Information verification method and device, electronic equipment and readable storage medium

By generating dynamic verification information based on terminal environment characteristics and random function groups, the problem of existing information verification mechanisms being easily cracked is solved, achieving highly reliable and user-friendly information verification.

CN121786809APending Publication Date: 2026-04-03RIVER INFORMATION TECH SHANGHAI CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-16
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing information verification mechanisms are easily cracked by automated tools, leading to reduced reliability.

Method used

By acquiring environmental feature data of the terminal, dynamic verification information is generated by combining static verification templates and randomly selected function groups, and verification operations are performed in response to the user's dynamic operation results.

Benefits of technology

It improves the reliability of information verification, resists attacks from automated tools, balances security and user experience, adapts to constantly evolving attack methods, and ensures stable protection of the system in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786809A_ABST
    Figure CN121786809A_ABST
Patent Text Reader

Abstract

The invention discloses an information verification method and device, electronic equipment and a readable storage medium, and relates to the technical field of computers, in particular to artificial intelligence technologies such as big data and image processing. According to the specific implementation scheme, in response to an information verification request triggered by a user based on a terminal, environment feature data of the terminal is obtained; obtaining dynamic verification information of the terminal according to a static verification template, the environment characteristic data and a randomly selected function group; outputting the dynamic verification information; and in response to a dynamic operation result provided by the user according to the dynamic verification information, executing verification operation on the dynamic operation result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, specifically to the fields of big data, image processing, and other artificial intelligence technologies. Background Technology

[0002] With the deepening development of the internet, applications (APPs) on terminals are emerging in endless streams. Users may encounter situations requiring information verification while using these applications. Common verification mechanisms currently include image cutout, mathematical calculations, and inputting characters from images.

[0003] However, existing verification mechanisms are easily cracked by automated tools. For example, automated attack methods such as Optical Character Recognition (OCR) technology, trajectory prediction, and script automation can quickly identify verification targets and methods, thereby reducing the reliability of information verification. Summary of the Invention

[0004] This disclosure provides an information verification method to improve the reliability of information verification.

[0005] According to one aspect of this disclosure, an information verification method is provided, comprising:

[0006] In response to a user's information verification request triggered by the terminal, the environmental feature data of the terminal is obtained;

[0007] Based on the static verification template, the environmental feature data, and the randomly selected function group, the dynamic verification information of the terminal is obtained;

[0008] Output the dynamic verification information;

[0009] In response to the dynamic operation result provided by the user based on the dynamic verification information, a verification operation is performed on the dynamic operation result.

[0010] According to another aspect of this disclosure, an information verification device is provided, comprising:

[0011] The verification triggering unit is used to obtain the environmental feature data of the terminal in response to the information verification request triggered by the user based on the terminal.

[0012] The verification selection unit is used to obtain the dynamic verification information of the terminal based on the static verification template, the environmental feature data, and a randomly selected function group;

[0013] A verification output unit is used to output the dynamic verification information;

[0014] The verification execution unit is used to perform a verification operation on the dynamic operation result provided by the user based on the dynamic verification information.

[0015] According to another aspect of this disclosure, an electronic device is provided, comprising:

[0016] At least one processor; and

[0017] A memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the methods described above and any possible implementations.

[0019] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions for causing the computer to perform the methods described above and any possible implementation thereof.

[0020] According to another aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the aspects and any possible implementations described above.

[0021] As can be seen from the above technical solution, the embodiments of this disclosure, in response to the information verification request triggered by the user based on the terminal, obtain the environmental feature data of the terminal. Then, based on the static verification template, the environmental feature data, and a randomly selected function group, the dynamic verification information of the terminal can be obtained and output. This enables the verification operation to be performed on the dynamic operation result provided by the user based on the dynamic verification information. Since the generation of dynamic verification information depends on the terminal's unique environmental features and a random function group, and the verification process is deeply bound to the user's dynamic operation, automated tools cannot obtain fixed verification targets or evolution patterns in advance. This fundamentally resists common risks of automated tools such as static question bank collection and replay attacks, thereby significantly improving the reliability of information verification.

[0022] In addition, the technical solution provided in this disclosure takes into account both security and user experience. The generation and output of dynamic verification information do not require users to learn additional operation procedures, and the initial interaction form can be consistent with traditional verification methods, which can effectively reduce the user's operation threshold.

[0023] Furthermore, by adopting the technical solution provided in this disclosure, adaptive protection can be achieved through environmental characteristics and dynamic evolution mechanisms. Without the need for frequent manual adjustments to verification rules, it can cope with constantly upgraded automated attack methods, effectively improving the practicality and adaptability of the verification solution, thereby ensuring the system's stable protection capability in complex network environments.

[0024] In addition, the technical solutions provided in this disclosure can effectively improve the user experience.

[0025] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0026] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. The drawings are used to better understand this solution and do not constitute a limitation of this disclosure. Wherein:

[0027] Figure 1 This is a schematic diagram based on the first embodiment of the present disclosure;

[0028] Figure 2 This is a schematic diagram according to the second embodiment of the present disclosure;

[0029] Figure 3 This is a schematic diagram according to the third embodiment of the present disclosure;

[0030] Figure 4 This is a block diagram of an electronic device used to implement the information verification method of the embodiments of this disclosure. Detailed Implementation

[0031] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0032] Obviously, the described embodiments are only some, not all, of the embodiments disclosed herein. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without inventive effort are within the scope of protection of this disclosure.

[0033] It should be noted that the terminal devices involved in the embodiments of this disclosure may include, but are not limited to, smart devices such as mobile phones, personal digital assistants (PDAs), wireless handheld devices, and tablet computers; the display devices may include, but are not limited to, personal computers, televisions, and other devices with display functions.

[0034] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0035] Common verification mechanisms currently include sliding image cutout, mathematical calculation, and inputting characters from an image.

[0036] However, existing verification mechanisms are easily cracked by automated tools. For example, automated attack methods such as Optical Character Recognition (OCR) technology, trajectory prediction, and script automation can quickly identify verification targets and methods, thereby reducing the reliability of information verification.

[0037] Therefore, there is an urgent need to provide an information verification method that can effectively improve the reliability of information verification.

[0038] Figure 1 This is a schematic diagram based on the first embodiment of the present disclosure, as shown below. Figure 1 As shown.

[0039] 101. In response to an information verification request triggered by the user based on the terminal, obtain the environmental feature data of the terminal.

[0040] 102. Based on the static verification template, the environmental feature data, and the randomly selected function group, obtain the dynamic verification information of the terminal.

[0041] The static verification template may include, but is not limited to, sliding cutout, mathematical calculation, input of characters in the image, input of characters indicated by homophones, time length control, etc. This embodiment does not impose any special limitations on this.

[0042] The function set may include, but is not limited to, at least one of linear functions (such as linear functions) and nonlinear functions (such as hyperbolic, elliptical, parabolic, and spiral functions), and this embodiment does not impose any particular limitation on this. Compared with linear functions, nonlinear functions can effectively improve the verification complexity.

[0043] 103. Output the dynamic verification information.

[0044] 104. In response to the dynamic operation result provided by the user based on the dynamic verification information, perform a verification operation on the dynamic operation result.

[0045] Therefore, after obtaining the dynamic operation results provided by the user, during the verification operation of the dynamic operation results provided by the user, the verification result information corresponding to the output dynamic verification information and the evolution rules of the randomly selected function group can be used as the verification standard of the application to determine whether the verification operation passes.

[0046] It is understood that the application can be a native program installed on the local terminal, or it can be a web application of a browser on the local terminal. This embodiment does not limit this.

[0047] It should be noted that some or all of the execution entities 101 to 104 can be applications located on the local terminal, or they can be plugins or software development kits (SDKs) or other functional units set in applications located on the local terminal, or they can be processing engines located on the network-side server, or they can be distributed systems located on the network side, such as processing engines or distributed systems in information verification processing platforms on the network side. This embodiment does not impose any special limitations on these.

[0048] In this way, by responding to the information verification request triggered by the user based on the terminal, the environmental feature data of the terminal is obtained. Then, based on the static verification template, the environmental feature data, and a randomly selected function group, the dynamic verification information of the terminal can be obtained and output. This enables the verification operation to be performed on the dynamic operation result provided by the user based on the dynamic verification information. Since the generation of dynamic verification information depends on the terminal's unique environmental features and a random function group, and the verification process is deeply bound to the user's dynamic operation, automated tools cannot obtain fixed verification targets or evolution patterns in advance. This fundamentally resists common risks of automated tools such as static question bank collection and replay attacks, thereby significantly improving the reliability of information verification.

[0049] Optionally, in one possible implementation of this embodiment, before step 101, relevant data about the terminal device and its operating environment can be collected, provided that permissions are compliant, to serve as environmental characteristic data for the terminal. This data may include, but is not limited to, compliant characteristic data such as device posture (e.g., gyroscope or accelerometer data), ambient light intensity, device hardware fingerprint, network environment parameters, and geographic location information. This embodiment does not impose any particular limitations on this. This data is used to subsequently generate dynamic verification information adapted to the terminal environment and can also serve as the basis for environmental modal verification, preventing the verification operation from being recorded and replayed.

[0050] In actual execution, environmental characteristic data can be collected through the terminal-side SDK or local application interface. After collection, the data needs to be dynamically encrypted before being uploaded to the server (such as a server) for further processing to ensure the security of data transmission and storage.

[0051] Optionally, in one possible implementation of this embodiment, in step 102, the dynamic verification information of the terminal can be generated by combining multi-dimensional information.

[0052] Specifically, the terminal identification information of the terminal can be obtained based on the environmental feature data, which can be used to distinguish the verification sessions of different terminals.

[0053] Then, after obtaining the terminal identification information, the terminal identification information and the function group can be further fused to obtain the terminal's dynamic credentials. For example, the terminal identification information and the function group can be bound together using a fusion algorithm such as a hash algorithm or an encryption algorithm to generate a dynamic credential unique to the terminal for this verification session, ensuring the uniqueness and timeliness of the dynamic verification information.

[0054] Finally, after obtaining the dynamic credentials of the terminal, the dynamic verification information can be generated based on the dynamic credentials and the randomly selected static verification template.

[0055] Since the terminal's dynamic credentials are generated based on the terminal's environmental characteristics and a set of random functions, they are only valid for the current verification request, which can effectively avoid the risk of cracking caused by the reuse of verification templates in traditional static verification.

[0056] By integrating terminal identifiers with function groups, the dynamic verification information of each terminal becomes unique, preventing attackers from bypassing the protection by copying or forging verification information, thus further enhancing the security of information verification.

[0057] This implementation organically combines environmental features, function sets, and static verification templates. It retains the diverse adaptability advantages of static verification templates (such as sliding image cutout and mathematical calculations) while injecting dynamic evolution logic into dynamic credentials, giving the static verification templates dynamic protection capabilities. Compared to the limitations of traditional static verification templates that only provide fixed verification scenarios, the technical solution in this implementation can dynamically adjust the verification dimensions according to different terminal environments and verification requests. Without increasing the complexity of user operations, it achieves high-security protection by verifying one verification code at a time, thereby improving the flexibility and anti-attack capabilities of the verification scheme.

[0058] In a specific implementation process, dynamic verification information can be generated in the following ways.

[0059] Specifically, at least one basic element of the static verification template can be obtained based on the type of the static verification template. The static verification template may include, but is not limited to, at least one of the following: sliding image cutout, mathematical calculation, inputting characters from an image, inputting characters with homophones, and time length control. This embodiment does not impose any particular limitations on this.

[0060] Correspondingly, the basic elements corresponding to each type of the static verification template can be cutout blocks and background images, numbers and operators in calculation formulas, characters in images, homophones, time indicator characters, etc.

[0061] Next, an evolution function can be selected from the function group for the dynamic evolution of each of the at least one basic element.

[0062] Then, the association process can be performed on each basic element and the evolution function used for the dynamic evolution of that basic element to obtain the association relationship.

[0063] At this point, the relationship between each basic element and its corresponding evolution function is established by associating them.

[0064] Finally, the dynamic verification information can be generated based on the dynamic credentials, the static verification template, and the association relationship.

[0065] Thus, based on the dynamic credentials, the static verification template, and the association, dynamic verification information is generated. This dynamic verification information includes both the basic form of the static verification template and the dynamic evolution rules of each basic element.

[0066] In the implementation process, the dynamic evolution of dynamic verification information was precisely and controllably achieved. Since each basic element in the static verification template can correspond to an independent evolution function, and the evolution dimension can cover, but is not limited to, at least one of trajectory, size, shape, and value, this implementation process does not impose such limitations, making the dynamic evolution of the verification target more complex and random. Attack methods of automated tools such as OCR and trajectory prediction are difficult to accurately match the evolution rules, which greatly increases the difficulty of attacking and cracking.

[0067] The establishment of the relationship between basic elements and evolution functions creates a closed loop for the generation and verification of dynamic verification information. The evolution criteria for each basic element can be clearly defined through this relationship, enabling precise verification of the legality of user operation trajectories in subsequent verifications. Simultaneously, the flexible binding of basic elements and evolution functions supports diverse static verification template types. Whether it's the graphic elements of a sliding image verification template or the numerical elements of a mathematical calculation verification template, dynamic evolution can be achieved through this logic. There's no need to design separate dynamic mechanisms for different static verification templates, improving the scalability and development efficiency of the solution and reducing system integration costs.

[0068] Optionally, in one possible implementation of this embodiment, in step 104, the static verification template may be output. Then, in response to the user's initial operation result provided by the static verification template, the static verification template is dynamically adjusted using the evolution rules of the function group in the dynamic verification information and the correlation relationships in the dynamic verification information to generate dynamic adjustment information. Subsequently, in response to the user's dynamic operation result provided by the dynamic adjustment information, a verification operation is performed on the dynamic operation result.

[0069] The static verification template output in the initial stage is consistent with the traditional verification form, so users do not need to adapt to the new operation method, ensuring ease of use. After the user triggers the initial operation, the static verification template can be dynamically adjusted based on the function group evolution rules, so that attackers cannot complete automated operations by pre-identifying static targets. This solves the security defects of traditional static verification and avoids the impact of complex dynamic interactions on user experience, achieving a balance between security and ease of use.

[0070] By dynamically binding adjustments to user actions in real time, the evolution of the verification process can be driven by user input, rather than evolving in a fixed sequence. Compared to the evolution rhythm determined by rate parameters in a static verification template, this makes the verification trajectory more closely resemble human operating habits. It also increases the difficulty of automated script simulation, requiring attackers not only to crack the function evolution rules but also to accurately simulate the timing and rhythm of human actions, further enhancing the effectiveness of the protection.

[0071] In a specific implementation process, the dynamic operation result may include, but is not limited to, the following:

[0072] When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element; or

[0073] When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element and the current environment data of the terminal are obtained.

[0074] It provides comprehensive data support for multimodal verification. Trajectory data directly reflects the fit between user operations and the evolution rules of basic elements, and is the core basis for judging the legality of operations. It can effectively resist trajectory forgery and simulation attacks. The addition of current environmental data enables the server to compare the differences between the initial environment and the environment during the verification process, accurately identify recording and replay attacks. Even if attackers obtain trajectory data, it is difficult for them to replicate completely identical environmental characteristics, further strengthening the protection barrier from the environmental dimension.

[0075] The design of two dynamic operation results supports flexible adaptation to verification scenarios with different security levels: for scenarios with low security requirements, only trajectory data can be collected, reducing data transmission and verification costs while ensuring basic security; for high-risk scenarios such as payment and login, environmental data collection can be added to achieve dual verification of behavior and environment, thereby improving the protection level. This differentiated adaptation capability allows the solution to meet the security needs of various network services, enhancing the practicality and universality of the technology.

[0076] In another specific implementation, the evolution rule of each basic element in the at least one basic element can be determined based on the evolution rule of each evolution function in the function group and the associated relationship. Then, the basic element can be dynamically adjusted using the evolution rule of each basic element to generate the dynamic adjustment information.

[0077] The evolution rules of each basic element are traced back to the initially selected function group and strictly correspond to the association relationship, avoiding logical confusion in the evolution process. This enables the server to accurately verify the legality of user operations based on preset rules, reducing misjudgments or omissions caused by ambiguity in evolution rules, and improving the accuracy and reliability of verification.

[0078] It supports independent evolution and collaborative matching of multiple basic elements. For example, the differentiated evolution of the cutout graphic and the target position in the sliding cutout verification template makes the dynamic evolution of the verification target more complex. Automated tools find it difficult to simultaneously crack the evolution rules of multiple basic elements and achieve accurate matching. At the same time, the logic of adjusting each element one by one allows the evolution of each basic element to be controlled independently. It supports flexible adjustment of the evolution dimension according to the needs of the verification scenario (such as adjusting only the trajectory, or adjusting the size and shape at the same time), which further enriches the diversity of dynamic verification and improves the adaptability of the solution to different attack methods.

[0079] In this embodiment, by responding to the information verification request triggered by the user based on the terminal, the environmental feature data of the terminal is obtained. Then, based on the static verification template, the environmental feature data, and a randomly selected function group, the dynamic verification information of the terminal can be obtained and output. This enables the verification operation to be performed on the dynamic operation result provided by the user based on the dynamic verification information. Since the generation of dynamic verification information depends on the terminal's unique environmental features and a random function group, and the verification process is deeply bound to the user's dynamic operation, automated tools cannot obtain fixed verification targets or evolution patterns in advance. This fundamentally resists common risks of automated tools such as static question bank collection and replay attacks, thereby significantly improving the reliability of information verification.

[0080] In addition, the technical solution provided in this disclosure takes into account both security and user experience. The generation and output of dynamic verification information do not require users to learn additional operation procedures, and the initial interaction form can be consistent with traditional verification methods, which can effectively reduce the user's operation threshold.

[0081] Furthermore, by adopting the technical solution provided in this disclosure, adaptive protection can be achieved through environmental characteristics and dynamic evolution mechanisms. Without the need for frequent manual adjustments to verification rules, it can cope with constantly upgraded automated attack methods, effectively improving the practicality and adaptability of the verification solution, thereby ensuring the system's stable protection capability in complex network environments.

[0082] In addition, the technical solutions provided in this disclosure can effectively improve the user experience.

[0083] The following example, using the verification operation of sliding image cutout through interaction between the terminal and the server, will be used to explain in detail the technical solution of this disclosure. Figure 2 As shown.

[0084] 201. The server sends a JS SDK to the terminal to collect the terminal's initial environment data as the terminal's environmental feature data.

[0085] Specifically, when the terminal first requests an application page (such as the application homepage) from the server, the server can send a JS SDK to the terminal, and the terminal can collect relevant data about the terminal device and operating environment.

[0086] 202. The terminal sends a page request to the server to request an application page (such as the application homepage). The page request carries the first terminal credential client_token, which contains environmental feature data, namely the first client_token (environmental feature data).

[0087] 203. The server encrypts the environmental feature data to obtain the terminal identification information (i.e., terminal ID); it encrypts the randomly selected function group (i.e., f1 and f2) to obtain the encrypted function group; and it concatenates the terminal ID and the encrypted function group (i.e., f1 and f2) to obtain the terminal's dynamic credential server_token.

[0088] 204. The server sends page data to the terminal, which includes the dynamic credential server_token.

[0089] 205. The terminal parses the dynamic credential server_token to obtain the function group and terminal ID, and adds the terminal ID to the second terminal credential client_token, i.e., the second client_token (terminal ID), to identify the terminal.

[0090] 206. The terminal sends an information verification request to the server to request the login page. The information verification request carries the terminal's current environment data and the second client_token (terminal ID).

[0091] 207. Based on the type of the randomly selected sliding cutout verification template, the server obtains the cutout graphic and target position contained in the sliding cutout verification template. From the function group (i.e., f1 and f2), it selects the evolution function f1 used for dynamic evolution of the cutout graphic and the evolution function f2 used for dynamic evolution of the target position. The server then performs association processing on the cutout graphic and evolution function f1, and the target position and evolution function f2, respectively, to obtain the association relationship. Based on the dynamic credential server_token, the sliding cutout verification template, and the association relationship, the server generates dynamic verification information.

[0092] 208. The server sends dynamic verification information to the terminal.

[0093] 209. The sliding cutout verification template in the dynamic verification information output by the terminal.

[0094] 210. In response to the dynamic operation result provided by the user based on the dynamic verification information, perform a verification operation on the dynamic operation result.

[0095] Specifically, the terminal can respond to the initial operation result provided by the user based on the sliding cutout verification template, and dynamically adjust the cutout graphic contained in the sliding cutout verification template using the evolution rules of the evolution function f1 in the dynamic verification information and the correlation in the dynamic verification information to generate dynamic adjustment information for the cutout graphic. It can also dynamically adjust the target position contained in the sliding cutout verification template using the evolution rules of the evolution function f2 in the dynamic verification information and the correlation in the dynamic verification information to generate dynamic adjustment information for the target position. Then, the terminal feeds back the dynamic operation result provided by the user based on the dynamic adjustment information to the server, and the server performs a verification operation on the dynamic operation result.

[0096] The dynamic operation results can include the trajectory data of the evolution of the cutout graphic and the evolution of the target position when the dynamic target conditions are met, that is, when the cutout graphic evolves and adjusts according to the evolution rule of evolution function f1 and the target position evolves and adjusts according to the evolution rule of evolution function f2, the trajectory data of the evolution trajectory of the cutout graphic, the trajectory data of the evolution trajectory of the target position, and the current environment data of the terminal.

[0097] The terminal can encrypt the dynamic operation results and add them to the second terminal credential, client_token (which includes the terminal ID, trajectory data of the evolution trajectory of the cutout graphic, trajectory data of the evolution trajectory of the target location, and the current environmental data of the terminal). The terminal then reports this information to the server, which performs the verification operation on the dynamic operation results.

[0098] The server performs verification operations on the results of dynamic operations, which can be multi-dimensional verification.

[0099] For example, behavioral modality verification: verify whether the evolution trajectory of the cutout graphic conforms to the evolution rules of the evolution function f1, whether the evolution trajectory of the target position conforms to the evolution rules of the evolution function f2, whether the overlapping position of the user operation is consistent with the overlapping position calculated by the server, and whether the current trajectory has a replay risk, i.e., whether it exists in the historical replay trajectory in the historical sample table. If the trajectory is valid and there is no replay risk, it is marked as behavioral verification passed.

[0100] Alternatively, for example, environmental modality verification: compare the differences between the current environmental data submitted by the user and the initially collected environmental feature data. If the difference value is less than or equal to a preset threshold, it indicates that there is no risk of replay and the environment verification can be marked as passed.

[0101] Only when both the behavioral modality and the environmental modality pass the verification is the overall information verification deemed successful, and the valid or invalid trajectory of this verification is added to the historical sample table.

[0102] At this point, based on the verification result of the verification operation, the requested application service can be provided to the terminal or the requested application service can be refused to be provided to the terminal.

[0103] In this embodiment, sliding image matting is used as the verification carrier. Through dynamic evolution logic and multimodal verification mechanism in collaboration between the terminal and the server, the security and adaptability of traditional static sliding verification codes are upgraded. The specific technical effects are as follows:

[0104] 1. Dynamic evolution logic implements resistance to automated attacks.

[0105] Unlike traditional sliding masking which uses static logic to fix the masked area and target position, this embodiment binds an evolution function f1 to the masked area and an evolution function f2 to the target position. During user operation, both functions dynamically adjust synchronously along a non-linear trajectory. The fixed coordinate matching and preset trajectory simulation methods relied upon by automated tools become completely ineffective and cannot adapt to real-time changes in the target position and masked area trajectory. This effectively resists automated attacks such as OCR recognition and trajectory prediction, solving the technical problem of traditional sliding CAPTCHAs being easily cracked.

[0106] The dynamic credential server_token binds the terminal ID to the function group, which enables the evolution rules of each verification to be strongly correlated with the terminal environment. Different verification sessions on the same terminal and the same verification template on different terminals will have different evolution trajectories, avoiding the risk of batch cracking after the verification template library is collected.

[0107] 2. Dual-modal verification to build an anti-replay protection system

[0108] Behavioral modality verification checks whether the evolution trajectory of the cutout image and the target position matches the evolution rules of evolution function f1 and evolution function f2 respectively, and whether the operation overlap point is consistent with the server-side calculated value. At the same time, it compares the historical sample table to intercept replay trajectory, which not only ensures the authenticity of the operation, but also eliminates the possibility of replay attacks after recording a legitimate operation trajectory.

[0109] Environmental modal verification effectively identifies attacks such as remotely recorded verification interfaces and local replay operations by comparing initial environmental data with the current environmental data during user operations. It achieves full-dimensional verification from operational behavior to terminal environment, with a protection coverage far exceeding that of traditional single-behavior verification.

[0110] 3. Lightweight integration and adaptation ensure a balance between security and user experience.

[0111] It leverages the JS SDK to complete terminal environment data collection, operation trajectory recording, and encrypted credential reporting. No additional applications need to be installed on the terminal. It can be quickly integrated through front-end scripts and adapted to multiple terminal forms such as web pages and lightweight applications, reducing the deployment cost of applications.

[0112] The initial verification interface is different from the traditional sliding cutout. Figure 1 Therefore, users do not need to learn new operating logic. The trajectory is dynamically adjusted only during the operation. This improves security while avoiding the negative impact of complex interactions on user experience, thus balancing verification security and ease of use.

[0113] 4. The terminal identification and credential system enables the personalization and traceability of verification sessions.

[0114] The terminal ID generated based on the terminal environment data can be used to uniquely identify the verification terminal. Combined with the two-way verification of client_token and server_token, the terminal source of abnormal verification sessions can be accurately located.

[0115] Valid tracks that pass verification or invalid tracks that fail verification will be added to the historical sample table to form a historical replay track library. Subsequently, the function evolution rules can be optimized based on the data in the library to continuously improve the verification's resistance to attacks and realize the self-iteration and self-optimization of the verification system.

[0116] 5. Layered interaction process ensures the security of data transmission and terminal adaptation.

[0117] Environmental and trajectory data collected on the terminal side are encrypted and encapsulated into the client_token. The server_token generated on the server side uses the concatenation logic of the terminal ID and the encryption function group. No plaintext sensitive data is transmitted throughout the process, ensuring user privacy and data security.

[0118] The phased page request and verification request process enables the data collection of the terminal environment, the issuance of dynamic credentials, and the push of dynamic verification information to be completed step by step. It can adapt to the interaction needs of different network environments and terminals with different performance, effectively avoid verification lag caused by excessive data transmission in a single transaction, and improve the stability and compatibility of the verification process.

[0119] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions, because according to this disclosure, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure.

[0120] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0121] Figure 3 This is a schematic diagram based on the second embodiment of the present disclosure, as shown below. Figure 3 As shown. The information verification device 300 of this embodiment may include a verification triggering unit 301, a verification selection unit 302, a verification output unit 303, and a verification execution unit 304. The verification triggering unit 301 is used to obtain environmental feature data of the terminal in response to an information verification request triggered by a user based on the terminal; the verification selection unit 302 is used to obtain dynamic verification information of the terminal based on a static verification template, the environmental feature data, and a randomly selected function group; the verification output unit 303 is used to output the dynamic verification information; and the verification execution unit 304 is used to perform a verification operation on the dynamic operation result provided by the user based on the dynamic verification information.

[0122] It should be noted that some or all of the information verification device in this embodiment may be an application located on a local terminal, or it may be a plugin or software development kit (SDK) or other functional unit set in an application located on a local terminal, or it may be a processing engine located on a network-side server, or it may be a distributed system located on the network side, such as a processing engine or distributed system in a network-side information verification processing platform, etc. This embodiment does not impose any particular limitations on this.

[0123] It is understood that the application can be a native program installed on the local terminal, or it can be a web application of a browser on the local terminal. This embodiment does not limit this.

[0124] Optionally, in one possible implementation of this embodiment, the verification selection unit 302 may be used to obtain the terminal identification information of the terminal based on the environmental feature data; perform fusion processing on the terminal identification information and the function group to obtain the dynamic credentials of the terminal; and generate the dynamic verification information based on the dynamic credentials and the randomly selected static verification template.

[0125] In a specific implementation, the verification selection unit 302 can be used to obtain at least one basic element of the static verification template according to the type of the static verification template; select the evolution function used for dynamic evolution of each basic element from the function group; perform association processing on each basic element and the evolution function used for dynamic evolution of the basic element to obtain an association relationship; and generate the dynamic verification information according to the dynamic credential, the static verification template and the association relationship.

[0126] Optionally, in one possible implementation of this embodiment, the verification execution unit 304 may be specifically used to dynamically adjust the static verification template in response to the user's initial operation result provided by the static verification template, using the evolution rules of the function group in the dynamic verification information and the correlation relationship in the dynamic verification information to generate dynamic adjustment information; and to perform a verification operation on the dynamic operation result provided by the user based on the dynamic adjustment information.

[0127] In a specific implementation process, the result of the dynamic operation may include the following:

[0128] When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element; or

[0129] When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element and the current environment data of the terminal are obtained.

[0130] In another specific implementation, the verification execution unit 304 can be used to determine the evolution rule of each basic element in the at least one basic element according to the evolution rule of each evolution function in the function group and the association relationship; and to dynamically adjust the basic element using the evolution rule of each basic element to generate the dynamic adjustment information.

[0131] In this embodiment, the verification triggering unit responds to the information verification request triggered by the user based on the terminal and obtains the environmental feature data of the terminal. Then, the verification selection unit obtains and outputs the dynamic verification information of the terminal based on the static verification template, the environmental feature data, and a randomly selected function group. This allows the verification execution unit to respond to the dynamic operation result provided by the user based on the dynamic verification information and perform a verification operation on the dynamic operation result. Since the generation of dynamic verification information depends on the terminal's unique environmental features and a random function group, and the verification process is deeply bound to the user's dynamic operation, automated tools cannot obtain fixed verification targets or evolution patterns in advance. This fundamentally resists common risks of automated tools such as static question bank collection and replay attacks, thereby significantly improving the reliability of information verification.

[0132] In addition, the technical solution provided in this disclosure takes into account both security and user experience. The generation and output of dynamic verification information do not require users to learn additional operation procedures, and the initial interaction form can be consistent with traditional verification methods, which can effectively reduce the user's operation threshold.

[0133] Furthermore, by adopting the technical solution provided in this disclosure, adaptive protection can be achieved through environmental characteristics and dynamic evolution mechanisms. Without the need for frequent manual adjustments to verification rules, it can cope with constantly upgraded automated attack methods, effectively improving the practicality and adaptability of the verification solution, thereby ensuring the system's stable protection capability in complex network environments.

[0134] In addition, the technical solutions provided in this disclosure can effectively improve the user experience.

[0135] Figure 4 A schematic block diagram of an example electronic device 400 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workbenches, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0136] like Figure 4As shown, the electronic device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. The RAM 403 may also store various programs and data required for the operation of the electronic device 400. The computing unit 401, ROM 402, and RAM 403 are interconnected via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0137] Multiple components in electronic device 400 are connected to I / O interface 405, including: input unit 406, such as keyboard, mouse, etc.; output unit 407, such as various types of displays, speakers, etc.; storage unit 408, such as disk, optical disk, etc.; and communication unit 409, such as network card, modem, wireless transceiver, etc. Communication unit 409 allows electronic device 400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0138] The computing unit 401 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 performs the various methods and processes described above, such as the information verification method. For example, in some embodiments, the information verification method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 400 via ROM 402 and / or communication unit 409. When the computer program is loaded into RAM 403 and executed by the computing unit 401, one or more steps of the information verification method described above may be performed. Alternatively, in other embodiments, the computing unit 401 may be configured to perform the information verification method by any other suitable means (e.g., by means of firmware).

[0139] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0140] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0141] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0142] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0143] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), the Internet, and blockchain networks.

[0144] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.

[0145] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0146] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. An information verification method, characterized in that, include: In response to a user's information verification request triggered by the terminal, the environmental feature data of the terminal is obtained; Based on the static verification template, the environmental feature data, and the randomly selected function group, the dynamic verification information of the terminal is obtained; Output the dynamic verification information; In response to the dynamic operation result provided by the user based on the dynamic verification information, a verification operation is performed on the dynamic operation result.

2. The method according to claim 1, characterized in that, The step of obtaining the dynamic verification information of the terminal based on the static verification template, the environmental feature data, and the randomly selected function group includes: Based on the environmental feature data, obtain the terminal identification information of the terminal; The terminal identification information and the function group are fused together to obtain the dynamic credentials of the terminal; The dynamic verification information is generated based on the dynamic credentials and the randomly selected static verification template.

3. The method according to claim 2, characterized in that, The step of generating the dynamic verification information based on the dynamic credential and the randomly selected static verification template includes: Based on the type of the static verification template, obtain at least one basic element of the static verification template; From the function group, select the evolution function used for the dynamic evolution of each of the at least one basic element; For each basic element and the evolution function used for the dynamic evolution of that basic element, an association process is performed to obtain the association relationship; The dynamic verification information is generated based on the dynamic credential, the static verification template, and the association relationship.

4. The method according to claim 3, characterized in that, The step of performing a verification operation on the dynamic operation result provided by the user based on the dynamic verification information includes: In response to the user's initial operation result based on the static verification template, the static verification template is dynamically adjusted using the evolution rules of the function group in the dynamic verification information and the correlation relationships in the dynamic verification information to generate dynamic adjustment information; In response to the dynamic operation result provided by the user based on the dynamic adjustment information, a verification operation is performed on the dynamic operation result.

5. The method according to claim 4, characterized in that, The results of the dynamic operation include: When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element; or When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element and the current environment data of the terminal are obtained.

6. The method according to claim 4 or 5, characterized in that, The step of dynamically adjusting the static verification template using the evolution rules of the function group in the dynamic verification information and the correlation relationships in the dynamic verification information to generate dynamic adjustment information includes: Based on the evolution rules of each evolution function in the function group and the correlation relationship, determine the evolution rules of each basic element in the at least one basic element; The evolution rules of each basic element are used to dynamically adjust the basic element to generate the dynamic adjustment information.

7. An information verification device, characterized in that, include: The verification triggering unit is used to obtain the environmental feature data of the terminal in response to the information verification request triggered by the user based on the terminal. The verification selection unit is used to obtain the dynamic verification information of the terminal based on the static verification template, the environmental feature data, and a randomly selected function group; A verification output unit is used to output the dynamic verification information; The verification execution unit is used to perform a verification operation on the dynamic operation result provided by the user based on the dynamic verification information.

8. The apparatus according to claim 7, characterized in that, The verification selection unit is specifically used for Based on the environmental feature data, obtain the terminal identification information of the terminal; The terminal identification information and the function group are fused together to obtain the dynamic credentials of the terminal; as well as The dynamic verification information is generated based on the dynamic credentials and the randomly selected static verification template.

9. The apparatus according to claim 8, characterized in that, The verification selection unit is specifically used for Based on the type of the static verification template, obtain at least one basic element of the static verification template; From the function group, select the evolution function used for the dynamic evolution of each of the at least one basic element; For each basic element and the evolution function used for the dynamic evolution of that basic element, an association process is performed to obtain the association relationship; as well as The dynamic verification information is generated based on the dynamic credential, the static verification template, and the association relationship.

10. The apparatus according to claim 9, characterized in that, The verification execution unit is specifically used for In response to the user's initial operation result based on the static verification template, the static verification template is dynamically adjusted using the evolution rules of the function group in the dynamic verification information and the correlation relationships in the dynamic verification information to generate dynamic adjustment information; as well as In response to the dynamic operation result provided by the user based on the dynamic adjustment information, a verification operation is performed on the dynamic operation result.

11. The apparatus according to claim 10, characterized in that, The results of the dynamic operation include: When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element; or When the evolution rule of each basic element satisfies the dynamic target condition, the trajectory data of each basic element and the current environment data of the terminal are obtained.

12. The apparatus according to claim 10 or 11, characterized in that, The verification execution unit is specifically used for Based on the evolution rules of each evolution function in the function group and the associated relationships, determine the evolution rules of each basic element in the at least one basic element; and The evolution rules of each basic element are used to dynamically adjust the basic element to generate the dynamic adjustment information.

13. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-6.

14. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-6.

15. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-6.