Login authentication method, device, equipment, medium and product
By using the Super SIM card to obtain and verify returned information under different network environments, the problem of high user memory costs and security risks in existing login authentication is solved, enabling secure login without account passwords, thus improving user experience and system security.
Patent Information
- Application Number
- CN202411612174.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-12-12
AI Technical Summary
Existing login authentication methods rely on account and password systems, which result in high memory costs for users and pose security risks. In particular, they cannot be effectively verified without a network connection, increasing the possibility of account theft or impersonation.
A multi-environment secure login method based on a super SIM card is adopted. The returned information is obtained through the SIM card for verification, including online, intranet and offline scenarios. The encrypted calculation and permission management of the SIM card are used to avoid users having to remember their account and password, and the user's identity is verified directly through the SIM card.
It reduces the user's memory burden, improves the security of the login process, prevents account theft or impersonation, and ensures effective verification of user permissions in various network environments.
Smart Images

Figure CN121125135A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security, and in particular to a login authentication method, apparatus, device, medium, and product. Background Technology
[0002] Login authentication, as a process to ensure the authenticity of user identity, is an important part of information security. The existing login authentication is mainly based on the account and password system. Although there are methods such as SMS verification codes and biometric recognition to simplify the login process, users usually still need to create an account and enter a password before they can use it. This can easily increase the user's memory burden and make it easy for accounts to be stolen or impersonated, resulting in security risks to login authentication.
[0003] Therefore, it is necessary to propose a solution to reduce the user's memory cost and security risks during the login authentication process.
[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of this application is to provide a login authentication method, apparatus, device, medium and product, which aims to reduce the user's memory cost and security risks in the login authentication process.
[0006] To achieve the above objectives, this application provides a login authentication method, which is applied to a business system and includes:
[0007] In response to receiving a login request initiated by the user in the current login scenario, the system obtains the SIM card's return information based on the current login scenario.
[0008] The returned information is validated to obtain a validation result, which is used to determine whether the user is allowed to log in.
[0009] In one embodiment, the step of obtaining the SIM card's return information based on the current login scenario further includes:
[0010] Obtain account information and / or authorization information;
[0011] The account information and / or authorization information are encrypted to obtain encrypted information;
[0012] The encrypted information is sent to the data security operation platform, which converts the encrypted information into application protocol data unit instructions and sends the application protocol data unit instructions to the SIM card, so that the SIM card can complete key exchange and data writing to obtain the pre-processing data. The pre-processing data is used to generate or determine the return information.
[0013] In one embodiment, the current login scenario includes at least one of an online login verification scenario, an intranet login verification scenario, and an offline login verification scenario. The returned information includes first returned information, second returned information, and third returned information. The step of obtaining the SIM card's returned information based on the current login scenario includes at least one of the following:
[0014] If the current login scenario is an online login verification scenario, then the first return information of the SIM card is obtained through the data security operation platform and software development kit;
[0015] If the current login scenario is an intranet login verification scenario, then the second return information of the SIM card is obtained through the software development kit;
[0016] If the current login scenario is an offline login verification scenario, then the user information is read through near-field communication and sent to the SIM card to obtain the third return information corresponding to the user information sent by the SIM card, wherein the third return information includes user group information and / or permission information.
[0017] In one embodiment, the step of obtaining the first return information of the SIM card through the data security operation platform and software development kit includes:
[0018] A user login request is initiated to the data security operation platform, so that the data security operation platform can find the corresponding SIM card according to the user login request and forward the user login request to the SIM card. The card application in the SIM card obtains the user login confirmation through the software development kit. After obtaining the user login confirmation, the card application performs encrypted calculations based on the user login request and the previous data to obtain the confirmation result. The confirmation result and the user login confirmation are sent to the business system as the first return information through the software development kit.
[0019] Receive the first return information sent by the software development kit.
[0020] In one embodiment, the step of obtaining the second return information of the SIM card through the software development kit includes:
[0021] The software development kit (SDK) is used to obtain the device identifier and local time of the device, and a data instruction is generated based on the device identifier and local time of the device and sent to the SIM card. The SIM card generates a temporary token code based on the data instruction and displays the temporary token code to the user's device interface through the SSD, so as to obtain the account name and temporary verification code entered by the user based on the temporary token code.
[0022] The account name and temporary verification code are used as the second returned information.
[0023] In one embodiment, after the step of obtaining the second return information of the SIM card through the software development kit, the method further includes:
[0024] Generate at least one check code within a preset time range based on the aforementioned pre-set data;
[0025] The at least one verification code is matched with the temporary verification code in the second returned information;
[0026] If the at least one check code matches the temporary check code, the verification is deemed successful.
[0027] Furthermore, to achieve the above objectives, this application also proposes a login authentication method, the method comprising:
[0028] Furthermore, to achieve the above objectives, this application also proposes a login authentication device, which is applied to a business system and includes:
[0029] The response module is used to respond to a login request initiated by the user in the current login scenario and obtain the return information of the SIM card according to the current login scenario.
[0030] The verification module is used to verify the returned information and obtain a verification result, which is used to determine whether the user is allowed to log in.
[0031] In addition, to achieve the above objectives, this application also proposes a login authentication device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the login authentication method as described above.
[0032] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the login authentication method described above.
[0033] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the login authentication method described above.
[0034] One or more technical solutions proposed in this application have at least the following technical effects:
[0035] In response to receiving a login request initiated by a user in the current login scenario, the system obtains the SIM card's return information based on the current login scenario; verifies the return information to obtain a verification result, which is used to determine whether the user is allowed to log in. By obtaining the return information using the SIM card and determining whether to allow the user to log in based on the verification result of the return information, the system eliminates the need for users to remember specific accounts and passwords, reducing the user's memory cost during the login authentication process. It also eliminates the need for verification methods such as account passwords or verification codes, preventing account theft or impersonation, thereby reducing security risks during the login authentication process. Attached Figure Description
[0036] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0037] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0038] Figure 1 This is a flowchart illustrating the login authentication method of this application in Embodiment 1;
[0039] Figure 2 This is a flowchart illustrating Embodiment 2 of the login authentication method of this application;
[0040] Figure 3 This is a schematic diagram illustrating the key exchange and data distribution process according to the first embodiment of this application;
[0041] Figure 4 This is a flowchart illustrating Embodiment 3 of the login authentication method of this application;
[0042] Figure 5 This is a schematic diagram illustrating the online login verification process according to the third embodiment of this application;
[0043] Figure 6 This is a schematic diagram of an intranet login verification process according to the third embodiment of this application;
[0044] Figure 7 This is a schematic diagram of the module structure of the login authentication device in an embodiment of this application;
[0045] Figure 8 This is a schematic diagram of the device structure of the hardware operating environment involved in the login authentication method in this application embodiment.
[0046] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0047] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0048] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0049] The main solution of this application embodiment is: in response to receiving a login request initiated by a user in the current login scenario, obtaining the return information of the SIM card according to the current login scenario; verifying the return information to obtain a verification result, the verification result being used to determine whether the user is allowed to log in. By obtaining the return information with the help of the SIM card, and determining whether to allow the user to log in based on the verification result of the return information, the user does not need to remember a specific account and password, reducing the user's memory cost in the login authentication process. There is no need to use account password or verification code login for verification, avoiding account theft or impersonation, thereby reducing the security risks in the login authentication process.
[0050] In this embodiment, for ease of description, the login authentication device will be used as the execution subject in the following description.
[0051] Technical terms used in the embodiments of this application:
[0052] SIM (Subscriber Identity Module);
[0053] SDK (Software Development Kit);
[0054] APDU (Application Protocol Data Unit);
[0055] DSOP (Data Security Operations Platform);
[0056] BIP (Bearer Independent Protocol);
[0057] NFC (Near Field Communication);
[0058] IMEI (International Mobile Equipment Identity);
[0059] SEID (Secure Element Identifier);
[0060] UICC (Universal Integrated Circuit Card).
[0061] Existing login authentication systems are still based on account and password systems. Users need to create an account, enter a password, and complete the initial login. In recent years, one-click login methods have emerged that integrate with telecom operators' SDKs (Software Development Kits), providing authentication capabilities through telecom operators. However, the actual account still uses the user's mobile phone number. Although methods such as SMS verification codes and biometric recognition (fingerprint, palm print, face) simplify the login process, users usually still need to create an account and enter a password before they can use the service.
[0062] For users, remembering passwords is usually quite troublesome, and improper password storage may also pose a risk of account theft. Moreover, existing methods such as SMS verification codes and biometric identification often require an internet connection, and these methods cannot be used properly when network conditions are limited.
[0063] Current login methods primarily rely on passwords or SMS verification codes. Improperly stored passwords pose a risk of account theft. As users use more software or platforms, their number of accounts also increases, creating a burden of remembering accounts and passwords. Using the same password across multiple platforms significantly reduces account security, making users vulnerable to "credential stuffing" attacks. SMS verification codes also have vulnerabilities that can be exploited in telecommunications operator systems or rules, allowing them to be forwarded to other phone numbers. Furthermore, SMS verification codes can be easily accessed by apps with SMS reading permissions, further compromising their security.
[0064] In an intranet environment where there is no internet connection, users often need to open an intranet account to log in to the internal system. Since intranet accounts only require username and password verification, there is a possibility of account theft, which may lead to users having their accounts misused without their knowledge.
[0065] When users are without an internet connection, they generally cannot log in or perform verification operations, and their behavior cannot be restricted through the permission system. If permission control is required, the account and password system is powerless, and users can only be restricted through user agreements or other rules and regulations, which has very little control in this situation.
[0066] The Super SIM card has a built-in security module. The SIM card itself has an operating system and storage devices that are independent of the card insertion device. The card operating system also runs independently of the device, providing a high level of protection for data security.
[0067] This application proposes a multi-environment secure login method based on a super SIM card, which can solve the problem of verifying user permissions when the user is connected to the Internet, connected to the intranet, or without network access. This allows users to securely log in to the corresponding system in various environments, while preventing users from having their accounts stolen or misused without their knowledge.
[0068] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or login authentication device capable of performing the above functions. The following description uses a login authentication device as an example to illustrate this embodiment and the subsequent embodiments.
[0069] Based on this, the embodiments of this application provide a login authentication method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the login authentication method of this application.
[0070] In this embodiment, the login authentication method includes steps S10 to S20:
[0071] Step S10: In response to receiving a login request initiated by the user in the current login scenario, obtain the SIM card's return information according to the current login scenario;
[0072] Specifically, the login authentication method in this application embodiment is not only applicable to online login verification scenarios, but also to intranet login verification scenarios and offline login verification scenarios. It can solve the problem of verifying user permissions when the user is connected to the Internet, connected to the intranet, or without network access, allowing users to securely log in to the corresponding business system in various environments.
[0073] For example, before the business party (i.e. the business system) can use it, it must first send the data to the Super SIM card. This operation includes two steps: key exchange and data writing.
[0074] For example, when a business unit connects, it first sends its public key PK1 to the DSOP. The DSOP then sends a key generation instruction to the Super SIM card via SMS, BIP, or SIM card channel. The Super SIM card generates an asymmetric encrypted public and private key within the card, and sends the public key to the business unit via the SDK after symmetric encryption. The business unit then decrypts and saves the public key PK2.
[0075] For example, the service access party initiates a data delivery request to the DSOP platform through the agreed interface. DSOP verifies the received encrypted data. After verifying that the data source is a trusted access party, it delivers the encrypted data to the corresponding user's Super SIM card through DSOP's secure communication capabilities (data SMS, SIM card channel, BIP). After receiving the data, the user's Super SIM card uses the private key in the card to decrypt the data and saves it as a file in the Super SIM card for subsequent use by the card application.
[0076] Step S20: Verify the returned information to obtain a verification result, which is used to determine whether the user is allowed to log in.
[0077] Furthermore, when the business system receives a login request initiated by the user in the current login scenario, it can obtain the SIM card's return information based on the current login scenario and then verify the return information. If the return information passes the verification, the user is allowed to log in.
[0078] For example, in an online login verification scenario, when a user initiates a login request through an internet-connected business system, the business system sends a login request to the DSOP. The DSOP obtains the phone number from the request, locates and forwards it to the user's Super SIM card. The card application, through its built-in SDK, initiates login to the user via the operating system. After the user confirms the login, the card application performs encrypted calculations using the timestamp from the request and the data already stored on the card to obtain a confirmation result. The SDK sends the confirmation result ("confirm"), the user's confirmation timestamp, and the device serial number (IMEI and SEID) to the business platform. The platform verifies the login based on the returned confirmation result and timestamp. If the result matches the returned confirmation result, the user's login is successful.
[0079] For example, in an intranet login verification scenario, where a user logs into the internal network (which is unable to communicate with the external network), the user opens a mini-program or the card application tool in the SIM card toolkit. The SIM card uses UICC capabilities to obtain the device's local time. Whenever the second is a multiple of 30, the card application generates a 5-digit temporary token code containing alphanumeric characters based on the previously downloaded user authorization data and initial key, the current second, and the device IMEI. This token code is then displayed to the user's device via the SDK. The user enters their username and the temporary token code. Upon receiving the user's login data, the business's internal system, based on the previously issued data and initial key, retrieves the most recent multiple of 30 seconds from the current time, and then retrieves two consecutive multiples of 30 seconds before and after this second. A verification code is calculated for these five times. If the user's submitted verification code matches any one of the five calculated verification codes, the verification is successful, and the user can log into the internal network.
[0080] For example, in an offline login verification scenario, where the user is offline and the business system is not connected to any network, if the user wants to log in to the business system, the user's account and related permission information need to be read through an NFC card reader. The card returns the current user's group and permission information. The business system uses the group and permission information to confirm whether the current user has permission to log in to the system according to the level or rules of internal permissions. It allows users with permissions to log in and denies users without permissions from logging in.
[0081] This embodiment, through the above-described scheme, specifically responds to receiving a login request initiated by a user in the current login scenario, obtains the return information from the SIM card based on the current login scenario, verifies the return information, and obtains a verification result. The verification result is used to determine whether to allow the user to log in. By obtaining the return information with the help of the SIM card and determining whether to allow the user to log in based on the verification result of the return information, the user does not need to remember specific accounts and passwords, reducing the user's memory cost in the login authentication process. It also eliminates the need for verification methods such as account passwords or verification codes, avoiding account theft or impersonation, thereby reducing the security risks in the login authentication process.
[0082] Based on the first embodiment of this application, a second embodiment of this application is proposed. In this second embodiment, content that is the same as or similar to that in the first embodiment described above can be referred to the above description and will not be repeated hereafter. Based on this, please refer to... Figure 2 Before step S10, the login authentication method further includes steps S01 to S02:
[0083] Step S01: Obtain account information and / or authorization information;
[0084] Step S02: Encrypt the account information and / or authorization information to obtain encrypted information;
[0085] Step S03: Send the encrypted information to the data security operation platform, so that the data security operation platform can convert the encrypted information into application protocol data unit instructions and send the application protocol data unit instructions to the SIM card, so that the SIM card can complete key exchange and data writing to obtain the pre-processing data, which is used to generate or determine the return information.
[0086] Reference Figure 3 , Figure 3 This is a schematic diagram illustrating the key exchange and data distribution process according to the first embodiment of this application, as shown below. Figure 3 As shown, before the business can use it, it must first send the data to the Super SIM card. This operation includes two steps: key exchange and data writing.
[0087] For example, when a service provider connects, it first sends its public key PK1 to the DSOP to facilitate the identification of the source of subsequent verification requests. The DSOP sends a key generation command to the Super SIM card via SMS, BIP, or SIM card channel. The Super SIM card then generates an asymmetric encryption public and private key within its own memory. The security features of the Super SIM card ensure that the private key is held exclusively by the card itself. The SDK then symmetrically encrypts the public key and sends it to the service provider. The service provider decrypts and saves the public key PK2, using it to encrypt service data during subsequent interactions. This completes the key exchange process.
[0088] For example, the service access party initiates a data delivery request to the DSOP platform through an agreed interface. DSOP verifies the received encrypted data. After verifying that the data source is a trusted access party, it delivers the encrypted data to the corresponding user's Super SIM card through DSOP's secure communication capabilities (such as data SMS, SIM card channel, and BIP). After receiving the data, the user's Super SIM card decrypts the data using the private key in the card and saves it as a file in the Super SIM card for subsequent use by the card application.
[0089] For example, the business party initiates a data distribution request to DSOP with the following content: {"uid":"cotsl13811112222","mode":"0","group":"bsc&mng&adm","ticket":"5ZGL6aOa5Zea5Zmk5ZeS6bq8","permission":"dGhpcyBpcyBhIHBlcm1p","algorithm":"SM2","initSec":"5aO96Ku46Zq45YOn6ZmN5a95LyP6} Ku45a","sign":"3045022100A475D2C98B69AC10AED19430C796F6CF29CBFD4D7175A43773D02FAE42785BB302207E1157198CAE3A287BCA768BCA74EA29C138898C4C7C9B106F19C6EDEBC001EF"}, where uid identifies a unique user in the business system, mode indicates the data delivery mode (0 for first download, 1 for update, 2 for deletion), Group indicates the group the user belongs to, Ticket is the credential granted to the user by the business provider for online login to the business system, and permission is used to generate a verification code offline, ensuring consistency between the verification code generated by the Super SIM card and the business provider based on the same timestamp through the initial key InitSec.
[0090] For example, in the DSOP verification request, the sign field, after passing verification, concatenates the remaining fields according to their names in ASCII order to obtain SM2$bsc&mng&adm$5aO96Ku46Zq45YOn6ZmN5a95LyP6Ku45a$0$dGhpcyBpcyBhIHBlcm1p$5ZGL6aOa5Zea5Zmk5ZeS6bq8$cotsl13811112222. After converting this to hexadecimal, it is segmented into 16-byte segments and used as data to write to the card file. Based on the file generation and file writing instructions in the GP specification, instructions that the card can directly execute are generated.
[0091] For example, the above fields can be converted into instructions as follows: 00A4040024D15200CA114514F810, 8050000008FC25E2774A09B500, 84820300102CC9DC6DE86655CC649F2A2E0D774A11, 850A00100F534d3224627363266d6e672661646 After receiving all instructions, the SDK sends them to the device for execution one by one. It also checks the instruction response status word returned by the card. If it's 9000, it sends the installation progress to the DSOP and continues sending the next instruction to the device; otherwise, it returns an error status word to the DSOP and exits instruction execution. This process continues until all instructions have been executed. The DSOP then sends the execution progress or result to the business side. If all instructions are successfully executed, the data writing process in the pre-processing is complete.
[0092] This embodiment, through the above scheme, specifically involves obtaining account information and / or authorization information; encrypting the account information and / or authorization information to obtain encrypted information; sending the encrypted information to the data security operation platform, whereby the data security operation platform converts the encrypted information into application protocol data unit instructions and sends the application protocol data unit instructions to the SIM card, enabling the SIM card to complete key exchange and data writing to obtain pre-processing data. The pre-processing data is used to generate or determine the return information. The business party encrypts its own system's account information and authorization information and sends it to the DSOP. The DSOP converts the encrypted information into APDU instructions and sends them to the Super SIM card via BIP, data SMS, and SIM card channel. After receiving the complete data, the SIM card decrypts it to obtain complete account and authorization data.
[0093] Based on any of the above embodiments of this application, a third embodiment of this application is proposed. In this third embodiment, content that is the same as or similar to any of the above embodiments can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 4 In step S10, the step of obtaining the SIM card's return information based on the current login scenario further includes at least one of steps S101 to S103:
[0094] Step S101: If the current login scenario is an online login verification scenario, then obtain the first return information of the SIM card through the data security operation platform and software development kit;
[0095] For example, the step of obtaining the first return information of the SIM card through the data security operation platform and software development kit includes:
[0096] A user login request is initiated to the data security operation platform, so that the data security operation platform can find the corresponding SIM card according to the user login request and forward the user login request to the SIM card. The card application in the SIM card obtains the user login confirmation through the software development kit. After obtaining the user login confirmation, the card application performs encrypted calculations based on the user login request and the previous data to obtain the confirmation result. The confirmation result and the user login confirmation are sent to the business system as the first return information through the software development kit.
[0097] Receive the first return information sent by the software development kit.
[0098] Reference Figure 5 , Figure 5 This is a schematic diagram of an online login verification process according to the third embodiment of this application, as shown below. Figure 5 As shown, when a user initiates a login request on an internet-connected business system, the system sends a user login request to the DSOP. For example, the request body might contain the following content: {"openId":"1b96-d213-ea2b-caac","mobile_no":"13811112222","timestamp":1726214627042,"sign":"3045022100A475D2C98B69AC10DEA20770C796F6CF29} CBFD4D7175A43773D02FAE42785BB302207E1157198CAE3A287BCA768BCA74EA29C138898C4C7C9B106F19C6EDEBC001EF"}, openId is the unique identifier given to the access party by DSOP, mobile_no is the mobile phone number of the logged-in user, timestamp is the timestamp of the operation, and sign is the signature of the business party. DSOP verifies the signature to confirm that the request source party is trustworthy.
[0099] For example, DSOP obtains the phone number from the request, locates and forwards it to the user's Super SIM card. The card application, through its built-in SDK, sends a login pop-up or interface to the user via the operating system. After the user confirms the login, the card application performs encrypted calculations using the timestamp from the request and the data already stored in the card to obtain a confirmation result. The SDK sends the confirmation result ("confirm"), the user's confirmation timestamp, and the device serial number (IMEI) and SEID to the service platform. For example, the request body returned by the SDK to the service platform could be: {"confirm":"5c8edcc6a09e637fa82358c382b148dc","timestamp":"1726214633070","IMEI":"865396742536330","SEID":"2396000C1AC000353444"," The platform verifies the login status based on the returned confirmation result and timestamp. If the result matches the returned confirmation result, the user has successfully logged in. During this process, the user only needs to confirm whether they are logged in; the confirmation information is generated by the card application, and the user does not need to enter any password or verification code.
[0100] Step S102: If the current login scenario is an intranet login verification scenario, then obtain the second return information of the SIM card through the software development kit;
[0101] For example, the step of obtaining the second return information of the SIM card through the software development kit includes:
[0102] The software development kit (SDK) is used to obtain the device identifier and local time of the device, and a data instruction is generated based on the device identifier and local time of the device and sent to the SIM card. The SIM card generates a temporary token code based on the data instruction and displays the temporary token code to the user's device interface through the SSD, so as to obtain the account name and temporary verification code entered by the user based on the temporary token code.
[0103] The account name and temporary verification code are used as the second returned information.
[0104] For example, after the step of obtaining the second return information of the SIM card through the software development kit, the method further includes:
[0105] Generate at least one check code within a preset time range based on the aforementioned pre-set data;
[0106] The at least one verification code is matched with the temporary verification code in the second returned information;
[0107] If the at least one check code matches the temporary check code, the verification is deemed successful.
[0108] Reference Figure 6 , Figure 6 This is a schematic diagram of an intranet login verification process according to the third embodiment of this application, as shown below. Figure 6 As shown, when a user needs to log in to the internal network, the internal network cannot communicate with the external network. When a user needs to log in, they open the mini-program or the card application tool in the SIM card toolkit. The SIM card then obtains the device's local time (accurate to the second) via UICC capability. Whenever the second is a multiple of 30, the card application generates a 5-digit temporary token code containing alphanumeric characters based on the previously downloaded user authorization data and initial key, according to the current second and the device IMEI. This token code is then displayed to the user's device via the SDK. The user then enters their username and the temporary token code. After receiving the user's login data, the business's internal system, based on the previously issued data and initial key, retrieves the most recent multiple of 30 seconds from the current time, and then retrieves two more multiples of 30 seconds before and after this last second. The system calculates a checksum corresponding to these five times. If the user's submitted checksum matches any one of the five calculated checksums, the verification is successful, and the user can log in to the internal network.
[0109] Step S103: If the current login scenario is an offline login verification scenario, then read the user information through near-field communication and send the user information to the SIM card to obtain the third return information corresponding to the user information sent by the SIM card, wherein the third return information includes user group information and / or permission information.
[0110] For example, when a user is offline and the business system is not connected to any network, if the user wants to log in, an NFC reader needs to read the user's account and related permission information. The card returns the current user's group and permission information. The business system then determines access based on internal permission levels or rules. For example: users in group bsc are not allowed to access the system; users in group mng have partial access to the system, with the access scope determined by the user's permissions; users in group adm have full access to the current system. Specific access control depends on the business requirements; this is just one example. The group and permission information are used to confirm whether the current user has permission to log in to the system, allowing authorized users to log in and denying access to unauthorized users.
[0111] This embodiment, through the above-described scheme, specifically includes: if the current login scenario is an online login verification scenario, obtaining the first return information of the SIM card through the data security operation platform and software development kit; if the current login scenario is an intranet login verification scenario, obtaining the second return information of the SIM card through the software development kit; if the current login scenario is an offline login verification scenario, reading user information through near-field communication and sending the user information to the SIM card to obtain the third return information corresponding to the user information sent by the SIM card. The third return information includes user group information and / or permission information. Therefore, users do not need to remember specific accounts and passwords, reducing the user's memory cost during the login authentication process. Verification is not required using account passwords or verification codes, preventing account theft or impersonation, thereby reducing security risks during the login authentication process.
[0112] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the login authentication method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0113] This application also provides a login authentication device, please refer to... Figure 7 The device is used in the business system, and the login authentication device includes:
[0114] The response module is used to respond to a login request initiated by the user in the current login scenario and obtain the return information of the SIM card according to the current login scenario.
[0115] The verification module is used to verify the returned information and obtain a verification result, which is used to determine whether the user is allowed to log in.
[0116] For example, in this embodiment of the application, the business party encrypts the account information and authorization information of its own system and sends it to the DSOP. The DSOP converts the encrypted information into APDU instructions and sends them to the Super SIM card through BIP, data SMS, and SIM card channel. After receiving the complete data, the card decrypts it to obtain the complete account and authorization data.
[0117] For example, when a user logs into a system connected to the Internet, the business platform sends a login request to the DSOP. The DSOP routes the request to the corresponding device, and the SDK on the device converts the parameters in the request into instructions for the card to execute. The card uses its own secure computing capabilities to calculate the parameters and authorization information, and sends the calculation results and signature data to the business through the SDK. After the business verifies that the results are correct, the user login is completed.
[0118] For example, when a user wants to log in to the intranet system, they open their mobile phone or other device and launch the corresponding application. The application interacts with the card via the SDK. The card calculates a 5-digit verification code offline based on user and authorization data, and updates it periodically. The user can then log in to the intranet system using their account and verification code. When a user uses a system that does not require login but requires authorization verification, they can swipe their card to read the user's authorization information stored in the Super SIM card, determine whether to grant access, and if authorization is granted, the user successfully logs in to the system.
[0119] In this embodiment, the service provider first obtains the Super SIM card's public key, encrypts the request data using the public key, and then converts it into card instructions via DSOP. The SDK sends the instructions to the card for execution. After the card executes the instructions, it decrypts them using the private key within the card to obtain complete authorization data. Leveraging the physical security and uniqueness of the Super SIM card, the service provider's authorization data for a specific user cannot be copied or misused; it can only be possessed by that user, ensuring the security of the authorization data, eliminating the possibility of account misuse, and improving the security of the service provider's system. The service provider only needs to issue authorization data once. By combining it with the three login methods implemented in the Super SIM card's application, users can flexibly choose the login method based on the network environment of the service provider's system, eliminating the hassle of remembering passwords and providing a better user experience.
[0120] The login authentication method in this embodiment, compared to the account and password method, avoids the inconvenience of users remembering passwords. All login actions require active confirmation or initiation by the user, preventing unauthorized misuse of user accounts. User authorization and permission information are stored on the Super SIM card, ensuring data security. Furthermore, all operations require card participation, greatly reducing the risk of account theft. Compared to verification codes, it avoids the predicament of login failure due to internal network inability to send verification codes. It also implements NFC card reader access, ensuring user login even when both the business system and the user are offline. Integrating multiple verification methods into a single card application reduces user burden and improves user experience.
[0121] The login authentication device provided in this application, employing the login authentication method in the above embodiments, can solve the technical problem of login authentication. Compared with the prior art, the beneficial effects of the login authentication device provided in this application are the same as those of the login authentication method provided in the above embodiments, and other technical features in the login authentication device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0122] This application provides a login authentication device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the login authentication method in Embodiment 1 above.
[0123] The following is for reference. Figure 8 The diagram illustrates a structural schematic suitable for implementing the login authentication device in the embodiments of this application. The login authentication device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 8 The login authentication device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0124] like Figure 8As shown, the login authentication device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the login authentication device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the login authentication device to communicate wirelessly or wiredly with other devices to exchange data. Although login authentication devices with various systems are shown in the figures, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.
[0125] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0126] The login authentication device provided in this application, employing the login authentication method described in the above embodiments, can solve the technical problem of login authentication. Compared with the prior art, the beneficial effects of the login authentication device provided in this application are the same as those of the login authentication method provided in the above embodiments, and other technical features of the login authentication device are the same as those disclosed in the method of the previous embodiment, and will not be repeated here.
[0127] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0128] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0129] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the login authentication method in the above embodiments.
[0130] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0131] The aforementioned computer-readable storage medium may be included in the login authentication device; or it may exist independently and not assembled into the login authentication device.
[0132] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the login authentication device, the login authentication device: responds to receiving a login request initiated by a user in the current login scenario, obtains the return information from the SIM card based on the current login scenario; verifies the return information to obtain a verification result, which is used to determine whether the user is allowed to log in. By obtaining the return information using the SIM card and determining whether to allow the user to log in based on the verification result of the return information, the user does not need to remember specific accounts and passwords, reducing the user's memory cost in the login authentication process. It also eliminates the need for verification methods such as account passwords or verification codes, preventing account theft or impersonation, thereby reducing security risks in the login authentication process.
[0133] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0134] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0135] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0136] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described login authentication method, thereby solving the technical problem of login authentication. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the login authentication method provided in the above embodiments, and will not be repeated here.
[0137] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the login authentication method described above.
[0138] The computer program product provided in this application can solve the technical problem of login authentication. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the login authentication method provided in the above embodiments, and will not be repeated here.
[0139] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A login authentication method, characterized in that, The method is applied to a business system and includes: In response to receiving a login request initiated by the user in the current login scenario, the system obtains the SIM card's return information based on the current login scenario. The returned information is validated to obtain a validation result, which is used to determine whether the user is allowed to log in.
2. The method as described in claim 1, characterized in that, Before the step of obtaining the SIM card's return information based on the current login scenario, the method further includes: Obtain account information and / or authorization information; The account information and / or authorization information are encrypted to obtain encrypted information; The encrypted information is sent to the data security operation platform, which converts the encrypted information into application protocol data unit instructions and sends the application protocol data unit instructions to the SIM card, so that the SIM card can complete key exchange and data writing to obtain the pre-processing data. The pre-processing data is used to generate or determine the return information.
3. The method as described in claim 2, characterized in that, The current login scenario includes at least one of online login verification scenario, intranet login verification scenario, and offline login verification scenario. The returned information includes first returned information, second returned information, and third returned information. The step of obtaining the SIM card's returned information according to the current login scenario includes at least one of the following: If the current login scenario is an online login verification scenario, then the first return information of the SIM card is obtained through the data security operation platform and software development kit; If the current login scenario is an intranet login verification scenario, then the second return information of the SIM card is obtained through the software development kit; If the current login scenario is an offline login verification scenario, then the user information is read through near-field communication and sent to the SIM card to obtain the third return information corresponding to the user information sent by the SIM card, wherein the third return information includes user group information and / or permission information.
4. The method as described in claim 3, characterized in that, The step of obtaining the first return information of the SIM card through the data security operation platform and software development kit includes: A user login request is initiated to the data security operation platform, so that the data security operation platform can find the corresponding SIM card according to the user login request and forward the user login request to the SIM card. The card application in the SIM card obtains the user login confirmation through the software development kit. After obtaining the user login confirmation, the card application performs encrypted calculations based on the user login request and the previous data to obtain the confirmation result. The confirmation result and the user login confirmation are sent to the business system as the first return information through the software development kit. Receive the first return information sent by the software development kit.
5. The method as described in claim 3, characterized in that, The step of obtaining the second return information of the SIM card through the software development kit includes: The software development kit (SDK) is used to obtain the device identifier and local time of the device, and a data instruction is generated based on the device identifier and local time of the device and sent to the SIM card. The SIM card generates a temporary token code based on the data instruction and displays the temporary token code to the user's device interface through the SSD, so as to obtain the account name and temporary verification code entered by the user based on the temporary token code. The account name and temporary verification code are used as the second returned information.
6. The method as described in claim 5, characterized in that, Following the step of obtaining the second return information of the SIM card through the software development kit, the method further includes: Generate at least one check code within a preset time range based on the aforementioned pre-set data; Match the at least one verification code with the temporary verification code in the second returned information; If the at least one check code matches the temporary check code, the verification is deemed successful.
7. A login authentication device, characterized in that, The device is used in a business system and includes: The response module is used to respond to a login request initiated by the user in the current login scenario and obtain the return information of the SIM card according to the current login scenario. The verification module is used to verify the returned information and obtain a verification result, which is used to determine whether the user is allowed to log in.
8. A login authentication device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the login authentication method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the login authentication method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the login authentication method as described in any one of claims 1 to 6.