Login verification method and electronic equipment

By generating a dynamic interactive interface based on a real physical motion model on the client, generating a motion trajectory based on user operation information, and performing deviation distance judgment on the server, the security and privacy leakage problems of existing user verification methods are solved, and efficient and secure login verification is achieved.

CN120705847AActive Publication Date: 2025-09-26INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511181418.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-09-26
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

Existing user verification methods are not secure enough and are easily cracked when facing attacks from generative artificial intelligence and deep fake technology. In addition, SMS and email verification have high latency and privacy leakage risks.

Method used

By generating a dynamic interactive interface based on a real physical motion model on the client, generating a motion trajectory based on user operation information, and performing deviation distance judgment on the server, a dynamic and physically based verification method is implemented to avoid image recognition and trajectory reproduction attacks.

Benefits of technology

It improves the protection capability of verification, prevents malicious logins and automated attacks, avoids delays and privacy leaks, adapts to different devices and scenarios, and improves security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705847A_ABST
    Figure CN120705847A_ABST
Patent Text Reader

Abstract

The invention discloses a login verification method and electronic equipment, and relates to the technical field of login verification, and the method comprises the steps: responding to a verification data packet sent by a server, generating a verification interaction interface at least comprising a first object and a second object, and setting the position of the first object according to a first position parameter, setting the position of the second object according to the second position parameter; recording operation information of the user on the first object in response to the acquired interaction starting operation of the user on the first object; in response to an obtained interaction ending operation of the user on the first object, generating a first motion track of the first object, and determining a corresponding first drop point position; and sending the interaction data packet at least comprising the first drop point position to a server side, so that the server side executes verification judgment. According to the method, real physical motion modeling and client interaction behavior analysis can be fused, the verification protection capability is improved, and the problem that the verification attack protection capability is insufficient in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of login verification, and in particular to a login verification method and electronic device. Background Art

[0002] As information systems, mobile applications, and web platforms increasingly demand more user authentication, various verification code technologies are widely used to prevent malicious logins and automated attacks. Existing user verification methods primarily include character recognition verification codes, image selection verification, SMS or email verification codes, and dynamic interactive verification methods like sliding puzzles. While these verification methods have achieved some success in improving user experience and preventing simple script attacks, their security is facing severe challenges in the face of increasingly complex adversarial attack techniques.

[0003] Against the backdrop of the rapid development of generative artificial intelligence (AIGC) and deep fake technology, attack methods based on image recognition and trajectory reproduction are constantly evolving. On the one hand, static verification methods such as character recognition verification codes and image selection verification codes can achieve extremely high cracking rates. On the other hand, although sliding puzzle verification introduces behavioral trajectory analysis, fixed simple paths are also easily cracked by trajectory reproduction technology. In addition, SMS and email verification methods also face the problems of high latency and privacy leakage risks. Summary of the Invention

[0004] The present application provides a login verification method and electronic device that can integrate real physical motion modeling with client interaction behavior analysis to improve the protection capability of verification, thereby effectively preventing malicious logins and automated attacks and ensuring system security, so as to at least solve the problems in related technologies of insufficient resistance to existing verification attack technologies such as image recognition and trajectory reproduction, high latency, and the risk of privacy leakage.

[0005] On the one hand, the present application provides a login verification method, which is applied to a client, including: In response to the client receiving the verification data packet sent by the server, the client parses the verification data packet to obtain verification interaction interface generation parameters, object ejection motion model, first position parameters and second position parameters; Generate a verification interaction interface including at least a first object and a second object according to the verification interaction interface generation parameter, and set the position of the first object according to the first position parameter and the position of the second object according to the second position parameter; In response to obtaining a user's interaction start operation on the first object, recording the user's operation information on the first object and updating the display position of the first object; In response to obtaining a user interaction end operation on the first object, generating a first motion trajectory of the first object based on the object ejection motion model, the operation information, and the current position of the first object, and determining a corresponding first landing point position; The interactive data packet including at least the first landing point position is sent to the server for the server to perform verification and determination.

[0006] On the other hand, the present application provides a login verification method, which is applied to the server, including: In response to the server receiving the verification request sent by the client, the server selects a verification interaction interface that matches the client and generates a first position parameter and a second position parameter to respectively control the position of the first object and the second object on the verification interaction interface; Setting the object ejection motion model, and combining the verification interaction interface generation parameters, the first position parameters, and the second position parameters, generating a verification data packet and sending it to the client; In response to receiving the interaction data packet fed back by the client, parsing the interaction data packet to obtain a first landing point position of the first object; Calculating a deviation distance between the first landing point position and the position of the second object, and comparing the deviation distance with a deviation threshold; In response to the deviation distance being less than or equal to the deviation threshold, determining that the verification is passed, and sending a verification pass data packet to the client; In response to the deviation distance being greater than the deviation threshold, it is determined that the verification fails, and an object position reset parameter is generated, encapsulated into a verification failure data packet, and sent to the client.

[0007] On the other hand, the present application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any one of the above-mentioned login verification methods when executing the computer program.

[0008] Through this application, the verification data packet is parsed on the client and the verification interaction interface is generated based on the parameters, object ejection motion model and position parameters of the verification interaction interface, and the motion trajectory and landing position are generated by combining the user's actual operation information with the object ejection motion model. This realizes the introduction of real physical motion simulation into the user verification process. Compared with traditional static or fixed-path verification codes, a dynamic and physical-based interaction method is realized, which makes it difficult to automatically crack through image recognition or trajectory reproduction attack technology, thereby improving the verification protection capability; in addition, compared with SMS email verification, this application does not need to obtain additional user information, and performs real-time verification through the device network, avoiding the problems of high latency and user privacy leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0010] Figure 1 An application environment for a login verification method provided in an embodiment of the present application; Figure 2 A flowchart of a login verification method applied to a client provided in an embodiment of the present application; Figure 3 A flowchart of a login verification method applied to a server provided in an embodiment of the present application; Figure 4 A login verification interaction flow chart provided in an embodiment of the present application; Figure 5 A schematic diagram of a verification interaction interface provided in an embodiment of the present application; Figure 6 A schematic diagram of a login verification process provided in an embodiment of the present application; Figure 7 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0011] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0012] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.

[0013] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0014] This application provides a login verification method that can be applied to Figure 1In the application environment shown. Among them, the client 102 communicates with the server 104 through the network, and the user enters the login information such as the account and password in the client 102. When the information is correct, the client 102 sends a verification request to the server 104, and the server 104 feeds back a verification data packet. The client 102 generates and displays a verification interaction interface. The user operates the first object on the verification interaction interface for verification. The client 102 records the final first landing position and sends it to the server 104, and based on the verification result fed back by the server 104, the user is logged in or re-verified. Among them, the client 102 can be, but is not limited to, various personal computers, laptops, smart phones, tablet computers and portable wearable devices, and the server 104 can be implemented with an independent server or a server cluster consisting of multiple servers.

[0015] like Figure 2 As shown, an embodiment of the present application provides a login verification method, which is applied to the client 102 and includes: Step 201: In response to receiving a verification data packet sent by a server, parsing the verification data packet to obtain verification interaction interface generation parameters, an object ejection motion model, a first position parameter, and a second position parameter; Step 202: Generate a verification interaction interface including at least a first object and a second object according to the verification interaction interface generation parameters, and set the position of the first object according to the first position parameter and the position of the second object according to the second position parameter; Step 203: In response to obtaining the user's interaction start operation on the first object, recording the user's operation information on the first object and updating the display position of the first object; Step 204: In response to obtaining the user's interaction end operation on the first object, generating a first motion trajectory of the first object based on the object ejection motion model, the operation information, and the current position of the first object, and determining a corresponding first landing point position; Step 205: Send the interactive data packet including at least the first landing point location to the server for the server to perform verification and determination.

[0016] Specifically, this application parses the verification data packet on the client and generates a verification interaction interface based on the verification interaction interface parameters, object ejection motion model and position parameters, and combines the user's actual operation information with the object ejection motion model to generate the motion trajectory and landing position, thereby introducing real physical motion simulation into the user verification process. Compared with traditional static or fixed-path verification codes, a dynamic and physical-based interaction method is realized, which makes it difficult to automatically crack through image recognition or trajectory reproduction attack technology, thereby improving the verification protection capability; in addition, compared with SMS email verification, this application does not need to obtain additional user information, and performs real-time verification through the device network, avoiding the problems of high latency and user privacy leakage.

[0017] In one embodiment, before the client receives the verification data packet sent by the server, the process further includes: Generate a login data packet based on the account information entered by the user and send it to the server, so that the server can compare the account information with the user data stored in the database and feedback the comparison results; In response to receiving a comparison result from the server that is consistent, the account information entered by the user is determined to be correct, and a verification request is sent to the server to obtain a verification data packet; In response to receiving a comparison result from the server that is inconsistent, it is determined that the account information entered by the user is incorrect and a login failure prompt is output.

[0018] Specifically, in this embodiment, by adding an account information consistency comparison step before receiving the verification data packet, it is possible to eliminate obviously incorrect or non-existent accounts in advance in the first stage of identity authentication, reduce the triggering frequency of invalid verification interactions, thereby reducing server and client resource consumption, and improving the overall login response speed.

[0019] In one embodiment, generating a first motion trajectory of the first object based on the object ejection motion model, the operation information, and the current position of the first object, and determining a corresponding first landing point position includes: Calculate an initial velocity vector of the first object according to the operation information; Inputting the initial velocity vector and the current position of the first object into the object ejection motion model, simulating the two-dimensional motion process of the first object based on the gravity acceleration and air resistance simulation parameters set in the object ejection motion model, and generating a first motion trajectory; Determine the intersection of the first motion trajectory and the horizon in the verification interaction interface, and use the position of the intersection as the first landing point.

[0020] Specifically, in this embodiment, physical simulation parameters such as gravitational acceleration and air resistance are introduced when generating the first motion trajectory, so that the motion trajectory of the object is closer to the real physical motion process, which can prevent attackers from simply fitting a fixed trajectory model, significantly increase the difficulty of automated scripts simulating clicks / dragging, and enhance security.

[0021] In one embodiment, calculating the initial velocity vector of the first object according to the operation information includes: Determine the starting position coordinates of the first object according to the first position parameter and use them as the emission reference point; Parse the operation information to obtain the stretching end point coordinates and displacement duration of the first object; According to the coordinates of the launch reference point and the stretching end point, the stretching displacement and displacement direction are calculated; The opposite direction of the displacement direction is used as the initial movement direction of the first object; Calculating an initial velocity of the first object according to the stretching displacement and the displacement duration; The initial motion direction and initial velocity are combined to obtain the initial velocity vector.

[0022] Specifically, this embodiment extracts the coordinates of the stretching end point and the displacement duration from the user operation information, calculates the initial velocity vector, and uses the opposite direction of the displacement as the initial movement direction. This enables fine-grained restoration of the mechanical characteristics of the user operation, further improving the randomness and personalization of the trajectory. Even if an attacker captures the operation data, it is difficult to reproduce the same trajectory on different devices and scenarios.

[0023] In a preferred embodiment, calculating the initial velocity of the first object based on the stretching displacement and the displacement duration further includes: Based on the adaptive calculation method combining the device interaction accuracy and the interface scaling parameters, the pixel length scale coefficient is set, which is specifically expressed as: ; Wherein, k represents the pixel length ratio coefficient, k0 represents the preset initial ratio coefficient, preferably in the range of 0.5-1.5 mm / px, more preferably 1.0 mm / px, S ui Generate parameters for verifying the interactive interface, is the device interaction accuracy, which is obtained by the server from the client; f(·) is preferably a monotonically increasing function so that low-precision devices can appropriately amplify the displacement mapping; The stretch displacement is multiplied by the set pixel length ratio coefficient, and the stretch displacement of the first object in the verification interaction interface in pixels is converted into a physical displacement in the object ejection motion model, and the converted stretch displacement is obtained and the initial velocity is calculated.

[0024] Specifically, this embodiment introduces a pixel length scaling coefficient in the initial speed calculation process and adopts an adaptive calculation method that combines device interaction accuracy and interface scaling parameters. This ensures that the initial speeds generated by devices with different resolutions and scaling ratios under the same gesture operation remain consistent, significantly improving the consistency and fairness of the cross-device interaction experience. At the same time, the preferred range of the scaling coefficient is 0.5-1.5 mm / px, and the displacement mapping and amplification compensation of low-precision devices is performed through a monotonically increasing function, which can effectively reduce the speed attenuation caused by insufficient touch accuracy, thereby improving the accuracy of interactive verification and the controllability of user operations. In addition, this embodiment has good scalability and can adapt to different screen sizes, resolutions and interface layouts, avoiding the instability problem caused by a fixed scaling coefficient in a multi-terminal environment.

[0025] It is worth noting that, in a preferred embodiment, the object ejection motion model is a parabolic motion model, the verification interaction interface is a two-dimensional plane coordinate system, the horizontal direction is the x-axis, the vertical direction is the y-axis, the gravitational acceleration is g, and the air resistance is α (α=0 when there is no air resistance), the first motion trajectory can be expressed as: ; Among them, (x s ,y s ) is the coordinate of the stretching end point of the first object, v 0x Represents the component of the initial velocity vector on the x-axis, which is the initial velocity vector multiplied by the cosine of the displacement direction, v 0y represents the component of the initial velocity vector on the y-axis, which is the initial velocity vector multiplied by the sine of the displacement direction, and t represents the motion time of the first object; The first motion trajectory can also be expressed in the form of y(x): ; Wherein, x represents the horizontal displacement of the first object in the verification interaction interface, and y represents the vertical displacement of the first object. Both are calculated with the coordinates of the stretching end point of the first object as the reference point, and the interaction interface coordinates are converted into physical coordinates through the pixel length scale coefficient.

[0026] like Figure 3 As shown, the embodiment of the present application also provides a login verification method, which is applied to the server 104 and includes: Step 301: In response to receiving a verification request sent by a client, selecting a verification interaction interface that matches the client, and generating a first position parameter and a second position parameter to respectively control the position of a first object and a second object on the verification interaction interface; Step 302: Set the object ejection motion model, and generate a verification data packet based on the verification interaction interface generation parameters, the first position parameter, and the second position parameter, and send the verification data packet to the client; Step 303: In response to receiving the interactive data packet fed back by the client, the interactive data packet is parsed to obtain a first landing point position of the first object; Step 304: Calculate the deviation distance between the first landing point position and the position of the second object, and compare the deviation distance with a deviation threshold; Step 305: In response to the deviation distance being less than or equal to the deviation threshold, it is determined that the verification is passed, and a verification pass data packet is sent to the client; In step 306 , in response to the deviation distance being greater than the deviation threshold, the verification is determined to be unsuccessful, and object position reset parameters are generated, encapsulated into a verification failure data packet, and sent to the client.

[0027] Specifically, this application introduces the object ejection motion model and position parameters when the server generates the verification data packet, and determines the result by comparing the deviation distance with the threshold after receiving the landing position of the client. It can achieve unified control and verification of the physical simulation trajectory by the server, avoid unilateral falsification of verification results by the client, and at the same time, send reset parameters in case of failure, support multiple rounds of defense and dynamic difficulty adjustment, and improve the security and availability of verification protection.

[0028] In one embodiment, selecting a verification interaction interface that matches the client includes: Parse the verification request to obtain the client's device type information and interface display parameters; According to the device type information, an interface matching the client is selected from a preset verification interaction interface template as the verification interaction interface, and corresponding verification interaction interface generation parameters are generated according to the interface display parameters.

[0029] Specifically, this embodiment matches the verification interaction interface template by parsing the client device type information and interface display parameters, which can optimize the interaction interface for different devices, such as PCs and mobile devices, and improve the smoothness and adaptability of operations; at the same time, it prevents the imbalance of verification difficulty due to device resolution or interaction differences, and enhances the user experience.

[0030] In one embodiment, generating a first position parameter and a second position parameter to respectively control positions of a first object and a second object on a verification interaction interface includes: Determine the interactive area based on the verified interactive interface; Randomly select multiple candidate initial position coordinates within the interactive area, and randomly select a safe initial position whose distance from the interface boundary of the verification interaction interface is greater than or equal to a first safe distance threshold as the position of the first object and generate a first position parameter; Parse the verification request and obtain the client's interactive feature parameters; Obtaining a hittable area of ​​the first object by calculating the object ejection motion model according to the first position parameter and the interaction characteristic parameter; A safe target position whose distance from the interface boundary of the verification interaction interface is greater than or equal to a second safe distance threshold is randomly selected in the hittable area as the position of the second object and a second position parameter is generated.

[0031] Specifically, in this embodiment, the dynamic calculation of the safety distance threshold and the hittable area is introduced in the process of generating the first object position and the second object position, which not only ensures the feasibility of the interaction, but also avoids erroneous operations caused by the object position being close to the interface boundary; at the same time, by randomizing the position in combination with the interaction characteristic parameters, it prevents attackers from predicting the target position and improves the randomness of protection.

[0032] In one embodiment, before calculating the deviation distance between the first landing point position and the second object position and comparing the deviation distance with a deviation threshold, the method further includes: Get the client's device interaction accuracy; According to the device interaction accuracy and verification interaction interface generation parameters, a deviation threshold is set, where the deviation threshold is preferably set to 50 pixels.

[0033] Specifically, in this embodiment, the deviation threshold is dynamically set according to the interaction accuracy of the client device before judging the verification result. It can automatically adjust the verification fault tolerance range according to the differences in device input accuracy, such as touch screen and mouse, which not only ensures security, but also avoids misjudgment caused by too small a threshold, thereby improving the verification success rate across devices.

[0034] In a preferred embodiment, after setting the deviation threshold according to the device interaction accuracy and the verification interaction interface generation parameters, the method further includes: In response to the server determining that the user's current verification fails and receiving a re-verification request from the client, the server queries the cumulative number of verification failures of the user within a preset period; If the cumulative number of verification failures is less than or equal to the cumulative failure limit, a tolerance threshold is generated based on the cumulative number of verification failures and the failure tolerance coefficient, and the deviation threshold is increased by the tolerance threshold. When the next interactive data packet fed back by the client is received, the verification judgment is re-executed based on the increased deviation threshold, and the process is repeated recursively until the cumulative number of verification failures exceeds the cumulative failure limit. If the cumulative number of verification failures is greater than the cumulative failure limit, all tolerance thresholds are deleted to reset the deviation threshold.

[0035] Specifically, this embodiment introduces a dynamic tolerance threshold adjustment mechanism based on the number of recent user verification failures on the basis of setting a deviation threshold according to device interaction accuracy and verification interaction interface generation parameters. The deviation threshold can be gradually relaxed according to the cumulative number of verification failures within a preset period to reduce the misjudgment rate caused by factors such as accidental operation deviation, insufficient touch accuracy or network delay, thereby improving the verification pass rate of real users; at the same time, an upper limit on cumulative failures is set and all tolerance thresholds are deleted after exceeding the limit to reset the deviation threshold, so as to prevent attackers from gradually expanding the fault tolerance range through multiple attempts to crack, thereby achieving a dynamic balance between security and user experience.

[0036] In one embodiment, determining that the verification fails and generating object position reset parameters include: Record the current first position parameter and the current second position parameter; Randomly select a safe reset position other than the current first position parameter from the interactive area as the reset position of the first object and generate the first object position reset parameter; Based on the reset position of the first object, the hittable area of ​​the first object is recalculated, and a safe target reset position other than the current second position parameter is randomly selected as the reset position of the second object and the second object position reset parameter is generated.

[0037] Specifically, in this embodiment, by recording the current first position parameters and the second position parameters and excluding these parameters when reselecting the position, the predictability of the trajectory caused by position duplication is avoided, thereby effectively improving the randomness and security of the verification process; at the same time, by recalculating the hittable area after the first object position is reset, and selecting the reset position of the second object accordingly, the rationality and interactive challenge of the spatial distribution of the target position and the starting position are guaranteed, so that the verification task is both completeable and can prevent users from circumventing verification by memorizing or speculating on the position to a certain extent.

[0038] like Figure 4 As shown, the embodiment of the present application also provides a login verification method, including: Step 401: The client sends a verification request to the server, and the server generates and feeds back a verification data packet to the client. Step 402: The client generates a verification interaction interface including at least a first object and a second object according to the verification data packet, and sets the position of the first object and the position of the second object respectively; In step 403, in response to obtaining the user's interaction start operation on the first object, the client records the corresponding operation information. In response to obtaining the user's interaction end operation on the first object, the client determines the first landing point of the first object based on the operation information and the current position of the first object and sends the first landing point position to the server. Step 404: The server determines whether the verification is successful based on the deviation distance between the first landing point and the second object, and feeds back the verification result to the client. Step 405: In response to the verification result being passed, the client ends the verification interaction interface; Step 406: In response to the verification result being a failure, the client retains the verification interaction interface and resets the position of the first object and the position of the second object respectively.

[0039] Specifically, this embodiment implements a complete closed loop of verification request, interaction generation, trajectory landing point calculation and server-side judgment between the client and the server, and dynamically adjusts the interactive interface state according to the verification results, which not only improves the continuity and interactivity of user verification, but also strikes a balance between security and user experience.

[0040] like Figure 5 As shown, in one embodiment, a verification interaction interface is set, in which a sports ball 501 as a first object and a fixed ball 502 as a second object are set. The user clicks and long presses the sports ball 501 to move it backward to achieve a slingshot stretch. After the user loosens and releases the sports ball 501, the sports ball 501 moves parabolically to the position of the landing ball 503, that is, the first landing position. At this time, the distance between the center of the landing ball 503 and the fixed ball 502 is used as the deviation distance to perform subsequent verification judgment.

[0041] It's worth noting that to enhance the user interaction experience, this embodiment can display the object's ejection trajectory in real time within the verification interface and provide animated feedback to clarify the user's operation results. Furthermore, interactive objects can be designed with a variety of shapes, colors, or features to indicate the user's operation direction and force. This embodiment is highly scalable, allowing for the addition of new object types, interface templates, or gesture operations without impacting existing solutions, facilitating system upgrades and cross-platform deployment.

[0042] like Figure 6As shown, in one embodiment, the user enters login information, such as an account name and password, into the client. When the login information is correct, the client initiates a verification request to the server, and the server feeds back a verification data packet, which stores verification interaction interface generation parameters, an object ejection motion model, a first position parameter, and a second position parameter. The client generates and displays a verification interaction interface to the user based on the received verification data packet. On the verification interface, the user uses the position of the second object as a reference target to operate the first object, such as clicking and long pressing to stretch and drag, and releasing to release the object to pop up, so that the first object moves in a motion manner that conforms to the object ejection motion model, such as throwing the object. The object moves linearly, generates a first trajectory, and arrives at the first landing point; the client sends the first landing point to the server, and the server determines whether the verification is passed based on the deviation distance between the first landing point and the position of the second object and feeds back to the client; if passed, the client ends the verification interaction interface and allows the user to log in; if not, the client records the number of failures and re-requests the first position parameter and the second position parameter from the server to update the positions of the first object and the second object on the verification interaction interface for the user to re-operate, until the number of user failures reaches the upper limit, for example 3 times, at which time the verification interaction interface is closed and the user's login operation is denied for 5-10 minutes.

[0043] In one embodiment, the present application provides a login verification method, further comprising: The client calculates the initial velocity vector of the first object based on the acquired user operation information, and makes multiple small adjustments to the initial velocity direction and rate to increase the unpredictability of the motion trajectory. When detecting that the duration, displacement length, or operation speed of the user's stretching operation is abnormal, triggering a security process, which at least includes: regenerating the positions of the first object and the second object, and adjusting the verification target position to increase the difficulty of verification; The server collects statistics on the user's interactive behavior data within a preset period, analyzes the operation mode, identifies abnormal or repetitive behaviors, and dynamically adjusts the verification parameters based on the identification results, including at least: deviation threshold and random perturbation amplitude, to improve verification security.

[0044] It is worth noting that in this embodiment, when a user manipulates a first object on the verification interaction interface, the client generates an initial velocity vector for the first object based on the user's stretching action. Subsequently, the client adds a small random perturbation to the initial velocity vector, so that the same user operation produces slightly different motion trajectories in each verification, thereby enhancing the system's anti-attack capabilities. During the operation, the client will continuously monitor the user's operation status. If it detects that the operation time is too short or too long, the stretching displacement is too large or too small, or the operation speed is abnormal, the system will trigger a safety processing mechanism. The safety processing includes re-randomly generating the positions of the first and second objects, or adjusting the verification target position to increase the verification difficulty appropriately, thereby preventing users or attack programs from using extreme operations to bypass the verification logic. In addition, the server will collect statistics on the user's interactive behavior data within a preset period, including trajectory shape, operation time and speed distribution, and analyze the operation pattern; by identifying abnormal or repetitive patterns, the system can dynamically adjust the verification parameters, such as appropriately increasing the random perturbation amplitude or adjusting the deviation threshold, making it difficult for automated attacks and trajectory reproduction attacks to succeed, while ensuring that legitimate user operations can still successfully complete verification.

[0045] Specifically, in this embodiment, random perturbations are introduced into the initial velocity vector and motion trajectory, making it impossible for attackers to accurately reproduce the user trajectory, thereby enhancing the security of the system and improving the anti-attack capability; detecting and processing overly fast, overly slow or extreme operations to prevent users or attack programs from bypassing the verification logic, enhancing protection against abnormal operations, and thus improving verification reliability; by counting multiple user operation data, identifying abnormal and repetitive behaviors, and dynamically adjusting verification parameters, dynamically adapting to multiple interactions, and improving the system's ability to resist automated attacks and batch cracking behaviors; combining device interaction accuracy and interface parameters to set random perturbations and security processing amplitudes to ensure that the verification difficulty and operation experience are consistent under different terminal devices, achieve consistency across devices, and improve user experience and fairness.

[0046] It is worth noting that the login verification method provided by the present application can significantly overcome the shortcomings of traditional verification methods in terms of security, user experience and cross-device adaptability compared to the existing technology. Specifically: First, in response to the problem that static verification methods such as character recognition verification codes and image selection verification codes are easily hacked by image recognition algorithms and deep fake technologies, the present application introduces a dynamic interaction method based on a physical motion model. By generating an operable first object and a second object on the client, and combining user operations to generate an initial velocity vector and a motion trajectory, the object's ejection motion conforms to real physical laws, such as parabolic motion and air resistance simulation, making it difficult for attackers to achieve automated cracking through fixed trajectory fitting or trajectory reproduction technology; secondly, in response to the problem that fixed paths in sliding puzzle verification are easily attacked by trajectory reproduction, the present application randomizes the initial position, target position and The introduction of small random disturbances makes the trajectory of each verification different and unpredictable, greatly improving the anti-attack capability; secondly, in response to the high latency and privacy leakage risks of SMS or email verification codes, the present application solution performs verification through real-time network communication between the client and the server, without the need for additional user information, which not only shortens the verification response time but also effectively protects user privacy; in addition, the present application also solves the problem of inconsistent operations caused by differences in terminal devices, resolutions and interaction accuracy through dynamic tolerance thresholds and device interaction accuracy adaptive setting deviation ranges, ensuring the fairness and availability of the verification process; finally, the present application solution forms a complete closed loop on the client and server, which can dynamically adjust the verification parameters according to user operation abnormalities, repeated behaviors and cumulative failures, achieving a balance between security and user experience, and significantly improving the overall protection capability and applicability of the system.

[0047] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0048] like Figure 7 As shown, an embodiment of the present application further provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above login verification method embodiments.

[0049] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0050] The above is a detailed introduction to a login verification method and electronic device provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only intended to help understand the method and core ideas of the present application. It should be pointed out that, for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the present application.

Claims

1. A login verification method, applied to a client, characterized in that: include: In response to receiving a verification data packet sent by the server, parsing the verification data packet to obtain verification interaction interface generation parameters, an object ejection motion model, a first position parameter, and a second position parameter; generating a verification interaction interface including at least a first object and a second object according to the verification interaction interface generation parameter, and setting a position of the first object according to the first position parameter and setting a position of the second object according to the second position parameter; In response to obtaining a user's interaction start operation on the first object, recording the user's operation information on the first object and updating the display position of the first object; In response to obtaining the user's interaction ending operation on the first object, generating a first motion trajectory of the first object based on the object ejection motion model, the operation information, and the current position of the first object, and determining a corresponding first landing point position; An interactive data packet including at least the first landing point position is sent to the server for the server to perform verification and determination.

2. The login verification method according to claim 1, characterized in that: Before the client receives the verification data packet sent by the server, the method further includes: Generate a login data packet based on the account information input by the user and send it to the server, so that the server can compare the account information with the user data stored in the database and feedback the comparison result; In response to receiving a comparison result fed back by the server that is consistent, determining that the account information input by the user is correct, and sending a verification request to the server to obtain the verification data packet; In response to receiving a comparison result from the server that is inconsistent, it is determined that the account information input by the user is incorrect, and a login failure prompt is output.

3. The login verification method according to claim 1, wherein: The generating a first motion trajectory of the first object based on the object ejection motion model, the operation information, and the current position of the first object, and determining a corresponding first landing point position includes: Calculating an initial velocity vector of the first object according to the operation information; Inputting the initial velocity vector and the current position of the first object into the object ejection motion model, simulating the two-dimensional motion process of the first object based on gravity acceleration and air resistance simulation parameters set in the object ejection motion model, and generating the first motion trajectory; An intersection point between the first motion trajectory and a horizon line in the verification interaction interface is determined, and a position of the intersection point is used as the first landing point position.

4. The login verification method according to claim 3, characterized in that: The calculating, according to the operation information, an initial velocity vector of the first object includes: Determine the starting position coordinates of the first object according to the first position parameter and use them as a transmitting reference point; Parsing the operation information to obtain the stretching end point coordinates and displacement duration of the first object; Calculating the stretching displacement and the direction of the stretching displacement according to the emission reference point and the stretching end point coordinates; Using the opposite direction of the displacement direction as the initial movement direction of the first object; Calculating an initial velocity of the first object according to the stretching displacement and the displacement duration; The initial motion direction and the initial velocity are combined to obtain the initial velocity vector.

5. A login verification method, applied to a server, characterized in that: include: In response to receiving a verification request sent by a client, selecting a verification interaction interface that matches the client, and generating a first position parameter and a second position parameter to respectively control the position of a first object and a second object on the verification interaction interface; Setting an object ejection motion model, and combining verification interaction interface generation parameters, the first position parameter, and the second position parameter to generate a verification data packet and send the verification data packet to the client; In response to receiving the interaction data packet fed back by the client, parsing the interaction data packet to obtain a first landing point position of the first object; Calculating a deviation distance between the first landing point position and the second object position, and comparing the deviation distance with a deviation threshold; In response to the deviation distance being less than or equal to the deviation threshold, determining that the verification is passed, and sending a verification pass data packet to the client; In response to the deviation distance being greater than the deviation threshold, it is determined that the verification fails, and an object position reset parameter is generated, encapsulated into a verification failure data packet, and sent to the client.

6. The login verification method according to claim 5, characterized in that: The selecting a verification interaction interface that matches the client includes: Parsing the verification request to obtain device type information and interface display parameters of the client; According to the device type information, an interface matching the client is selected from a preset verification interaction interface template as the verification interaction interface, and corresponding verification interaction interface generation parameters are generated according to the interface display parameters.

7. The login verification method according to claim 5, characterized in that: The generating of the first position parameter and the second position parameter to respectively control the positions of the first object and the second object on the verification interaction interface includes: Determining an interactive area based on the verification interaction interface; Randomly selecting a plurality of candidate initial position coordinates within the interactive area, and randomly selecting a safe initial position whose distance from the interface boundary of the verification interaction interface is greater than or equal to a first safe distance threshold as the position of the first object and generating the first position parameter; Parsing the verification request to obtain interaction characteristic parameters of the client; Obtaining a hittable area of ​​the first object by calculating the object ejection motion model according to the first position parameter and the interaction characteristic parameter; A safe target position whose distance from the interface boundary of the verification interaction interface is greater than or equal to a second safe distance threshold is randomly selected in the hittable area as the position of the second object and the second position parameter is generated.

8. The login verification method according to claim 5, characterized in that: Before calculating the deviation distance between the first landing point position and the second object position and comparing the deviation distance with a deviation threshold, the method further includes: Obtaining device interaction accuracy of the client; The deviation threshold is set according to the device interaction accuracy and the verification interaction interface generation parameters.

9. A login verification method according to claim 7, characterized in that: The determination verification fails and the object position reset parameters are generated, including: Record the current first position parameter and the current second position parameter; Randomly selecting a safe reset position other than the current first position parameter from the interactive area as the reset position of the first object and generating a first object position reset parameter; Based on the reset position of the first object, the hittable area of ​​the first object is recalculated, and a safe target reset position other than the current second position parameter is randomly selected as the reset position of the second object and a second object position reset parameter is generated.

10. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the login verification method according to any one of claims 1 to 9 when executing the computer program.

Citation Information

Patent Citations

  • Method and system for preventing cheating plug-in in online game

    CN103577677A

  • Verification method and device, computing equipment and medium

    CN112738065A

  • Real-time anti-fraud intelligent verification method

    CN114386977A

  • Human-computer interaction verification method and device, electronic equipment and storage medium

    CN115357884A

  • Verification code verification method and device

    CN115712879A