Login verification method and electronic equipment
By obtaining the user's target login related information, judging the credibility of the login environment and selecting the corresponding verification method, the problem of balance between security and experience of the login verification method is solved, and flexible verification is achieved in different environments to ensure user security and experience.
Patent Information
- Application Number
- CN202510534170.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-08-15
AI Technical Summary
The existing login verification methods are difficult to balance between ensuring user information security and improving login experience. They cannot flexibly conduct login verification, resulting in high risk of user accounts being stolen and poor login experience.
By obtaining the user's target login related information, determine whether the login environment is a trusted login environment, and select the corresponding login verification method based on the judgment results, including not verifying or preset login verification, and use the preset account and IP address determination strategy to determine the credibility of the login environment.
There is no additional verification step required in a trusted login environment to ensure the user's login efficiency and experience; verify in an untrusted environment to effectively prevent security risks and ensure the user's login security.
Smart Images

Figure CN120498724A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of network security technology, and in particular to a login verification method and electronic device. Background Art
[0002] In the current information technology environment, account login verification is a critical component in ensuring system security and user data privacy. Traditional account and password verification methods, due to their simplicity, are widely used across various systems and platforms, such as office software and website services. However, this verification method carries significant security risks, posing a high risk of user account theft, leading to personal information leakage and data loss. Consequently, some systems have begun to introduce more complex login verification methods. While these methods improve account security to a certain extent, they also result in a poor user login experience.
[0003] Therefore, the login verification method in the related art cannot flexibly perform login verification on the basis of balancing the protection of user information security and improving the login experience as much as possible. Summary of the Invention
[0004] The embodiments of the present application provide a login verification method and an electronic device to solve the problem that the login verification method in the related art cannot flexibly perform login verification on the basis of balancing the protection of user information security and improving the login experience.
[0005] In a first aspect, an embodiment of the present application provides a login verification method, comprising:
[0006] Upon receiving a login request, obtaining target login related information of the user corresponding to the login request;
[0007] Determine whether the login environment is a trusted login environment based on target login related information;
[0008] Determine a matching login verification method based on the login environment determination result; wherein the login verification method is no login verification or at least one preset login verification;
[0009] Perform login verification according to the matching login verification method.
[0010] In the above-mentioned technical solution, after receiving a login request, the target login-related information of the corresponding user is obtained. This information is then used to determine whether the login environment is secure. Based on the determination of the login environment, whether login verification is performed is determined. Thus, in a trusted login environment, the user may not need to perform additional verification steps, ensuring login efficiency and a good login experience. In an untrusted environment, however, login verification is performed, effectively preventing potential security risks and ensuring user login security. Thus, the decision to perform login verification can be flexibly made based on the specific circumstances of the login environment, thereby ensuring both login security and a good login experience.
[0011] In one possible implementation, the target login related information includes: a target login account and a target login Internet Protocol IP address;
[0012] Determine whether the login environment is a trusted login environment based on the target login-related information, including:
[0013] Determine whether the target login account is a trusted login account according to the preset account judgment policy;
[0014] and / or, determining whether the target login IP address is a trusted login IP address according to a preset address determination policy;
[0015] Determine whether the login environment is a trusted login environment based on the determination result.
[0016] In the above technical solution, a preset account determination strategy is used to check the credibility of the target login account, and a preset address determination strategy is used to verify the credibility of the target login IP address. By comprehensively considering the target login account and the target login IP address, it is determined whether the login environment is safe. This can conveniently and quickly determine whether the login environment is safe, ensuring the security of the user's login and the smoothness of the login experience.
[0017] In one possible implementation, determining whether the target login account is a trusted login account according to a preset account determination policy includes:
[0018] Get the preset list of trusted accounts;
[0019] If the target login account is in the trusted account list, determine that the target login account is a trusted login account;
[0020] When the target login account is not in the trusted account list, the target login account is determined to be an untrusted login account.
[0021] In the above technical solution, the administrator can pre-set a list of trusted accounts. When determining whether a target login account is a trusted account, the administrator first obtains the trusted account list and compares the target login account with the login accounts on the trusted account list to determine whether the target login account is a trusted account. Thus, the preset trusted account list can quickly and accurately determine the credibility of the target login account.
[0022] In one possible implementation, determining whether the target login IP address is a trusted login IP address according to a preset address determination policy includes:
[0023] Get a preset list of trusted network domain names;
[0024] If the target login IP address is in the trusted network domain name list, determine that the target login IP address is a trusted login IP address;
[0025] When the target login IP address is not in the trusted network domain name list, the target login IP address is determined to be an untrusted login IP address.
[0026] In the above technical solution, the administrator can pre-set a list of trusted network domain names. When determining whether a target login IP address is a trusted login IP address, the administrator first obtains the list of trusted network domain names and compares the target login IP address with the login IP addresses in the list to determine whether the target login IP address is a trusted login IP address. Thus, the preset list of trusted network domain names allows the administrator to quickly and accurately determine the credibility of the target login IP address.
[0027] In one possible implementation, before obtaining the preset trusted network domain name list, the method further includes:
[0028] Determine whether the target login IP address is the same as the user's previous login IP address;
[0029] When the target login IP address is within the trusted network domain name list, determining that the target login IP address is a trusted login IP address includes:
[0030] When the target login IP address is in the trusted network domain name list and the target login IP address is different from the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0031] In the above technical solution, before obtaining the preset trusted network domain name list, it is first confirmed whether the target login IP address is the same as the previous login IP address. When the target login IP address is the same as the previous login IP address and the target login IP address is in the trusted network domain name list, then the target login IP address can be considered as a trusted login IP address.
[0032] In one possible implementation, the method further includes:
[0033] When the target login IP address is the same as the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0034] In the above technical solution, when the target login IP address is the same as the previous login IP address, it can be determined that the target login IP address is a trusted login IP address. Then there is no need to determine whether the target login IP address is in the trusted network domain name list, thereby simplifying the judgment process of the target login IP address.
[0035] In one possible implementation, determining whether the login environment is a trusted login environment according to the determination result includes:
[0036] If the target login account is a trusted login account and the target login IP address is a trusted login IP address, determining that the login environment is a trusted login environment;
[0037] When the target login account is an untrusted login account or the target login IP address is an untrusted login IP address, the login environment is determined to be an untrusted login environment.
[0038] In the above technical solution, if both the target login account and the target login IP address are credible, the login environment is considered secure. If either the target login account or the target login IP address is untrustworthy, the login environment is considered unsafe. Thus, through dual authentication of the target login account and the target login IP address, the security of the user login can be guaranteed.
[0039] In a possible implementation, the target login related information includes: target login time;
[0040] Determine whether the login environment is a trusted login environment based on the target login-related information, including:
[0041] Get the preset trusted login time period;
[0042] When the target login time is within the trusted login time period, determining the login environment as a trusted login environment;
[0043] When the target login time is not within the trusted login time period, the login environment is determined to be an untrusted login environment.
[0044] In the above technical solution, administrators can pre-set a trusted login time period. When determining whether a login environment is trustworthy, the target login time is compared with the preset trusted login time period to determine whether the current login environment is trustworthy. By adding login time as a factor in determining whether a login environment is trustworthy, the system enriches the methods for determining whether a login environment is trustworthy and better ensures user login security.
[0045] In a possible implementation, the target login related information includes: at least one of the target login account, the target login IP address, and the target login time;
[0046] Determine whether the login environment is a trusted login environment based on the target login-related information, including:
[0047] Inputting target login related information into the login environment prediction model trained to convergence;
[0048] A login environment prediction model trained to convergence is used to determine whether the login environment is a trusted login environment based on target login related information.
[0049] In the above technical solution, the target login related information includes the target login account, target login IP address and target login time. By inputting the target login related information into the trained and converged login environment prediction model, it is possible to quickly and accurately evaluate whether the login environment is trustworthy and ensure the user's login security.
[0050] In one possible implementation, determining a matching login verification method based on the login environment determination result includes:
[0051] If the login environment is determined to be a trusted login environment, the matching login verification method is determined to be no login verification;
[0052] When the login environment is determined to be an untrusted login environment, the matching login verification method is determined to be performing at least one preset login verification.
[0053] In the above technical solution, in a trusted login environment, users do not need to perform tedious login verification and can log in quickly, ensuring the user's login experience. In an untrusted login environment, users need to perform at least one login verification, which can effectively prevent malicious attacks or unauthorized access, thereby ensuring the user's login security.
[0054] In a possible implementation, when the login environment is determined to be an untrusted login environment, determining a matching login verification method is to perform at least one preset login verification, including:
[0055] If the login environment is determined to be an untrusted login environment, determine the target cause corresponding to the untrusted login environment;
[0056] A matching login verification method is determined according to the target reason, the matching login verification method is associated with the target reason, and the matching login verification method is to perform at least one preset login verification.
[0057] In the above technical solution, after determining that the login environment is untrusted, the target cause of the untrusted login environment is also determined, and the target cause is then used to determine the corresponding login verification method. This allows for flexible response to different login scenarios and corresponding login verification, better ensuring user login security.
[0058] In one possible implementation, before determining a matching login verification method based on the login environment determination result, the method further includes:
[0059] Configure and store the login verification method that matches the judgment result of each login environment.
[0060] In the above technical solution, before determining the matching login verification method based on the login environment judgment result, the administrator can configure and store the login verification method matching each login environment judgment result according to the actual application scenario to ensure the user's login security and login experience.
[0061] In one possible implementation, the method further includes:
[0062] Store the preset trusted account list and the preset trusted network domain name list in the blockchain network;
[0063] A data fingerprint is generated through a hash algorithm and is used to verify whether the trusted account list and trusted network domain name list stored on the blockchain have been tampered with.
[0064] In the above technical solution, by storing the trusted account list and the trusted network domain name list in the blockchain network and generating data fingerprints through the hash algorithm, the security and credibility of the trusted account list and the trusted network domain name list can be guaranteed, thereby ensuring the user's login security.
[0065] In a second aspect, an embodiment of the present application provides a login verification device, the device comprising: an acquisition module, a determination module and a login verification module, wherein:
[0066] The acquisition module is used to, when receiving a login request, obtain target login related information of the user corresponding to the login request;
[0067] The determination module is used to determine whether the login environment is a trusted login environment based on target login related information;
[0068] The determination module is further configured to determine a matching login verification method according to the login environment determination result; wherein the login verification method is to perform no login verification or to perform at least one preset login verification;
[0069] The login verification module is used to perform login verification according to the matching login verification method.
[0070] In the above-mentioned technical solution, after receiving a login request, the target login-related information of the corresponding user is obtained. This information is then used to determine whether the login environment is secure. Based on the determination of the login environment, whether login verification is performed is determined. Thus, in a trusted login environment, the user may not need to perform additional verification steps, ensuring login efficiency and a good login experience. In an untrusted environment, however, login verification is performed, effectively preventing potential security risks and ensuring user login security. Thus, the decision to perform login verification can be flexibly made based on the specific circumstances of the login environment, thereby ensuring both login security and a good login experience.
[0071] In a possible implementation, the target login related information includes: a target login account and a target login Internet Protocol (IP) address; the determination module is specifically configured to:
[0072] Determine whether the target login account is a trusted login account according to the preset account judgment policy;
[0073] and / or, determining whether the target login IP address is a trusted login IP address according to a preset address determination policy;
[0074] Determine whether the login environment is a trusted login environment based on the determination result.
[0075] In the above technical solution, a preset account determination strategy is used to check the credibility of the target login account, and a preset address determination strategy is used to verify the credibility of the target login IP address. By comprehensively considering the target login account and the target login IP address, it is determined whether the login environment is safe. This can conveniently and quickly determine whether the login environment is safe, ensuring the security of the user's login and the smoothness of the login experience.
[0076] In a possible implementation, the determination module is specifically configured to:
[0077] Get the preset list of trusted accounts;
[0078] If the target login account is in the trusted account list, determine that the target login account is a trusted login account;
[0079] When the target login account is not in the trusted account list, the target login account is determined to be an untrusted login account.
[0080] In the above technical solution, the administrator can pre-set a list of trusted accounts. When determining whether a target login account is a trusted account, the administrator first obtains the trusted account list and compares the target login account with the login accounts on the trusted account list to determine whether the target login account is a trusted account. Thus, the preset trusted account list can quickly and accurately determine the credibility of the target login account.
[0081] In a possible implementation, the determination module is specifically configured to:
[0082] Get a preset list of trusted network domain names;
[0083] If the target login IP address is in the trusted network domain name list, determine that the target login IP address is a trusted login IP address;
[0084] When the target login IP address is not in the trusted network domain name list, the target login IP address is determined to be an untrusted login IP address.
[0085] In the above technical solution, the administrator can pre-set a list of trusted network domain names. When determining whether a target login IP address is a trusted login IP address, the administrator first obtains the list of trusted network domain names and compares the target login IP address with the login IP addresses in the list to determine whether the target login IP address is a trusted login IP address. Thus, the preset list of trusted network domain names allows the administrator to quickly and accurately determine the credibility of the target login IP address.
[0086] In a possible implementation, the determination module is further configured to:
[0087] Determine whether the target login IP address is the same as the user's previous login IP address;
[0088] When the target login IP address is within the trusted network domain name list, determining that the target login IP address is a trusted login IP address includes:
[0089] When the target login IP address is in the trusted network domain name list and the target login IP address is different from the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0090] In the above technical solution, before obtaining the preset trusted network domain name list, it is first confirmed whether the target login IP address is the same as the previous login IP address. When the target login IP address is the same as the previous login IP address and the target login IP address is in the trusted network domain name list, then the target login IP address can be considered as a trusted login IP address.
[0091] In a possible implementation, the determination module is further configured to:
[0092] When the target login IP address is the same as the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0093] In the above technical solution, when the target login IP address is the same as the previous login IP address, it can be determined that the target login IP address is a trusted login IP address. Then there is no need to determine whether the target login IP address is in the trusted network domain name list, thereby simplifying the judgment process of the target login IP address.
[0094] In a possible implementation, the determination module is specifically configured to:
[0095] If the target login account is a trusted login account and the target login IP address is a trusted login IP address, determining that the login environment is a trusted login environment;
[0096] When the target login account is an untrusted login account or the target login IP address is an untrusted login IP address, the login environment is determined to be an untrusted login environment.
[0097] In the above technical solution, if both the target login account and the target login IP address are credible, the login environment is considered secure. If either the target login account or the target login IP address is untrustworthy, the login environment is considered unsafe. Thus, through dual authentication of the target login account and the target login IP address, the security of the user login can be guaranteed.
[0098] In a possible implementation, the target login related information includes: target login time, and the determination module is specifically used to:
[0099] Get the preset trusted login time period;
[0100] When the target login time is within the trusted login time period, determining the login environment as a trusted login environment;
[0101] When the target login time is not within the trusted login time period, the login environment is determined to be an untrusted login environment.
[0102] In the above technical solution, administrators can pre-set a trusted login time period. When determining whether a login environment is trustworthy, the target login time is compared with the preset trusted login time period to determine whether the current login environment is trustworthy. By adding login time as a factor in determining whether a login environment is trustworthy, the system enriches the methods for determining whether a login environment is trustworthy and better ensures user login security.
[0103] In a possible implementation, the target login related information includes: at least one of a target login account, a target login IP address, and a target login time, and the determination module is specifically configured to:
[0104] Inputting target login related information into the login environment prediction model trained to convergence;
[0105] A login environment prediction model trained to convergence is used to determine whether the login environment is a trusted login environment based on target login related information.
[0106] In the above technical solution, the target login related information includes the target login account, target login IP address and target login time. By inputting the target login related information into the trained and converged login environment prediction model, it is possible to quickly and accurately evaluate whether the login environment is trustworthy and ensure the user's login security.
[0107] In one possible implementation, the login verification module is specifically used to:
[0108] If the login environment is determined to be a trusted login environment, the matching login verification method is determined to be no login verification;
[0109] When the login environment is determined to be an untrusted login environment, the matching login verification method is determined to be performing at least one preset login verification.
[0110] In the above technical solution, in a trusted login environment, users do not need to perform tedious login verification and can log in quickly, ensuring the user's login experience. In an untrusted login environment, users need to perform at least one login verification, which can effectively prevent malicious attacks or unauthorized access, thereby ensuring the user's login security.
[0111] In one possible implementation, the login verification module is specifically used to:
[0112] If the login environment is determined to be an untrusted login environment, determine the target cause corresponding to the untrusted login environment;
[0113] A matching login verification method is determined according to the target reason, the matching login verification method is associated with the target reason, and the matching login verification method is to perform at least one preset login verification.
[0114] In the above technical solution, after determining that the login environment is untrusted, the target cause of the untrusted login environment is also determined, and the target cause is then used to determine the corresponding login verification method. This allows for flexible response to different login scenarios and corresponding login verification, better ensuring user login security.
[0115] In a possible implementation, the login verification device further includes: a configuration module, the configuration module being specifically configured to:
[0116] Configure and store the login verification method that matches the judgment result of each login environment.
[0117] In the above technical solution, before determining the matching login verification method based on the login environment judgment result, the administrator can configure and store the login verification method matching each login environment judgment result according to the actual application scenario to ensure the user's login security and login experience.
[0118] In a possible implementation, the login verification device further includes: a storage module, the storage module being specifically configured to:
[0119] Store the preset trusted account list and the preset trusted network domain name list in the blockchain network;
[0120] A data fingerprint is generated through a hash algorithm and is used to verify whether the trusted account list and trusted network domain name list stored on the blockchain have been tampered with.
[0121] In the above technical solution, by storing the trusted account list and the trusted network domain name list in the blockchain network and generating data fingerprints through the hash algorithm, the security and credibility of the trusted account list and the trusted network domain name list can be guaranteed, thereby ensuring the user's login security.
[0122] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: a memory and a processor;
[0123] Memory and processor coupling;
[0124] The memory is used to store program instructions;
[0125] The processor is used to call program instructions to enable the electronic device to execute any method in the first aspect.
[0126] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the method according to any one of the first aspects is implemented.
[0127] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which implements any method in the first aspect when executed by a computer. BRIEF DESCRIPTION OF THE DRAWINGS
[0128] Figure 1 This is a schematic diagram of an application scenario corresponding to the login verification method provided in an embodiment of the present application;
[0129] Figure 2 This is a flowchart of the login verification method provided in the embodiment of the present application. Figure 1 ;
[0130] Figure 3 This is a flowchart of the login verification method provided in the embodiment of the present application. Figure 2 ;
[0131] Figure 4 This is a schematic diagram of the structure of the login verification device provided in the embodiment of the present application. Figure 1 ;
[0132] Figure 5 This is a schematic diagram of the structure of the login verification device provided in the embodiment of the present application. Figure 2 ;
[0133] Figure 6 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0134] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numbers in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible implementations consistent with the present invention. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present invention, as detailed in the appended claims.
[0135] To facilitate understanding of the login verification method provided in the embodiment of the present application, Figure 1 , describes the application scenarios involved in the embodiments of this application.
[0136] Figure 1A schematic diagram of an application scenario corresponding to the login verification method provided in an embodiment of the present application. The login system includes a user terminal 101 and a login verification device 102, and the user terminal 101 is in communication with the login verification device 102. Specifically, after the user enters the account and password through the user terminal 101, the user terminal 101 sends a login request to the login verification device 102; the login verification device 102 obtains the target login related information of the user terminal 101 corresponding to the login request; then determines whether the current login environment is a secure and trusted login environment through the target login related information; then determines the corresponding login verification method based on the login environment judgment result, wherein the login verification method includes no login verification or at least one preset login verification; the login verification device 102 sends the corresponding login verification method to the user terminal 101. Thus, it is possible to flexibly determine whether to perform login verification according to the situation of the login environment, ensuring login security while ensuring the user's login experience.
[0137] The following specific embodiments are used to describe the technical solutions of the embodiments of the present application in detail. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0138] Figure 2 Schematic diagram of the login verification method provided in this embodiment of the application Figure 1 See Figure 2 , the method may include:
[0139] The execution entity of this method can be Figure 1 The login verification device in the embodiment may be an electronic device, such as a server or a computing device, etc., and is not limited here.
[0140] S201. When a login request is received, obtain target login related information of the user corresponding to the login request.
[0141] The login request is used to send the user's authentication information such as username and password to the login verification device so that the login verification device can check whether the verification information is consistent with the user information stored in the database, thereby confirming the user's identity.
[0142] Login requests can take many forms, depending on how the user logs in. For example, when a user enters their username and password through a web form, the form data is sent to the login verification device via an HTTP POST request. When a user logs in through a client application, the login request includes a pre-obtained key or token.
[0143] Target login-related information is information associated with the login operation of the corresponding user. Target login-related information can be used to verify the user's identity and determine whether the user's login request is approved. This target login-related information includes but is not limited to the user ID, the request source IP address, the request time, the number of requests, the device type used, the operating system version, the browser type, etc.
[0144] S202: Determine whether the login environment is a trusted login environment based on target login related information.
[0145] After obtaining target login related information, first confirm whether the current login environment is a trusted login environment.
[0146] The login environment is the environment in which the login operation is performed, which may include the network environment and device environment when the user logs in. A trusted login environment can be considered a secure login environment.
[0147] Optionally, there are many ways to use the target login related information to determine whether it is a trusted login environment, for example,
[0148] Whether the login environment is a trusted login environment is determined based on whether the user's IP address changes. Specifically, when the user's IP address changes, the login environment can be determined to be an untrusted login environment. Otherwise, the login environment is determined to be a trusted login environment.
[0149] Whether the login environment is a trusted login environment is determined based on whether the user's device type has changed. Specifically, when the user's device type has changed, the login environment is determined to be an untrusted login environment. Otherwise, the login environment is determined to be a trusted login environment.
[0150] Whether the login environment is a trusted login environment is determined based on whether the user's requested login time is the regular login time. Specifically, when the user's requested login time is late at night or is significantly different from the historical login time, the login environment is determined to be an untrusted login environment. Otherwise, the login environment is determined to be a trusted login environment.
[0151] Alternatively, the user's IP address, device type, and requested login time may be used to determine whether the login environment is a trusted one. For example, if none of the three parameters change, the login environment is considered trusted. If one or two of the three parameters change, the login environment is considered untrusted.
[0152] It should be noted that, in this embodiment, there is no specific limitation on how to determine whether it is a trusted login environment based on target login related information, and it can be flexibly set according to the needs of actual application.
[0153] S203. Determine a matching login verification method according to the login environment determination result; wherein the login verification method is to perform no login verification or to perform at least one preset login verification.
[0154] The preset login verification method is a pre-set method for verifying the user's identity. Optionally, the preset login verification method can be SMS verification, facial recognition verification, fingerprint verification, or verification by a preset question, etc. In this embodiment, the preset login verification method is not specifically limited; as long as it can achieve user identity verification, it can be used.
[0155] Optionally, there may be multiple login environment determination results. For example, the login environment determination result may be a highly trusted login environment, a moderately trusted login environment, or an untrusted login environment.
[0156] For example, a high-trust login environment indicates that the security of the user's network environment or device environment is high. In this case, it may be necessary to not perform login verification so that the user can log in quickly; a medium-trust login environment indicates that the security of the user's network environment or device environment is average. In this case, a simple login verification method can be used, such as mobile phone SMS verification; an untrusted login environment indicates that the security of the user's network environment or device environment is very low, and there may be a risk of personal data leakage. In this case, a complex login verification method can be used, such as mobile phone SMS verification plus face recognition verification, to ensure the security of the user account.
[0157] Optionally, the login environment determination result can be set to two types, for example, a trusted login environment and an untrusted login environment. Accordingly, when the login environment determination result is a trusted login environment, the login verification method is to not perform login verification; when the login environment determination result is an untrusted login environment, the login verification method is to perform at least one preset login verification.
[0158] It should be noted that, in this embodiment, there is no specific limitation on how to determine the matching login verification method based on the login environment determination result, and it can be flexibly set according to actual application requirements.
[0159] S204: Perform login verification according to the matching login verification method.
[0160] After the login verification method is determined, the verification interface is displayed to the user or verification information is sent.
[0161] It should be noted that when the login verification is passed, the user can log in successfully; when the login verification fails, the verification failure processing is executed, and the verification failure processing can be allowing the user to perform login verification again, locking the user account or sending a warning notification, etc.
[0162] The login verification method provided in the embodiment of the present application obtains the target login related information of the corresponding user after obtaining the login request, and then determines whether the login environment is safe based on the target login related information, and determines whether to perform login verification based on the judgment result of the login environment. Thus, in a trusted login environment, the user may not need to perform additional verification steps, ensuring the user's login efficiency and login experience; while in an untrusted environment, login verification is performed, which can effectively prevent potential security risks and ensure the user's login security. The method of the embodiment of the present application can flexibly determine whether to perform login verification based on the specific circumstances of the login environment, thereby ensuring login security while ensuring the user's login experience.
[0163] On the basis of the above embodiments, in order to better understand the login verification method provided in the embodiments of the present application, the embodiments of the present application provide a solution for determining whether the login environment is a trusted login environment based on the target login related information. Specifically, the login verification method provided in the embodiments of the present application, the target login related information includes: the target login account and the target login Internet Protocol IP address.
[0164] Determine whether the login environment is a trusted login environment based on the target login-related information, including:
[0165] Determine whether the target login account is a trusted login account based on the preset account judgment policy; and / or determine whether the target login IP address is a trusted login IP address based on the preset address judgment policy; determine whether the login environment is a trusted login environment based on the judgment result.
[0166] When a login request is received, the target login account is obtained, and whether the target login account is a trusted login account is determined according to a preset account determination policy.
[0167] The preset account determination policy is a pre-set policy for determining whether a target login account is a trusted login account.
[0168] Optionally, there may be multiple options for the preset account determination strategy. For example, whether the target login account is a trusted login account may be determined based on parameters such as account login frequency, account login time, or account login device.
[0169] For example, taking the account login frequency as an example, when it is determined that the target login account has a very low login frequency, such as logging in once every half a month, a month or longer, then the target login account can be considered an untrusted login account; when it is determined that the target login account has a high and regular login frequency, such as logging in at a fixed time period every day, then the target login account can be considered a trusted login account.
[0170] It should be noted that, in this embodiment, the preset account determination strategy is not specifically limited and can be flexibly set according to actual needs.
[0171] When a login request is received, the target IP address is obtained, and a determination is made based on a preset address determination strategy as to whether the target login IP address is a trusted login IP address.
[0172] The preset address determination strategy is a pre-set strategy for determining whether the target IP address is a trusted login IP address.
[0173] Optionally, there may be multiple options for the preset address determination strategy. For example, whether the target IP address is a trusted login IP address may be determined based on parameters such as the IP address geographic location, IP address history, or IP address login frequency.
[0174] For example, taking the geographical location of the IP address as an example, when it is determined that the geographical location of the target IP address is different from the geographical location of the IP address at the previous login, the target IP address can be considered as an untrusted login IP address; when it is determined that the geographical location of the target IP address is the same as the geographical location of the IP address at the previous login, the target IP address can be considered as a trusted login IP address.
[0175] It should be noted that, in this embodiment, the preset address determination strategy is not specifically limited and can be flexibly set according to actual needs.
[0176] Specifically, the embodiments of the present application provide three solutions for determining whether a login environment is a trusted login environment:
[0177] First, determine whether the target login account is a trusted login account based on the preset account judgment strategy. Specifically, if the target login account is determined to be a trusted login account, the login environment can be considered a trusted login environment; if the target login account is determined to be an untrusted login account, the login environment can be considered an untrusted login environment.
[0178] Secondly, determine whether the target IP address is a trusted login IP address based on the preset address judgment strategy. Specifically, if the target IP address is determined to be a trusted login IP address, the login environment can be considered a trusted login environment; if the target IP address is determined to be an untrusted login IP address, the login environment can be considered an untrusted login environment.
[0179] Third, determine whether the login environment is a trusted login environment based on the judgment results of the target login account and the target IP address. Optionally, when the target login account is determined to be a trusted login account and the target IP address is determined to be a trusted login IP address, the login environment is considered to be a highly trusted login environment; when the target login account is determined to be an untrusted login account and the target IP address is determined to be an untrusted login IP address, the login environment is considered to be an untrusted login environment; when the target login account is determined to be an untrusted login account or the target IP address is determined to be an untrusted login IP address, the login environment is considered to be a generally trusted login environment.
[0180] It should be noted that, in this embodiment, there is no specific limitation on which solution to use to determine whether a login environment is a trusted login environment, and it can be flexibly set according to actual application requirements.
[0181] The login verification method provided in the embodiment of the present application uses a preset account determination strategy to check the credibility of the target login account, and uses a preset address determination strategy to verify the credibility of the target login IP address. By comprehensively considering the target login account and the target login IP address, it is determined whether the login environment is safe. It can conveniently and quickly determine whether the login environment is safe, thereby ensuring the security of the user login and the smoothness of the login experience.
[0182] On the basis of the above embodiments, in order to facilitate a better understanding of the login verification method provided by the embodiments of the present application, the embodiments of the present application provide a solution for determining whether the target login account is a trusted login account based on a preset account determination strategy.
[0183] Specifically, first, obtain a preset list of trusted accounts.
[0184] The preset trusted account list is a pre-set list of login accounts deemed trustworthy, which can be stored in a database. For example, the accounts of enterprise or company managers can be pre-set to the trusted account list, or authenticated and authorized users can be added to the trusted account list. Alternatively, the trusted account list can be determined based on a combination of factors, such as the user's historical login behavior, account security settings, and account activity. It should be noted that in actual applications, the trusted account list can be adjusted at any time.
[0185] Secondly, after obtaining the trusted account list, further confirm whether the target login account is in the trusted account list. If it is determined that the target login account is in the trusted account list, the target login account can be determined as a trusted login account; if it is determined that the target login account is not in the trusted account list, it can be preliminarily determined that the target login account is an untrusted login account.
[0186] Optionally, if the target login account is determined to be on the trusted account list, the user's login request can be approved. If the target login account is determined not to be on the trusted account list, the target login account is considered a potential risk account and the user may be required to enter additional verification information, such as a text message verification code, graphic verification code, or fingerprint authentication.
[0187] The login verification method provided in the embodiments of the present application first obtains a list of trusted accounts when determining whether a target login account is a trusted login account, compares the target login account with the login accounts on the list, and thereby determines whether the target login account is a trusted login account. Thus, the credibility of the target login account can be quickly and accurately determined using the preset list of trusted accounts.
[0188] On the basis of the above embodiments, in order to facilitate a better understanding of the login verification method provided by the embodiments of the present application, the embodiments of the present application provide a solution for determining whether the target login IP address is a trusted login IP address based on a preset address determination strategy.
[0189] Specifically, first, a preset trusted network domain name list is obtained.
[0190] A network domain can be understood as a logical area divided based on the network structure.
[0191] The preset trusted network domain name list is a pre-set list of trusted network domains. Optionally, the trusted network domain name list can be preset based on factors such as geographic location, corporate intranet, and partner network. Alternatively, the trusted network domain name list can be determined based on a combination of factors, such as the network domain's historical security record, the legitimacy of domain name resolution, and network traffic characteristics. This trusted network domain name list can be stored in a database or configuration file for quick access during login verification.
[0192] It should be noted that with changes in the enterprise network architecture, the increase or decrease of partners, and adjustments to security policies, the network domains or IP address segments in the trusted network domain name list can be flexibly adjusted.
[0193] Secondly, the extracted target login IP address is compared with the preset trusted network domain name list. If the target login IP address is in the trusted network domain name list, the target login IP address is determined to be a trusted login IP address; if the target login IP address is not in the trusted network domain name list, the target login IP address is determined to be an untrusted login IP address.
[0194] It should be noted that after obtaining the target login IP address, the network domain to which the target login IP address belongs is first resolved, which can be achieved by reverse resolution from the target login IP address to the domain name.
[0195] Optionally, when the network domain to which the target login IP address belongs is in the list of trusted network domain names, the target login IP address can be preliminarily considered to be a trusted login IP address, and its corresponding login request can be directly allowed.
[0196] Alternatively, if the target login IP address belongs to a network domain that is not on the list of trusted network domains, the target login IP address can be considered a potentially risky IP address. Further verification steps can then be performed, optionally requiring the user to provide additional verification information, such as a text message verification code or an image verification code.
[0197] The login verification method provided in the embodiments of the present application first obtains a list of trusted network domain names when determining whether a target login IP address is a trusted login IP address, compares the target login IP address with the login IP addresses in the list of trusted network domain names, and thereby determines whether the target login IP address is a trusted login IP address. Thus, the credibility of the target login IP address can be quickly and accurately determined using the preset list of trusted network domain names.
[0198] Based on the above embodiments, the login verification method provided in the embodiments of the present application also adds a judgment on whether the IP address has changed, thereby enriching the judgment logic of the login verification method to cope with complex and changeable scenarios, such as IP address changes caused by users on business trips or working from home.
[0199] Specifically, before obtaining the preset trusted network domain name list, the login verification method of the embodiment of the present application also includes the following method:
[0200] Based on the acquired target login IP address, determine whether the target login IP address is the same as the previous login IP address corresponding to the user.
[0201] Then, after introducing the judgment of whether the login IP address has changed, when the target login IP address is in the trusted network domain name, the method of determining whether the target login IP address is a trusted login IP address can be further refined as follows:
[0202] When the target login IP address is in the trusted network domain name list and the target login IP address is different from the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0203] It should be noted that if the target login IP address belongs to a network domain in the trusted network domain list, but the target login IP address is different from the user's previous login IP address, the user may be attempting to log in from a different but trusted network environment, such as switching between home and work networks, or between different offices within the same company. In this case, although the target login IP address is different from the user's previous login IP address, it is still a trusted login IP address.
[0204] The login verification method provided in the embodiment of the present application confirms whether the target login IP address is the same as the previous login IP address before obtaining the preset trusted network domain name list. When the target login IP address is the same as the previous login IP address and the target login IP address is in the trusted network domain name list, then the target login IP address can be considered to be a trusted login IP address.
[0205] Furthermore, when the target login IP address is the same as the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0206] It should be noted that when the target login IP address is the same as the user's previous login IP address, it indicates that the user is logging in from the same network environment. At this time, the target login IP address can be considered a trusted login IP address.
[0207] Of course, this does not mean that the login environment must be a trusted login environment. For example, when a user account is stolen or the user device is controlled by malware, the attacker may use the same login IP address to attempt to log in. Therefore, the security of the login environment can be further judged based on other judgment methods.
[0208] Optionally, if the target login IP address is the same as the user's previous login IP address, further security checks can be performed to determine the login environment. Specifically, these checks may include checking the frequency of user login attempts, determining whether login times are reasonable, and checking whether the account has any unusual behavior. If no abnormalities are found in any of the above tests, the login environment is considered secure. If one or more of the above tests are found to be abnormal, the current login environment is considered unsafe and requires additional user identity verification, such as fingerprint or facial recognition.
[0209] The login verification method provided in the embodiment of the present application can determine that the target login IP address is a trusted login IP address when the target login IP address is the same as the previous login IP address. In this case, there is no need to determine whether the target login IP address is in the trusted network domain name list, thereby simplifying the determination process of the target login IP address.
[0210] Based on the above embodiments, the login verification method provided in the embodiments of the present application provides a specific solution on how to determine whether the login environment is a trusted login environment based on the judgment result.
[0211] Specifically, if the target login account is a trusted login account and the target login IP address is a trusted login IP address, the login environment is determined to be a trusted login environment. In this case, it indicates that the user's target login account and target login IP address have been verified and there are no abnormalities. In this case, the login environment can be considered a trusted login environment. Specifically, if the target login account is an untrusted login account or the target login IP address is an untrusted login IP address, the login environment is determined to be an untrusted login environment. In this case, it indicates that there is an abnormality or risk in the user's target login account or target login IP address. In this case, the current login environment is considered to be an untrusted login environment.
[0212] The login verification method provided in the embodiments of the present application considers the login environment to be secure if both the target login account and the target login IP address are credible. If either the target login account or the target login IP address is untrustworthy, the login environment is considered to be unsafe. Thus, through dual authentication of the target login account and the target login IP address, the security of the user's login can be guaranteed.
[0213] Based on the above embodiments, considering that the time of user login is also an important reference factor for judging the login environment, the login verification method provided in the embodiment of the present application also provides a solution for determining whether the login environment is a trusted login environment based on the user's login time.
[0214] Specifically, the target login related information includes: target login time.
[0215] When determining whether the login environment is a trusted login environment according to target login related information, first, a preset trusted login time period is obtained.
[0216] The preset trusted login time period is a pre-set safe login time range. Optionally, the trusted login time period can be set based on factors such as the user's historical login behavior and work habits. For example, if a user typically logs in during the day on weekdays, the trusted login time period can be set to the weekday working hours. This trusted login time period can be stored in a database or configuration file for quick access during the login verification process.
[0217] It should be noted that the preset trusted login time period can be flexibly adjusted according to changes in work habits and living habits.
[0218] When the target login time is within the trusted login time period, the login environment is determined to be a trusted login environment. At this time, it indicates that the user logs in within a reasonable or regular time period, and the login environment can be considered to be a trusted login environment.
[0219] If the target login time is outside the trusted login time period, the login environment is determined to be untrusted. This indicates that the user attempted to log in during an unusual time period, and the current login environment can be preliminarily considered untrusted. Other methods can be combined to determine whether the current login environment is a trusted login environment.
[0220] The login verification method provided in the embodiments of the present application determines whether the login environment is trustworthy by comparing the target login time with a preset trusted login time period. This allows the user to determine whether the current login environment is trustworthy. By adding the login time factor, the method for determining whether the login environment is trustworthy is enriched, thereby better ensuring the user's login security.
[0221] On the basis of the above-mentioned embodiments, the login verification method provided in the embodiments of the present application also considers a solution of determining whether the login environment is a trusted login environment through a prediction model.
[0222] Specifically, the target login related information includes: at least one of the target login account, the target login IP address, and the target login time.
[0223] When determining whether the login environment is a trusted login environment based on target login related information, the target login related information is input into the login environment prediction model trained to convergence, and the login environment prediction model trained to convergence is used to determine whether the login environment is a trusted login environment based on the target login related information.
[0224] In this embodiment, the target login-related information obtained, such as the target login account, target login IP address, and target login time, is input as input data into a login environment prediction model that has been trained to convergence. The login environment prediction model that has been trained to convergence analyzes and predicts the input target login-related information and outputs a credibility score or credibility result for the login environment. The credibility score or credibility result output is then used to determine whether the login environment is a credible login environment. For example, a score threshold can be set. When the credibility score is higher than the score threshold, the login environment is considered credible; otherwise, the login environment is considered untrustworthy.
[0225] Specifically, the training process of the login environment prediction model is as follows:
[0226] First, collect historical login data, including sample data of normal and abnormal logins. The historical login data includes login scenarios such as different time periods, different account types, and different IP addresses.
[0227] Secondly, the collected historical login data is preprocessed, including steps such as data cleaning, feature extraction, data labeling and data standardization, to form input data suitable for machine learning models.
[0228] Again, select a suitable machine learning algorithm, such as decision tree, random forest, or neural network, and build an initial login environment prediction model based on the preprocessed historical login data.
[0229] Finally, the constructed initial login environment prediction model is trained until the model converges. During the training process, methods such as cross-validation and grid search can be used to adjust model parameters and improve the model's generalization ability.
[0230] The login verification method provided in the embodiment of the present application, the target login related information includes the target login account, target login IP address and target login time. By inputting the target login related information into the trained and converged login environment prediction model, it is possible to quickly and accurately evaluate whether the login environment is trustworthy and ensure the user's login security.
[0231] On the basis of the above-mentioned embodiments, the login verification method provided in the embodiments of the present application also provides a solution for how to determine a matching login verification method based on the login environment determination result.
[0232] Specifically, if the login environment is determined to be a trusted login environment, the matching login verification method is determined to be no login verification. At this point, the user's login environment can be considered safe and trusted, and the user can be directly allowed to log in without additional login verification, thereby simplifying the login process and improving the user's login experience.
[0233] Specifically, if the login environment is determined to be untrusted, the matching login verification method is determined to be at least one preset login verification method. In this case, the user is considered to be in an unsafe and risky login environment, so additional login verification is required to ensure login security. At least one preset login verification method can be selected, such as SMS verification code verification, fingerprint recognition verification, facial recognition verification, etc.
[0234] It should be noted that the preset verification method can be configured and adjusted according to actual needs to ensure the security and flexibility of login.
[0235] The login verification method provided in the embodiment of the present application does not require users to perform tedious login verification in a trusted login environment and can log in quickly, thereby ensuring the user's login experience. In an untrusted login environment, users need to perform at least one login verification, which can effectively prevent malicious attacks or unauthorized access, thereby ensuring the user's login security.
[0236] On the basis of the above embodiments, the login verification method provided in the embodiments of the present application may have certain differences in the corresponding subsequent login verification methods due to differences in the causes of the untrusted login environment.
[0237] Based on this, in an embodiment of the present application, when the login environment is determined to be an untrusted login environment, and it is determined that the matching login verification method is to perform at least one preset login verification, the following steps are performed:
[0238] When the login environment is determined to be an untrusted login environment, a target cause corresponding to the untrusted login environment is determined.
[0239] The target reason is the reason why the login environment is an untrusted login environment. Optionally, the target reason can have various possibilities, such as an abnormal login IP address, abnormal login time, or multiple login failures. In this embodiment, the target reason is not specifically limited.
[0240] After determining the target reason, a matching login verification method is determined according to the target reason. The matching login verification method is associated with the target reason and the matching login verification method is to perform at least one preset login verification.
[0241] Optionally, the preset verification method includes but is not limited to SMS verification code verification, email verification code verification, fingerprint recognition verification, and facial recognition verification.
[0242] Exemplarily, when the target reason is one, for example, the target reason is an abnormal login IP address, then the abnormal login IP address can be associated with one of a plurality of preset verification methods. When it is determined that the target reason of the untrusted login environment is an abnormal login IP address, the user is required to perform login verification through a corresponding verification method.
[0243] Exemplarily, when there are multiple target reasons, for example, the target reason also includes abnormal login IP address and abnormal login time, then the login verification corresponding to the target reason can be one, such as fingerprint recognition verification or facial recognition verification; of course, the login verification corresponding to the target reason can also be multiple, for example, SMS verification code verification and facial recognition verification are combined for login verification.
[0244] It should be noted that, in this embodiment, there is no specific limitation on how the target cause matches the verification method, and it can be flexibly set according to different actual application scenarios.
[0245] The login verification method provided in the embodiments of the present application, after determining that the login environment is untrusted, further determines the target cause of the untrusted login environment, and then determines a corresponding login verification method based on the target cause. This allows for flexible response to different login scenarios and corresponding login verification, better ensuring user login security.
[0246] Based on the above embodiment, the login verification method provided in the embodiment of the present application further performs the following steps before determining a matching login verification method based on the login environment determination result:
[0247] Configure and store the login verification method that matches the judgment result of each login environment.
[0248] It should be noted that the method of the embodiment of the present application can pre-configure the login verification method that matches the judgment results of each login environment according to different application scenarios or business needs, and after the configuration is completed, the configuration results are stored in the database to form login verification policy configuration information. The login verification policy configuration information is used to execute different login verifications according to different judgment results.
[0249] Optionally, the login environment determination results can be divided into high-trust login environment, medium-trust login environment, general-trust login environment and untrust login environment according to the complexity of the application scenario, and a verification method can be assigned to each login environment determination result.
[0250] The login verification method provided in the embodiment of the present application allows the administrator to configure and store the login verification methods that match the login environment judgment results according to the actual application scenario before determining the matching login verification method based on the login environment judgment results, thereby ensuring the user's login security and login experience.
[0251] On the basis of the above embodiments, in order to ensure the security of data, the login verification method provided in the embodiments of the present application also provides a solution to ensure data security.
[0252] Specifically, the preset trusted account list and the preset trusted network domain name list are stored in the blockchain network.
[0253] Since the preset trusted account list and the preset trusted network domain name list are important references for determining whether the user login account and user login IP address are safe, they are stored on the blockchain network, leveraging the decentralized and tamper-proof nature of the blockchain to ensure the security of the preset trusted account list and the preset trusted network domain name list.
[0254] Specifically, a data fingerprint is generated through a hash algorithm, and the data fingerprint is used to verify whether the trusted account list and trusted network domain name list stored on the blockchain have been tampered with.
[0255] Optionally, the hash algorithm may be a secure triple hash algorithm 256-bit or a message digest algorithm.
[0256] Furthermore, a hash calculation is performed on the data of the trusted account list and trusted network domain name list stored on the blockchain to generate a corresponding data fingerprint. The data fingerprint will serve as an important basis for verifying the integrity and authenticity of the list data. The generated data fingerprint is associated with the corresponding list data and stored. During subsequent verification, the data fingerprint can be easily obtained and compared, thus ensuring the authenticity and integrity of the preset trusted account list and preset trusted network domain name list.
[0257] Optionally, in addition to the preset trusted account list and the preset trusted network domain name list, data stored in the blockchain network can also be added according to the needs of the application scenario, such as a preset trusted login time period.
[0258] The login verification method provided in the embodiment of the present application can ensure the security and credibility of the trusted account list and the trusted network domain name list by storing the trusted account list and the trusted network domain name list in the blockchain network and generating a data fingerprint through a hash algorithm, thereby ensuring the user's login security.
[0259] In order to better understand the login verification method provided by this application, in the implementation of this application, illustratively, taking the target login related information including the target login account and the target login IP address as an example, a complete flow chart of the login verification method is introduced. Figure 3 Schematic diagram of the login verification method provided for this application Figure 2 , Figure 3 The execution subject of the login verification method in can be Figure 1 Login verification device in. Reference Figure 3 As shown in , specifically, the login verification method includes the following steps:
[0260] S301. Obtain a preset list of trusted accounts and a preset list of trusted network domain names, and store them in the regional blockchain network.
[0261] S302: Configure and store the login verification methods that match the login environment determination results.
[0262] S303. When a login request is received, obtain target login related information of the user corresponding to the login request, where the target login related information includes but is not limited to the target login account and target login IP address.
[0263] S304: Obtain a preset list of trusted accounts.
[0264] S305: Determine whether the target login account is in the trusted account list.
[0265] S306: If the target login account is not in the trusted account list, determine that the target login account is an untrusted login account, and perform at least one preset login verification method.
[0266] S307: If the target login account is in the trusted account list, determine that the target login account is a trusted login account.
[0267] S308: Determine whether the target login IP address is the same as the previous login IP address corresponding to the user.
[0268] S309. When the target login IP address is the same as the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address, and the login verification method is to not perform login verification.
[0269] S310: When the target login IP address is different from the previous login IP address corresponding to the user, obtain a preset trusted network domain name list.
[0270] S311, determine whether the target login IP address is in the trusted network domain name list.
[0271] S312: When the target login IP address is not in the trusted network domain name list, the target login IP address is determined to be an untrusted login IP address, and the login verification method is to perform at least one preset login verification.
[0272] S313: In the list of trusted network domain names for the target login IP address, determine that the target login IP address is a trusted login IP address, and the login verification mode is to not perform login verification.
[0273] It should be noted that the login verification method provided in the embodiment of the present application can implement the login verification method described in the above method embodiment, and its implementation principle and technical effects are similar, which will not be repeated here.
[0274] Figure 4 Schematic diagram of the structure of the login verification device provided in the embodiment of the present application Figure 1The login verification device is applied to electronic equipment, specifically, referring to Figure 4 As shown, the login verification device 40 includes: an acquisition module 41 , a determination module 42 and a login verification module 43 .
[0275] The acquisition module 41 is used to, when receiving a login request, acquire target login related information of the user corresponding to the login request;
[0276] The determination module 42 is used to determine whether the login environment is a trusted login environment based on the target login related information;
[0277] The determination module 42 is further configured to determine a matching login verification method based on the login environment determination result; wherein the login verification method is to perform no login verification or to perform at least one preset login verification;
[0278] The login verification module 43 is used to perform login verification according to the matching login verification method.
[0279] In a possible implementation, the target login related information includes: the target login account and the target login Internet Protocol IP address; the determination module 42 is specifically used to:
[0280] Determine whether the target login account is a trusted login account according to the preset account judgment policy;
[0281] and / or, determining whether the target login IP address is a trusted login IP address according to a preset address determination policy;
[0282] Determine whether the login environment is a trusted login environment based on the determination result.
[0283] In a possible implementation, the determination module 42 is specifically configured to:
[0284] Get the preset list of trusted accounts;
[0285] If the target login account is in the trusted account list, determine that the target login account is a trusted login account;
[0286] When the target login account is not in the trusted account list, the target login account is determined to be an untrusted login account.
[0287] In a possible implementation, the determination module 42 is specifically configured to:
[0288] Get a preset list of trusted network domain names;
[0289] If the target login IP address is in the trusted network domain name list, determine that the target login IP address is a trusted login IP address;
[0290] When the target login IP address is not in the trusted network domain name list, the target login IP address is determined to be an untrusted login IP address.
[0291] In a possible implementation, the determination module 42 is further configured to:
[0292] Determine whether the target login IP address is the same as the user's previous login IP address;
[0293] When the target login IP address is within the trusted network domain name list, determining that the target login IP address is a trusted login IP address includes:
[0294] When the target login IP address is in the trusted network domain name list and the target login IP address is different from the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0295] In a possible implementation, the determination module 42 is further configured to:
[0296] When the target login IP address is the same as the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
[0297] In a possible implementation, the determination module 42 is specifically configured to:
[0298] If the target login account is a trusted login account and the target login IP address is a trusted login IP address, determining that the login environment is a trusted login environment;
[0299] When the target login account is an untrusted login account or the target login IP address is an untrusted login IP address, the login environment is determined to be an untrusted login environment.
[0300] In a possible implementation, the target login related information includes: target login time, and the determination module 42 is specifically configured to:
[0301] Get the preset trusted login time period;
[0302] When the target login time is within the trusted login time period, determining the login environment as a trusted login environment;
[0303] When the target login time is not within the trusted login time period, the login environment is determined to be an untrusted login environment.
[0304] In a possible implementation, the target login related information includes: at least one of the target login account, the target login IP address, and the target login time. The determination module 42 is specifically configured to:
[0305] Inputting target login related information into the login environment prediction model trained to convergence;
[0306] A login environment prediction model trained to convergence is used to determine whether the login environment is a trusted login environment based on target login related information.
[0307] In a possible implementation, the login verification module 43 is specifically configured to:
[0308] If the login environment is determined to be a trusted login environment, the matching login verification method is determined to be no login verification;
[0309] When the login environment is determined to be an untrusted login environment, the matching login verification method is determined to be performing at least one preset login verification.
[0310] In a possible implementation, the login verification module 43 is specifically configured to:
[0311] If the login environment is determined to be an untrusted login environment, determine the target cause corresponding to the untrusted login environment;
[0312] A matching login verification method is determined according to the target reason, the matching login verification method is associated with the target reason, and the matching login verification method is to perform at least one preset login verification.
[0313] Figure 5 Schematic diagram of the structure of the login verification device provided in the embodiment of the present application Figure 2 . refer to Figure 5 ,exist Figure 4 In addition to the structure of the login verification device shown, the login verification device 40 further includes a configuration module 44 and a storage module 45 .
[0314] In a possible implementation, the configuration module 44 is specifically configured to:
[0315] Configure and store the login verification method that matches the judgment result of each login environment.
[0316] In a possible implementation, the storage module 45 is specifically configured to:
[0317] Store the preset trusted account list and the preset trusted network domain name list in the blockchain network;
[0318] A data fingerprint is generated through a hash algorithm and is used to verify whether the trusted account list and trusted network domain name list stored on the blockchain have been tampered with.
[0319] It should be noted that the login verification device provided in the embodiment of the present application can implement the login verification method described in the above method embodiment, and its implementation principle and technical effects are similar, which will not be repeated here.
[0320] Figure 6 This is a schematic diagram of the structure of the electronic device provided in the embodiment of the present application, refer to Figure 6 As shown in FIG, the electronic device 50 may include a memory 51 and a processor 52; the memory 51 and the processor 52 are coupled. The memory 51 and the processor 52 are communicatively connected via a communication bus; the memory 51 is used to store program instructions; the processor 52 is used to call the program instructions so that the electronic device executes the technical solution shown in the above method embodiment.
[0321] Optionally, the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), or application-specific integrated circuits (ASIC). A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of the present application may be directly implemented as being executed by a hardware processor, or may be implemented by a combination of hardware and software modules in the processor.
[0322] An embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the login verification method described in the above embodiment is implemented.
[0323] An embodiment of the present application provides a computer program product, including a computer program, which implements the login verification method of the above embodiment when executed by a computer.
[0324] All or part of the steps of the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above-mentioned method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disc, and any combination thereof.
[0325] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable terminal device to generate a machine, so that the instructions executed by the processing unit of the computer or other programmable terminal device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0326] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0327] In the description of the embodiments of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to a fixed connection, an indirect connection via an intermediate medium, internal communication between two components, or an interaction between two components. Those skilled in the art will understand the specific meanings of the above terms in the embodiments of this application based on specific circumstances.
[0328] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present application, rather than to limit them. Although the embodiments of the present application have been described in detail with reference to the aforementioned embodiments, ordinary technicians in this field should understand that they can still modify the technical solutions recorded in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A login verification method, characterized in that: include: Upon receiving a login request, obtaining target login related information of the user corresponding to the login request; Determining whether the login environment is a trusted login environment based on the target login related information; Determining a matching login verification method based on the login environment determination result; wherein the login verification method is no login verification or at least one preset login verification; Perform login verification according to the matching login verification method.
2. The method according to claim 1, characterized in that Target login related information includes: target login account and target login Internet Protocol IP address; Determining whether the login environment is a trusted login environment based on the target login related information includes: Determine whether the target login account is a trusted login account according to a preset account determination strategy; and / or, determining whether the target login IP address is a trusted login IP address according to a preset address determination strategy; Determine whether the login environment is a trusted login environment based on the determination result.
3. The method according to claim 2, characterized in that The determining whether the target login account is a trusted login account according to a preset account determination policy includes: Get the preset list of trusted accounts; If the target login account is in the trusted account list, determining that the target login account is a trusted login account; When the target login account is not in the trusted account list, the target login account is determined to be an untrusted login account.
4. The method according to claim 2, characterized in that The determining whether the target login IP address is a trusted login IP address according to a preset address determination strategy includes: Get a preset list of trusted network domain names; If the target login IP address is a single trusted network domain name, determining the target login IP address as a trusted login IP address; When the target login IP address is not in the trusted network domain name list, the target login IP address is determined to be an untrusted login IP address.
5. The method according to claim 4, characterized in that Before obtaining the preset trusted network domain name list, the method further includes: Determine whether the target login IP address is the same as the previous login IP address corresponding to the user; When the target login IP address is within the trusted network domain name, determining that the target login IP address is a trusted login IP address includes: When the target login IP address is in the trusted network domain name list and the target login IP address is different from the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
6. The method according to claim 5, characterized in that Also includes: When the target login IP address is the same as the previous login IP address corresponding to the user, the target login IP address is determined to be a trusted login IP address.
7. The method according to claim 2, characterized in that Determining whether the login environment is a trusted login environment according to the determination result includes: If the target login account is a trusted login account and the target login IP address is a trusted login IP address, determining that the login environment is a trusted login environment; When the target login account is an untrusted login account or the target login IP address is an untrusted login IP address, the login environment is determined to be an untrusted login environment.
8. The method according to claim 1, characterized in that The target login related information includes: target login time; Determining whether the login environment is a trusted login environment based on the target login related information includes: Get the preset trusted login time period; If the target login time is within the trusted login time period, determining that the login environment is a trusted login environment; When the target login time is not within the trusted login time period, the login environment is determined to be an untrusted login environment.
9. The method according to claim 1, characterized in that The target login related information includes: at least one of the target login account, target login IP address and target login time; Determining whether the login environment is a trusted login environment based on the target login related information includes: Inputting the target login related information into the login environment prediction model trained to convergence; The login environment prediction model trained to convergence is used to determine whether the login environment is a trusted login environment based on the target login related information.
10. An electronic device, characterized in that: include: memory and processor; The memory is coupled to the processor; The memory is used to store program instructions; The processor is used to call the program instructions so that the electronic device executes the login verification method according to any one of claims 1 to 9.