Verification code verification method and device, electronic equipment and nonvolatile storage medium
Through dynamic key derivation algorithm and multi-factor behavior feature modeling verification code verification method, combined with the dual-factor verification mechanism of user behavior data and verification code, the problem of fixed verification code encryption method is solved, intelligent secondary verification is realized, and the security and user experience of the system are enhanced.
Patent Information
- Application Number
- CN202510742098.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-08-29
AI Technical Summary
The verification code encryption method in the prior art is fixed and the verification dimension is single, resulting in insufficient system security and it is difficult to effectively prevent automated attacks and malicious logins.
Through dynamic key derivation algorithm and multi-factor behavior feature modeling, combining the dual-factor verification mechanism of user behavior data and verification codes, the verification code is generated and verified, and the complexity and validity period of verification codes are dynamically adjusted, and the user behavior baseline model is used to judge the feature similarity, and intelligent secondary verification is realized.
It enhances the security of the system, effectively prevents automated attacks and malicious login attempts, improves the flexibility and security protection capabilities of the system, and optimizes the user experience.
Smart Images

Figure CN120567508A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a verification code verification method, device, electronic device, and non-volatile storage medium. Background Art
[0002] With the continuous development of the internet, security issues are receiving increasing attention, and verification codes are a common means of preventing automated attacks. In scenarios such as web login, registration, and password retrieval, the system typically sends a verification code to the user, who must enter it before completing subsequent operations. Traditional verification codes primarily use text, numbers, graphics, and other information as carriers, requiring the user to enter the correct information before the subsequent operation can be completed. However, verification codes in related technologies suffer from technical issues such as fixed encryption methods and a single verification dimension.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0004] The embodiments of the present application provide a verification code verification method, device, electronic device and non-volatile storage medium to at least solve the technical problems in the related art of fixed verification code encryption method and single verification dimension.
[0005] According to one aspect of an embodiment of the present application, a verification code verification method is provided, including: obtaining a first verification code input by a user, and user behavior data when the user enters the first verification code, wherein the user behavior data is used to characterize the behavioral characteristics of the user when entering the first verification code; obtaining an encrypted verification code corresponding to a current session identifier in a target database, and decrypting the encrypted verification code using a target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to identify a uniquely determined user session, in which the user requests a server to generate a verification code, and completes verification by entering the verification code issued by the server in a front-end interactive interface, and each user session corresponds to a target key; when the feature similarity between the user behavior data and a user behavior baseline model is greater than a target similarity threshold, and the first verification code is the same as the second verification code, it is determined that the first verification code input by the user has passed verification, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
[0006] Optionally, the method also includes: generating a second verification code in response to the verification code generation request, and determining context information corresponding to the verification code generation request, wherein the context information includes at least one of the following: an Internet Protocol address of the user device, a device fingerprint hash value of the user device, and a timestamp of receiving the verification code generation request; determining a target salt value based on the context information, and using a key derivation algorithm to generate a target key based on the target salt value, wherein the validity period of the target key is consistent with the validity period of the second verification code; encrypting the second verification code based on the target key to obtain an encrypted verification code; and storing the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in a target database.
[0007] Optionally, generating a second verification code includes: obtaining relevant information of the user who triggered the verification code generation request, wherein the relevant information includes at least one of the following: the frequency of the verification code generation request triggered by the user within a preset time period, and whether the Internet Protocol address of the user device is in the abnormal address list; based on the relevant information, determining the comprehensive risk score of the user session corresponding to the verification code generation request; based on the comprehensive risk score, determining the complexity coefficient of the verification code, wherein the complexity coefficient is used to indicate the generation parameters of the verification code, wherein the generation parameters include at least one of the following: character length, number of interference lines, and noise intensity, wherein the higher the comprehensive risk score, the higher the complexity corresponding to the corresponding complexity coefficient; generating a second verification code according to the generation parameters corresponding to the complexity coefficient.
[0008] Optionally, storing the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in the target database includes: determining a key identifier based on the session identifier and the comprehensive risk score of the user session, and forming a key-value pair with the key identifier and the encrypted verification code; when the comprehensive risk score is greater than a preset risk score threshold, storing the key-value pair in an encrypted partition in the target database, wherein the target database includes: a Redis database; setting the validity period of the second verification code corresponding to the key-value pair located in the encrypted partition to a first duration, and setting the validity period of the second verification code corresponding to the key-value pair located in other areas of the target database except the encrypted partition to a second duration, wherein the first duration is greater than the second duration, and within the validity period of the verification code, the user cannot trigger a new verification code generation request.
[0009] Optionally, the method also includes: determining a target similarity threshold based on the comprehensive risk score, wherein the higher the comprehensive risk score, the corresponding target similarity threshold is; performing feature extraction on the user behavior data to obtain the user's behavior feature vector, wherein the user behavior data includes at least one of the following: the input time interval between each character when the user enters the verification code, and the time series of the user's focus switching when entering the verification code; determining the feature similarity between the user's behavior feature vector and the behavior pattern feature represented by the user behavior baseline model, and comparing the size relationship between the feature similarity and the target similarity threshold.
[0010] Optionally, the method also includes: when the first verification code and the second verification code are different, determining that the first verification code input by the user has failed verification, increasing the comprehensive risk score, and regenerating a new second verification code according to the increased comprehensive risk score, and sending it to the user device for re-verification; when the feature similarity is not greater than the target similarity threshold and the first verification code and the second verification code are the same, sending other types of verification information different from the type of the second verification code to the user device to perform a second verification on the user, wherein the other types include at least one of the following: SMS verification, slider verification.
[0011] Optionally, when the validity period of the second verification code has expired, the encrypted verification code corresponding to the second verification code is removed from the target database; obtaining the encrypted verification code corresponding to the current session identifier in the target database also includes: when the encrypted verification code corresponding to the session identifier is not queried in the target database, sending a first prompt message to the user device, wherein the first prompt message is used to indicate that the verification code has expired.
[0012] According to another aspect of an embodiment of the present application, a verification code verification device is also provided, including: a data acquisition module, used to obtain a first verification code input by a user, and user behavior data when the user enters the first verification code, wherein the user behavior data is used to characterize the behavioral characteristics of the user when entering the first verification code; a key decryption module, used to obtain an encrypted verification code corresponding to the current session identifier in a target database, and decrypt the encrypted verification code using a target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to identify a uniquely determined user session, in which the user requests the server to generate a verification code, and completes the verification by entering the verification code issued by the server in a front-end interactive interface, and each user session corresponds to a target key; a multiple verification module, used to determine that the first verification code input by the user has passed the verification when the feature similarity between the user behavior data and the user behavior baseline model is greater than the target similarity threshold and the first verification code is the same as the second verification code, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
[0013] According to another aspect of the embodiments of the present application, an electronic device is provided, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the verification code verification method is executed when the program is run.
[0014] According to another aspect of the embodiments of the present application, a non-volatile storage medium is provided. The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the verification code verification method by running the computer program.
[0015] According to another aspect of the embodiments of the present application, a computer program product is provided, including a computer program, which implements the steps of the verification code verification method when executed by a processor.
[0016] In an embodiment of the present application, a first verification code input by a user and user behavior data when the user enters the first verification code are obtained, wherein the user behavior data is used to characterize the behavioral characteristics of the user when entering the first verification code; an encrypted verification code corresponding to the current session identifier in a target database is obtained, and the encrypted verification code is decrypted using a target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to uniquely identify a user session. In a user session, the user requests a server to generate a verification code and completes verification by entering the verification code issued by the server in a front-end interactive interface. Each user session corresponds to a target key; if the feature similarity between the user behavior data and a user behavior baseline model is greater than a target similarity threshold, and the first verification code and the second verification code are identical, the first verification code input by the user is determined to have passed verification. The user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction. By combining the user behavior data and the verification code to form a dual verification mechanism, the system security is enhanced, and the purpose of effectively preventing automated attacks and malicious login attempts is achieved, thereby solving the technical problems of fixed verification code encryption method and single verification dimension in the related art. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0018] Figure 1 This is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a verification code verification method provided in an embodiment of the present application;
[0019] Figure 2 This is a schematic diagram of a verification code verification method according to an embodiment of the present application;
[0020] Figure 3 This is a flow chart of an intelligent verification code generation and verification method based on dynamic key and behavior analysis provided in an embodiment of the present application;
[0021] Figure 4 It is a structural diagram of a verification code verification device provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0024] To facilitate those skilled in the art to better understand the embodiments of the present application, some technical terms or nouns involved in the embodiments of the present application are explained as follows:
[0025] Redis: The full name is Remote Dictionary Server, which is a remote dictionary service. It is a key-value storage database that contains multiple data structures, supports networking, is memory-based, and has optional persistence.
[0026] Hutool: is a small but comprehensive Java tool library designed to simplify Java development and improve work efficiency.
[0027] Maven: A build management tool based on the Project Object Model (POM), it is primarily used to manage and automate the build of Java projects. Maven provides a standardized project structure and build specifications to help developers quickly build, test, and deploy projects.
[0028] In related technologies, verification codes suffer from technical issues such as fixed encryption methods and a single verification dimension. To address this issue, the present application provides a solution in its embodiments. By utilizing a dynamic key derivation algorithm, multi-factor behavioral feature modeling, and an intelligent risk scoring mechanism, it achieves replay-resistant verification code generation and intelligent secondary verification, which is described in detail below.
[0029] According to an embodiment of the present application, an embodiment of a method for verification code verification is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0030] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG1 shows a hardware structure block diagram of a computer terminal (or electronic device) for implementing a verification code verification method. Figure 1 As shown, the computer terminal 10 (or electronic device) may include one or more (illustrated as 102a, 102b, ..., 102n in the figure) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0031] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry". The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuitry may be a single independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10 (or electronic device). As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0032] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the verification code verification method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the above-mentioned verification code verification method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0033] The transmission device 106 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 10. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is configured to communicate with the Internet wirelessly.
[0034] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or electronic device).
[0035] In the above operating environment, the embodiment of the present application provides a verification code verification method. Figure 2 This is a schematic diagram of a verification code verification method according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps:
[0036] Step S202: obtaining a first verification code input by the user and user behavior data when the user enters the first verification code, wherein the user behavior data is used to characterize the behavioral characteristics of the user when entering the first verification code;
[0037] Step S204: Obtain the encrypted verification code corresponding to the current session identifier from the target database, and decrypt the encrypted verification code using the target key corresponding to the session identifier to obtain a second verification code. Each session identifier is used to uniquely identify a user session. In a user session, the user requests the server to generate a verification code and completes verification by entering the verification code issued by the server in the front-end interactive interface. Each user session corresponds to a target key.
[0038] Step S206: When the feature similarity between the user behavior data and the user behavior baseline model is greater than the target similarity threshold, and the first verification code is the same as the second verification code, it is determined that the first verification code input by the user has passed the verification, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
[0039] Through the above steps, by combining the dual verification mechanism of user behavior data and verification code, the security of the system is enhanced, and the purpose of effectively preventing automated attacks and malicious login attempts is achieved, thereby solving the technical problems of fixed verification code encryption method and single verification dimension in related technologies.
[0040] The verification code verification method in steps S202 to S206 of the embodiment of the present application is further introduced below.
[0041] Figure 3 This is a flow chart of a method for generating and verifying an intelligent verification code based on dynamic keys and behavior analysis according to an embodiment of the present application. Figure 3 As shown, the embodiment of the present application realizes the generation of verification codes and intelligent secondary verification that are resistant to replay attacks through a dynamic key derivation algorithm, multi-factor behavioral feature modeling, and an intelligent risk scoring mechanism, which is described in detail below.
[0042] First, a dynamic key verification code generation mechanism is introduced in the embodiment of the present application. When a user needs to perform verification code verification, a user session is opened to send a verification code generation request to the server. After receiving the verification code generation request, the server generates and encrypts the key, and generates and renders the verification code, as follows.
[0043] In some embodiments of the present application, the method further includes the following steps: generating a second verification code in response to a verification code generation request, and determining context information corresponding to the verification code generation request, wherein the context information includes at least one of the following: an Internet Protocol address of the user device, a device fingerprint hash value of the user device, and a timestamp of receiving the verification code generation request; determining a target salt value based on the context information, and using a key derivation algorithm to generate a target key based on the target salt value, wherein the validity period of the target key is consistent with the validity period of the second verification code; encrypting the second verification code based on the target key to obtain an encrypted verification code; and storing the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in a target database.
[0044] Specifically, on the one hand, Hutool can be used to generate a configurable second verification code (character set / length / style / color); on the other hand, a unique salt value (i.e., target salt value) can be generated through the SHA256 algorithm based on the request context information (e.g., IP address, device fingerprint hash, timestamp, etc.); then a key derivation algorithm (e.g., PBKDF2WithHmacSHA256 algorithm) is used to generate a 256-bit AES key (i.e., target key). The computational complexity of the key derivation can be increased through multiple iterations to prevent brute force cracking; and the target key is bound to the life cycle (validity period) of the second verification code to ensure that each generated second verification code has a unique key.
[0045] Afterwards, the second verification code can be encrypted with the target key and stored in the target database (taking Redis as an example) to ensure the security of the stored verification code; and the encrypted byte array can be converted into a Base64 string for easy storage and transmission.
[0046] This embodiment of the application generates a dynamic salt value based on context information and iteratively generates an AES session key using the PBKDF2 algorithm, implementing a "one request, one key" encryption strategy. The key is strongly bound to the verification code lifecycle, ensuring that a single key leak does not affect other verification codes.
[0047] In this embodiment, when generating the second verification code, the complexity of the verification code can be dynamically adjusted according to the risk score. For example, low risk uses 4 digits + simple interference lines, and high risk uses 8-bit mixed characters (including special symbols) + distortion + noise, etc. The specific steps are as follows.
[0048] In some embodiments of the present application, generating a second verification code includes: obtaining relevant information of the user who triggered the verification code generation request, wherein the relevant information includes at least one of the following: the frequency of the verification code generation request triggered by the user within a preset time period, and whether the Internet Protocol address of the user device is in the abnormal address list; based on the relevant information, determining the comprehensive risk score of the user session corresponding to the verification code generation request; based on the comprehensive risk score, determining the complexity coefficient of the verification code, wherein the complexity coefficient is used to indicate the generation parameters of the verification code, wherein the generation parameters include at least one of the following: character length, number of interference lines, and noise intensity, wherein the higher the comprehensive risk score, the higher the complexity corresponding to the corresponding complexity coefficient; generating the second verification code according to the generation parameters corresponding to the complexity coefficient.
[0049] Specifically, the embodiments of this application have taken security enhancement measures. Based on information factors such as request frequency, IP reputation database matching, and device anomaly detection, the risk index (comprehensive risk score) of the request can be calculated in real time. Based on the comprehensive risk score, the verification code complexity coefficient can be dynamically adjusted (for example, by adding interference lines, noise, encryption, character length, etc.) to increase the difficulty of cracking by automated tools. At the same time, it supports regular replacement of the verification code character set and algorithm to prevent long-term cracking.
[0050] For example, you can count the number of times a user triggers a verification code generation request within a preset time period (such as 1 minute). A higher request frequency may indicate abnormal user behavior and a higher risk score. Check whether the user's device's Internet Protocol (IP) address is on a list of abnormal addresses. If the IP address is included in the abnormal list, the risk score will increase accordingly. Check whether the user's device's fingerprint information matches known malicious devices. If the device fingerprint is abnormal, the risk score will also increase. Then, the scores of the above risk factors are weighted and summed to obtain a comprehensive risk score. A higher comprehensive risk score indicates a higher security risk for the user session, and the corresponding complexity coefficient corresponds to a higher level of complexity. For example, assuming a comprehensive risk score of 30, determine a complexity coefficient of 3 (high risk). Select generation parameters: Character length: 8 characters, Number of interference lines: 5, Noise intensity: High, Character set: Letters + Numbers + Special Symbols, Image distortion: Severe distortion. Use these parameters to generate a second verification code and store it encrypted in Redis.
[0051] In addition, a lightweight layered encryption system can also be used, and a layered processing architecture can be designed based on the characteristics of the verification code. The core characters use the AES-256-GCM encryption (integrity assurance) mode to ensure data integrity and anti-tampering capabilities, and resist replay attacks; the interference elements use the AES-128-CTR encryption (performance optimization) mode to optimize encryption performance and reduce resource usage; the transmission channel uses the HMAC-SHA256 signature (anti-tampering) mechanism to prevent middleman tampering and ensure end-to-end security; compared with the traditional unified encryption scheme, the performance is greatly improved, and the security is improved by multiple orders of magnitude.
[0052] At the same time, during the storage stage, you can also divide the storage area based on the risk level of the comprehensive risk score, store high-risk verification codes independently in Redis encrypted partitions, and extend their survival period, as follows.
[0053] In some embodiments of the present application, storing the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in the target database includes: determining a key identifier based on the session identifier and the comprehensive risk score of the user session, and forming a key-value pair with the key identifier and the encrypted verification code; when the comprehensive risk score is greater than a preset risk score threshold, storing the key-value pair in an encrypted partition in the target database, wherein the target database includes: a Redis database; setting the validity period of the second verification code corresponding to the key-value pair located in the encrypted partition to a first duration, and setting the validity period of the second verification code corresponding to the key-value pair located in other areas of the target database except the encrypted partition to a second duration, wherein the first duration is greater than the second duration, and within the validity period of the verification code, the user cannot trigger a new verification code generation request.
[0054] Specifically, in this embodiment, a composite key structure captcha:{sessionId (session identifier)}:{riskLevel (comprehensive risk score)} can be set to independently store high-risk verification codes in an encrypted partition and extend the validity period. For example, the first duration can be set to 10 minutes, and the second duration can be set to 5 minutes. This approach of dynamically adjusting the validity period of the verification code can enhance the monitoring and protection of high-risk sessions without affecting the user experience. For high-risk sessions, setting a longer validity period can reduce the frequent requests for new verification codes and reduce the burden on the system; for low-risk sessions, a shorter validity period can clear expired data more quickly and save database space. At the same time, restricting users from triggering new verification code generation requests within the validity period of the verification code can prevent malicious users from consuming system resources by continuously requesting verification codes, thereby protecting the stability and security of the system.
[0055] In addition, the CRC16 hash algorithm can be used to disperse data to Redis Cluster nodes to achieve master-slave read and write separation. The master node processes generated requests, and the slave node load verifies traffic to ensure stability in high-concurrency scenarios; thereby achieving efficient query of the Redis cluster.
[0056] The embodiments of this application achieve a balance between security and user experience by dynamically adjusting the complexity and storage strategy of the verification code through real-time risk scoring. In low-risk scenarios, the verification steps are simplified, shortening the user operation path and making the normal user verification process smoother. In high-risk scenarios, the complexity of the verification code is increased (such as character length, number of interference lines, noise intensity, etc.), and the validity period of the verification code is extended to enhance monitoring and protection against high-risk behaviors.
[0057] During the verification phase, the behavior verification threshold (i.e., the target similarity threshold) can be dynamically adjusted based on the comprehensive risk score. For example, the threshold can be increased by 20% for high-risk requests to achieve elastic defense. The following is a detailed introduction to the multi-factor verification and exception handling process in the verification phase.
[0058] First, during the verification phase, the server not only obtains the first verification code entered by the user, but also obtains the user's behavior data when entering the first verification code;
[0059] The server then uses the session identifier of the current user session to retrieve the encrypted verification code corresponding to the current session from Redis. If the result retrieved from Redis is null at this time, it means that the verification code has expired or does not exist, as follows.
[0060] In some embodiments of the present application, when the validity period of the second verification code has expired, the encrypted verification code corresponding to the second verification code is removed from the target database; obtaining the encrypted verification code corresponding to the current session identifier in the target database also includes: when the encrypted verification code corresponding to the session identifier is not queried in the target database, sending a first prompt message to the user device, wherein the first prompt message is used to indicate that the verification code has expired.
[0061] Specifically, when the encrypted verification code corresponding to the current session identifier is not obtained from the target database, a failed verification result may be returned, prompting "the verification code has expired".
[0062] If the verification code exists, the encrypted verification code is decrypted using the target key corresponding to the user session to obtain the original verification code text (i.e., the second verification code). Two-factor authentication is then performed: on the one hand, the first verification code entered by the user is determined to be consistent with the decrypted second verification code; on the other hand, the similarity between the user's real-time behavior feature vector and the behavior baseline model is calculated to determine whether the similarity exceeds the target similarity threshold. If both conditions are met, the verification passes; otherwise, the verification fails.
[0063] The specific process of collecting and verifying behavioral characteristics is as follows.
[0064] In some embodiments of the present application, the method also includes: determining a target similarity threshold based on a comprehensive risk score, wherein the higher the comprehensive risk score, the corresponding target similarity threshold is; performing feature extraction on the user behavior data to obtain a user behavior feature vector, wherein the user behavior data includes at least one of the following: the input time interval between each character when the user enters the verification code, and the time series of focus switching when the user enters the verification code; determining the feature similarity between the user's behavior feature vector and the behavior pattern feature represented by the user behavior baseline model, and comparing the size relationship between the feature similarity and the target similarity threshold.
[0065] Specifically, a behavioral feature vector can be constructed based on user behavior data (such as input interval discreteness, focus switching timing), etc., where the input time interval between each character when the user enters the verification code (input interval discreteness) can reflect the stability of the user's input speed, and the time series of focus switching can reveal the user's attention shift during the input process; the behavioral feature vector is calculated to have a similarity with the behavioral baseline model pre-stored in the database (i.e., the standardized behavior vector constructed by PCA dimensionality reduction) (for example, the weighted Euclidean distance between the real-time behavioral feature vector and the behavioral baseline model can be calculated), and the calculated similarity parameter is compared with the target similarity threshold, where the target similarity threshold can be dynamically adjusted based on the comprehensive risk score (for example, the default is 0.75, and the high-risk request is increased to 0.95).
[0066] By converting user behavior data into behavioral feature vectors, the system can leverage machine learning models for more precise behavioral analysis, identifying anomalous patterns and effectively distinguishing between real users and automated attacks. This feature extraction and analysis process not only enhances the system's security capabilities but also enables timely adjustments to verification strategies based on subtle changes in user behavior, improving system flexibility and responsiveness.
[0067] When the first verification code verification fails, you can perform re-verification or secondary verification based on the reason for verification identification, as follows.
[0068] In some embodiments of the present application, the method also includes the following steps: when the first verification code and the second verification code are different, determining that the first verification code entered by the user has failed verification, increasing the comprehensive risk score, and regenerating a new second verification code according to the increased comprehensive risk score, and sending it to the user device for re-verification; when the feature similarity is not greater than the target similarity threshold and the first verification code and the second verification code are the same, sending other types of verification information different from the type of the second verification code to the user device to perform a second verification on the user, wherein the other types include at least one of the following: SMS verification, slider verification.
[0069] For example, if a user enters an incorrect verification code three times in a row, their overall risk score can increase from an initial 20 points to 50 points. This dynamic adjustment of the risk score allows the system to update the user's risk level in real time based on their actual behavior. For users who frequently make mistakes, the system will consider them to be at a higher risk and generate more complex verification codes for verification. This approach enhances defense against potential malicious behavior through a penalty mechanism, while also reminding users to pay attention to their operational safety, thereby improving the overall security of the system.
[0070] If the user's behavioral feature vector is only 65% similar to the baseline model, which is lower than the target similarity threshold of 70%, the system will consider the risk of a potential automated attack even if the verification code is correct. In this case, the system can send a text message verification code to the user or require the user to complete a slider verification for secondary confirmation. This secondary verification mechanism provides an additional layer of security for high-risk scenarios, ensuring the security of the account. It can also effectively respond to complex and changing network attack methods, improving the system's security protection capabilities. By combining different types of verification information, the system can build a multi-layered security line of defense. Even if a verification link is breached, subsequent verification can prevent illegal access and protect the security of user data.
[0071] Alternatively, a sliding window verification mechanism can be adopted: a maximum of three attempts are allowed within the validity period, and after exceeding the limit, a forced refresh and an upgraded complexity are implemented.
[0072] Through these measures, we can update the user's risk level in real time based on their actual behavior, strengthening defenses against potential malicious behavior. Furthermore, we can select an appropriate secondary verification method, such as SMS verification or slider verification, based on the reason for the verification failure to ensure account security. Furthermore, we only allow a limited number of attempts, forcing a refresh and increasing the complexity after exceeding the limit to prevent brute force attacks. This not only improves the security and stability of the system, but also optimizes the user experience and ensures efficient system operation.
[0073] The present application scheme significantly enhances the security of the system and effectively prevents automated attacks and malicious login attempts by combining a dual verification mechanism of user behavior data and verification codes. By dynamically adjusting the complexity and validity period of the verification code, as well as the similarity threshold of user behavior, the verification process is made more intelligent and flexible, and the verification strategy can be adaptively adjusted according to the risk level of the user session, thereby improving the efficiency of security protection while ensuring the user experience. For high-risk sessions, the security of the account is further ensured through secondary verification, while for low-risk sessions, unnecessary verification steps are reduced, improving the smoothness of user operations. In addition, by distinguishing between encrypted and non-encrypted data for storage in the database, efficient management and secure storage of data are achieved, reducing the risk of data leakage. The combination and interaction of these technical features together constitute a verification code verification system that can effectively resist automated attacks while taking into account user experience, solving the problems of security vulnerabilities and poor user experience in traditional verification code verification mechanisms. By using technical means including but not limited to Redis database, key derivation algorithm, user behavior analysis model, etc., this technical solution can be widely used in various online services and systems. It can be applied to various occasions requiring verification code verification, such as website login, user registration, payment verification, etc., providing strong protection for system security and user experience.
[0074] According to an embodiment of the present application, an embodiment of a verification code verification device is also provided. Figure 4 Schematic diagram of a verification code verification device according to an embodiment of the present application. Figure 4 As shown, the device includes:
[0075] The data acquisition module 40 is configured to acquire a first verification code input by a user and user behavior data when the user inputs the first verification code, wherein the user behavior data is used to characterize the user's behavior characteristics when inputting the first verification code;
[0076] The key decryption module 42 is configured to obtain an encrypted verification code corresponding to the current session identifier from the target database and decrypt the encrypted verification code using the target key corresponding to the session identifier to obtain a second verification code. Each session identifier is used to uniquely identify a user session. In a user session, a user requests the server to generate a verification code and completes verification by entering the verification code issued by the server in a front-end interactive interface. Each user session corresponds to a target key.
[0077] The multiple verification module 44 is used to determine whether the first verification code input by the user has passed the verification when the feature similarity between the user behavior data and the user behavior baseline model is greater than the target similarity threshold and the first verification code is the same as the second verification code, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
[0078] Optionally, the verification code verification device is also used to: generate a second verification code in response to a verification code generation request, and determine context information corresponding to the verification code generation request, wherein the context information includes at least one of the following: an Internet Protocol address of the user device, a device fingerprint hash value of the user device, and a timestamp of receiving the verification code generation request; determine a target salt value based on the context information, and use a key derivation algorithm to generate a target key based on the target salt value, wherein the validity period of the target key is consistent with the validity period of the second verification code; encrypt the second verification code based on the target key to obtain an encrypted verification code; and store the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in a target database.
[0079] Optionally, generating a second verification code includes: obtaining relevant information of the user who triggered the verification code generation request, wherein the relevant information includes at least one of the following: the frequency of the verification code generation request triggered by the user within a preset time period, and whether the Internet Protocol address of the user device is in the abnormal address list; based on the relevant information, determining the comprehensive risk score of the user session corresponding to the verification code generation request; based on the comprehensive risk score, determining the complexity coefficient of the verification code, wherein the complexity coefficient is used to indicate the generation parameters of the verification code, wherein the generation parameters include at least one of the following: character length, number of interference lines, and noise intensity, wherein the higher the comprehensive risk score, the higher the complexity corresponding to the corresponding complexity coefficient; generating a second verification code according to the generation parameters corresponding to the complexity coefficient.
[0080] Optionally, storing the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in the target database includes: determining a key identifier based on the session identifier and the comprehensive risk score of the user session, and forming a key-value pair with the key identifier and the encrypted verification code; when the comprehensive risk score is greater than a preset risk score threshold, storing the key-value pair in an encrypted partition in the target database, wherein the target database includes: a Redis database; setting the validity period of the second verification code corresponding to the key-value pair located in the encrypted partition to a first duration, and setting the validity period of the second verification code corresponding to the key-value pair located in other areas of the target database except the encrypted partition to a second duration, wherein the first duration is greater than the second duration, and within the validity period of the verification code, the user cannot trigger a new verification code generation request.
[0081] Optionally, the verification code verification device is also used to: determine a target similarity threshold based on a comprehensive risk score, wherein the higher the comprehensive risk score, the corresponding target similarity threshold is; perform feature extraction on user behavior data to obtain a user behavior feature vector, wherein the user behavior data includes at least one of the following: the input time interval between each character when the user enters the verification code, and the time series of focus switching when the user enters the verification code; determine the feature similarity between the user's behavior feature vector and the behavior pattern feature represented by the user behavior baseline model, and compare the size relationship between the feature similarity and the target similarity threshold.
[0082] Optionally, the verification code verification device is also used to: when the first verification code and the second verification code are different, determine that the first verification code input by the user has failed verification, increase the comprehensive risk score, and regenerate a new second verification code according to the increased comprehensive risk score, and send it to the user device for re-verification; when the feature similarity is not greater than the target similarity threshold and the first verification code and the second verification code are the same, send other types of verification information different from the type of the second verification code to the user device to perform a second verification on the user, wherein the other types include at least one of the following: SMS verification, slider verification.
[0083] Optionally, when the validity period of the second verification code has expired, the encrypted verification code corresponding to the second verification code is removed from the target database; obtaining the encrypted verification code corresponding to the current session identifier in the target database also includes: when the encrypted verification code corresponding to the session identifier is not queried in the target database, sending a first prompt message to the user device, wherein the first prompt message is used to indicate that the verification code has expired.
[0084] It should be noted that the various modules in the above-mentioned verification code verification device can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.
[0085] It should be noted that the verification code verification device provided in this embodiment can be used to perform Figure 2 The verification code verification method shown, therefore, the relevant explanations of the above verification code verification method are also applicable to the embodiments of the present application and will not be repeated here.
[0086] An embodiment of the present application also provides a non-volatile storage medium, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the following verification code verification method by running the computer program: obtaining a first verification code input by a user, and user behavior data when the user enters the first verification code, wherein the user behavior data is used to characterize the behavioral characteristics of the user when entering the first verification code; obtaining an encrypted verification code corresponding to a current session identifier in a target database, and decrypting the encrypted verification code using a target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to identify a uniquely determined user session, in which the user requests a server to generate a verification code, and completes verification by entering the verification code issued by the server in a front-end interactive interface, and each user session corresponds to a target key; when the feature similarity between the user behavior data and the user behavior baseline model is greater than a target similarity threshold, and the first verification code is the same as the second verification code, it is determined that the first verification code input by the user has passed verification, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
[0087] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the verification code verification method described in each embodiment of the present application: obtaining a first verification code input by a user, and user behavior data when the user enters the first verification code, wherein the user behavior data is used to characterize the behavioral characteristics of the user when entering the first verification code; obtaining an encrypted verification code corresponding to a current session identifier in a target database, and decrypting the encrypted verification code using a target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to identify a uniquely determined user session, in which the user requests a server to generate a verification code, and completes verification by entering the verification code issued by the server in a front-end interactive interface, and each user session corresponds to a target key; if the feature similarity between the user behavior data and the user behavior baseline model is greater than a target similarity threshold, and the first verification code is the same as the second verification code, determining that the first verification code input by the user has passed verification, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
[0088] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0089] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0090] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0091] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0092] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0093] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0094] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A verification code verification method, characterized in that: include: Obtaining a first verification code input by a user and user behavior data of the user when entering the first verification code, wherein the user behavior data is used to characterize behavioral characteristics of the user when entering the first verification code; Obtaining an encrypted verification code corresponding to the current session identifier in the target database, and decrypting the encrypted verification code using the target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to identify a uniquely determined user session. In the user session, the user requests the server to generate a verification code and completes verification by entering the verification code issued by the server in the front-end interactive interface. Each user session corresponds to one target key; When the feature similarity between the user behavior data and the user behavior baseline model is greater than the target similarity threshold, and the first verification code is the same as the second verification code, it is determined that the first verification code input by the user has passed the verification, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
2. The verification code verification method according to claim 1, wherein: The method further comprises: In response to the verification code generation request, generate the second verification code, and determine context information corresponding to the verification code generation request, wherein the context information includes at least one of the following: an Internet Protocol address of the user device, a device fingerprint hash value of the user device, and a timestamp of receiving the verification code generation request; Determining a target salt value based on the context information, and generating the target key based on the target salt value using a key derivation algorithm, wherein the validity period of the target key is consistent with the validity period of the second verification code; Encrypting the second verification code according to the target key to obtain the encrypted verification code; The session identifier of the user session corresponding to the verification code generation request and the encrypted verification code are stored in the target database.
3. The verification code verification method according to claim 2, characterized in that: Generating the second verification code includes: Obtaining relevant information about the user who triggered the verification code generation request, wherein the relevant information includes at least one of the following: the frequency of the verification code generation request triggered by the user within a preset time period, and whether the Internet Protocol address of the user device is in a list of abnormal addresses; Determining a comprehensive risk score of the user session corresponding to the verification code generation request based on the relevant information; Determining a complexity coefficient of the verification code based on the comprehensive risk score, wherein the complexity coefficient is used to indicate generation parameters of the verification code, wherein the generation parameters include at least one of the following: character length, number of interference lines, and noise intensity, wherein a higher comprehensive risk score corresponds to a higher degree of complexity corresponding to the complexity coefficient; The second verification code is generated according to the generation parameter corresponding to the complexity coefficient.
4. The verification code verification method according to claim 3, wherein: Storing the session identifier of the user session corresponding to the verification code generation request and the encrypted verification code in the target database includes: Determine a key identifier based on the session identifier of the user session and the comprehensive risk score, and form a key-value pair with the key identifier and the encrypted verification code; If the comprehensive risk score is greater than a preset risk score threshold, the key-value pair is stored in an encrypted partition in the target database, wherein the target database includes: a Redis database; The validity period of the second verification code corresponding to the key-value pair located in the encrypted partition is set to a first duration, and the validity period of the second verification code corresponding to the key-value pair located in other areas of the target database except the encrypted partition is set to a second duration, wherein the first duration is greater than the second duration, and within the validity period of the verification code, the user cannot trigger a new verification code generation request.
5. The verification code verification method according to claim 3, wherein: The method further comprises: Determining the target similarity threshold based on the comprehensive risk score, wherein the higher the comprehensive risk score, the higher the target similarity threshold; Performing feature extraction on the user behavior data to obtain a user behavior feature vector, wherein the user behavior data includes at least one of the following: an input time interval between each character when the user enters the verification code, and a time series of focus switching when the user enters the verification code; The feature similarity between the user's behavior feature vector and the behavior pattern feature represented by the user behavior baseline model is determined, and the magnitude relationship between the feature similarity and the target similarity threshold is compared.
6. The verification code verification method according to claim 5, characterized in that: The method further comprises: If the first verification code is different from the second verification code, determining that the first verification code entered by the user fails verification, increasing the comprehensive risk score, regenerating a new second verification code according to the increased comprehensive risk score, and sending the new second verification code to the user device for re-verification; When the feature similarity is not greater than the target similarity threshold and the first verification code is the same as the second verification code, other types of verification information that are different from the type of the second verification code are sent to the user device to perform a second verification on the user, wherein the other types include at least one of the following: SMS verification and slider verification.
7. The verification code verification method according to claim 2, wherein: When the validity period of the second verification code has expired, removing the encrypted verification code corresponding to the second verification code from the target database; Obtaining the encrypted verification code corresponding to the current session identifier in the target database also includes: If the encrypted verification code corresponding to the session identifier is not found in the target database, first prompt information is sent to the user equipment, wherein the first prompt information is used to indicate that the verification code has expired.
8. A verification code verification device, characterized in that: include: a data acquisition module, configured to acquire a first verification code input by a user and user behavior data of the user when inputting the first verification code, wherein the user behavior data is used to characterize the behavioral characteristics of the user when inputting the first verification code; a key decryption module, configured to obtain an encrypted verification code corresponding to the current session identifier in a target database, and decrypt the encrypted verification code using a target key corresponding to the session identifier to obtain a second verification code, wherein each session identifier is used to identify a uniquely determined user session. In the user session, the user requests the server to generate a verification code and completes verification by entering the verification code issued by the server in a front-end interactive interface. Each user session corresponds to one target key; A multiple verification module is used to determine whether the first verification code input by the user has passed verification when the feature similarity between the user behavior data and the user behavior baseline model is greater than a target similarity threshold and the first verification code is the same as the second verification code, wherein the user behavior baseline model is used to characterize the behavioral pattern characteristics of human users during normal interaction.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the verification code verification method according to any one of claims 1 to 7 is executed when the program is run.
10. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the verification code verification method according to any one of claims 1 to 7 by running the computer program.
11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the verification code verification method according to any one of claims 1 to 7 are implemented.