Cross-device login authentication method and system based on SIM (Subscriber Identity Module) card

Through the cross-device login authentication method based on SIM card, the Internet application login process on the PC and PAD side is simplified, the problems of poor user experience and security risks are solved, and convenient and secure cross-device login is achieved.

CN120302285APending Publication Date: 2025-07-11CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510335864.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, the Internet application login method of PC clients and PAD clients is complex and has security risks, poor user experience, and cannot effectively solve the problems of operational convenience and security.

Method used

The cross-device login authentication method based on SIM card is adopted, and the encrypted information is pushed to the SIM card through the SIM card authentication server. The generated card pop-up window is displayed on the second device. The user confirms or enters information on the card pop-up window for authorization and authentication to complete cross-device login.

Benefits of technology

It simplifies the cross-device login process, improves the user experience, realizes a flexible security control mechanism, enhances the convenience and security of login, and prevents information tampering and impersonation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120302285A_ABST
    Figure CN120302285A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of mobile communication. The invention provides a cross-device login authentication method and system based on an SIM (Subscriber Identity Module) card. The method comprises the steps that when a user logs in an application on first equipment, application login information is sent to an application server side, an SIM card is called for authentication, and after an authentication server side encrypts authorization text information, the authorization text information is pushed to the SIM card through a signaling channel of an operation service party; after the authorization text information is decrypted, the generated card popup window is displayed on second equipment, and authorization authentication is carried out by clicking a confirmation button on the card popup window or manually inputting information; and when the authentication is passed, the authentication server sends authentication passing information to the application server, and login is completed through the application client of the first device. According to the method and the device, the login process of a user when the user logs in the Internet application at terminal equipment such as a PC terminal and a PAD terminal is simplified, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of mobile communication, and provides a cross-device login authentication method and system based on a SIM card. Background Art

[0002] With the in-depth development of mobile Internet applications, more and more applications have established ecological systems adapted to other types of terminal devices, such as PC clients, PAD clients, etc. The login methods of applications on different terminals are more or less the same. Currently, for Internet application clients on PC clients and PAD clients, their login methods not only have complex processes, but also have information security problems such as account password collision attacks and verification code leakage. Moreover, due to the lack of a security authentication mechanism, users need to repeatedly perform cross-device operations to complete the login, which greatly affects the user login experience.

[0003] Currently, the login scenarios of applications such as PC clients and PAD clients mainly have the following problems: poor user experience. When users log in, they often need to operate simultaneously on the mobile side. The operation steps are complex and the operation time is long, which affects the user experience. For example, when using the account password login method, users need to remember the passwords of each account. When using the SMS verification code login method, users need to wait to receive the SMS and manually input and fill in the verification code. These login methods will obviously cause inconvenience to users; information security risks. When using terminal device applications on PC clients and PAD clients, due to the lack of a physical SIM card for identity authentication, the login process will be more complex. Using methods such as account passwords, SMS verification codes, and biometric recognition, these login methods have security risks such as account password collision attacks, verification code hijacking, and face attacks.

[0004] In addition, in the prior art, when users log in to Internet applications on terminal devices such as PC terminals and PAD terminals, the login process is cumbersome and the operation is complex, and there are serious security problems. Although the existing methods have improved a certain degree of security, they still fail to effectively solve the problem of operation convenience.

[0005] Therefore, it is necessary to provide a new cross-device login authentication method and system based on a SIM card to solve the above problems. Summary of the Invention

[0006] The present invention provides a cross-device login authentication method and system based on a SIM card to solve the problem that in the prior art, on a mobile phone, it is necessary to rely on each APP and application client, and each APP on the mobile phone must be in a logged-in and running state to allow cross-device login authentication or login confirmation. This results in a cumbersome login process, complex operations, and serious security problems such as account password collision attacks, verification code hijacking, and face attacks when users log in to Internet applications on terminal devices such as PC terminals and PAD terminals. The technical problems to be solved by the present invention are achieved through the following technical solutions.

[0007] In the first aspect of the present invention, a cross-device login authentication method based on a SIM card is proposed. The cross-device login authentication method includes: when a user logs in to an application on a first device, sending the login application information to an application server and invoking SIM card authentication. After encrypting the authorization text information, the authentication server pushes it to the SIM card through the signaling channel of the operation service provider. After decrypting the authorization text information, the generated card pop-up window is displayed on a second device, and a confirmation button is clicked on the card pop-up window or information can be manually input to perform authorization authentication. When the authentication is passed, the authentication server sends the authentication passed information to the application server, and the login is completed through the application client of the first device. In the second aspect of the present invention, a cross-device login authentication system based on a SIM card is proposed. It executes the cross-device login authentication method based on a SIM card described in the first aspect of the present invention. The cross-device login authentication system includes: a login request module, which is used for when a user logs in to an application on a first device, sending the login application information to an application server and invoking SIM card authentication. After encrypting the authorization text information, the authentication server pushes it to the SIM card through the signaling channel of the operation service provider. A pop-up input module, which is used for after decrypting the authorization text information, displaying the generated card pop-up window on a second device, and clicking a confirmation button on the card pop-up window or manually inputting information to perform authorization authentication. An authentication determination module, when the authentication is passed, the authentication server sends the authentication passed information to the application server, and the login is completed through the application client of the first device.

[0008] In the third aspect of the present invention, an electronic device is provided, including: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the cross-device login authentication method based on a SIM card described in the first aspect of the present invention.

[0009] In the fourth aspect of the present invention, a computer-readable medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it implements the cross-device login authentication method based on a SIM card described in the first aspect of the present invention.

[0010] The embodiments of the present invention have the following advantages: Compared with the prior art, through the cross-device login authentication method based on a SIM card, as long as the user's mobile phone inserts a SIM card and the mobile phone is in the boot state, the cross-device application login authentication can be completed, without installing various application clients on the mobile phone, effectively simplifying the login process when the user logs in to Internet applications on terminal devices such as the PC side and the PAD side, and thus improving the user experience.

[0011] In addition, for application logins with different security levels in the present invention, users can perform different login authentication operations, which can not only implement a flexible hierarchical security control mechanism but also ensure the convenience of cross-device login. In addition, the present invention has a wide range of applications. The second device receives data messages based on the SIM card to implement pop-up window authentication, which is not restricted by the communication distance or the operating system of the first device and can be adapted to various types of clients (PC clients, PAD clients, WEB clients, mobile clients) of Internet applications.

[0012] In addition, the method of the present invention significantly improves security. By using the asymmetric encryption algorithm SM4, it ensures that the key information for users to log in to Internet applications cannot be tampered with or misused. With multiple optional login methods and more application login scenarios with security requirements, users can customize the PIN code. When logging in and confirming on a mobile phone, the cross-device login can only be completed after the PIN code verification passes, further improving security and avoiding potential risks caused by the loss of the user's mobile device. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a flowchart of the steps of an example of the cross-device login authentication method based on the SIM card of the present invention; Figure 2 is a schematic flowchart of the cross-device login authentication method based on the SIM card of the present invention from another angle; Figure 3 is a schematic diagram of an example of the login page of the first device in the cross-device login authentication method based on the SIM card of the present invention; Figure 4 is a schematic diagram of an example of the card pop-up window of the second device in the cross-device login authentication method based on the SIM card of the present invention; Figure 5 is a block diagram of the structure of the cross-device login authentication system based on the SIM card of the present invention; Figure 6 is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention; Figure 7 is a schematic diagram of the structure of a computer-readable medium according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0014] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.

[0015] In view of the above problems, the present invention proposes a cross-device login authentication method based on a SIM card. The present invention provides an application login authentication method for cross-device applications such as PC clients, PAD clients, and WEB clients. In this method, when a user logs in to an application on a first device, the login application information is sent to the application server, and the SIM card authentication is called. After encrypting the authorization text information, the authentication server pushes it to the SIM card through the signaling channel of the operation service provider; after decrypting the authorization text information, the generated card pop-up window is displayed on the second device, and the confirmation button is clicked on the card pop-up window or information can be manually input to perform authorization authentication; when the authentication is passed, the authentication server sends the authentication passed information to the application server, and the login is completed through the application client of the first device. Through the cross-device login authentication method based on the SIM card, as long as the user's mobile phone inserts the SIM card and the mobile phone is in the boot state, the cross-device application login authentication can be completed without installing various application clients on the mobile phone, effectively simplifying the login process when the user logs in to Internet applications on terminal devices such as the PC side and the PAD side, and thus improving the user experience.

[0016] In addition, for the application logins with different security levels in the present invention, the user can perform different login authentication operations, which can not only implement a flexible hierarchical security control mechanism, but also ensure the convenience of cross-device login.

[0017] Embodiment 1 The following will refer to Figure 1 、 Figure 2 、 Figure 3 and Figure 4 to describe the content of the present invention in detail.

[0018] Figure 1 is a step flowchart of an example of the cross-device login authentication method based on a SIM card of the present invention. Figure 2 is a schematic flowchart of the cross-device login authentication method based on a SIM card of the present invention from another angle.

[0019] Referring to Figure 1 and Figure 2 In step S101, when a user logs in to an application on a first device, the login application information is sent to the application server, and the SIM card authentication is called. After encrypting the authorization text information, the authentication server pushes it to the SIM card through the signaling channel of the operation service provider.

[0020] As Figure 2 shown, in a specific application example, it specifically includes a client, a first device (such as a computer, etc.), a second device (or a mobile device, such as a mobile phone, a tablet, etc.), an application server, and an authentication server.

[0021] In Figure 2In the example, when the user logs in to a certain application on the first device, the user can select the login method on the login page. Specifically, select the method of logging in to the application using the SIM card (specifically, such as the two options on the login page shown in Figure 3 ). When the application server corresponding to the application receives the login application request, it calls the SIM card authentication of the authentication server according to the user's mobile phone number.

[0022] Specifically, the SIM card and each application protocol their respective authorization text information. The authentication server encrypts the authorization text information formed based on, for example, the unique identifier of the SIM card to generate a login confirmation message. Among them, the authorization information includes the display text content and business identifier for logging in on the business side. The display text content is used to guide the user to confirm on the first device, and the business identifier is used to correspond to the application server. The business identifier can be composed of the enterprise name, enterprise abbreviation, and application name.

[0023] When calling the SIM card authentication, a card pop-up window is sent to the user's mobile phone to determine whether to use the SIM card authentication (specifically, see Figure 4 ). When the user clicks OK, the SIM card authentication is used for authentication.

[0024] For the encryption of the authorization text information, it includes the key generation rule for SIM card authentication. Specifically, the SIM card uses, for example, the sha-256 algorithm to take the specified position and specified number of bytes (such as the first 16, the first 10, 10 in the middle position, 8 at the end, etc.) of the ICCID unique identifier in the card as the uplink data encryption key K1 to encrypt the authorization text, and takes the specified position and specified number of bytes as the decryption key K2 for receiving the authorization text information. The specified position includes the front part, the middle part, and the end part. The specified number is 8 to 20 bits.

[0025] For example, the encryption example is as follows. Among them, take the first 16 bytes as the uplink data encryption key K1; take the last 16 bytes as the decryption key K2 for receiving the authorization text information: ICCID: 89860122811000123456, the result of SHA-256 encryption is: d00fb879f2d21127c31ae****5658feb469e6961d3572d8240e66f Therefore, K1 = d00fb879f2d21127c31ae690a7f406e7 K2 = 3e25658feb469e6961d3572d8240e66f.

[0026] It should be noted that the SIM cards of various communication operators are a type of CPU card, which has key generation, key-based encryption and decryption capabilities, and computing capabilities. Each SIM card has a unique ICCID in the card, which is associated with the mobile phone number.

[0027] Encryption calculations can also be performed based on the application identifier and the unique ICCID identifier in the card.

[0028] Next, the authentication server encrypts the authorization text information and pushes it to the SIM card through the signaling channel of the operator service provider. The SIM card is pre-installed with a SIM card authentication pop-up card application. The SIM card authentication pop-up card application (hereinafter referred to as the card application) is used to receive remote instructions from the authentication server and automatically execute the data SMS content. It also has functions such as GSM 03.48 data SMS processing and data content encryption and decryption.

[0029] The specific process of the card application pop-up window implemented by the pop-up card application for SIM card authentication includes the following steps: The authentication server encrypts the authorization text information and pushes it to the SIM card through the signaling channel of the operator service provider.

[0030] The SIM card is pre-installed with a SIM card authentication pop-up card application to perform the authentication process of the card application pop-up window, which specifically includes the following steps: Step S201: the authentication server remotely sends a command to trigger the pop-up card application to automatically execute and send data SMS content, and the sent data SMS content includes encrypted authorization information.

[0031] In a specific implementation, the authentication server sends a data SMS and triggers the pop-up card application to automatically execute the sent data SMS content. The sent data SMS content includes K2 encrypted authorization information. After decryption, the card application displays the pop-up display content to the user.

[0032] Step S202: the card application sends the decrypted pop-up window display content to the corresponding user, the user clicks to confirm, and the encrypted data is sent back to the authentication server.

[0033] Specifically, the user confirms that the displayed content is the login content and clicks to confirm. The card application encrypts the data with K1 and then transmits it back to the authentication server. Step S203: The authentication server decrypts the uplink data, matches the business party identifier, and verifies the user's secondary confirmation to implement login.

[0034] Specifically, the authentication server decrypts the uplink data to match it with the business party identifier and verifies the user's secondary confirmation to enable login.

[0035] Specifically, the above encryption process uses the SM4 algorithm.

[0036] It should be noted that the above is only an optional example for illustration and should not be construed as a limitation to the present invention.

[0037] Next, in step S102, after decrypting the authorized text information, the generated card pop-up window is displayed on the second device, and the confirmation button is clicked on the card pop-up window or information can be manually input to perform authorization authentication.

[0038] Specifically, the second device (such as the user's mobile phone) decrypts the authorized information according to the decryption key K2 determined above. Using the service name in the decrypted authorized text information, it is presented to the user, and the user is asked to confirm whether the login address is the same. When the user clicks OK, the card application encrypts and sends back the service identifier in the authorized information to the authentication server. The authentication server decrypts the encrypted service identifier and compares it with the application server. After passing, it notifies the service provider to perform the login.

[0039] The login information is sent to the second device in the form of a card pop-up window according to the user's mobile phone number for inputting login information (such as Figure 2 the "user input information" shown).

[0040] In a specific embodiment, the user manually inputs, for example, a PIN code or a custom password on the card pop-up window, and returns the manually input PIN code or custom password to the authentication server. The authentication server determines whether it passes the verification according to the PIN code or custom password to perform authorization authentication (such as Figure 2 the "verifying user input information" shown).

[0041] In another specific embodiment, the user clicks the confirmation button on the card pop-up window, and returns the confirmation information to the authentication server. The authentication server determines whether it passes the verification according to the PIN code or custom password to perform authorization authentication.

[0042] It should be noted that the above is only an optional example for illustration and should not be construed as a limitation to the present invention.

[0043] Next, in step S103, when the authentication is passed, the authentication server sends the authentication passed information to the application server and completes the login through the application client of the first device.

[0044] When the verification is passed (i.e., the authentication is successful), the result of the passed verification is returned to the application server, and then the application server allows the user to log in to a certain application on the first device (i.e., complete the login through the application client on the first device), thus completing the login. Through the cross-device login authentication method based on the SIM card, as long as the user's mobile phone inserts the SIM card and the mobile phone is in the boot state, the cross-device application login authentication can be completed, without installing various application clients on the mobile phone.

[0045] It should be noted that the above is only described as an optional example and should not be construed as a limitation to the present invention.

[0046] Compared with the prior art, through the cross-device login authentication method based on the SIM card, as long as the user's mobile phone inserts the SIM card and the mobile phone is in the boot state, the cross-device application login authentication can be completed, without installing various application clients on the mobile phone, effectively simplifying the login process when the user logs in to Internet applications on terminal devices such as the PC side and the PAD side, and thus improving the user experience.

[0047] In addition, for the application logins with different security levels in the present invention, the user can perform different login authentication operations, which can not only implement a flexible hierarchical security control mechanism but also ensure the convenience of cross-device login. In addition, the present invention has a wide range of applications, is not limited by the communication distance and the operating system of the first device, and can be adapted to various clients (PC clients, PAD clients, WEB clients, mobile clients) of Internet applications.

[0048] In addition, the method of the present invention significantly improves security. By using the asymmetric encryption algorithm SM4, it is ensured that the key information for the user to log in to Internet applications cannot be tampered with or misused. With multiple optional login methods and more application login scenarios with security requirements, the user can customize the PIN code. When logging in and confirming on the mobile phone, it is necessary to pass the PIN code verification to complete the cross-device login, further improving security and avoiding potential risks caused by the loss of the user's mobile device.

[0049] Embodiment 2 The following is an embodiment of the system of the present invention, which can be used to execute the method embodiment of the present invention. For the details not disclosed in the system embodiment of the present invention, please refer to the method embodiment of the present invention.

[0050] Figure 5 It is a schematic structural diagram of an example of the cross-device login authentication system based on the SIM card according to the present invention. The cross-device login authentication system will be described below with reference to Figure 5 , and the cross-device login authentication system executes the cross-device login authentication method based on the SIM card described in Embodiment 1 of the present invention.

[0051] like Figure 5 As shown, the cross-device login authentication system 300 includes a login request module 310 , a pop-up window input module 320 , and an authentication determination module 330 .

[0052] In a specific implementation, the login request module 310 is used to send the login application information to the application server when the user logs in to the application on the first device, and call the SIM card authentication. The authentication server encrypts the authorization text information and pushes it to the SIM card through the signaling channel of the operator service provider. The pop-up window input module 320 is used to display the generated card pop-up window on the second device after decrypting the authorization text information, and click the confirmation button on the card pop-up window or manually enter information to perform authorization authentication. The authentication confirmation module 330 sends the authentication pass information to the application server when the authentication is passed, and completes the login through the application client of the first device.

[0053] According to an optional implementation manner, the SIM card is pre-installed with a pop-up card application for SIM card authentication to perform the authentication process for user login, which specifically includes the following steps: Step S201: When a user logs into an application, the authentication server remotely sends a command to the user's device, triggering a pop-up card application to automatically execute the sent data SMS content, and the sent data SMS content includes encrypted authorization information.

[0054] Step S202: After the card application decrypts the data SMS content, it displays the content on the user's device through a pop-up card application. The user clicks to confirm, and the encrypted data is sent back to the authentication server.

[0055] Step S203: The authentication server decrypts the uplink data, matches the business party identifier, and verifies the user's secondary confirmation to implement login.

[0056] According to an optional implementation, the encryption of the authorization text information includes a key generation rule for SIM card authentication, wherein the SIM card uses the SHA-256 algorithm to obtain a specified position and a specified number of bytes of the ICCID unique identifier in the card as the uplink data encryption key K1, encrypts the authorization text, and obtains a specified position and a specified number of bytes as the decryption key K2 for receiving the authorization text information.

[0057] The designated position includes the front part, the middle part, and the tail part, and the designated number is 8 to 20 digits.

[0058] According to an optional implementation manner, the service name in the decrypted authorized text information is used to show the user to confirm whether the login address is consistent. After the user clicks OK, the card application encrypts the service identifier in the authorization information and sends it back to the authentication server side. The authentication server decrypts it and performs corresponding operations with the service provider, and notifies the service provider to perform the login.

[0059] The login information is sent to the second device in the form of a card pop-up window according to the user's mobile phone number for inputting the login information.

[0060] The user manually enters the PIN code or the custom password on the card pop-up window, and returns the PIN code or the custom password manually entered by the user to the authentication server. The authentication server determines whether the verification is passed according to the PIN code or the custom password for authorization authentication.

[0061] The login information is sent to the second device in the form of a card pop-up window according to the user's mobile phone number for inputting the login information; the user clicks the confirmation button on the card pop-up window, and returns the confirmation information to the authentication server. The authentication server determines whether the verification is passed according to the PIN code or the custom password for authorization authentication.

[0062] It should be noted that since Figure 5 the cross-device login authentication method executed by the cross-device login authentication system of Figure 1 is substantially the same as the cross-device login authentication method in the example of

[0063] Compared with the prior art, the present invention, through the cross-device login authentication method based on the SIM card, as long as the user's mobile phone inserts the SIM card and the mobile phone is in the boot state, the cross-device application login authentication can be completed without installing various application clients on the mobile phone, effectively simplifying the login process when the user logs in to Internet applications on terminal devices such as the PC side and the PAD side, and thus improving the user experience.

[0064] In addition, for the application logins of different security levels in the present invention, the user can perform different login authentication operations, which can not only implement a flexible hierarchical security control mechanism, but also ensure the convenience of cross-device login. In addition, the application of the present invention is extensive, not limited by the communication distance and the operating system of the first device, and can be adapted to various clients of Internet applications (PC clients, PAD clients, WEB clients, mobile clients).

[0065] In addition, the method of the present invention significantly improves security. By adopting the asymmetric encryption algorithm SM4, it ensures that the key information for users to log in to Internet applications cannot be tampered with or misused. There are multiple optional login methods, which are applicable to login scenarios with more security requirements. Users can customize the setting of the PIN code. When logging in and confirming on a mobile phone, the cross-device login can only be completed after the PIN code verification passes, further enhancing security and avoiding potential risks caused by the loss of the user's mobile device, etc.

[0066] Figure 6 It is a schematic structural diagram of an embodiment of an electronic device according to the present invention.

[0067] As Figure 6 shown, the electronic device is presented in the form of a general-purpose computing device. The processor can be one or multiple and work collaboratively. The present invention does not exclude distributed processing, that is, the processors can be dispersed in different physical devices. The electronic device of the present invention is not limited to a single entity, but can also be the sum of multiple physical devices.

[0068] The memory stores computer-executable programs, usually machine-readable codes. The computer-readable programs can be executed by the processor so that the electronic device can execute the method of the present invention or at least some of the steps in the method.

[0069] The memory includes volatile memory, such as a random access storage unit (RAM) and / or a cache storage unit, and can also be non-volatile memory, such as a read-only storage unit (ROM).

[0070] Optionally, in this embodiment, the electronic device further includes an I / O interface, which is used for data exchange between the electronic device and external devices. The I / O interface can represent one or more of several bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in multiple bus structures.

[0071] It should be understood that Figure 6 the electronic device shown is only an example of the present invention. The electronic device of the present invention may further include elements or components not shown in the above example. For example, some electronic devices also include a display unit such as a display screen, and some electronic devices also include human-computer interaction elements, such as buttons, keyboards, etc. As long as the electronic device can execute the computer-readable program in the memory to implement the method of the present invention or at least some of the steps of the method, it can be considered as the electronic device covered by the present invention.

[0072] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, as Figure 7 shown, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several commands to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiments of the present invention.

[0073] The software product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0074] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with a command execution system, apparatus, or device. The program code contained on the readable storage medium can be transmitted by any appropriate medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.

[0075] Program code for performing the operations of the present invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or, it can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0076] The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by a device, the computer-readable medium implements the data interaction method of the present disclosure.

[0077] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are uniquely different from this embodiment. The modules of the above embodiments can be combined into one module, or further split into multiple sub-modules.

[0078] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several commands to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present invention.

[0079] It should be noted that the above detailed description is exemplary and is intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present application belongs.

[0080] In the foregoing detailed description, reference has been made to the accompanying drawings, which form a part hereof. In the drawings, like numerals typically identify like components, unless the context indicates otherwise. The illustrated embodiments described in the detailed description, the drawings, and the claims are not meant to be limiting. Other embodiments may be used and other changes may be made without departing from the spirit or scope of the subject matter presented herein.

[0081] The foregoing are only preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A cross-device login authentication method based on a SIM card, characterized in that, The cross-device login authentication method includes the following steps: When a user logs in to an application on a first device, the login application information is sent to the application server, and the SIM card authentication is invoked. After encrypting the authorization text information, the authentication server pushes it to the SIM card through the signaling channel of the operation service provider. After decrypting the authorization text information, the generated card pop-up window is displayed on the second device, and the user clicks the confirmation button on the card pop-up window or manually enters information to perform authorization authentication. When the authentication is successful, the authentication server sends the authentication success information to the application server, and the login is completed through the application client on the first device.

2. The cross-device login authentication method according to claim 1, wherein The process of the authentication server encrypting the authorization text information and pushing it to the SIM card through the signaling channel of the operation service provider includes: The SIM card is pre-installed with a pop-up card application for SIM card authentication to carry out the authentication process of user login, which specifically includes the following steps: Step S201: When the user logs in to the application, the authentication server remotely sends an instruction to the user device to trigger the pop-up card application, and automatically executes the data SMS content to be sent. The data SMS content to be sent includes encrypted authorization information. Step S202: After decrypting the data SMS content, the card application displays the content on the user device through the pop-up card application. The user clicks to confirm and sends the encrypted data back to the authentication server. Step S203: The authentication server decrypts the uplink data, matches the business party identifier, and verifies the user's secondary confirmation to achieve login.

3. The cross-device login authentication method according to claim 1, wherein It includes: Regarding the encryption of the authorization text information, it includes the key generation rule for SIM card authentication. Among them, The SIM card, based on the unique ICCID in the card, uses the sha-256 algorithm to take a specified number of bytes at a specified position of the unique ICCID in the card as the uplink data encryption key K1 to encrypt the authorization text, and takes a specified number of bytes at a specified position as the decryption key K2 for receiving the authorization text information.

4. The cross-device login authentication method according to claim 3, wherein, It includes: The specified position includes the front part, the middle part, and the tail part, and the specified number is 8 to 20 bits.

5. The cross-device login authentication method according to claim 1, wherein It includes: Using the service name in the decrypted authorization text information to show the user to confirm whether the login address is consistent. After the user clicks OK, the card application encrypts the service identifier in the authorization information and sends it back to the authentication server side. The authentication server decrypts and corresponds to the business party, and notifies the business party to perform the login.

6. The cross-device login authentication method according to claim 1, wherein It further includes Sending the login information to the second device in the form of a card pop-up window according to the user's mobile phone number for entering the login information; The user manually enters the PIN code or the custom password on the card pop-up window, and returns the manually entered PIN code or the custom password to the authentication server. The authentication server determines whether the verification is passed according to the PIN code or the custom password to perform authorization authentication.

7. The cross-device login authentication method according to claim 1, wherein It includes: Sending the login information to the second device in the form of a card pop-up window according to the user's mobile phone number for entering the login information; The user clicks the confirmation button on the card pop-up window, and returns the confirmation information to the authentication server. The authentication server determines whether the verification is passed according to the PIN code or the custom password to perform authorization authentication.

8. A cross-device login authentication system based on a SIM card, characterized in that, It implements the SIM card-based cross-device login authentication method according to any one of claims 1 to 7, and the cross-device login authentication system comprises: The login request module is used to send the login application information to the application server when the user logs in to the application on the first device, and call the SIM card authentication. The authentication server encrypts the authorization text information and pushes it to the SIM card through the signaling channel of the operator service provider; A pop-up window input module, used to display the generated card pop-up window on the second device after decrypting the authorization text information, and click a confirmation button on the card pop-up window or manually enter information to perform authorization authentication; Authentication confirmation module, when the authentication is passed, the authentication server sends the authentication pass information to the application server, and completes the login through the application client of the first device.

9. The cross-device login authentication system according to claim 8, wherein include: The authentication server encrypts the authorization text information and pushes it to the SIM card through the signaling channel of the operator service provider; The SIM card is pre-installed with a SIM card authentication pop-up card application to perform the authentication process of the card application pop-up window, which specifically includes the following steps: Step S201: using the PP DOWNLOAD event to trigger the pop-up card application to automatically execute and send the data SMS content, and the sent data SMS content includes the encrypted authorization information; Step S202: The card application sends the decrypted pop-up window display content to the corresponding user, and the user clicks to confirm, and the encrypted data is sent back to the authentication server; Step S203: The authentication server decrypts the uplink data, matches the business party identifier, and verifies the user's secondary confirmation to implement login.

10. The cross-device login authentication system according to claim 8, wherein, include: For the encryption of authorized text information, including the key generation rules for SIM card authentication, The SIM card uses the SHA-256 algorithm to obtain the specified position and number of bytes of the ICCID unique identifier in the card as the uplink data encryption key K1, encrypts the authorization text, and obtains the specified position and number of bytes as the decryption key K2 for receiving the authorization text information.