Information processing method and electronic device

By evaluating user behavior and risk information in real time, and combining this with time-based information for fragmentation and encapsulation, the system addresses the shortcomings in the security and convenience of authentication methods in storage systems, achieving a dynamic and adaptive authentication process.

CN121030715BActive Publication Date: 2026-04-14INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INSPUR SUZHOU INTELLIGENT TECH CO LTD
Filing Date
2025-10-24
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing storage systems rely on static credentials or have complex authentication methods for information processing and authentication, resulting in insufficient authentication security and convenience, making it difficult to meet security management needs.

Method used

By evaluating user behavior and risk information in real time, the system dynamically generates information to be authenticated, and performs fragmentation and encapsulation based on preset strategies and time information to generate encapsulated processing information for authorization information authentication.

Benefits of technology

It achieves security, dynamism, and adaptability in the information processing process, improves the security and convenience of authentication, and adapts to dynamic adjustments based on different risk levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121030715B_ABST
    Figure CN121030715B_ABST
Patent Text Reader

Abstract

The application provides an information processing method and an electronic device, which can be applied to the technical field of information authentication and information storage management. The method comprises the following steps: in response to receiving a login request triggered by a user through a terminal device, obtaining to-be-authenticated information based on the behavior information of the user in the login request and the risk information indicated by the behavior information, wherein the to-be-authenticated information has time information; performing fragmentation and encapsulation processing on the to-be-authenticated information based on a preset strategy, the risk information and the time information, to obtain processed information after encapsulation, wherein the preset strategy comprises a fragmentation strategy for fragmenting the to-be-authenticated information and an encapsulation strategy for encapsulating the fragmentation result; and sending the processed information to a target address to perform permission information authentication based on the processed information, wherein the target address is used for authenticating the permission information of the user for logging into a storage resource and corresponds to the user information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information authentication and storage management technology, and specifically to an information processing method and an electronic device. Background Technology

[0002] With the increasing prevalence of storage systems, they typically employ multi-layered, combined authentication methods to ensure secure access. Related technologies mainly include centralized authentication through fixed passwords, digital certificates, integrating user authentication into a unified identity authentication system, or a combination of these methods. However, these technologies for information processing and authentication in storage systems suffer from reliance on static credentials or complex authentication methods, resulting in insufficient security and convenience, and failing to meet the security management requirements of storage systems. Summary of the Invention

[0003] In view of the above problems, the present invention provides an information processing method, apparatus, device, medium and program product.

[0004] According to a first aspect of the present invention, an information processing method is provided, comprising: responding to receiving a login request triggered by a user through a terminal device, obtaining authentication information based on user behavior information and risk information indicated by the behavior information in the login request, wherein the authentication information has time information; performing fragmentation and encapsulation processing on the authentication information based on a preset strategy, the risk information, and the time information to obtain encapsulated processing information, wherein the preset strategy includes a fragmentation strategy for fragmenting the authentication information and an encapsulation strategy for encapsulating the fragmentation results; and sending the processing information to a target address for authentication of permission information based on the processing information, wherein the target address is used to authenticate the user's permission information for logging into storage resources and corresponds to the user information.

[0005] A second aspect of the present invention provides an information processing apparatus, comprising: an information determination module, configured to, in response to receiving a login request triggered by a user through a terminal device, obtain authentication information based on user behavior information and risk information indicated by the behavior information in the login request, wherein the authentication information has time information; an information processing module, configured to perform fragmentation and encapsulation processing on the authentication information based on a preset strategy, risk information, and time information to obtain encapsulated processed information, wherein the preset strategy includes a fragmentation strategy for fragmenting the authentication information and an encapsulation strategy for encapsulating the fragmentation results; and an information sending module, configured to send the processed information to a target address for authentication of permission information based on the processed information, wherein the target address is used to authenticate the user's permission information for logging into storage resources and corresponds to the user information.

[0006] A third aspect of the present invention provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.

[0007] A fourth aspect of the present invention also provides a computer-readable storage medium having a computer program or instructions stored thereon, wherein the computer program or instructions, when executed by a processor, implement the steps of the above-described method.

[0008] A fifth aspect of the present invention also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method. Attached Figure Description

[0009] The above-described features, other objects, and advantages of the present invention will become clearer from the following description of embodiments of the invention with reference to the accompanying drawings, in which:

[0010] Figure 1 The illustration shows application scenarios of information processing methods, apparatus, devices, media, and program products according to embodiments of the present invention;

[0011] Figure 2 A flowchart of an information processing method according to an embodiment of the present invention is shown;

[0012] Figure 3A A flowchart of an information processing method according to another embodiment of the present invention is shown;

[0013] Figure 3B A flowchart of a two-way authentication login method according to an embodiment of the present invention is shown;

[0014] Figure 4 A block diagram of an information processing system for an information processing method according to an embodiment of the present invention is shown;

[0015] Figure 5 A structural block diagram of an information processing apparatus according to an embodiment of the present invention is shown;

[0016] Figure 6 A block diagram of an electronic device suitable for implementing an information processing method according to an embodiment of the present invention is shown;

[0017] Figure 7 A block diagram of another electronic device suitable for implementing an information processing method according to an embodiment of the present invention is shown. Detailed Implementation

[0018] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the invention. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the invention for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concept of the invention.

[0019] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0020] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0021] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0022] In the technical solution of this invention, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0023] In some examples, a complete static password can be sent to the user via email. However, the email content could be eavesdropped on or intercepted by a man-in-the-middle attack. Once the password is leaked, an attacker can log in at any time. Furthermore, no matter how complex the password generation rules are, the password itself is static; once recorded by unauthorized personnel, the password becomes invalid, making it difficult for the system to dynamically adjust authentication requirements based on current risks (such as logins from different locations).

[0024] In some examples, users possess dedicated hardware (such as a token card) that generates a one-time dynamic verification code periodically. Hardware tokens require additional hardware purchases, resulting in higher overall costs. Users must carry this hardware with them, and if it is lost or the battery runs out, they cannot log in, leading to inconvenience. Furthermore, the code generated by the hardware token is typically only linked to the user account, making it difficult to link it to the email domain for verification, and thus difficult to prove that the request originated from a trusted domain environment in the actual scenario.

[0025] In some examples, using email addresses instead of hardware tokens (e.g., sending dynamic verification codes via email) and adding domain binding verification (e.g., verifying the authenticity of the sender's domain) balances the security and cost of information authentication processing to some extent.

[0026] However, without encryption enabled on the mail server, CAPTCHAs are at risk of being intercepted or eavesdropped on during transmission. Attackers can obtain dynamic codes through man-in-the-middle attacks or network sniffing. Additionally, users may receive forged emails that trick them into entering CAPTCHAs on fraudulent websites. While domain name binding verification can reduce fake domains to some extent, attackers can still exploit similar domains or bypass verification mechanisms.

[0027] In view of this, the present invention provides an information processing method, comprising: responding to receiving a login request triggered by a user through a terminal device, obtaining authentication information based on the user's behavior information and risk information indicated by the behavior information in the login request, wherein the authentication information has time information; performing fragmentation and encapsulation processing on the authentication information based on a preset strategy, risk information and time information to obtain encapsulated processing information, wherein the preset strategy includes a fragmentation strategy for fragmenting the authentication information and an encapsulation strategy for encapsulating the fragmentation results; and sending the processing information to a target address for authentication of permission information based on the processing information, wherein the target address is used to authenticate the user's permission information for logging into storage resources and corresponds to the user information.

[0028] According to embodiments of the present invention, by evaluating user behavior information and associated risk information in login requests in real time, authentication information is dynamically generated. This allows for flexible adjustment of authentication and encapsulation strategies based on the time information and risk information of the authentication information. Since information processing utilizes a fragmentation strategy to distribute information, an encapsulation strategy to encrypt the fragments, and binding with time information to give the information timeliness, this achieves a multi-faceted integration of user behavior perception, real-time risk rating, dynamic fragmentation and encapsulation, and timestamp binding. This transforms the information processing process from a static flow to a dynamic decision-making process, satisfying the security, dynamism, and adaptability requirements of the information processing process.

[0029] Figure 1The illustration shows application scenarios of information processing methods, apparatus, devices, media, and program products according to embodiments of the present invention.

[0030] like Figure 1 As shown, the application scenario according to this embodiment may include terminal device 101, server 102, and network 103. Network 103 is used as a medium to provide a communication link between terminal device 101 and server 102. Network 103 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0031] Server 102 can be a server that provides various services, such as a storage system that provides data storage, querying, and other services. It can receive login requests sent by users through terminal device 101, verify user credentials, enforce security policies (such as generating and sending one-time passwords), and ultimately grant or deny user access permissions.

[0032] Terminal device 101 can be any electronic device with a display screen and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers. Various communication client applications, such as storage applications, can be installed on terminal device 101.

[0033] Users can use terminal device 101 to interact with server 102 via network 103 to receive or send messages, etc. For example, users can initiate a login request, enter credentials, receive and submit a secondary verification code through the login page of terminal device 101, and ultimately access the management interface or data of the storage system. As another example, if a user enters the management IP address of the storage system in the browser of terminal device 101, terminal device 101 will initiate a connection request to storage server 102 via network 103.

[0034] It should be noted that the information processing method provided in the embodiments of the present invention can generally be executed by server 102. Correspondingly, the information processing device provided in the embodiments of the present invention can generally be located in server 102. The information processing method provided in the embodiments of the present invention can also be executed by a server or server cluster that is different from server 102 and capable of communicating with terminal device 101 and / or server 102. Correspondingly, the information processing device provided in the embodiments of the present invention can also be located in a server or server cluster that is different from server 102 and capable of communicating with terminal device 101 and / or server 102.

[0035] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0036] The following will be based onFigure 1 The described scene, through Figures 2-4 The information processing method of the disclosed embodiments will be described in detail.

[0037] Figure 2 A flowchart of an information processing method according to an embodiment of the present invention is shown.

[0038] like Figure 2 As shown, the information processing method of this embodiment includes operations S210 to S230.

[0039] In operation S210, in response to receiving a login request triggered by a user through a terminal device, the system obtains authentication information based on the user's behavior information and the risk information indicated by the behavior information in the login request. The authentication information includes time information.

[0040] In embodiments of the present invention, a login request may be a request initiated by a user through the graphical user interface of a terminal device to log in to a data storage system. A user's login request may correspond to various login methods, including password login and dynamic login based on user behavior awareness. A user's login request at a previous moment or at the current moment has corresponding behavioral data, which can be used to determine whether the login request is abnormal or risky. Risk information may include various risk level information and risk type information.

[0041] In embodiments of the present invention, the authentication information can be used to authenticate user-triggered login requests to determine whether the user has the corresponding permissions to log in to the data system, and may include dynamic passwords and dynamic passwords. The complexity of the authentication information can correspond to multiple risk levels or risk types. The time information can be the timestamp of the current login request.

[0042] For example, after receiving a login request triggered by a user, the storage management system can collect the current behavior information of the current login request and obtain the previous behavior information corresponding to the user's previous login request from the system database. The current behavior information is then compared with the previous behavior information to obtain the risk information corresponding to the current login request, and then a dynamic password is generated.

[0043] In operation S220, the information to be authenticated is processed based on the preset strategy, risk information and time information to obtain encapsulated processing information. The preset strategy includes a fragmentation strategy for fragmenting the information to be authenticated and an encapsulation strategy for encapsulating the fragmentation results.

[0044] In embodiments of the present invention, the fragmentation strategy can be a strategy for fragmenting and encapsulating the authentication information based on a fragmentation algorithm or fragmentation rules. The encapsulation strategy can be a strategy for encapsulating and encrypting the fragmentation results based on an encapsulation algorithm or encapsulation rules. The processed information may include the fragmentation results and the encapsulation results.

[0045] For example, after obtaining the authentication information from the upstream, a sharding algorithm corresponding to the risk level of the current login request can be used to shard the authentication information to obtain multiple sharding results. Then, an encapsulation strategy can be used to encapsulate and encrypt the multiple sharding results respectively, thereby obtaining the encapsulated result in the encapsulated processing information.

[0046] In operation S230, processing information is sent to the target address to authenticate permission information based on the processing information. The target address is used to authenticate the user's permission information for logging into storage resources and corresponds to the user information.

[0047] In embodiments of the present invention, the user's permission information may be permission information specific to the user's login to the storage system and data retrieval or query. User information may be various aspects of the user collected from the system database when the user triggers a login request, including username, password, and email address. The target address may be email address information or related URLs used to authenticate user permission information.

[0048] For example, after obtaining the encapsulation result, the encapsulation result can be sent to the user's email address or relevant address link information so that the user can process the received information to obtain the processing result, and then authenticate the user's permissions with the storage management system based on the processing result to determine whether the user can successfully log in to the storage system.

[0049] In one feasible embodiment, users can select a login authentication method through the graphical user interface of the terminal device. The login authentication method can include "username + password" or "user behavior-aware and email segmented dynamic password". For the user behavior-aware and email segmented dynamic password, the validity of the configured email address can be verified, and a query function for the user login authentication method can be provided, thereby providing users with the functionality of user behavior-aware and email segmented dynamic password.

[0050] In one feasible embodiment, a multi-factor authentication method can be implemented by modifying the data transmission protocol, command line, and graphical user interface of the storage management system. For example, the graphical user interface can be modified to implement user behavior awareness and management of dynamic passwords for email sharding, including functions such as modification, query, enabling, and disabling.

[0051] According to embodiments of the present invention, by evaluating user behavior information and associated risk information in login requests in real time, authentication information is dynamically generated. This allows for flexible adjustment of authentication and encapsulation strategies based on the time information and risk information of the authentication information. Since information processing utilizes a fragmentation strategy to distribute information, an encapsulation strategy to encrypt the fragments, and binding with time information to give the information timeliness, this achieves a multi-faceted integration of user behavior perception, real-time risk rating, dynamic fragmentation and encapsulation, and timestamp binding. This transforms the information processing process from a static flow to a dynamic decision-making process, satisfying the security, dynamism, and adaptability requirements of the information processing process.

[0052] Figure 3A A flowchart of an information processing method according to another embodiment of the present invention is shown.

[0053] like Figure 3A As shown, the information processing method can include operations S301 to S308.

[0054] When operating S301, the user enters the username through the graphical user interface of the terminal device and clicks to send the dynamic password.

[0055] When operating S302, the storage management system extracts the user's email information and triggers a dynamic password sending command.

[0056] When operating S303, the risk information of the instruction is checked to determine whether it is a graphical user interface call.

[0057] If not, proceed with the subsequent procedures when operating S304.

[0058] When operating S305, if so, check whether the user has already registered and whether the email dynamic password policy is enabled.

[0059] In operation S306, if yes, call the password generation service, obtain the dynamic password through hash calculation, and save the timestamp of the dynamic password generation. If no, return to S304.

[0060] When operating S307, processing information is generated based on risk information, fragmentation strategy, and packaging strategy.

[0061] When operating S308, processing information is sent to the user's email address for subsequent authentication.

[0062] According to an embodiment of the present invention, the information processing method further includes: when the risk level is greater than or equal to the level threshold, obtaining the target duration of the information to be certified based on the baseline duration of the information to be certified, the risk coefficient indicated by the risk level, and the reference duration, so as to control the validity of the information to be certified based on the target duration.

[0063] In embodiments of the present invention, the baseline duration can be set according to system policies and used as a reference for adjusting the target duration. The risk coefficient can be a specific value corresponding to the risk level. The reference duration can be the minimum duration (e.g., 1 minute) to prevent availability issues caused by excessively short durations.

[0064] For example, the validity period T of the information to be authenticated can be dynamically calculated using risk levels. effective The specific formula is shown in formula (1) below:

[0065] T effective =T base ×(1-R score )+T min (1);

[0066] Among them, T base R can be the base duration. score It can be the risk factor, T min It can be the minimum duration.

[0067] According to an embodiment of the present invention, by dynamically adjusting the effective duration of the information to be authenticated based on the risk level, the duration is no longer fixed but changes in real time with the risk. Compared with the rule engine, it is more flexible, can identify unknown threats, and achieves the optimal balance between system security and user experience.

[0068] According to an embodiment of the present invention, the behavioral information includes the user's previous login information, previous device information, and previous frequency information of the user triggering a login request; the method further includes: determining multiple matching degrees between the user's current login information, current device information, and current frequency information and the previous login information, previous device information, and previous frequency information, respectively, wherein the multiple matching degrees have their own weights; and weighting the multiple matching degrees using the weights to obtain risk information.

[0069] In embodiments of the present invention, real-time evaluation of user behavior information to determine risk levels is crucial for improving security during login authentication in the storage system. By analyzing multi-dimensional data such as historical login locations, device fingerprints, and operation frequency, the system can intelligently identify potential threats and dynamically adjust authentication strategies. Risk assessment aims to detect abnormal patterns in user behavior, thereby preventing unauthorized access, fraud, and attacks.

[0070] Considering that traditional rule engines are prone to false positives and lack adaptability, this invention employs a hierarchical risk assessment model combined with supervised learning to achieve higher accuracy.

[0071] For example, historical labeled data (such as known attack logs) can be used to train classification models (such as random forests or gradient boosting trees) to output risk levels (low, medium, high). The model can be deployed at the edge or in the cloud, calculating risk scores in real time upon login requests. For instance, a random forest outputs probability values; values ​​exceeding a risk threshold (e.g., 0.7) can be considered high-risk. It should be noted that the risk threshold can be dynamic, adapting to changes based on the user's historical behavior. For example, users who frequently travel might have a more lenient location threshold, optimized through reinforcement learning. Alternatively, the model can continuously learn from new data, using incremental learning algorithms (such as online random forests) to update and adapt to behavioral drift (e.g., users changing devices).

[0072] According to embodiments of the present invention, by integrating machine learning, real-time stream processing, and adaptive learning, false positives and false negatives can be reduced, security efficiency can be improved, and new attack patterns (such as slow password guessing) can be identified, surpassing rule-based systems. Through online learning, the system can be optimized according to changes in user behavior, and it is effective in the long term.

[0073] According to an embodiment of the present invention, the behavioral information includes at least one of login information, device information, and frequency information; based on the user's behavioral information and the risk information indicated by the behavioral information in the login request, the information to be authenticated is obtained, including: based on at least one of the login information, device information, and frequency information, determining a target risk level corresponding to the login request from multiple risk levels of the risk information; and generating the information to be authenticated based on the target risk level and a complexity function of the target risk level.

[0074] In embodiments of the present invention, login information may include the user's login location and the stability coefficient of the login location. Device information may include the device fingerprint and the matching rate of the device fingerprint, and frequency information may characterize the frequency of user login requests. Risk level may include high risk level, medium risk level, relatively low risk level, and low risk level. Target risk level may be the current risk level corresponding to the behavioral information of the current login request. Different risk levels correspond to different complexity calculation methods.

[0075] For example, when the login authentication method is "user behavior awareness and email segmentation dynamic password", the information to be authenticated can be a dynamic password. The rules for generating dynamic passwords can be obtained from user behavior information. The complexity (length and character set) of the dynamic password can be dynamically determined based on the user's historical login data (device fingerprint, geofencing of network address) and real-time request environment (risk level of current network address, login time).

[0076] For example, the complexity of dynamic passwords can be adjusted in real time based on the comparison or matching degree between historical behavior information such as user's historical login location, historical device fingerprints, and historical operation frequency, and the current behavior information of the current login request. Risk levels can include: high risk level, medium risk level, relatively low risk level, and low risk level.

[0077] For example, high-risk logins generate 12-character passwords containing special characters, while low-risk logins generate 6-character numeric passwords. The system can calculate the risk coefficient in real time using a behavioral analysis engine (e.g., based on machine learning or rule engines).

[0078] The risk coefficient for a low-risk level can be denoted as R, where R=0. The corresponding user behavior information can include: a 95% match between the current login location and historical login locations, and a fingerprint matching rate greater than 96% in city A. The risk coefficient for a lower-risk level is R=1. The corresponding user behavior information can include: a 98% match between the current operation frequency and historical operation frequency, both occurring between 8:00 AM and 7:00 PM on weekdays.

[0079] The risk coefficient R=2 for medium-risk level, and the corresponding user behavior information may include: the current login location is a new location but is in a common city (e.g., a different location in China), the matching rate between the current device fingerprint and the historical device fingerprint is 60% (e.g., a change in browser version), and the current operation frequency is slightly abnormal compared to the historical operation frequency (e.g., logging in at midnight).

[0080] The risk coefficient R=3 for high-risk level, and the corresponding user behavior information may include: the matching degree between the current login location and the historical login location is 0, cross-border address login, the matching rate between the current device fingerprint and the historical device fingerprint is 0, and the current operation frequency is high-frequency abnormal (e.g., more than 20 attempts within 1 minute).

[0081] In one feasible embodiment, the character information of the information to be authenticated can be determined according to the target risk level. The character information can be composed of a combination of multiple characters. The method for determining the character information set for different risk levels can include: when the risk level is greater than or equal to a first risk threshold, the character information set constituting the dynamic password contains three or more types of characters. When the risk level is less than a second risk threshold, the dynamic password can consist only of numbers.

[0082] In one feasible implementation, the validity period of the authentication information can be determined based on the target risk level. For example, the password validity period can be dynamically shortened or extended based on the risk level of the login network address (IP) (e.g., proxy IP, unfamiliar geographical location) (e.g., passwords expire after 5 minutes for logins from high-risk IPs, and remain valid for 30 minutes for logins from frequently used devices).

[0083] In one feasible implementation, a username can be associated with an email domain, for example, enterprise users must use the company domain email; "trusted devices" can be set to bypass dynamic password verification; login on frequently used devices can be set to bypass dynamic password verification for a period of time (e.g., 7 days), and new devices will be forced to trigger it.

[0084] According to an embodiment of the present invention, multiple risk levels correspond to multiple length parameters and multiple character parameters; the method further includes: determining a target length parameter and a target character parameter from the multiple length parameters and multiple character parameters based on the target risk level; and constructing a complexity function using the update coefficient, the target length parameter, and the target character parameter corresponding to the target risk level, wherein the update coefficient is an exponential coefficient determined according to the target risk level for controlling the length of the information to be authenticated.

[0085] In embodiments of the present invention, the risk level can be represented as a risk coefficient, which is directly proportional to both the value of the length parameter and the complexity of the character parameter. The target length parameter and the target character parameter both correspond to the target risk level. The update coefficient can be an exponential coefficient determined in real-time based on the risk level to control the length of the information to be authenticated, thereby rapidly increasing the security strength of the information to be authenticated when the risk level is high, thus improving the security of the information to be authenticated.

[0086] For example, by combining the length parameter and the character parameter, the result of the complexity function Complexity_params can be quantified as an entropy value, as shown in the following formula (2):

[0087] Complexity_params ={length:L(R score ), charset:C(R score )} (2;

[0088] Where L() and C() can be mapping functions between the target risk level and the length parameter, and between the target risk level and the character parameter, respectively. R score It can be a risk factor.

[0089] In related technologies, the length of passwords or passphrases is mainly achieved through linear adjustment. However, the growth rate of linear adjustment is constant, making it difficult to keenly detect changes in risk levels and respond to sudden threats in a timely manner.

[0090] Embodiments of this invention introduce an update coefficient k (e.g., k≥2) to allow the password length to grow non-linearly with changes in risk level. The password length calculation formula can be length = base_length + (max_length − base_length) × R. scorek Where base_length can be the base length and max_length can be the maximum length.

[0091] For example, with k=2, under the same parameters, when the update coefficient is an exponential coefficient, the risk coefficient increases from 0.5 to 0.9, and the length increases from 8 characters to 11 characters (an increase of 3 characters), with the growth rate accelerating as the risk level increases. At high risk levels (R... score In the case of > 0.7), the growth curve is steep, for example, the length is about 10 characters when the risk coefficient is 0.8 and about 11 characters when it is 0.9, while the linear adjustment only increases from 10.8 characters to 11.4 characters in the same range.

[0092] According to an embodiment of the present invention, the nonlinear response enables the exponential adjustment to more sensitively capture changes in risk level, especially at critical high-risk points, and rapidly enhance the defense strength. The exponential adjustment ensures that the strong password is applied only when it is really needed (e.g., when the risk coefficient is above 0.8), avoiding the decline in user experience caused by "over-security".

[0093] According to an embodiment of the present invention, the information to be authenticated is fragmented and encapsulated based on a preset strategy, risk information, and time information to obtain encapsulated processing information, including: fragmenting the information to be authenticated based on the fragmentation strategy and risk information to obtain fragmentation results; and encapsulating the fragmentation results based on the encapsulation strategy to obtain encapsulation results in the encapsulated processing information.

[0094] In embodiments of the present invention, the fragmentation result can be multiple results obtained by fragmenting the information to be authenticated when the risk level meets preset conditions. The time information can be a timestamp generated in real time based on the login request to indicate that the login request was triggered.

[0095] For example, the sharding process can use random cut-off points to ensure that each shard is different. The cut-off point can be generated based on a random seed, such as the session unique identifier (ID) in this login request or the timestamp of the authentication information, to enhance the security of the authentication information sharding process.

[0096] For example, encapsulation processing can involve packaging and distributing fragmented results through different channels and formats to enhance security and reliability. Encapsulation strategies can define how fragments are sent, encryption measures, and channel selection, and can be tied to risk levels. Encapsulation strategies may include channel selection, encryption, and metadata addition.

[0097] For example, based on risk levels, fragments can be sent via heterogeneous channels to increase the difficulty of attacks: low risk can correspond to a single channel (e.g., all sent via email body). High risk can correspond to multiple channels (e.g., fragment 1 via email header, fragment 2 via email body, fragment 3 via SMS, and fragment 4 via application push). Fragments can be lightly encrypted or obfuscated to prevent eavesdropping. XOR operations can be used to bind to timestamps or add integrity check codes to prevent tampering. Contextual information, such as expiration date and serial number, can be added to each fragment for easier reassembly and verification.

[0098] According to an embodiment of the present invention, based on a sharding strategy and risk information, the information to be authenticated is sharded to obtain a sharding result, including: when the risk level in the risk information is greater than or equal to a level threshold, hashing the identification information or time information generated based on the login request to obtain a converted value; updating the initial generation function using the converted value to obtain a generation function; generating sharding information based on the generation function within a preset value range; and using the sharding information to shard the information to be authenticated to obtain a sharding result, wherein the preset value range corresponds to the risk level.

[0099] In embodiments of the present invention, the identification information can be the identifier information of this login request, such as a session unique identifier (ID). The time information can be the timestamp of the dynamic password generation. The session ID can be generated by the server when the user initiates a login request and associated with the entire authentication session, which can ensure that the sharding mode is consistent within the same session, but the differences between different sessions are huge. The timestamp can record the precise time of password generation (e.g., milliseconds), so that the sharding mode changes over time and is different even when the same user logs in multiple times.

[0100] In embodiments of the present invention, the converted value can be a fixed-length hash value obtained by hashing the identification information or time information. The generation function can be used to convert the identification information or time information into a digital fingerprint of preset bytes.

[0101] For example, by filling, segmenting, and initializing the session ID into a vector, a vector result can be obtained. Then, multiple rounds of bitwise operations can be performed on the vector result to obtain multiple operation results. These multiple operation results can be concatenated to obtain a digital seed (converted value). The digital seed can then be used to initialize the initial generation function to obtain the initialized generation function. The generation function can then be bound to the session ID. Furthermore, the number of fragments can be determined from a preset value range based on the risk level. On this basis, the information to be authenticated can be fragmented to obtain multiple fragment results.

[0102] Taking the information to be authenticated as “374921” as an example, if the risk level of the current login request is determined to be medium risk, the process of sharding the information to be authenticated can include: obtaining the session ID of the current session, hashing the session ID to generate a fixed-length seed, and using the generated seed to initialize a random number generator (e.g., PRNG) so that the random sequence generated based on the same seed is exactly the same each time; using the random number generator to generate N-1 random cut points, for example, for a 6-digit password (“374921”), cut points [2, 4] can be generated, thus obtaining the sharding result [“37”, “49”, “21”].

[0103] The session ID is a unique identifier generated by the system, and the timestamp can be accurate to the millisecond level. Both have high entropy values ​​and serve as the seed for a pseudo-random number generator (PRNG), generating random sequences of sharding points. For example, for the dynamic password "374921", the timestamp-based sharding might be [37, 49, 21] one time and [3, 74, 92, 1] the next, with no discernible pattern, significantly increasing the attack cost for attackers.

[0104] According to embodiments of the present invention, dynamic data sharding driven by identification information or time information can achieve the uniqueness and unpredictability of the sharding pattern. Each login request has a different sharding pattern, making intercepted fragments unusable; attackers find it difficult to recover the complete password from partial fragments and would need to compromise multiple channels simultaneously; the sharding strategy can be dynamically adjusted according to real-time risks, balancing security and user experience; and during the verification phase, the server can accurately reproduce the sharding process, ensuring successful authentication for legitimate users.

[0105] According to an embodiment of the present invention, the sharding result is encapsulated based on an encapsulation strategy to obtain the encapsulated result in the encapsulated processing information, including: generating mask information corresponding to each of the multiple shards in the sharding result based on identification information or time information; updating the multiple shards using the mask information to obtain multiple updated shards; and encapsulating the mask information and the updated shards of the mask information to obtain the encapsulation result.

[0106] In embodiments of the present invention, the mask information can be a randomly generated random number or random characters. Updating fragments can be achieved by masking multiple fragments using the mask information. The encapsulation result can include multiple encapsulation sub-results, the number of which can be related to the address type or transmission method of the target address in the actual scenario.

[0107] For example, the session ID or high-precision timestamp of the current login session can be extracted as the numerical seed for the mask, ensuring that the mask key is different for each login. A hash operation is performed on the dynamic numerical seed to generate a fixed-length mask key. To simplify the operation, the hash output can be truncated or converted to numerical form for XOR operation, and the first four bytes of the hash value can be used as the integer key. The XOR operation is then used to mask each fragment. During encapsulation, the timestamp or session ID can be appended as metadata to the mask fragment for verification and demasking at the receiving end. After masking, the encapsulation process for the mask information and its updated fragments can include combining different mask fragments with metadata (such as timestamps and sequence numbers) to obtain structured data, which serves as the encapsulation result.

[0108] According to embodiments of the present invention, by updating multiple fragments using mask information, the mask renders the fragments garbled during transmission, preventing attackers from directly obtaining the original fragments even if they are abnormally intercepted. The mask key depends on a timestamp, allowing fragments to be demasked only within their validity period (e.g., 5 minutes), automatically expiring and becoming invalid, effectively defending against replay attacks.

[0109] According to an embodiment of the present invention, sending processing information to a target address includes: when the target address is email address information, constructing multiple data packets corresponding to multiple encapsulation sub-results in the encapsulation result; and sending the combined result of the multiple data packets to the email address information to authenticate user permission information.

[0110] In embodiments of the present invention, the encapsulation result may include multiple encapsulation sub-results depending on the sending method. Data packets may include various types, such as model information data packets corresponding to email address information, text information, and attachment information. Email protocols and the default standard protocol (Multipurpose Internet Mail Extensions, MIME) can be used to create an email containing multiple parts.

[0111] For example, encapsulated sub-results (such as masked fragment strings, timestamp hashes, etc.) can be embedded in different parts of the email. The email subject can be used to place a brief encapsulation result, such as the first fragment or a notification message; the email body can be used to place detailed encapsulation results, including multiple fragments, checksums, or explanatory text, and can support multiple formats (such as plain text and HTML). Email attachments can be used to place additional encapsulation results, such as binary data, attached as a file.

[0112] For example, masked update fragment 1 can be used for the email header, masked update fragment 2 for the email body, and masked update fragment 3 for the email attachments. Metadata (timestamp hash or expiration information) can also be included, resulting in multiple data packets. Then, using the MIME protocol, these multiple data packets (text, HTML, attachments) can be encapsulated into a single email, creating an email container. This container can include a root container to hold all parts; the body container can support both plain text and HTML versions; and attachments can be directly added to the root container. Finally, the combined result of these multiple data packets is sent to the email address using a mail transfer protocol, with encrypted connections used to protect transmission security.

[0113] According to embodiments of the present invention, the encapsulation results are sent to the email subject, body, and attachments through different channels, realizing a multi-layered and secure authentication information distribution mechanism and reducing the risk of a single attack point. Users can intuitively view the fragment information in the email, and the attachments provide additional data downloads, thus satisfying the user experience.

[0114] In one feasible embodiment, after a user successfully logs into the storage system, the storage management system can send an interface command to the email server to automatically delete emails containing passwords.

[0115] In the storage system login authentication process, two-way domain name verification is a mechanism to enhance security. It involves both the client and the storage management system verifying the authenticity of the domain name to ensure the trustworthiness of both parties in communication.

[0116] For enterprise users, usernames can be set to match the email domain (e.g., user@company.com, usernames must include the "company_" prefix), and include an anti-spoofing mechanism. The system can query email initialization records in real time and verify domain validity. This function first verifies the legality of calls and parameters (whether it's GUI login, whether the user is locked, whether the parameters are valid, etc.) to perform dynamic password verification. The email dynamic password is passed to the backend through the same field that originally transmitted the user password. To distinguish between dynamic and user passwords in the authentication flow, a marker for the password type requested by the command can be added during the command or function assembly stage. Several environment variables are also added; for example, environment variables are passed during email dynamic password login authentication to mark it as pending authentication; after successful email dynamic password login authentication, the environment variables passed by the command are invoked to mark successful dynamic password authentication and login to the graphical user interface.

[0117] Figure 3B A flowchart of a two-way authentication login method according to an embodiment of the present invention is shown.

[0118] like Figure 3BAs shown, the two-way authentication login authentication method may include operations S310~S317.

[0119] When operating the S310, users can enter a dynamic password through the graphical user interface of the terminal device to trigger verification and call verification commands to perform verification.

[0120] When operating S311, the storage management system determines whether to use dynamic password authentication or user password authentication by obtaining environment variable information.

[0121] When operating S312, verify whether the username is correct.

[0122] If not, execute the login denial operation when operating S313.

[0123] If operating S314, verify the dynamic password.

[0124] When operating S315, determine whether the user is in an active lock state.

[0125] If the operation is in S316, return to operation S313.

[0126] If not, allow terminal login when operating S317.

[0127] Figure 4 A block diagram of an information processing system for an information processing method according to an embodiment of the present invention is shown.

[0128] like Figure 4 As shown, the information processing system for storage system login authentication may include a login authentication policy management and configuration subsystem 410 and a login authentication subsystem 420. Both the login authentication policy management and configuration subsystem 410 and the login authentication subsystem 420 have a graphical user interface 401, an instruction generation module 402 and an instruction execution module 403.

[0129] The login authentication policy management and configuration subsystem 410 can be used to view, enable or disable the "user behavior awareness and email fragmented dynamic password" login authentication policy. This module can provide confirmation control items on the user's terminal device's graphical user interface (GUI) 401. The GUI can detect the format validity of the login authentication information sending address information (such as email information).

[0130] The instruction generation module 402 of the storage management system can modify the "User Creation" instruction 411 to initialize the user's "User Behavior Awareness and Email Sharding Dynamic Password" login authentication policy and email information; it can modify the "User Modification" instruction 412 to support modifying the "User Behavior Awareness and Email Sharding Dynamic Password" login authentication policy and email information; it can modify the "User Information View" instruction 413 to view the current user's "User Behavior Awareness and Email Sharding Dynamic Password" login authentication policy and email information; and it can modify the "User Deletion" instruction 414 to delete the user's "User Behavior Awareness and Email Sharding Dynamic Password" login authentication policy and email information.

[0131] The instruction execution module 403 of the storage management system can execute various types of instructions in real time according to actual needs, including username and password authentication 415 and email dynamic password authentication 416.

[0132] For example, initializing the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy can include: modifying the "User Creation" 411 instruction to add the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy's enabled status and an email field. "User Behavior Awareness and Email Segmented Dynamic Password" can be disabled by default, and the email field can be left empty by default; no extended parameters are allowed.

[0133] For example, enabling or disabling the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy can include: modifying the "User Modification" command 412 to add the functionality to enable or disable the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy; expanding the `email_otp_status` (value 1 or 0) and `email_addr` parameters (value is the email address); email address validity checks can directly use the system's built-in implementation. When `email_otp_status` is 1, it can be followed by the `-email_addr` parameter (cannot be empty). When `email_otp_status` is 0, only the policy status value needs to be changed, without affecting the user's `email_addr` data.

[0134] For example, deleting the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy can include: modifying the "User Deletion" 414 command to delete the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy's enabled status and related data for the email field, without extending the parameters.

[0135] For example, checking the enabled status of the "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy can include: modifying the "User Information View" 413 command to view the enabled status of the user's "User Behavior Awareness and Email Segmented Dynamic Password" login authentication policy and the email field.

[0136] The login authentication subsystem 420 can provide a login option interface based on the graphical user interface 401. After enabling the "user behavior awareness and email sharding dynamic password" login authentication strategy, users can choose a login authentication method, such as username and password method 421 or email dynamic password method 422. The graphical user interface 401 can also provide a "user behavior awareness and email sharding dynamic password" interface, including a confirmation to send dynamic password control item and a graphic verification code control item, and can also provide a countdown function for obtaining the dynamic password again. In the instruction generation module 402 of the storage management system, the default setting is "email system usage instruction 423", and a "dynamic password sending instruction 424" corresponding to "user behavior awareness and email sharding dynamic password" can be added. The login authentication mechanism can be modified to support "user behavior awareness and email sharding dynamic password" login authentication, which can be implemented by extending the existing "username + password" login authentication mechanism.

[0137] The instruction execution module 403 of the storage management system can execute dynamic password generation 425 and information encapsulation 426. For example, the dynamic password generation part adds a dynamic password retrieval instruction, the instruction type is a cluster instruction, and the instruction parameters include the username; the login authentication part supports the "user behavior awareness and email sharding dynamic password" authentication mechanism, which is implemented by extending the user authentication process of the GUI and is executed when the "user information view" instruction 413 is called.

[0138] Based on the above information processing method, the present invention also provides an information processing apparatus. The following will be combined with... Figure 5 The device is described in detail.

[0139] Figure 5 A structural block diagram of an information processing apparatus according to an embodiment of the present invention is shown.

[0140] like Figure 5 As shown, the information processing device 500 of this embodiment includes an information determination module 510, an information processing module 520, and an information sending module 530.

[0141] The information determination module 510 is used to respond to a login request triggered by a user through a terminal device, and to obtain authentication information based on the user's behavior information and risk information indicated by the behavior information in the login request, wherein the authentication information includes time information. In one embodiment, the information determination module 510 can be used to perform the operation S210 described above, which will not be repeated here.

[0142] The information processing module 520 is used to segment and encapsulate the information to be authenticated based on a preset strategy, risk information, and time information to obtain encapsulated processed information. The preset strategy includes a segmentation strategy for segmenting the information to be authenticated and an encapsulation strategy for encapsulating the segmentation results. In one embodiment, the information processing module 520 can be used to execute the operation S220 described above, which will not be repeated here.

[0143] The information sending module 530 is used to send processed information to a target address for authentication of permission information based on the processed information. The target address is used to authenticate the user's permission information for logging into storage resources and corresponds to the user information. In one embodiment, the information sending module 530 can be used to perform the operation S230 described above, which will not be repeated here.

[0144] According to an embodiment of the present invention, based on the information determination module 510, information processing module 520, and information sending module 530 in the information processing device 500, the user's behavior information and associated risk information in the login request are evaluated in real time to dynamically generate authentication information. This allows for flexible adjustment of authentication and encapsulation strategies by combining the time information and risk information of the authentication information. Since the information processing utilizes a fragmentation strategy to distribute the information, an encapsulation strategy to encrypt the fragments, and binding with time information to give the information timeliness, it achieves the integration of multiple methods: user behavior perception, real-time risk rating, dynamic fragmentation and encapsulation, and timestamp binding. This transforms the information processing process from a static flow to a dynamic decision-making process, satisfying the security, dynamism, and adaptability requirements of the information processing process.

[0145] According to an embodiment of the present invention, the behavioral information includes at least one of login information, device information, and frequency information; the information determination module 510 includes a level determination submodule and an information generation submodule. The level determination submodule is used to determine the target risk level corresponding to the login request from multiple risk levels of risk information based on at least one of login information, device information, and frequency information; the information generation submodule is used to generate authentication information based on the target risk level and a complexity function of the target risk level.

[0146] According to an embodiment of the present invention, the information processing module 520 includes a fragmentation submodule and an encapsulation submodule. The fragmentation submodule is used to fragment the information to be authenticated based on a fragmentation strategy and risk information to obtain fragmentation results; the encapsulation submodule is used to encapsulate the fragmentation results based on an encapsulation strategy to obtain encapsulation results in the encapsulated processed information.

[0147] According to an embodiment of the present invention, the sharding submodule includes: a conversion unit, an update unit, and a sharding processing unit. The conversion unit is used to perform a hash conversion on the identifier information or time information generated based on the login request when the risk level in the risk information is greater than or equal to a level threshold, to obtain a converted value. The update unit is used to update the initial generation function using the converted value to obtain a generation function. The sharding processing unit is used to generate sharding information based on the generation function within a preset value range, and to perform sharding processing on the information to be authenticated using the sharding information to obtain a sharding result, wherein the preset value range corresponds to the risk level.

[0148] According to an embodiment of the present invention, the encapsulation submodule includes: a generation unit, a fragment update unit, and an encapsulation unit. The generation unit is used to generate mask information corresponding to each of the multiple fragments in the fragmentation result based on identification information or time information; the fragment update unit is used to update the multiple fragments using the mask information to obtain multiple updated fragments; the encapsulation unit is used to encapsulate the mask information and the updated fragments of the mask information to obtain an encapsulation result.

[0149] According to an embodiment of the present invention, the information sending module 530 includes a data packet construction submodule and an authentication submodule. The data packet construction submodule is used to construct multiple data packets corresponding to multiple encapsulation sub-results in the encapsulation result when the target address is email address information. The authentication submodule is used to send the combined result of the multiple data packets to the email address information to authenticate user authorization information.

[0150] According to an embodiment of the present invention, the behavioral information includes the user's previous login information, previous device information, and previous frequency information of the user triggering login requests; the device further includes: a matching degree determination module and a weighting module. The matching degree determination module is used to determine multiple matching degrees between the user's current login information, current device information, and current frequency information and the previous login information, previous device information, and previous frequency information, respectively, wherein the multiple matching degrees have their own weights; the weighting module is used to weight the multiple matching degrees using the weights to obtain risk information.

[0151] According to an embodiment of the present invention, the information processing device further includes: a duration determination module, configured to obtain a target duration of the information to be certified based on a baseline duration of the information to be certified, a risk coefficient indicating the risk level, and a reference duration when the risk level is greater than or equal to a level threshold, so as to control the validity of the information to be certified based on the target duration.

[0152] According to an embodiment of the present invention, multiple risk levels correspond to multiple length parameters and multiple character parameters; the information processing device further includes: a parameter determination module and a function construction module. The parameter determination module is used to determine a target length parameter and a target character parameter from the multiple length parameters and multiple character parameters based on the target risk level; the function construction module is used to construct a complexity function using an update coefficient corresponding to the target risk level, the target length parameter, and the target character parameter, wherein the update coefficient is an exponential coefficient determined according to the target risk level to control the length of the information to be authenticated.

[0153] According to embodiments of the present invention, any plurality of modules among the information determination module 510, information processing module 520, and information transmission module 530 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least a portion of the functionality of one or more of these modules may be combined with at least a portion of the functionality of other modules and implemented in one module. According to embodiments of the present invention, at least one of the information determination module 510, information processing module 520, and information transmission module 530 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the information determination module 510, information processing module 520, and information transmission module 530 may be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0154] Figure 6 A block diagram of an electronic device suitable for implementing an information processing method according to an embodiment of the present invention is shown.

[0155] like Figure 6 As shown, the electronic device includes a memory 601 and a processor 602 configured to execute any of the above-described information processing methods according to instructions and data stored in the memory 601.

[0156] Figure 7 A block diagram of another electronic device suitable for implementing an information processing method according to an embodiment of the present invention is shown.

[0157] like Figure 7As shown, an electronic device according to an embodiment of the present invention includes a first processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage portion 708 into a random access memory (RAM) 703. The first processor 701 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor, and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The first processor 701 may also include onboard memory for caching purposes. The first processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.

[0158] RAM 703 stores various programs and data required for the operation of the electronic device. The first processor 701, ROM 702, and RAM 703 are interconnected via bus 704. The first processor 701 executes various operations of the method flow according to embodiments of the present invention by executing programs in ROM 702 and / or RAM 703. It should be noted that the programs may also be stored in one or more memories other than ROM 702 and RAM 703. The first processor 701 may also execute various operations of the method flow according to embodiments of the present invention by executing programs stored in said one or more memories.

[0159] According to embodiments of the present invention, the electronic device may further include an input / output (I / O) interface 705, which is also connected to a bus 704. The electronic device may also include one or more of the following components connected to the input / output (I / O) interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the input / output (I / O) interface 705 as needed. A removable medium 711, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 710 as needed so that computer programs read from it can be installed into the storage section 708 as needed.

[0160] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present invention.

[0161] According to embodiments of the present invention, a computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of the present invention, a computer-readable storage medium may include ROM 702 and / or RAM 703 and / or one or more memories other than ROM 702 and RAM 703 described above.

[0162] Embodiments of the present invention also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the information processing method provided in the embodiments of the present invention.

[0163] When the computer program is executed by the first processor 701, it performs the functions defined in the system / apparatus of this invention. According to embodiments of the invention, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0164] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 709, and / or installed from a removable medium 711. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0165] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709, and / or installed from the removable medium 711. When the computer program is executed by the first processor 701, it performs the functions defined in the system of this embodiment of the invention. According to embodiments of the invention, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0166] According to embodiments of the present invention, program code for executing the computer programs provided in the embodiments of the present invention can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0167] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0168] Those skilled in the art will understand that the features described in the various embodiments of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, the features described in the various embodiments of the present invention can be combined and / or combined in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or combinations fall within the scope of the present invention.

[0169] The embodiments of the present invention have been described above. However, these embodiments are merely illustrative and not intended to limit the scope of the invention. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of the invention, and all such substitutions and modifications should fall within the scope of the invention.

Claims

1. An information processing method, characterized in that, The method includes: In response to receiving a login request for logging into the data storage system triggered by a user through a terminal device, based on the user's behavior information and the risk information indicated by the behavior information in the login request, information to be authenticated is obtained. The information to be authenticated has time information and a target duration for controlling the validity of the information to be authenticated. The target duration of the information to be authenticated is determined in the following way: when the risk level is greater than or equal to the level threshold, the target duration of the information to be authenticated is obtained based on the baseline duration of the information to be authenticated, the risk coefficient indicated by the risk level, and the reference duration. Based on a preset strategy, the risk information, and the time information, the information to be authenticated is fragmented and encapsulated to obtain encapsulated processed information. The preset strategy includes a fragmentation strategy for fragmenting the information to be authenticated and an encapsulation strategy for encapsulating the fragmentation results. The fragmentation strategy includes: if the risk level in the risk information is greater than or equal to a level threshold, hashing the session unique identifier or time information generated based on the login request to obtain a converted value; updating the initial generation function using the converted value to obtain a generation function; generating fragmented information within a preset value range based on the generation function; and using the fragmented information to fragment the information to be authenticated to obtain the fragmentation result. The encapsulation strategy includes: generating mask information corresponding to each fragment in the fragmentation result based on the session unique identifier or the time information; updating the multiple fragments using the mask information to obtain multiple updated fragments; and encapsulating the mask information and the updated fragments of the mask information to obtain the encapsulation result. The processing information is sent to the target address to perform permission information authentication based on the processing information. The target address is used to authenticate the user's permission information for logging into storage resources and corresponds to the user information.

2. The method according to claim 1, characterized in that, The behavioral information includes at least one of login information, device information, and frequency information; Based on the user's behavioral information and the risk information indicated by the behavioral information in the login request, the authentication information is obtained, including: Based on at least one of the login information, the device information, and the frequency information, determine the target risk level corresponding to the login request from multiple risk levels of the risk information; The authentication information is generated based on the target risk level and the complexity function of the target risk level.

3. The method according to claim 1, characterized in that, Based on a preset strategy, the risk information, and the time information, the information to be authenticated is fragmented and encapsulated to obtain encapsulated processed information, including: Based on the sharding strategy and the risk information, the information to be authenticated is sharded to obtain the sharding result; The fragmentation results are encapsulated based on the encapsulation strategy to obtain the encapsulation result in the processing information.

4. The method according to claim 3, characterized in that, Sending the processing information to the target address includes: If the target address is an email address, construct multiple data packets corresponding to the multiple encapsulation sub-results in the encapsulation result; The combined result of the multiple data packets is sent to the email address information to authenticate the user's permission information.

5. The method according to claim 1, characterized in that, The behavioral information includes the user's previous login information, previous device information, and the frequency information of the user triggering login requests. The method further includes: Multiple matching degrees are determined between the user's current login information, current device information, and current frequency information and the previous login information, previous device information, and previous frequency information, respectively, and the multiple matching degrees have their own weights; The risk information is obtained by weighting the multiple matching degrees using the weights.

6. The method according to claim 2, characterized in that, The multiple risk levels correspond to multiple length parameters and multiple character parameters; The method further includes: Based on the target risk level, the target length parameter and the target character parameter are determined from the plurality of length parameters and the plurality of character parameters, respectively; The complexity function is constructed using the update coefficient corresponding to the target risk level, the target length parameter, and the target character parameter, wherein the update coefficient is an exponential coefficient determined according to the target risk level to control the length of the information to be authenticated.

7. An electronic device, characterized in that, include: Memory; A processor configured to execute the method according to any one of claims 1 to 6, based on instructions and data stored in the memory.

Citation Information

Patent Citations

  • Cross-system non-inductive switching authentication method and device for e-commerce

    CN120602224A

  • Data processing method and device, electronic equipment, medium and program product

    CN120687492A