve the problem that in a single challenge word update rule, there is a certain probability that the challenge word does not match, resulting in user authentication failure; it can also reduce the risk of user activation failure caused by the risk of verification failure of a single challenge word, thereby reducing the risk of the service client frequently authenticating to the service platform; it can also reduce the risk of user information being exposed on the public network due to the plaintext transmission of the challenge word.

[0106] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.

[0107] Based on the same inventive concept, an embodiment of the present application further provides a service authentication device for implementing the service authentication method involved above. The solution for solving problems provided by this device is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the service authentication device provided below can refer to the limitations on the service authentication method in the above text, and will not be repeated here.

[0108] In one embodiment, as Figure 5 shown, a service authentication device is provided, including:

[0109] A challenge word processing module 501, for the previous authentication in two adjacent authentications. After the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches the latest challenge word in the challenge word combination, the generated new challenge word is sent to the service client;

[0110] The challenge word processing module 501 is further configured to, after the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches a non-latest challenge word in the challenge word combination, send the latest challenge word in the challenge word combination to the service client;

[0111] The authentication request processing module 502 is configured to, for the subsequent authentication in the adjacent two authentications, obtain the encrypted subsequent authentication parameters and the latest challenge word obtained by the service client as of the subsequent authentication according to the subsequent authentication request initiated by the service client after the user logs in.

[0112] The challenge word verification module 503 is configured to, after the verification of the subsequent authentication parameter parsing result obtained according to the encrypted subsequent authentication parameters passes, if challenge word verification is required, parse the latest challenge word obtained by the service client as of the subsequent authentication to obtain a challenge word parsing result.

[0113] The authentication result processing module 504 is configured to determine that the subsequent authentication for the service client passes if the subsequent authentication parameter parsing result matches the challenge word parsing result.

[0114] In one embodiment, the non-latest challenge word in the challenge word combination is the challenge word generated last time before the latest challenge word in the challenge word combination.

[0115] In one embodiment, the apparatus further includes a challenge word maintenance module, configured to:

[0116] After generating a new challenge word, update the non-latest challenge word in the challenge word combination to the latest challenge word, and update the latest challenge word in the challenge word combination to the generated new challenge word.

[0117] In one embodiment, the apparatus further includes a decryption module, configured to:

[0118] Obtain the secret key agreed upon by the service client and the local end; according to the secret key, decrypt the encrypted subsequent authentication parameters to obtain the plaintext subsequent authentication parameters; parse the plaintext subsequent authentication parameters to obtain a subsequent authentication parameter parsing result; the subsequent authentication parameter parsing result includes the unique identifier of the terminal where the service client is located and the user's access address.

[0119] In one embodiment, the apparatus further includes a verification judgment module, configured to:

[0120] Judge whether the service client is a client of a third-party institution outside the institution where the local end is located; if so, determine that challenge word verification is required.

[0121] In one embodiment, the authentication result processing module 504 is further configured to:

[0122] After the verification of the subsequent authentication parameter parsing result obtained according to the encrypted subsequent authentication parameters passes, if challenge word verification is not required, determine that the subsequent authentication for the service client passes.

[0123] Each module in the above-mentioned service authentication device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor in the service platform in hardware form or independent of it, or stored in the memory in the service platform in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0124] In an exemplary embodiment, a service platform is provided, and its internal structure diagram can be as Figure 6 shown. The service platform includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the service platform is used to provide computing and control capabilities. The memory of the service platform includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the service platform is used to store the data involved in the above method. The input / output interface of the service platform is used to exchange information between the processor and external devices. The communication interface of the service platform is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a service authentication method.

[0125] Those skilled in the art can understand that Figure 6 the structure shown in [the figure] is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the service platform to which the solution of this application is applied. The specific service platform may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0126] In one embodiment, a service platform is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps in each of the above method embodiments.

[0127] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps in each of the above method embodiments.

[0128] In one embodiment, a computer program product is provided, on which a computer program is stored, and the computer program is executed by the processor to implement the steps in each of the above method embodiments.

[0129] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0130] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0131] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.

[0132] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.

Claims

1. A service authentication method, characterized in that: The method comprises: For the previous authentication of two adjacent authentications, after the previous authentication is passed, if the latest challenge word obtained by the service client up to the previous authentication matches the latest challenge word in the challenge word combination, then the generated new challenge word is sent to the service client; After the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches the non-latest challenge word in the challenge word combination, the latest challenge word in the challenge word combination is sent to the service client; For the latter authentication of the two adjacent authentications, according to the latter authentication request initiated by the service client after the user logs in, the encrypted latter authentication parameter and the latest challenge word obtained by the service client up to the time of the latter authentication are obtained; After the subsequent authentication parameter parsing result obtained according to the encrypted subsequent authentication parameter passes the verification, if a challenge word verification is required, the latest challenge word obtained by the service client as of the subsequent authentication is parsed to obtain a challenge word parsing result; If the subsequent authentication parameter parsing result matches the challenge word parsing result, it is determined that the subsequent authentication for the service client is passed.

2. The method according to claim 1, characterized in that The non-latest challenge word in the challenge word combination is the challenge word generated last time before the latest challenge word in the challenge word combination.

3. The method according to claim 1 or 2, characterized in that: After generating the new challenge word, the method further includes: The non-latest challenge word in the challenge word combination is updated to the latest challenge word, and the latest challenge word in the challenge word combination is updated to the generated new challenge word.

4. The method according to claim 1, characterized in that The method further comprises: Get the secret key agreed upon by the business client and this end; Decrypting the encrypted secondary authentication parameter according to the secret key to obtain the plaintext secondary authentication parameter; The plain text post-authentication parameter is parsed to obtain a post-authentication parameter parsing result; the post-authentication parameter parsing result includes a terminal unique identifier where the service client is located and an access address of the user.

5. The method according to claim 1, characterized in that The method further comprises: Determine whether the service client is a client of a third-party organization other than the organization where the terminal is located; If yes, it is determined that a challenge word check is required.

6. The method according to claim 1, characterized in that After the subsequent authentication parameter parsing result obtained according to the encrypted subsequent authentication parameter passes verification, the method further includes: If the challenge word verification is not required, it is determined that the subsequent authentication for the service client is passed.

7. A service authentication device, characterized in that: The device comprises: A challenge word processing module is used for sending a generated new challenge word to the business client for the previous authentication of two adjacent authentications, if the latest challenge word obtained by the business client up to the previous authentication matches the latest challenge word in the challenge word combination after the previous authentication is passed; The challenge word processing module is further used for, after the previous authentication is passed, if the latest challenge word obtained by the service client as of the previous authentication matches the non-latest challenge word in the challenge word combination, sending the latest challenge word in the challenge word combination to the service client; An authentication request processing module, for obtaining, for a later authentication of the two adjacent authentications, encrypted later authentication parameters and a latest challenge word obtained by the service client up to the time of the later authentication according to a later authentication request initiated by the service client after the user logs in; A challenge word verification module, for parsing the latest challenge word obtained by the service client up to the next authentication to obtain a challenge word parsing result if challenge word verification is required after the next authentication parameter parsing result obtained according to the encrypted next authentication parameter has been verified; The authentication result processing module is used to determine that the subsequent authentication for the service client is passed if the subsequent authentication parameter parsing result matches the challenge word parsing result.

8. A service platform, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.