Verification code acquisition method and system based on SIM card identity verification
By adopting a verification code acquisition method based on SIM card identity verification, the problem of difficulty in obtaining verification codes under weak or no mobile signal conditions is solved, enabling convenient and secure verification code acquisition in WiFi environments, thus improving user experience and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-09
- Publication Date
- 2026-03-10
AI Technical Summary
The existing mobile phone number-based verification code login method results in a poor user experience and inability to obtain verification codes in a timely manner when the mobile signal is weak or non-existent, the SMS service is abnormal, or the user has not linked an email address.
By receiving the target mobile phone number entered by the user, the system provides a SIM card identity verification option, detects the WiFi network connection, collects SIM card information, encrypts and transmits it to the server for identity verification, and generates and displays a verification code.
In situations where there is no mobile signal or SMS service is unstable, SIM card information verification is performed using WiFi networks, ensuring that users can easily obtain verification codes, providing hardware-level security, and improving user experience.
Smart Images

Figure CN121645231A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of mobile communication and information security technology, and particularly relates to a verification code obtaining method based on SIM card identity verification. BACKGROUND
[0002] With the popularity of mobile Internet, the verification code login based on mobile phone number has become the mainstream identity verification method of mobile application (APP). This method usually relies on the short message service provider to issue the verification code to the mobile phone number bound by the user. However, the reliability of this method is highly limited by the state of mobile communication network and the stability of short message service provider.
[0003] In actual application, users often face the following problems that lead to the failure to receive the verification code in time: 1) being in the basement, elevator, remote mountainous area and other scenarios with weak or no mobile signal; 2) the short message service provider has system abnormalities, channel congestion or is attacked; 3) the user's mobile phone number cannot receive short messages due to arrears or setting up short message interception rules. These situations will cause the user login process to be blocked, affecting the user experience.
[0004] The existing alternative solutions usually include "resending the verification code" and "switching to email verification". "Resending" still essentially relies on the short message channel with faults or instability, and cannot fundamentally solve the problem. "Email verification" requires the user to complete the email binding in advance, but many users do not have the habit of binding a backup email, resulting in limited actual availability of this solution.
[0005] Therefore, there is an urgent need in the art for a technical solution that does not rely on the traditional short message transmission channel and can ensure that the user safely and conveniently obtains the verification code in a special network environment. SUMMARY
[0006] In order to solve the above-mentioned problems in the prior art, on the one hand, the present application provides a verification code obtaining method based on SIM card identity verification, comprising the following steps: S1: receiving a target mobile phone number input by a user, and providing an interactive option triggered based on SIM card identity verification; S2: in response to the user triggering the interactive option, detecting whether the current device has connected to a WiFi network; S3: if the current device has connected to a WiFi network, loading a verification code obtaining page, and collecting at least one SIM card identification information in the current device through the device operating system; S4: encrypting and transmitting the target mobile phone number and the collected SIM card identification information to a server for identity verification; S5: The server checks whether the target mobile phone number and the SIM card identification information match based on the pre-stored binding relationship; if they match, a verification code is generated and transmitted to the verification code acquisition page for display.
[0007] As a further improvement of the application, in step S1, the interactive option is a "unable to receive verification code" button set in the application verification code input interface.
[0008] As a further improvement of the application, after step S2, if it is detected that the current device is not connected to a WiFi network, the device is automatically redirected to a WiFi network connection page.
[0009] As a further improvement of the application, in step S3, the collected SIM card identification information includes at least one of the following: SIM card number, international mobile subscriber identity, integrated circuit card identifier.
[0010] As a further improvement of the application, in step S5, the identity verification includes: if the SIM card number is collected, the SIM card number is directly compared with the target mobile phone number to determine whether they are consistent, and if they are consistent, the identity verification is determined to be passed.
[0011] As a further improvement of the application, in step S5, if multiple SIM cards are inserted into the device, the server sequentially verifies the binding relationship between the identification information of each SIM card and the target mobile phone number, and if any of the SIM cards passes the verification, the identity verification is determined to be passed.
[0012] As a further improvement of the application, step S3 further includes collecting hardware identification information of the device. In step S5, if the SIM card identity verification fails, it is further determined whether the hardware identification information of the device collected this time is consistent with the historical login device information of the target mobile phone number, and if they are consistent, the identity verification is determined to be passed.
[0013] As a further improvement of the application, the hardware identification information includes an international mobile equipment identity.
[0014] As a further improvement of the application, the process of collecting SIM card information in step S3 includes: the application layer calls a system API; the system layer performs permission verification and then forwards the request to the baseband chip driver; the hardware layer sends a read instruction to the SIM card through the baseband chip, and after the SIM card returns the data, the system layer processes and returns the data to the application layer.
[0015] On the other hand, the application also provides a verification code acquisition system based on SIM card identity verification for implementing the above method, comprising: A client module deployed on a user device, configured to provide an interactive interface, detect a network, collect local SIM card and device information, and display a verification code; A server module deployed on a server, configured to receive information uploaded by the client, perform identity verification, generate and manage verification codes, and perform final login verification. The client module and the server module perform data interaction through an encrypted communication channel.
[0016] Compared with the prior art, the present application has the following advantages: 1. The core innovation of the present application is to bypass the traditional SMS delivery channel, use the device to read the SIM card information locally, and perform remote verification through the WiFi network. This makes it possible for users to successfully obtain the verification code and ensure smooth login as long as there is a usable WiFi network, even in scenarios where mobile signals are completely missing (such as basements, remote areas) or the SMS service provider is malfunctioning, thus making up for the shortcomings of existing solutions.
[0017] 2. The core identity verification of the present application is based on the physical hardware identification of the SIM card; the SIM card information (such as IMSI, ICCID) is difficult to be imitated or tampered with by software, providing a hardware-level security guarantee and higher security performance. BRIEF DESCRIPTION OF DRAWINGS
[0018] In order to more clearly illustrate the schemes in the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings described below are some embodiments of the present application, and those skilled in the art can obtain other drawings based on these drawings without creative labor.
[0019] Figure 1 is the overall flowchart of the verification code acquisition method based on SIM card identity verification in the present application. DETAILED DESCRIPTION
[0020] Unless otherwise defined, all technical and scientific terms used in the present application have the same meaning as commonly understood by those skilled in the art to which the present application belongs; the terms used in the specification are only for the purpose of describing specific embodiments and are not intended to limit the present application; the terms "include" and "have" in the specification and claims of the present application and their any variations are intended to cover non-exclusive inclusion. The terms "first", "second" and the like in the specification and claims of the present application or the above description of drawings are used to distinguish different objects, not to describe a particular order.
[0021] Reference to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily all referring to a common set of embodiments, although they can. Those skilled in the art will recognize that the application can be practiced with
[0022] In order to make the technical personnel in the technical field better understand the application scheme, the specific embodiments of the method and system described in the application are described in detail below in an application scenario.
[0023] For example: a user is in a mobile phone signal-free underground parking lot, and the user's mobile phone has been connected to the WiFi in the underground parking lot, and the network connection is stable; at this time, the user needs to log in to a commonly used entertainment APP using a verification code.
[0024] Trigger the backup verification option, the user opens the login interface of the APP, and clicks "get verification code" after entering the mobile phone number. Since there is no mobile phone signal, after waiting for a period of time, no SMS is received. At this time, a "unable to receive verification code" button (i.e. interactive option) appears below the login interface. The user clicks the button.
[0025] Detect the network environment, the APP (client module) responds to the click event and immediately detects whether the current device has a WiFi network connection. It is found that the current device has successfully connected to the public WiFi in the underground parking lot. The system determines that the condition for using the SIM card verification is met.
[0026] Load the page and collect SIM card information, the current device loads a HTTPS secure web page provided by the application server and specially used for this verification method through the built-in WebView component. The web page first requests the user's authorization to read the local SIM card information, and the user clicks "allow".
[0027] Then the APP calls a system-level API (such as the TelephonyManager-related interface of Android) to request the system to read the SIM card information. After the system layer performs necessary application permission verification (for example, checking whether the APP has been granted the permission to read the phone status), the request is forwarded to the baseband chip driver. The hardware layer sends a read instruction to the SIM card inserted in the device through the baseband chip. The SIM card returns the SIM card identification information, which includes: SIM card number (MSISDN), international mobile subscriber identity (IMSI), integrated circuit card identifier (ICCID). After processing by the system layer, the available identification information is securely returned to the APP application layer.
[0028] At the same time, APP can also collect the International Mobile Equipment Identity (IMEI) of the device as auxiliary information.
[0029] The APP client module transmits the target mobile phone number input by the user, the collected SIM card identification information, and the device IMEI to the server module of the APP through an encrypted communication channel such as HTTPS.
[0030] The server module's verification logic unit decrypts and performs verification after receiving the encrypted data: 1. Preferred verification path: the server queries the database to find the legal SIM card identification information pre-bound to the mobile phone number. Then, the uploaded SIM card identification information is compared with the SIM card identification information bound in the library, and it is found to be completely consistent.
[0031] 2. Verification passed: the server determines that the request this time comes from the device held by the owner. After verification, the server generates a set of dynamic verification codes and associates them with this session.
[0032] 3. Return and display: the server returns the verification code to the client's secure web page through an encrypted channel. The page safely displays the verification code to the user. The user inputs the verification code in the verification code input box on the login interface to complete the login.
[0033] In actual application, the case of multiple SIM cards installed on a mobile terminal often occurs. In this scenario, when the verification method of the application is triggered, the client will collect the identification information of all SIM cards in sequence and send it to the server. After receiving all the SIM card identification information, the server will perform a sequential comparison. Only when it is found that the received SIM card identification information is consistent with the SIM card identification information bound in the library, is the verification passed.
[0034] In another example, if the user changes the mobile phone number and new SIM card, but the old account has not been unbound. When he tries to log in with the original mobile phone number and triggers the verification method of the application, the new SIM card information will inevitably fail the verification. At this time, the server starts the backup verification logic: checks whether the uploaded device IMEI exists in the history of commonly used devices of the account (for example, the device IMEI has been used to successfully log in within the past month). If matched, the server determines that it is a reasonable account access behavior on a trusted device, still generates and issues a verification code, allows login, and prompts the user to update the binding information as soon as possible.
[0035] A system for implementing the above-mentioned verification code acquisition method based on SIM card identity verification mainly includes: Client module: SDK or integrated code in the APP. Contains: UI interaction submodule (responsible for displaying buttons and verification pages), network detection submodule, local information collection submodule (call system API to read SIM card and device information), encryption and decryption and communication submodule.
[0036] Server module: deployed in the business backend. Contains: communication interface submodule (receive / send data), encryption and decryption submodule, identity verification engine (execute SIM card information comparison, device IMEI history comparison, etc. Logic), verification code generation and management submodule, user binding relationship database (store mobile phone number, SIM card information, trusted device IMEI history, etc. Mapping relationship).
[0037] Client module and server module transmit data through encrypted communication channel.
[0038] The above specific embodiments are the preferred embodiments of the present application, and are not intended to limit the specific implementation range of the present application. The scope of the present application includes but is not limited to the specific embodiments, and any equivalent changes made in accordance with the present application are within the scope of protection of the present application.
Claims
1. A SIM card identity-based verification code obtaining method, characterized in that, The method comprises the following steps: S1: receiving a target mobile phone number input by a user and providing an interactive option of triggering identity verification based on a SIM card; S2: in response to the user triggering the interactive option, detecting whether the current device is connected to a WiFi network; S3: if the current device is connected to a WiFi network, loading a verification code acquisition page and collecting at least one SIM card identification information in the current device through a device operating system; S4: encrypting and transmitting the target mobile phone number and the collected SIM card identification information to a server for identity verification; S5: the server verifying, based on a pre-stored binding relationship, whether the target mobile phone number and the SIM card identification information match; if they match, generating a verification code and encrypting and transmitting the verification code to the verification code acquisition page for display. 2.The SIM card identity-based verification code obtaining method of claim 1, wherein: In step S1, the interactive option is a "cannot receive verification code" button set in an application verification code input interface. 3.The SIM card identity-based verification code obtaining method of claim 1, wherein: After step S2, if it is detected that the current device is not connected to a WiFi network, automatically jumping to a WiFi network connection page.
4. The SIM card identity-based verification code obtaining method of claim 1, wherein: In step S3, the collected SIM card identification information includes at least one of the following: a SIM card number, an international mobile subscriber identity, and an integrated circuit card identifier.
5. The SIM card identity based verification code obtaining method of claim 1, wherein: In step S5, the identity verification includes: if a SIM card number is collected, directly comparing whether the SIM card number and the target mobile phone number are consistent, and if they are consistent, determining that the verification is passed.
6. The SIM card identity based verification code obtaining method of claim 1, wherein: In step S5, if multiple SIM cards are inserted into the device, the server sequentially verifies the binding relationship between the identification information of each SIM card and the target mobile phone number, and if any of the SIM cards passes the verification, it is determined that the identity verification is passed.
7. The SIM card identity based verification code obtaining method of claim 1, wherein: Step S3 further comprises collecting hardware identification information of the device; In step S5, if the SIM card identity verification is not passed, further determining whether the hardware identification information of the device collected this time and historical login device information of the target mobile phone number are consistent, and if they are consistent, determining that the identity verification is passed.
8. The SIM card identity based verification code obtaining method of claim 7, wherein: The hardware identification information includes an international mobile equipment identity.
9. The SIM card identity based verification code obtaining method of claim 1, wherein: The process of collecting SIM card information in step S3 includes: an application layer calling a system API; a system layer forwarding a request to a baseband chip driver after permission verification; and a hardware layer sending a read instruction to a SIM card through the baseband chip, and returning data from the SIM card to the application layer through the system layer after processing.
10. A system for implementing the method for obtaining a verification code based on SIM card identity verification according to any one of claims 1-9, characterized in that, The method comprises: a client module deployed on a user device, configured to provide an interactive interface, detect a network, collect local SIM card and device information, and display a verification code; a server module deployed on a server, configured to receive information uploaded by the client and perform identity verification, generate and manage verification codes, and perform final login verification; wherein the client module and the server module perform data interaction through an encrypted communication channel.