Account authentication methods, devices, storage media, and software products

By utilizing authentication challenges and signature verification between terminal devices and first and second servers in a distributed service system, the problem of not being able to determine the primary regional server in a distributed system is solved, achieving efficient and secure account authentication without identifiers.

CN120750546BActive Publication Date: 2026-04-03BEIJING ZITIAO NETWORK TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In distributed service systems, existing identifierless authentication processes suffer from poor security and cannot be effectively applied to cross-region account authentication because they cannot determine the server serving the user's primary region.

Method used

The terminal device sends an authentication request to the first server to obtain authentication challenge information and a token. Using the second key associated with the account, it signs the token and digital signature and sends them to the second server serving the main region. The second server verifies the signature to determine the authentication result, thus achieving secure authentication without synchronizing user data across regions.

Benefits of technology

It achieves efficient and secure account authentication without identifiers in distributed service systems, avoids the risk of leakage during identifier transmission, and improves the efficiency and accuracy of cross-regional authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750546B_ABST
    Figure CN120750546B_ABST
Patent Text Reader

Abstract

Embodiments of this disclosure provide an account authentication method, apparatus, storage medium, and program product. The method includes: in response to an authentication trigger for an account, sending an authentication request for the account to a first server serving the region where a terminal device is located; receiving authentication challenge information and a token indicating the authentication challenge information from the first server; determining a second server holding a first key associated with the account based on identifier information associated with the account; sending the token and a digital signature to the second server; receiving an authentication result from the second server indicating whether the account authentication was successful; and sending the authentication result to the first server to obtain services provided by the first server. In this manner, a distributed service system can securely and efficiently perform account authentication using an "identifier-free" authentication process without needing to synchronize user data across regions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The exemplary embodiments disclosed herein generally relate to the field of computers, and particularly to account authentication methods, devices, computer-readable storage media, and computer program products. Background Technology

[0002] Account authentication is used to verify the authenticity and legitimacy of an operator's identity. When a user accesses a website or platform through an application or browser and performs actions requiring a high level of security, such as account login, the platform or website may require the user to perform account authentication to confirm the operator's identity. In this situation, how to securely and efficiently perform account authentication while protecting user privacy and data security becomes a common concern for platform or website service providers. Summary of the Invention

[0003] In a first aspect of this disclosure, an account authentication method is provided. The method includes: in response to an authentication trigger for an account, sending an authentication request for the account to a first server serving a region where a terminal device is located; receiving authentication challenge information and a token indicating the authentication challenge information from the first server; determining a second server holding a first key associated with the account based on identification information associated with the account; sending the token and a digital signature to the second server, the digital signature being obtained by signing the authentication challenge information using the second key matching the first key; receiving an authentication result from the second server indicating whether the account authentication was successful; and sending the authentication result to the first server to obtain services provided by the first server.

[0004] In a second aspect of this disclosure, an account authentication method is provided. The method includes: in response to receiving an authentication request for an account from a terminal device, generating authentication challenge information for the authentication request and a token indicating the authentication challenge information, wherein a first server serves the region where the terminal device is located; sending the authentication challenge information and the token to the terminal device; in response to receiving the token from a second server, sending the authentication challenge information to the second server; and receiving an authentication result from the terminal device indicating whether the account authentication is successful, wherein the authentication result is generated by the second server based on the authentication challenge information.

[0005] In a third aspect of this disclosure, an account authentication method is provided. The method includes: in response to receiving from a terminal device a digital signature corresponding to authentication challenge information and a token indicating the authentication challenge information, sending a token to a first server, the first server serving the region where the terminal device is located; receiving authentication challenge information from the first server; verifying the digital signature based on the authentication challenge information and a first key held by a second server and associated with the account to obtain an authentication result indicating whether the account authentication is successful; and sending the authentication result to the terminal device.

[0006] In a fourth aspect of this disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor. When executed by the at least one processor, the instructions cause the device to perform the method of the first aspect.

[0007] In a fifth aspect of this disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores computer-executable instructions that can be executed by a processor to implement the method of the first aspect.

[0008] In a sixth aspect of this disclosure, a computer program product is provided, including computer-executable instructions, wherein when executed by a processor, the computer-executable instructions implement the method according to a first aspect of this disclosure.

[0009] It should be understood that the content described in this content section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:

[0011] Figure 1 A schematic diagram is shown of an example environment in which embodiments of the present disclosure may be implemented;

[0012] Figures 2A to 2C Flowcharts of signaling flows for account authentication according to some embodiments of this disclosure are shown respectively;

[0013] Figures 3 to 5 Flowcharts of account authentication processes according to some embodiments of this disclosure are shown respectively;

[0014] Figures 6 to 8 Schematic structural block diagrams of example devices for account authentication according to some embodiments of the present disclosure are shown respectively; and

[0015] Figure 9 A block diagram of an electronic device capable of implementing several embodiments of the present disclosure is shown. Detailed Implementation

[0016] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0017] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may also be included below.

[0018] In this document, unless explicitly stated otherwise, performing a step in response to A does not mean that the step is performed immediately after A, but may include one or more intermediate steps.

[0019] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0020] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and user authorization should be obtained.

[0021] For example, in response to receiving a user's active request, a prompt message is sent to the user to clearly inform the user that the requested operation will require the acquisition and use of the user's personal information, thereby enabling the user to choose whether to provide personal information to the software or hardware such as electronic devices, applications, servers or storage media that perform the operation of the technical solution disclosed herein, based on the prompt message.

[0022] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0023] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0024] Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. In this example environment 100, an application 120 may be installed on a terminal device 110. A user 140 may interact with the application 120 via the terminal device 110 and / or an attachment device to the terminal device 110. For example, the user 140 may use the application 120 to access websites or platforms on the Internet. Of course, the user 140 may also access websites or platforms on the Internet through, for example, a browser (not shown).

[0025] In this example environment 100, if application 120 is active, terminal device 110 can present the user interface 150 of application 120. The user interface 150 may include various pages that application 120 can provide. For example, when accessing a website or platform, the website or platform may require user 140 to authenticate their account; the user interface 150 may include interfaces related to account authentication. Obviously, the user interface 150 may also include other interfaces of application 120, and the embodiments of this disclosure do not limit this.

[0026] In some embodiments, terminal device 110 communicates with at least one server 130 to provide services to application 120 or a browser. In some examples, the at least one server 130 may include multiple servers 130, such as server 130-1, server 130-2, ..., server 130-N, etc., where N is a positive integer. For ease of description, these multiple servers are collectively referred to as server 130 herein. The multiple servers 130 may serve different regions, which may be provinces, cities, countries, or regions composed of multiple countries, etc. If terminal device 110 is located in a different region, terminal device 110 may communicate with the server 130 serving the corresponding region to provide services to application 120 or a browser.

[0027] In some embodiments, terminal device 110 may be any type of mobile terminal, fixed terminal, or portable terminal, including mobile phones, desktop computers, laptop computers, notebook computers, netbook computers, tablet computers, media computers, multimedia tablets, personal communication system (PCS) devices, personal navigation devices, personal digital assistants (PDAs), audio / video players, digital cameras / camcorders, positioning devices, television receivers, radio receivers, e-book devices, gaming devices, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some embodiments, terminal device 110 may also support any type of user-facing interface (such as "wearable" circuitry).

[0028] In some embodiments, server 130 may be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms. Server 130 may include, for example, computing systems / servers such as mainframes, edge computing nodes, computing devices in a cloud environment, etc.

[0029] It should be understood that the structure and function of the various elements in environment 100 are described for illustrative purposes only and do not imply any limitation on the scope of this disclosure.

[0030] As mentioned above, if a user accesses a website or platform through an application or browser and performs actions such as account login or other operations with high security requirements, the platform or website may require the user to perform account authentication to verify the identity of the operator.

[0031] Traditionally, before performing account authentication, users typically need to provide an identifier to identify themselves, such as a username or email address. This method of account authentication can be called an "identifier-first" authentication process. Subsequently, an "identifier-free" authentication process emerged. In this process, users do not need to provide an identifier; instead, they can use authentication credentials to authenticate their accounts. Authentication credentials include a private key and a public key. The private key is stored in the user's authenticator, such as a hardware security key or a software authenticator on the terminal device. The public key is stored on a server provided by the service provider. During the authentication process, the server requires the terminal device to prove it possesses the private key, without transmitting the private key itself, significantly improving the security of the account authentication process.

[0032] In centrally deployed service systems, this "identifier-free" authentication process can operate without obstacles. However, distributed service systems are becoming increasingly widespread. Distributed service systems typically consist of multiple servers (or multiple service systems), each serving a different region. User data (protecting authentication credentials) is usually stored on servers in the "primary region" serving the user (i.e., the region where the account was initially registered), and cross-region synchronization of user data may be restricted or prohibited.

[0033] In the era of globalization, cross-regional personnel movement is becoming increasingly convenient. Some users may not be limited to requesting services in their "primary region"; some may request account authentication from servers serving those "non-primary regions" (i.e., regions outside the primary region). In this scenario, if the distributed service system adopts an "identifier-first" authentication process, it can use the user-provided identifier to locate the user's "primary region" and complete the authentication process through the server serving that region. However, identifiers are prone to leakage during transmission, resulting in relatively poor security.

[0034] While the "identifier-less" authentication process offers high security, users do not pre-provide an identifier. The system cannot determine the server serving the user's "primary zone," making this relatively secure authentication process unsuitable for distributed service systems.

[0035] In view of this, embodiments of the present disclosure propose an improved account authentication scheme. In this improved scheme, a first server serves the region where the terminal device is located. A second server serves the "main region" of the account, and the second server holds a first key associated with the account. If the terminal device determines that authentication for the account has been triggered, the terminal device sends an authentication request for the account to the first server, and the first server provides the terminal device with authentication challenge information and a token indicating the authentication challenge information. The terminal device signs the authentication challenge information using a second key matching the first key to obtain a digital signature corresponding to the authentication challenge information. Based on the identification information associated with the account, the terminal device determines the second server serving the "main region" of the account. The terminal device sends the token and digital signature to the second server. The second server sends the token to the first server, and the first server provides the second server with authentication challenge information corresponding to the token. The second server verifies the digital signature using the first key and the authentication challenge information it holds to obtain an authentication result indicating whether the account authentication is successful. The second server then feeds back the authentication result to the terminal device.

[0036] In the embodiments of this disclosure, the terminal device does not need to provide an identifier identifying the user to a first server serving the current region in advance. The first server only needs to provide authentication challenge information and a token to the terminal device. The terminal device independently determines a second server serving the "main region" and sends the digital signature of the token and authentication challenge information to the second server. This allows the second server to obtain the corresponding authentication challenge information from the first server using the token, thereby completing account authentication. In this way, the distributed service system can securely and efficiently perform account authentication using an "identifier-free" authentication process without needing to synchronize user data (e.g., authentication credentials) across regions.

[0037] The following description will continue with reference to the accompanying drawings, which will provide some exemplary embodiments of this disclosure. Figure 2A A flowchart of an example signaling flow 200A for account authentication according to some embodiments of the present disclosure is shown. Example signaling flow 200A relates to terminal device 110, server 130-1, server 130-2, and server 130-N. For ease of discussion, reference will be made to… Figure 1 The environment 100 is used to describe the example signaling flow 200A.

[0038] In some embodiments, as shown in signaling flow 200A, if terminal device 110 determines that authentication for an account has been triggered, terminal device 110 may send (204) an authentication request for the account to server 130-1 (sometimes referred to herein as "first server") serving the region where terminal device 110 is located. The account may be an account registered in any suitable distributed service system, such as an account registered on a website, an account registered on a network platform, an account registered in an application, etc. Embodiments of this disclosure do not limit the type of account. The account may have a primary region, that is, the region where the account was first registered. Here, the region where terminal device 110 is located may be a region other than the primary region. For example, if the account is registered in region A, then region A can be considered the account's primary region. If user 140 brings terminal device 110 to region B, and terminal device 110 determines that authentication for the account has been triggered, terminal device 110 may send an authentication request for the account to server 130-1 serving region B.

[0039] In some embodiments, terminal device 110 may determine that account authentication has been triggered in response to detecting an operation requiring account authentication. The operation requiring account authentication can be understood as requiring account authentication before performing the operation. If the authentication result indicates successful account authentication, terminal device 110 may perform the operation. If the authentication result indicates unsuccessful account authentication, terminal device 110 may abandon the operation. As an example, if terminal device 110 determines that an account login operation has been triggered, terminal device 110 may determine that account authentication has been triggered. As another example, if terminal device 110 detects an order generation operation, terminal device 110 may determine that account authentication is required, thereby determining that account authentication has been triggered.

[0040] An authentication request may include any appropriate request capable of triggering authentication of an account. In some embodiments, if terminal device 110 determines that authentication for an account has been triggered, terminal device 110 may send a request to server 130-1 requesting server 130-1 to directly perform authentication of the account. In some embodiments, if terminal device 110 detects an operation requiring account authentication, terminal device 110 may also send a request to server 130-1 requesting server 130-1 to perform that operation. If server 130-1 determines, based on the request, that account authentication is required before performing the operation, server 130-1 may trigger account authentication. In this case, the request can also be considered an authentication request. For example, if terminal device 110 sends a login request for an account to server 130-1, and server 130-1 determines that account authentication is required before performing the login operation, server 130-1 may trigger account authentication.

[0041] In some embodiments of this disclosure, as shown in signaling flow 200A, if server 130-1 receives an authentication request for an account from terminal device 110, server 130-1 generates (206) authentication challenge information for the authentication request and a token indicating the authentication challenge information. Server 130-1 sends (210) the authentication challenge information and the token to terminal device 110.

[0042] The authentication challenge information may include any suitable information that can be signed. In some embodiments, the authentication challenge information may include a set of characters, such as a set of random numbers. Alternatively or additionally, the authentication challenge information may also include other information, such as a set of random numbers and a timestamp corresponding to the authentication request. The token may include any suitable information that can identify the authentication challenge information, such as a number, identifier, or string. Of course, the authentication challenge information and token described above are exemplary. The embodiments of this disclosure are not limiting in this regard.

[0043] In some embodiments, if terminal device 110 determines that authentication for an account has been triggered, terminal device 110 can access a specific interface of server 130-1 to send an authentication request for the account to server 130-1. Server 130-1 can provide authentication challenge information and a token to terminal device 110 through this specific interface. As an example, server 130-1 can provide an authentication challenge information retrieval interface (e.g., denoted as the Getchallenge API). Terminal device 110 can retrieve authentication challenge information and a token through this authentication challenge information retrieval interface.

[0044] In some embodiments, after generating the authentication challenge information and the token, server 130-1 may store (208) the authentication challenge information and the token. For example, server 130-1 may store the authentication challenge information and the token together in a specific storage space on server 130-1's local machine so that server 130-1 can look up the authentication challenge information in subsequent steps.

[0045] In some embodiments of this disclosure, as shown in signaling flow 200A, terminal device 110 can obtain (214) identification information associated with an account. Based on the identification information, a server 130-N (sometimes referred to herein as a "second server") holding a first key associated with the account is determined.

[0046] In some embodiments, each account may have associated authentication credentials. Authentication credentials may include a first key and a second key matching the first key. The first key may be deployed at server 130-N serving the main area of ​​the account. The second key may be deployed within an authenticator associated with terminal device 110. This authenticator may be a hardware-based authenticator (e.g., a security key), a software-based authenticator, or a biometric-based authenticator. As an example, authentication credentials may include a public key (i.e., the first key) and a private key (i.e., the second key), the public key may be deployed at server 130-3, and the private key may be deployed within the authenticator associated with terminal device 110. Of course, the first key and the second key can be any suitable pair of keys capable of performing signing and verifying signatures.

[0047] In some embodiments, terminal device 110 may obtain identification information from an authenticator associated with the account in response to receiving authentication challenge information and a token from server 130-1. For example, the authenticator may be connected to or otherwise communicate with terminal device 110. Thus, terminal device 110 can obtain identification information from the authenticator. In some examples, the identification information may include a first identifier indicating the account. Examples of the first identifier include, but are not limited to, an account number, a user handle, or other identifier capable of uniquely identifying the account. Alternatively or additionally, the identification information may also include a second identifier indicating a first key. Examples of the second identifier may include, but are not limited to, identifiers used to uniquely identify the first key, the second key, or authentication credentials.

[0048] As an example, during account registration, server 130-N, serving the account's primary area, can generate authentication credentials, a user handle, and a credential number associated with the account. Server 130-N can store a first key from the authentication credentials, and server 130-N can provide a second key, user handle, and credential number to terminal device 110. Terminal device 110 can store the second key, user handle, and credential number in the authenticator. It should be understood that the above identification information is merely exemplary, and the embodiments of this disclosure do not limit the specific content of the identification information.

[0049] Regarding the determination of the server serving the primary region of the account, in some embodiments, the terminal device 110 may send (also referred to as "broadcast") a query request (sometimes referred to herein as a first query request) including identification information to multiple servers 130, each serving a different region. For each of the multiple servers 130, upon receiving a query request, the server 130 may determine whether it holds a first key corresponding to the identification information. Based on the determination result, the server 130 may send a response to the terminal device 110. If the terminal device 110 receives an acknowledgment response to the query request from one of the multiple servers 130, the terminal device 110 may determine that server 130 serves the primary region of the account.

[0050] As an example, in conjunction with signaling flow 200A, terminal device 110 can send a query request (216) to server 130-2 based on identification information. Server 130-2 determines whether it holds the public key corresponding to the identification information based on the identification information. If server 130-2 determines that it does not hold the corresponding public key, server 130-2 can send a response (218) to terminal device 110 indicating that it does not hold the corresponding public key. Terminal device 110 can also send a query request (220) to server 130-2 based on identification information. Server 130-N determines whether it holds the public key corresponding to the identification information based on the identification information. If server 130-N determines that it holds the corresponding public key, server 130-N can send a response (222) to terminal device indicating that it holds the corresponding public key (also known as a confirmation response).

[0051] In some embodiments of this disclosure, as shown in signaling flow 200A, terminal device 110 can obtain (212) a digital signature corresponding to the authentication challenge information. Terminal device 110 sends (224) a token and a digital signature to server 130-N. If server 130-N receives the digital signature and a token from terminal device 110, server 130-N sends (226) a token to server 130-1. Server 130-1 can determine the authentication challenge information indicated by the token, and then server 130-1 sends (228) the determined authentication challenge information to server 130-N.

[0052] The digital signature is generated by signing the authentication challenge information using a second key. Regarding the acquisition of the digital signature, in some embodiments, the terminal device 110 can provide the authentication challenge information to the authenticator corresponding to the account, and use the authenticator to generate the digital signature. The terminal device 110 can then obtain the digital signature from the authenticator. Additionally, the terminal device 110 can also simultaneously obtain the identification information mentioned above. In other embodiments, the terminal device 110 can obtain the second key from the authenticator. The terminal device can then use the second key to sign the authentication challenge information to obtain the corresponding digital signature. It is understood that although signaling flow 200A shows the digital signature being generated before obtaining the identification information, in practical applications, the terminal device 110 can also generate a digital signature by signing the authentication challenge information after obtaining the identification information, or the terminal device 110 can generate a digital signature after determining the server serving the account's primary region. The embodiments of this disclosure do not limit this.

[0053] In some embodiments of this disclosure, as shown in signaling flow 200A, server 130-N verifies (230) the digital signature based on authentication challenge information and the first key it holds to obtain an authentication result indicating whether the account has been successfully authenticated. Then, server 130-N sends (232) the authentication result to terminal device 110. Specifically, server 130-N can perform signature verification on the digital signature based on the authentication challenge information and the first key. If the signature verification is successful, server 130-N sends an authentication result indicating that the account has been successfully authenticated to terminal device 110. If the signature verification fails, server 130-N sends an authentication result indicating that the account has failed to be authenticated to terminal device 110.

[0054] In some embodiments of this disclosure, if a terminal device 110 receives an authentication result indicating successful account authentication from server 130-N, it can send (234) the authentication result to server 130-1 to request server 130-1 to provide services for the account. In response to receiving the authentication result from terminal device 110, server 130-1 can determine whether the authentication result indicates successful account authentication. If it determines that the authentication result indicates successful account authentication, server 130-1 provides (236) services for the account to terminal device 110. These services can be any suitable service that server 130-1 can provide. For example, server 130-1 can provide media content (e.g., audio, video, or text), interactive services, or shopping services to terminal device 110. Of course, the above service content is merely exemplary, and the embodiments of this disclosure do not limit the service content provided by server 130-1.

[0055] Figure 2B A flowchart of an example signaling flow 200B for account authentication according to other embodiments of this disclosure is shown. Example signaling flow 200B relates to terminal device 110, server 130-1, and server 130-N. For ease of discussion, signaling flow 200B will be described with reference to the environment 100 of the figures. It should be noted that some processes in signaling flow 200B are identical to some processes in signaling flow 200A, such as the processes shown in 204 to 214 and 224 to 236. These identical processes will not be repeated below; please refer to the explanation of signaling flow 200A. The following explanation will focus on the processes in signaling flow 200B that differ from those in signaling flow 200A.

[0056] In some embodiments of this disclosure, server 130-N may provide (238) account mapping information to at least one server 130, including server 130-1. The account mapping information indicates a mapping relationship between at least one piece of identification information associated with at least one account and server 130-N. The at least one account has the region served by server 130-N as its primary region. In some embodiments, the account mapping information may include a mapping relationship between identification information (e.g., credential number or user handle) and service information indicating server 130-N (e.g., IP address, server name, etc.). Alternatively or additionally, the account mapping information may also include a mapping relationship between identification information and the region served by server 130-N (e.g., region number, region name, etc.). Of course, the above account mapping information is merely exemplary, and the embodiments of this disclosure are not limiting.

[0057] In some embodiments, server 130-N may provide account mapping information to at least one server 130, including server 130-1, at a predetermined period to achieve periodic updates of the account mapping information. Alternatively or additionally, server 130-N may also provide updated account mapping information to other servers 130 in the distributed service system in response to the number of changed accounts in the service area exceeding a threshold, such as the number of newly registered accounts or the number of deregistered accounts exceeding a threshold.

[0058] It should be noted that although signaling flow 200B only shows server 130-N sending account mapping information to server 130-1, in actual application scenarios, each server 130 in the distributed service system can send its own account mapping information to server 130-1. For example, server 130-2 can also send its own account mapping information to server 130-1, which can indicate the mapping relationship between at least one identification information associated with at least one account and server 130-2. In this case, server 130-1 can receive at least one piece of account mapping information from at least one server other than server 130-1.

[0059] In some embodiments of this disclosure, as shown in signaling flow 200B, terminal device 110 may, in response to obtaining (214) identification information associated with an account, send (240) a query request (sometimes referred to herein as a second query request) containing the identification information to server 130-1. Server 130-1 may determine the server 130 (e.g., server 130-N) to which the identification information is mapped based on account mapping information indicating the mapping relationship between the identification information and server 130. Subsequently, server 130-1 may send (242) service information indicating server 130-N to terminal device 110. In this way, terminal device 110 does not need to broadcast query requests to multiple servers 130 in the distributed service system, which helps reduce the network traffic consumed by terminal device 110 and improves the server query efficiency of the main area serving the account.

[0060] Figure 2CA flowchart of an example signaling flow 200C for account authentication according to other embodiments of the present disclosure is shown. Example signaling flow 200C relates to terminal device 110, server 130-1, and server 130-N. For ease of discussion, signaling flow 200C will be described with reference to the environment 100 of the figures. It should be noted that some processes in signaling flow 200C are identical to some processes in signaling flows 200A and 200B. For example, processes shown in 204 to 214 and 220 to 236 of signaling flow 200C are identical to corresponding processes in signaling flow 200A; and processes shown in 240 to 242 of signaling flow 200C are identical to corresponding processes in signaling flow 200B.

[0061] In signaling flow 200C, each server 130 still maintains account mapping information for other servers in the distributed service system. For example, server 130-1 maintains account mapping information for servers 130-2, ..., and server 130-N. After terminal device 110 obtains (214) the identification information, terminal device 110 not only sends (240) a query request (sometimes referred to as a third query request in this document) to server 130-1 serving the current area of ​​terminal device 110, but also sends (220) query requests to other servers in the distributed service system (e.g., servers 130-2, ..., 130-N, etc.).

[0062] Server 130-1 determines the server to which the identification information received from terminal device 110 is mapped, based on account mapping information indicating the mapping relationship between identification information and servers. Then, server 130-1 sends (242) service information to terminal device 110 indicating server 130-N, which may be included in or referred to as the first response. Servers 130-2, ..., 130-N each send (222) a second response to terminal device 110, which may indicate whether the corresponding server holds the first key associated with the identification information. Terminal device 110 can determine (260) the server holding the first key, i.e., the server serving the main area of ​​the account (e.g., server 130-N), based on at least one response received from at least one server among multiple servers (e.g., the first response and / or the second response). In this way, the success rate of queries to the main area can be improved.

[0063] In some embodiments, if the at least one response received by the terminal device 110 includes a first response and a second response, the terminal device 110 can determine whether the servers indicated by the first response and the second response are the same. If it is determined that the servers indicated by the first response and the second response are the same, the terminal device 110 can identify that server as the server serving the primary region of the account. For example, if the servers indicated by the first response and the second response are both server 130-N, then the terminal device 110 can determine that the region served by server 130-N is the primary region. This improves the accuracy of primary region lookup.

[0064] In summary, according to the embodiments of this disclosure, the distributed service system can securely and efficiently perform account authentication using an "identifier-free" authentication process without the need for cross-regional synchronization of user data (e.g., authentication credentials).

[0065] Figure 3 A flowchart of an account authentication process 300 according to some embodiments of the present disclosure is shown. Process 300 can be applied to terminal device 110. Reference will be made below. Figure 1 The environment 100 describes the process 300.

[0066] In box 310, in response to an authentication trigger for an account, terminal device 110 sends an authentication request for the account to a first server serving the region where the terminal device is located.

[0067] In box 320, terminal device 110 receives authentication challenge information and a token indicating the authentication challenge information from the first server.

[0068] In box 330, terminal device 110 determines a second server holding a first key associated with the account based on identification information associated with the account.

[0069] In box 340, terminal device 110 sends a token and a digital signature to the second server. The digital signature is obtained by signing the authentication challenge information using a second key that matches the first key.

[0070] In box 350, terminal device 110 receives an authentication result from the second server indicating whether the account has been successfully authenticated.

[0071] In box 360, terminal device 110 sends the authentication result to the first server in order to obtain the services provided by the first server.

[0072] In some embodiments, determining a second server includes: sending a first query request, including identification information, to a plurality of servers, the plurality of servers serving different regions; and in response to receiving an acknowledgment response from one of the plurality of servers for the first query request, identifying that server as the second server.

[0073] In some embodiments, determining the second server includes: sending a second query request including identification information to the first server; and receiving service information from the first server indicating the second server.

[0074] In some embodiments, determining the second server includes: sending a third query request, including identification information, to a plurality of servers, the plurality of servers including a first server and the plurality of servers serving different regions; receiving at least one response to the third query request from at least one of the plurality of servers; and determining the second server from the plurality of servers based on the at least one response received from the at least one server.

[0075] In some embodiments, determining a second server from a plurality of servers includes: in response to at least one response including a first response indicating a server and a second response indicating another server holding a first key associated with identification information, determining whether the servers indicated by the first response and the second response are consistent; and in response to the servers indicated by the first response and the second response being consistent, determining that server as the second server.

[0076] In some embodiments, the identification information includes at least one of the following: a first identifier indicating an account, or a second identifier indicating a first key.

[0077] Figure 4 A flowchart of an account authentication process 400 according to some embodiments of the present disclosure is shown. Process 400 can be applied to a first server (i.e., server 130-1). Reference will be made below. Figure 1 The environment 100 describes the process 400.

[0078] In box 410, in response to receiving an authentication request for an account from the terminal device, the first server generates authentication challenge information for the authentication request and a token indicating the authentication challenge information. The first server serves the region where the terminal device is located.

[0079] In box 420, the first server sends authentication challenge information and a token to the terminal device.

[0080] In box 430, the first server, in response to receiving the token from the second server, sends an authentication challenge message to the second server.

[0081] In box 440, the first server receives an authentication result from the terminal device indicating whether the account has been successfully authenticated. The authentication result is generated by the second server based on the authentication challenge information.

[0082] In some embodiments, process 400 further includes: providing services for the account in response to an authentication result indicating that the account has been successfully authenticated.

[0083] In some embodiments, process 400 further includes: in response to receiving a query request from a terminal device including identification information associated with an account, determining a second server to which the identification information is mapped based on account mapping information indicating the mapping relationship between the identification information and the server; and sending service information indicating the second server to the terminal device.

[0084] In some embodiments, process 400 further includes receiving account mapping information from at least one server other than the first server.

[0085] In some embodiments, the identification information includes at least one of the following: a first identifier indicating an account, or a second identifier indicating a first key associated with an account.

[0086] Figure 5 A flowchart of an account authentication process 500 according to some embodiments of the present disclosure is shown. Process 500 can be applied to a second server (i.e., server 130-M). Reference will be made below. Figure 1 The environment 100 describes the process 500.

[0087] In box 510, in response to receiving a digital signature corresponding to the authentication challenge information and a token indicating the authentication challenge information from the terminal device, the second server sends a token to the first server, which serves the region where the terminal device is located.

[0088] In box 520, the second server receives authentication challenge information from the first server.

[0089] In box 530, the second server verifies the digital signature based on the authentication challenge information and the first key associated with the account held by the second server to obtain an authentication result indicating whether the account has been successfully authenticated.

[0090] In box 540, the second server sends the authentication result to the terminal device.

[0091] In some embodiments, process 500 further includes: in response to receiving a query request from a terminal device including identification information associated with an account, sending a confirmation response to the query request or instructing the second server for service information to the terminal device.

[0092] In some embodiments, process 500 further includes: providing account mapping information to at least one server including the first server, the account mapping information indicating a mapping relationship between at least one identification information associated with at least one account and the second server.

[0093] In some embodiments, the identification information includes at least one of the following: a first identifier indicating the corresponding account, or a second identifier indicating a first key associated with the corresponding account.

[0094] Embodiments of this disclosure also provide corresponding apparatus for implementing the above methods or processes. Figure 6 A schematic structural block diagram of an example device 600 for account authentication according to certain embodiments of the present disclosure is shown. Device 600 may be implemented as or included in terminal device 110. Various modules / components in device 600 may be implemented by hardware, software, firmware, or any combination thereof.

[0095] like Figure 6 As shown, the apparatus 600 includes: an authentication request sending module 610, configured to send an authentication request for an account to a first server serving the region where the terminal device is located in response to an authentication trigger for an account at a terminal device; a first authentication challenge information receiving module 620, configured to receive authentication challenge information and a token indicating the authentication challenge information from the first server; a server determination module 630, configured to determine a second server holding a first key associated with the account based on identification information associated with the account; a digital signature sending module 640, configured to send the token and a digital signature to the second server, wherein the digital signature is obtained by signing the authentication challenge information using a second key matching the first key; a first authentication result receiving module 650, configured to receive an authentication result indicating whether the account has been successfully authenticated from the second server; and a first authentication result sending module 660, configured to send the authentication result to the first server to obtain services provided by the first server.

[0096] In some embodiments, the server determination module 630 is further configured to: send a first query request including identification information to a plurality of servers, the plurality of servers serving different regions; and in response to receiving an acknowledgment response for the first query request from one of the plurality of servers, determine that server as a second server.

[0097] In some embodiments, the server determination module 630 is further configured to: send a second query request including identification information to the first server; and receive service information from the first server instructing the second server.

[0098] In some embodiments, the server determination module 630 is further configured to: send a third query request including identification information to a plurality of servers, the plurality of servers including a first server and the plurality of servers serving different regions; receive at least one response to the third query request from at least one of the plurality of servers; and determine a second server from the plurality of servers based on the at least one response received from the at least one server.

[0099] In some embodiments, the server determination module 630 is further configured to: determine whether the servers indicated by the first response and the second response are consistent in response to at least one response including a first response indicating a server and a second response indicating that another server holds a first key associated with identification information; and determine the server as the second server in response to the consistency between the servers indicated by the first response and the second response.

[0100] In some embodiments, the identification information includes at least one of the following: a first identifier indicating an account, or a second identifier indicating a first key.

[0101] Figure 7 A schematic structural block diagram of an example device 700 for account authentication according to certain embodiments of the present disclosure is shown. Device 700 may be implemented as or included in server 130-1. Various modules / components in device 700 may be implemented by hardware, software, firmware, or any combination thereof.

[0102] like Figure 7 As shown, the apparatus 700 includes: a challenge generation module 710, configured to generate authentication challenge information and a token indicating the authentication challenge information in response to receiving an authentication request for an account from a terminal device at a first server, wherein the first server serves the area where the terminal device is located; a challenge sending module 720, configured to send the authentication challenge information and the token to the terminal device; a token receiving module 730, configured to send the authentication challenge information to a second server in response to receiving a token from a second server; and a second authentication result receiving module 740, configured to receive an authentication result from the terminal device indicating whether the account has been successfully authenticated, wherein the authentication result is generated by the second server based on the authentication challenge information.

[0103] In some embodiments, the apparatus 700 further includes a service providing module configured to provide services for an account in response to an authentication result indicating that the account has been successfully authenticated.

[0104] In some embodiments, the apparatus 700 further includes: a service information providing module, configured to, in response to receiving a query request from a terminal device including identification information associated with an account, determine a second server to which the identification information is mapped based on account mapping information indicating the mapping relationship between the identification information and the server; and send service information indicating the second server to the terminal device.

[0105] In some embodiments, the apparatus 700 further includes a mapping information receiving module configured to receive account mapping information from at least one server different from the first server.

[0106] Figure 8A schematic structural block diagram of an example device 800 for account authentication according to certain embodiments of the present disclosure is shown. Device 800 may be implemented as or included in server 130-M. Various modules / components in device 800 may be implemented by hardware, software, firmware, or any combination thereof.

[0107] like Figure 8 As shown, the apparatus 800 includes: a token sending module 810, configured to send a token to a first server at a second server in response to receiving a digital signature corresponding to authentication challenge information and a token indicating the authentication challenge information from a terminal device, the first server serving the area where the terminal device is located; a second authentication challenge information receiving module 820, configured to receive authentication challenge information from the first server; a digital signature verification module 830, configured to verify the digital signature based on the authentication challenge information and a first key held by the second server associated with the account, to obtain an authentication result indicating whether the account has been successfully authenticated; and a second authentication result sending module 840, configured to send the authentication result to the terminal device.

[0108] In some embodiments, the apparatus 800 further includes a service information sending module configured to send a confirmation response to the query request or service information instructing a second server to the terminal device in response to receiving a query request from the terminal device that includes identification information associated with an account.

[0109] In some embodiments, the apparatus 800 further includes a mapping information providing module configured to provide account mapping information to at least one server including a first server, the account mapping information indicating a mapping relationship between at least one piece of identification information associated with at least one account and a second server.

[0110] In some embodiments, the identification information includes at least one of the following: a first identifier indicating the corresponding account, or a second identifier indicating a first key associated with the corresponding account.

[0111] The units and / or modules included in devices 600, 700, and 800 can be implemented using various methods, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units and / or modules can be implemented using software and / or firmware, such as machine-executable instructions stored on a storage medium. In addition to or as an alternative to machine-executable instructions, some or all of the units and / or modules in devices 600, 700, and 800 can be implemented at least partially by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that can be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), and so on.

[0112] Figure 9 A block diagram of an electronic device 900 in which one or more embodiments of the present disclosure may be implemented is shown. It should be understood that... Figure 9 The electronic device 900 shown is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 9 The illustrated electronic device 900 may include or be implemented as Figure 1 Terminal device 110, server 130-1 or server 130-M, or Figure 6 Device 600, Figure 7 Device 700 or Figure 8 Device 800.

[0113] like Figure 9 As shown, electronic device 900 is in the form of a general-purpose electronic device. Components of electronic device 900 may include, but are not limited to, one or more processors or processing units 910, memory 920, storage device 940, one or more communication units 940, one or more input devices 950, and one or more output devices 960. Processor 910 may be a physical or virtual processor and is capable of performing various processes according to computer-executable instructions stored in memory 920. In a multiprocessor system, multiple processors execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 900.

[0114] Electronic device 900 typically includes multiple computer storage media. Such media can be any accessible media that is accessible to electronic device 900, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 920 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 940 can be removable or non-removable media and can include machine-readable media, such as flash drives, disks, or any other media that can be used to store information and / or data and can be accessed within electronic device 900.

[0115] Electronic device 900 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not explicitly stated... Figure 9As shown, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks can be provided. In these cases, each drive can be connected to a bus (not shown) via one or more data media interfaces. Memory 920 may include computer program product 925 having one or more computer-executable instruction modules configured to perform various methods or actions of various embodiments of this disclosure.

[0116] The communication unit 940 enables communication with other electronic devices via a communication medium. Additionally, the functionality of the components of the electronic device 900 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, the electronic device 900 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node.

[0117] Input device 950 can be one or more input devices, such as a mouse, keyboard, trackball, etc. Output device 960 can be one or more output devices, such as a monitor, speaker, printer, etc. Electronic device 900 can also communicate with one or more external devices (not shown) via communication unit 940 as needed. These external devices include storage devices, display devices, etc., and can communicate with one or more devices that enable user interaction with electronic device 900, or with any device that enables electronic device 900 to communicate with one or more other electronic devices (e.g., network card, modem, etc.). Such communication can be performed via input / output (I / O) interface (not shown).

[0118] According to an exemplary implementation of this disclosure, a computer-readable storage medium is provided that stores computer-executable instructions thereon, wherein the computer-executable instructions are executed by a processor to implement the methods described above. According to an exemplary implementation of this disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable storage medium and includes computer-executable instructions, which are executed by a processor to implement the methods described above.

[0119] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions.

[0120] These computer-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-executable instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable storage medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0121] Computer-executable instructions can be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer-executable instruction products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, executable instruction, or portion of instructions, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0123] Various implementations of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various implementations disclosed herein.

Claims

1. An account authentication method, applied to a terminal device, comprising: In response to an authentication trigger for an account, an authentication request for the account is sent to a first server serving the region where the terminal device is located; Receive authentication challenge information and a token indicating the authentication challenge information from the first server; Based on the identification information associated with the account, a second server holding a first key associated with the account is identified; The token and digital signature are sent to the second server, the digital signature being obtained by signing the authentication challenge information using a second key that matches the first key; Receive an authentication result from the second server indicating whether the account has been successfully authenticated; as well as Send the authentication result to the first server to obtain the services provided by the first server.

2. The method of claim 1, wherein determining the second server comprises: The system sends a first query request, including the identification information, to multiple servers, which serve different regions. as well as In response to receiving an acknowledgment response for the first query request from one of the plurality of servers, that server is identified as the second server.

3. The method of claim 1, wherein determining the second server comprises: Send a second query request, including the identification information, to the first server; as well as Receive service information from the first server that instructs the second server.

4. The method of claim 1, wherein determining the second server comprises: A third query request, including the identification information, is sent to multiple servers, including the first server, and the multiple servers serve different regions. Receive at least one response to the third query request from at least one of the plurality of servers; as well as The second server is determined from the plurality of servers based on the at least one response received from the at least one server.

5. The method of claim 4, wherein determining the second server from the plurality of servers comprises: In response to the at least one response, including a first response indicating a server and a second response indicating another server holding a first key associated with the identification information, it is determined whether the servers indicated by the first response and the second response are consistent. as well as If the server indicated by the first response and the second response is consistent, then the server is identified as the second server.

6. The method according to claim 1, wherein the identification information includes at least one of the following: The first identifier indicating the account, or A second identifier that indicates the first key.

7. An account authentication method, applied to a first server, comprising: In response to receiving an authentication request for an account from a terminal device, the server generates authentication challenge information for the authentication request and a token indicating the authentication challenge information, wherein the first server serves the region where the terminal device is located; Send the authentication challenge information and the token to the terminal device; In response to receiving the token from the second server, the authentication challenge information is sent to the second server; as well as The terminal device receives an authentication result indicating whether the account has been successfully authenticated, the authentication result being generated by the second server based on the authentication challenge information.

8. The method according to claim 7, further comprising: In response to the authentication result indicating that the account has been successfully authenticated, services are provided for the account.

9. The method according to claim 7, further comprising: In response to receiving a query request from the terminal device including identification information associated with the account, the system determines the second server to which the identification information is mapped based on account mapping information indicating the mapping relationship between the identification information and the server. as well as Send the service information of the second server to the terminal device.

10. The method of claim 9, further comprising: Receive account mapping information from at least one server different from the first server.

11. The method of claim 9, wherein the identification information includes at least one of the following: The first identifier indicating the account, or A second identifier that indicates the first key associated with the account.

12. An account authentication method applied to a second server, comprising: In response to receiving a digital signature corresponding to authentication challenge information and a token indicating the authentication challenge information from a terminal device, the token is sent to a first server, the first server serving the region where the terminal device is located; Receive the authentication challenge information from the first server; Based on the authentication challenge information and the first key held by the second server and associated with the account, the digital signature is verified to obtain an authentication result indicating whether the account has been successfully authenticated; as well as The authentication result is sent to the terminal device.

13. The method of claim 12, further comprising: In response to receiving a query request from the terminal device including identification information associated with the account, a confirmation response to the query request or an instruction on the service information of the second server is sent to the terminal device.

14. The method of claim 12, further comprising: Account mapping information is provided to at least one server, including the first server, the account mapping information indicating the mapping relationship between at least one identification information associated with at least one account and the second server.

15. The method according to claim 13 or 14, wherein the identification information includes at least one of the following: The first identifier indicating the corresponding account, or A second identifier that indicates the first key associated with the corresponding account.

16. An electronic device comprising: At least one processor; as well as At least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor, the instructions causing the electronic device to perform the method according to any one of claims 1 to 6, 7 to 11 or 12 to 15 when executed by the at least one processor.

17. A computer-readable storage medium having stored thereon computer-executable instructions that can be executed by a processor to implement the method according to any one of claims 1 to 6, 7 to 11, or 12 to 15.

18. A computer program product comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 6, 7 to 11, or 12 to 15.

Citation Information

Patent Citations

  • Identity authentication server and identity authentication token

    CN108092776A

  • Method and system for implementing authentication processing of mobile terminal under the condition of no identification, processor and computer readable storage medium

    CN112784249A