Safety login information processing method and device based on two-factor verification and storage medium

The two-factor authentication method generates dynamic passwords and sets two login states, which solves the problems of easy leakage of static passwords and untimely delivery of dynamic passwords, and achieves more reliable login state management.

CN121356784APending Publication Date: 2026-01-16SHANGHAI INFORMATION IND MANAGEMENT CONSULTING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410950180.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-07-16
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Static passwords are easily leaked and the responsible party cannot be identified. Dynamic password verification is affected by the failure to deliver SMS messages in a timely manner, which hinders the work process. Existing technologies cannot effectively solve these problems.

Method used

A two-factor authentication method is adopted to generate a dynamic password and send it through a third-party server. Two login states are set: the first state is a standard login after the dynamic password is verified, and the second state is a delayed login. A depth judgment is performed based on the character field length to avoid accidental login.

Benefits of technology

It improves login security, avoids work interruptions caused by dynamic passwords not being delivered in time, reduces accidental logins, and enhances the reliability of login status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121356784A_ABST
    Figure CN121356784A_ABST
Patent Text Reader

Abstract

The invention relates to a safety login information processing method and device based on two-factor verification and a storage medium, and the method comprises the steps: extracting a first character field contained in a verification request if the verification request from login equipment is received after the verification of a dynamic password is overtime, and judging whether the first character field is consistent with the dynamic password or not; if yes, allowing the login device to log in in a first state, and otherwise, allowing the login device to log in in a second login state; and after the login equipment completes login, if an operation request sent by the login equipment is received, the operation code in the operation request is extracted, whether the required state corresponding to the extracted operation code is the first state login is judged, if yes, whether the login state of the current login equipment is the first state login is judged, and if yes, refusal information is returned. Compared with the prior art, the method has the advantages that the problem that work cannot be carried out due to dynamic password issuing delay is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of login security control, and in particular to a secure login information processing method, apparatus and storage medium based on two-factor authentication. Background Technology

[0002] Login verification is a standard function of internet services. Generally, common login verification methods include static password verification and dynamic password verification. Depending on the input data, static password verification can be further divided into character passwords and biometrics.

[0003] Among them, static password verification has simpler network requirements than dynamic password verification. It only requires the login terminal to send a one-way request, and the backend can issue a login command after successful verification. However, static passwords have the following problems:

[0004] 1. Static passwords, especially those that are not changed for a long time, may be leaked, leading to security problems;

[0005] 2. The lending of static passwords caused disputes over platform login operations, making it impossible to identify the responsible party.

[0006] In enterprise management, the second point above may be more critical. Therefore, existing enterprise management systems, especially key functions, need to implement dynamic password verification. The main method for dynamic password verification is SMS verification code. That is, after the system generates a dynamic password, it sends a dynamic verification code to the GSM server. Then, the GSM server distributes the code to a trusted mobile communication terminal through the telecommunications operator's channel. The system then receives the dynamic verification code sent by the login request device, and allows login after verification.

[0007] However, given the current state of technology, SMS operators may not be able to deliver messages instantly. In such cases, if SMS messages are not received for an extended period, it may affect the operation of the operator's work. Summary of the Invention

[0008] The purpose of this invention is to provide a secure login information processing method, apparatus, and storage medium based on two-factor authentication.

[0009] The objective of this invention can be achieved through the following technical solutions:

[0010] A secure login information processing method based on two-factor authentication includes:

[0011] Receive a login request and extract the login user information based on the login request, wherein the login request is sent by the login device;

[0012] Based on the extracted login user information, a dynamic password is generated, wherein the validity period of the dynamic password is a first set duration;

[0013] sending the generated dynamic password to the third-party server;

[0014] After sending the generated dynamic password to the third-party server, listening to the verification request from the login device and starting timing;

[0015] When the timing is within the second set time length, if the verification request from the login device is received, the first character segment contained in the verification request is extracted, and it is judged whether the first character segment and the dynamic password are consistent, if yes, the login device is allowed to log in in the first state;

[0016] When the timing is outside the second set time length, if the verification request from the login device is received, the first character segment contained in the verification request is extracted, and it is judged whether the first character segment and the dynamic password are consistent, if yes, the login device is allowed to log in in the first state, otherwise, the login device is allowed to log in in the second login state;

[0017] When the login device completes login, if the operation request sent by the login device is received, the operation code in the operation request is extracted, it is judged whether the required state corresponding to the extracted operation code is the first state login, if yes, it is judged whether the login state of the current login device is the first state login, if yes, the rejection information is returned.

[0018] The second set time length is less than the first set time length.

[0019] The third-party server is a GSM server.

[0020] The third-party server is an IM server.

[0021] When the timing is outside the second set time length, if the verification request from the login device is received, the first character segment contained in the verification request is extracted, and it is judged whether the first character segment and the dynamic password are consistent, if yes, it is judged whether the login state of the current login device is the first state login, if yes, the rejection information is returned, including:

[0022] When the timing is outside the second set time length, if the verification request from the login device is received, the first character segment contained in the verification request is extracted, it is judged whether the length of the first character segment and the dynamic password is consistent, if yes, the deep judgment step is executed, otherwise, the login device is allowed to log in in the second login state;

[0023] Deep judgment step: judging whether the first character segment and the dynamic password are consistent, if yes, the login device is allowed to log in in the first state, otherwise, an error is prompted.

[0024] When the verification request is sent, if the content of the first character field input box is empty, the first character field is set to -FF.

[0025] The login request is from a computer.

[0026] After receiving a rejection message, a "Log Back" button will be displayed.

[0027] A secure login information processing device based on two-factor authentication includes a memory, a processor, and a program stored in the memory, characterized in that the processor executes the program to implement the method described above.

[0028] A storage medium having a program stored thereon, which, when executed, implements the method described above.

[0029] Compared with the prior art, the present invention has the following beneficial effects:

[0030] 1. By designing two login states, the first login state is the standard state when the dynamic password verification is successful, and the second login state is available when the dynamic password verification fails. This allows some low-sense sensitive operations to be performed normally, avoiding the problem of work being unable to proceed due to the failure to receive the dynamic password. In addition, a certain delay is set for the second login state, so that the second login state cannot be used immediately, thereby increasing the probability of logging in in the first login state.

[0031] 2. When performing login verification for the second login state, the length of the first character field in the verification request is taken into account, which can avoid the situation of mistakenly logging in with the second login state due to input errors. Attached Figure Description

[0032] Figure 1 This is a schematic diagram of the main steps of the method of the present invention. Detailed Implementation

[0033] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. These embodiments are based on the technical solution of the present invention and provide detailed implementation methods and specific operating procedures. However, the scope of protection of the present invention is not limited to the following embodiments.

[0034] A secure login information processing method based on two-factor authentication, such as Figure 1 As shown, it includes:

[0035] Receive login requests and extract login user information based on the login requests, wherein the login requests are sent by the login device;

[0036] Based on the extracted login user information, a dynamic password is generated, wherein the validity period of the dynamic password is a first set duration;

[0037] The generated dynamic password is sent to a third-party server;

[0038] After sending the generated dynamic password to the third-party server, it listens for verification requests from the login device and starts timing.

[0039] When the timer is within the second set duration, if a verification request is received from the login device, the first character segment contained in the verification request is extracted, and it is determined whether the first character segment is consistent with the dynamic password. If it is consistent, the login device is allowed to log in in the first state.

[0040] When the timer is outside the second set duration, if a verification request is received from the login device, the first character segment contained in the verification request is extracted, and it is determined whether the first character segment is consistent with the dynamic password. If it is consistent, the login device is allowed to log in in the first state; otherwise, the login device is allowed to log in in the second login state.

[0041] After the login device completes the login, if an operation request is received from the login device, the operation code in the operation request is extracted, and it is determined whether the required status corresponding to the extracted operation code is the first state login. If it is, the login status of the current login device is the first state login. If it is, a rejection message is returned.

[0042] By designing two login states, the first login state is the standard state when the dynamic password verification is successful, and the second login state is available when the dynamic password verification fails. This allows some low-sense sensitive operations to proceed normally, avoiding the problem of work being unable to proceed due to the failure to receive the dynamic password. In addition, a certain delay is set for logging in in the second login state, so that logging in in the second login state cannot be done immediately, thereby increasing the probability of logging in in the first login state.

[0043] In this embodiment, the second set duration is shorter than the first set duration, which avoids the problem of excessively long waiting time when logging in with the second login status, or the problem of the dynamic password being valid for too short a time.

[0044] In this embodiment, the second set duration is 30 seconds, and the first set duration is 10 minutes.

[0045] In addition, the first login state is the standard login state, which has full permissions for the account, while the second login state is the restricted login state.

[0046] In some embodiments, the third-party server is a GSM server; in this embodiment, it is an IM server, such as a WeChat server or an Alibaba Cloud server. Of course, in some embodiments, multiple methods can be combined. The system generates different dynamic passwords corresponding to different servers, and determines which third-party server is most efficient based on the first character segment entered by the user.

[0047] In this embodiment, when the timer is outside the second preset duration, if a verification request is received from the login device, the first character segment contained in the verification request is extracted, and it is determined whether the first character segment matches the dynamic password. If they match, it is determined whether the current login device is in the first login state. If they match, a rejection message is returned, including:

[0048] When the timer is outside the second set duration, if a verification request is received from the login device, the first character segment contained in the verification request is extracted, and it is determined whether the length of the first character segment is consistent with the length of the dynamic password. If it is consistent, the depth judgment step is executed; otherwise, the login device is allowed to log in in the second login state.

[0049] Deep judgment steps: Determine whether the first character field and the dynamic password are consistent. If they are consistent, the login device is allowed to log in in the first state; otherwise, an error message is displayed.

[0050] When performing login verification for the second login state, the length of the first character field in the verification request is taken into account, which can prevent the situation of mistakenly logging in with the second login state due to input errors.

[0051] Furthermore, in this embodiment, when the verification request is sent and the content of the first character field input box is empty, the first character field is set to -FF.

[0052] Typically, the login request is made to a computer.

[0053] In addition, in some embodiments, a "Log Back" button is displayed after a rejection message is returned.

[0054] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for processing secure login information based on two-factor authentication, comprising: receiving a login request, and extracting login user information based on the login request, wherein the login request is sent by a login device; generating a dynamic password based on the extracted login user information, wherein the dynamic password is valid for a first set time period; sending the generated dynamic password to a third-party server; after sending the generated dynamic password to the third-party server, listening for a verification request from the login device and starting a timer; characterized in that it further comprises: when the timer is within a second set time period, if a verification request from the login device is received, extracting a first character segment contained in the verification request, and determining whether the first character segment and the dynamic password are consistent, if yes, allowing the login device to log in in a first state; when the timer is outside the second set time period, if a verification request from the login device is received, extracting a first character segment contained in the verification request, and determining whether the first character segment and the dynamic password are consistent, if yes, allowing the login device to log in in the first state, otherwise allowing the login device to log in in a second state; after the login device completes login, if an operation request sent by the login device is received, extracting an operation code in the operation request, determining whether the operation code corresponds to the first state, if yes, determining whether the login state of the current login device is the first state, if yes, returning a rejection message.

2. The secure login information processing method based on two-factor authentication according to claim 1, characterized in that, The second set time period is less than the first set time period.

3. The secure login information processing method based on two-factor authentication according to claim 1, characterized in that, The third-party server is a GSM server.

4. The secure login information processing method based on two-factor authentication according to claim 1, characterized in that, The third-party server is an IM server.

5. The secure login information processing method based on two-factor authentication according to claim 1, characterized in that, When the timer is outside the second set time period, if a verification request from the login device is received, extracting a first character segment contained in the verification request, determining whether the first character segment and the dynamic password are consistent, if yes, determining whether the login state of the current login device is the first state, if yes, returning a rejection message, comprising: When the timer is outside the second set time period, if a verification request from the login device is received, extracting a first character segment contained in the verification request, determining whether the first character segment and the dynamic password are consistent, if yes, executing a deep judgment step, otherwise, allowing the login device to log in in a second state; The deep judgment step: determining whether the first character segment and the dynamic password are consistent, if yes, allowing the login device to log in in the first state, otherwise prompting an error.

6. The secure login information processing method based on two-factor authentication according to claim 1, characterized in that, When the verification request is sent, the first character segment is set to -FF if the content in the first character segment input box is empty.

7. The secure login information processing method based on two-factor authentication according to claim 1, characterized in that, The login request is a computer. 8.The method of claim 1, wherein the method further comprises, if the first factor authentication is failed, transmitting a message to the user terminal device to request a second factor authentication. After returning the rejection message, a return login button is displayed. 9.A security login information processing apparatus based on two-factor authentication, comprising a memory, a processor, and a program stored in the memory, wherein, The processor implements the method of any one of claims 1-8 when executing the program.

10. A storage medium having stored thereon a program, characterized by The program implements the method of any one of claims 1-8 when executed.