An identity authentication method and device, a storage medium and an electronic device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-01
- Publication Date
- 2026-08-07
AI Technical Summary
可见传统方法无论是在用户体验还是安全性上,都存在明显不足
在本说明书提供的身份认证方法中,第一终端设备响应于身份认证请求,根据身份认证请求确定对应的认证操作,生成用于描述认证操作及认证操作的目的的第一描述文本和能够被已通过身份认证的第二终端设备扫描识别的机器可读编码,并将机器可读编码和第一描述文本显示在同一个验证界面中。用户能够利用第二终端设备扫描机器可读编码获得第二描述文本,并验证第二描述文本和第一描述文本是否一致,进而确定是否执行第一描述文本所描述的认证操作以进行授权。第一终端设备在接收到第二终端设备响应于用户执行认证操作发送的授权凭证后通过该用户的身份认证,并执行目标业务,否则,拒绝执行目标业务。
Smart Images

Figure CN121966886B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computers, and in particular to an authentication method, apparatus, storage medium, and electronic device. Background Technology
[0002] When logging into a new device with the same account, or registering a new account on a new device with the same identity, identity verification is usually required. A common method is to display a verification message on the old device, prompting the user to enter a verification code or scan a QR code to complete the identity verification.
[0003] However, this method can be disruptive to users of older devices. If an attacker launches an authentication attack on a new device, the older device will frequently receive verification messages, causing malicious disruption to its users. Furthermore, attackers can intercept verification messages by attacking the data transmission channel between the new and old devices, then forge verification information and send it to the older device to deceive its users into authenticating. Clearly, traditional methods have significant shortcomings in both user experience and security.
[0004] The background information is merely information known only to the inventor and does not imply that such information had entered the public domain before the date of this application, nor does it imply that it could be considered prior art in this disclosure. Summary of the Invention
[0005] This specification provides an authentication method, apparatus, storage medium, and electronic device to at least partially solve the aforementioned problems existing in the prior art.
[0006] The following technical solution is adopted in this specification: This specification provides an authentication method, which is applied to a first terminal device, and the method includes: In response to an authentication request initiated for a target service, determine the authentication operation corresponding to the authentication request; Generate a first description text, which is used to describe the authentication operation and the purpose of the authentication operation; Generate machine-readable encoding based on the first descriptive text; The machine-readable code and the first description text are displayed in the verification interface, and the verification interface is shown to the user so that the user can use a second terminal device that has been authenticated to scan the machine-readable code to obtain the second description text and verify the consistency between the second description text and the first description text. If the second terminal device receives an authorization credential in response to the user performing the authentication operation, the user is determined to have passed identity authentication based on the authorization credential, and the target service is executed; otherwise, the target service is refused to be executed.
[0007] Optionally, generating the machine-readable encoding based on the first descriptive text specifically includes: The first description text is converted into a string according to a preset encoding rule; the string is then converted into the machine-readable encoding. The second terminal device scans the machine-readable code to obtain the second descriptive text, specifically including: The second terminal device scans the machine-readable code to obtain the string; The second terminal device decodes the string into the second description text according to a preset decoding rule corresponding to the encoding rule.
[0008] Optionally, the machine-readable encoding can be any one of a one-dimensional barcode, a two-dimensional barcode, or a barcode-like barcode.
[0009] Optionally, the method further includes: After scanning the machine-readable code, the second terminal device displays the second description text in the authentication interface; If the user performs the authentication operation on the authentication interface, the second terminal device sends the authorization credential to the first terminal device.
[0010] Optionally, the authentication operation includes: Perform the target action in the target area of the authentication interface; or Enter the specified verification data in the authentication interface.
[0011] Optionally, the target action includes at least one of the following actions performed in the target area: clicking, touching, and swiping.
[0012] Optionally, the verification data includes at least one of a verification code and the user's physiological characteristic data.
[0013] Optionally, the target service includes account registration or account login.
[0014] This specification provides an identity authentication device, which is applied to a first terminal device, and the device includes: The response module is used to respond to an authentication request initiated for the target business and determine the authentication operation corresponding to the authentication request; A description text generation module is used to generate a first description text, which is used to describe the authentication operation and the purpose of the authentication operation. A machine-readable encoding generation module is used to generate machine-readable encoding based on the first descriptive text; The display module is used to display the machine-readable code and the first description text in the verification interface and show the verification interface to the user so that the user can use the second terminal device that has been authenticated to scan the machine-readable code to obtain the second description text and verify the consistency between the second description text and the first description text. The identity authentication module is used to determine that the user has passed identity authentication and execute the target service based on the authorization credential sent by the second terminal device in response to the user performing the authentication operation; otherwise, it refuses to execute the target service.
[0015] Optionally, the machine-readable encoding generation module is specifically used to convert the first description text into a string according to a preset encoding rule, convert the string into the machine-readable encoding, so that the user can use the second terminal device to scan the machine-readable encoding to obtain the string, and decode the string into the second description text according to a preset decoding rule corresponding to the encoding rule.
[0016] Optionally, the machine-readable encoding can be any one of a one-dimensional barcode, a two-dimensional barcode, or a barcode-like barcode.
[0017] Optionally, after scanning the machine-readable code, the second terminal device displays the second description text in the authentication interface; if the user performs the authentication operation in the authentication interface, the second terminal device sends the authorization credential to the first terminal device.
[0018] Optionally, the authentication operation includes: Perform the target action in the target area of the authentication interface; or Enter the specified verification data in the authentication interface.
[0019] Optionally, the target action includes at least one of the following actions performed in the target area: clicking, touching, and swiping.
[0020] Optionally, the verification data includes at least one of a verification code and the user's physiological characteristic data.
[0021] Optionally, the target service includes account registration or account login.
[0022] This specification provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described authentication method.
[0023] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the above-described authentication method.
[0024] The above-mentioned technical solutions adopted in this specification can achieve the following beneficial effects: In the authentication method provided in this specification, a first terminal device, in response to an authentication request, determines the corresponding authentication operation based on the request, generates a first description text describing the authentication operation and its purpose, and a machine-readable code that can be scanned and recognized by a second terminal device that has already passed authentication. The machine-readable code and the first description text are displayed on the same verification interface. The user can use the second terminal device to scan the machine-readable code to obtain the second description text and verify whether the second description text and the first description text are consistent, thereby determining whether to execute the authentication operation described in the first description text for authorization. Upon receiving the authorization credential sent by the second terminal device in response to the user's execution of the authentication operation, the first terminal device authenticates the user and executes the target service; otherwise, it refuses to execute the target service.
[0025] As can be seen from the above method, the verification interface is only displayed on the first terminal device, not the second terminal device. Even if the attacker launches an attack on the first terminal device, no verification message will be displayed on the second terminal device, thus avoiding disturbance to the user holding the second terminal device.
[0026] Machine-readable code and the first description text are not transmitted through a data transmission channel but are directly displayed to the user. Therefore, it is difficult for attackers to hijack the machine-readable code and the first description text by attacking the data transmission channel (such as SMS or email). The first terminal device displays both the machine-readable code and the first description text simultaneously in the verification interface. The user can determine the purpose of this authentication operation based on the first description text and decide whether to perform authentication, thus preventing accidental touches. Furthermore, after the user scans the machine-readable code using the second terminal device, they can verify whether the scanned second description text matches the first description text, thereby preventing attackers from deceiving the user by tampering with the first description text and ensuring the security of the entire authentication process. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] In the picture: Figure 1 This is a flowchart illustrating an identity authentication method provided in this specification. Figure 2 This is a schematic diagram illustrating the interaction process between the first terminal device and the second terminal device in the generation and parsing of machine-readable code provided in this specification. Figure 3 This is a schematic diagram of the verification interface provided in this manual; Figure 4 This is a schematic diagram of the structure of an identity authentication device provided in this specification; Figure 5 The corresponding information provided in this specification Figure 1 A schematic diagram of an electronic device. Detailed Implementation
[0029] First, it should be noted that the terminology used in the embodiments of this invention is for the purpose of describing specific embodiments only and is not intended to limit the invention. The singular forms “a,” “the,” and “the” used in the embodiments of this invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0030] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments in this specification, and not all of the embodiments. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0031] It should be noted that the steps of the corresponding methods are not necessarily performed in the order shown and described in this specification in other embodiments. In some other embodiments, the methods may include more or fewer steps than described in this specification. Furthermore, a single step described in this specification may be broken down into multiple steps in other embodiments; and multiple steps described in this specification may be combined into a single step in other embodiments.
[0032] The following section introduces the application scenarios of this manual.
[0033] The technical solutions provided in this manual are applicable to scenarios where the same account is used to log in to a new device, or the same identity is used to register a new account on a new device.
[0034] When logging into a new device with the same account, in order to protect against login from different locations, users are usually required to perform identity verification on the original terminal device that was bound when registering the account, which is the second terminal device.
[0035] In another scenario, some applications allow users to create a temporary, locally-only account using a device ID, but this account hasn't actually completed the full registration process. If a user creates such a temporary account on an older device and needs to complete the registration process on a new device to upgrade it into a permanent, cross-device-use account, the account's service platform will typically require the user to return to the older device for identity verification. This scenario is the same as the one described above where the same identity is used to register a new account on a new device.
[0036] In both of these authentication scenarios, when a user logs in or registers a new account on a new device, verification information needs to be sent to the old device. This information allows the user to authenticate their identity on the old device, authorizing their current action (login or account registration) on the new device. For example, a verification box might pop up on the old device, prompting the user to enter a verification code; or a QR code might appear on the old device, allowing the user to scan it using an application on the old device.
[0037] This authentication method can cause malicious disruption to users of older devices. Especially when attackers launch attacks targeting older device user accounts from new devices, the older devices will receive frequent verification messages, causing further disruption. Furthermore, if older device users misoperate, it can lead to the leakage of their private information.
[0038] To address the aforementioned existing authentication schemes, attackers might hijack genuine verification information by attacking the data transmission channel between new and old devices, then forge false verification information to deceive users into authentication. Furthermore, since users of older devices cannot verify the purpose of the verification information or whether it has been tampered with, attackers might also use social engineering techniques to trick them into scanning QR codes. For example, attackers could send forged official notifications via SMS or email to older devices, tricking users into scanning the QR codes in the messages or emails. Attackers might also impersonate industry professionals (such as non-profit workers or sales promoters) in offline scenarios, using forged QR codes to deceive users of older devices into scanning them.
[0039] It is clear that traditional methods have significant shortcomings in terms of both user experience and security.
[0040] To overcome the aforementioned problems, this specification provides an authentication method. In this method, the device that has undergone authentication is the second terminal device, and the device that has not undergone authentication is the first terminal device. Here, authentication refers to the target business. As mentioned above, taking the target business of logging into an existing account on a new device as an example, in this scenario, for the purpose of protecting against remote logins, the user is required to perform authentication on the original terminal device bound when registering the account, i.e., the second terminal device. The second terminal device completed the authentication process on the server corresponding to the account when registering the account; therefore, the second terminal device is an authenticated device for the target business of logging into this account.
[0041] In the authentication method provided in this specification, a first terminal device, in response to an authentication request, determines the corresponding authentication operation based on the request, generates a first description text describing the authentication operation and its purpose, and a machine-readable code that can be scanned and recognized by a second terminal device that has already passed authentication. The machine-readable code and the first description text are displayed on the same verification interface. The user can use the second terminal device to scan the machine-readable code to obtain the second description text and verify whether the second description text and the first description text are consistent, thereby determining whether to execute the authentication operation described in the first description text for authorization. Upon receiving the authorization credential sent by the second terminal device in response to the user's execution of the authentication operation, the first terminal device authenticates the user and executes the target service; otherwise, it refuses to execute the target service.
[0042] In the above method, the verification interface is only displayed on the first terminal device, not the second terminal device. Even if the attacker launches an attack on the first terminal device, no verification message will be displayed on the second terminal device, thus avoiding disturbance to the user holding the second terminal device.
[0043] Machine-readable code and the first description text are not transmitted through a data transmission channel but are directly displayed to the user. Therefore, it is difficult for attackers to hijack the machine-readable code and the first description text by attacking the data transmission channel (such as SMS or email), effectively preventing hijacking attacks. The first terminal device displays both the machine-readable code and the first description text simultaneously in the verification interface. The user can determine the purpose of the authentication operation based on the first description text and decide whether to proceed with authentication, thus preventing accidental activation. Furthermore, after scanning the machine-readable code with a second terminal device, the user can verify whether the scanned second description text matches the first description text, preventing attackers from deceiving the user by tampering with the first description text and ensuring the security of the entire authentication process.
[0044] The subjects of execution in this specification include a first terminal device and a second terminal device. The first and second terminal devices described in this specification can be intelligent terminals with a certain computing capability, such as mobile devices, tablet computers, laptops, personal computers, vehicle terminals, access control terminals, self-service terminals, etc. The first and second terminal devices may include hardware devices with data processing functions and the necessary computer programs to drive the hardware devices. These computer programs may be data or instructions for the authentication method described in this specification stored in memory, and the program can be executed by the hardware devices to implement the aforementioned authentication method.
[0045] The first terminal device can deploy an app or mini-program capable of initiating authentication requests. This app or mini-program provides the ability to receive operations and provides an interface, allowing users to initiate authentication requests by performing preset actions within the app or mini-program's interface. Such apps include, but are not limited to: financial apps, web browser apps, search apps, chat apps, shopping apps, video apps, wealth management apps, instant messaging tools, email clients, social media platforms, and so on.
[0046] Figure 1 This is a flowchart illustrating an authentication method provided in this specification. The method is applicable to a first terminal device and specifically includes the following steps: S100: In response to an authentication request initiated for the target service, determine the authentication operation corresponding to the authentication request.
[0047] As mentioned above, the first terminal device can deploy an APP or mini-program that can initiate identity authentication requests. The APP or mini-program can provide the ability to receive operations and the interface.
[0048] Users can perform preset operations in the interfaces provided by the aforementioned apps or mini-programs to initiate identity authentication requests for the target business.
[0049] The target business mentioned above can be account login (login to a new device with the same account) or account registration (registering a new account on a new device with the same identity).
[0050] After receiving the authentication request, the first terminal device determines the authentication operation corresponding to the authentication request.
[0051] In some implementations, the authentication operation described above may include performing a target action in a designated authentication interface, such as clicking, touching, or swiping in a target area of the authentication interface, or performing actions such as opening one's mouth, turning one's head, nodding, or waving one's hand according to prompts in the authentication interface.
[0052] In some implementations, the authentication operation described above may include inputting specified verification data in the authentication interface, such as a verification code, password, or physiological characteristic data of the user, such as fingerprints or facial photos.
[0053] S102: Generate the first description text.
[0054] The first descriptive text describes the authentication operation and its purpose, that is, it tells the user what to do and why.
[0055] S104: Generate machine-readable encoding based on the first description text.
[0056] In some implementations, the first terminal device may first convert the first description text into a string according to a preset encoding rule, and then convert the string into machine-readable encoding. The string may be one or more combinations of numbers, binary data, Chinese characters, letters, and special symbols.
[0057] The aforementioned machine-readable encoding can include one-dimensional codes, two-dimensional codes, or QR code-like codes. QR code-like codes are extensions of QR codes, such as color QR codes carrying color information, ArUco codes, AprilTags, or grid patterns that visually resemble QR codes and can be scanned and parsed by a second terminal device.
[0058] Taking a machine-readable QR code as an example, the specific process of generating a QR code based on the first descriptive text is as follows: First, the first descriptive text is encoded into binary data code; Next, error correction codes are added to the binary data code according to the error correction rules; Construct a data matrix, add patterns for positioning / calibration / timing determination to the data matrix to ensure that the direction and size can be identified when scanning, and then fill in binary data codes and error correction codes in other positions of the data matrix; The 0s and 1s in the data matrix are mapped to black and white blocks (0 is white, black is 1), and the QR code is finally rendered.
[0059] Corresponding to the machine-readable encoding generation process described above, the second terminal can employ a corresponding process for decoding. Please refer to [reference needed]. Figure 2 , Figure 2 The diagram illustrates the interaction process between the first terminal device and the second terminal device during the generation and parsing of machine-readable code.
[0060] like Figure 2As shown, the first terminal device converts the first description text into a string according to a preset encoding rule, then converts the string into machine-readable encoding and displays the machine-readable encoding to the second terminal device. The second terminal device scans the machine-readable encoding to obtain the string, and then decodes the string into the second description text according to a preset decoding rule corresponding to the encoding rule.
[0061] S106: Display the machine-readable code and the first description text in the verification interface, and show the verification interface to the user so that the user can use the second terminal device that has been authenticated to scan the machine-readable code to obtain the second description text, and verify the consistency between the second description text and the first description text.
[0062] Please refer to Figure 3 The first terminal device displays machine-readable code and first descriptive text on the verification interface and presents the verification interface to the user.
[0063] As mentioned earlier, the first descriptive text describes the authentication operation and its purpose, informing the user what needs to be done and why. Therefore, the user can understand the target business corresponding to this authentication based on the first descriptive text, and what authentication operation needs to be performed, thus deciding whether or not to proceed with authentication.
[0064] If the user confirms that they are to authenticate, they can obtain the second description text by scanning the machine-readable code through the second terminal device, and verify the consistency between the second description text and the first description text, thereby determining whether the first description text has been tampered with.
[0065] As mentioned earlier, the first terminal device is equipped with an app or mini-program capable of initiating authentication requests. This app or mini-program provides the ability to receive operations and provides an interface. Correspondingly, the second terminal device also has the same app or mini-program deployed. Users can use this app or mini-program to scan machine-readable codes. After decoding the machine-readable codes, the app or mini-program displays a second description text in the authentication interface. Users can compare the second description text in the authentication interface with the first description text in the verification interface. Once the user confirms that the second description text matches the first description text, they can perform the authentication operation specified in the first description text in the authentication interface. At this time, the server of the app or mini-program sends authorization credentials to the app or mini-program in the first terminal device.
[0066] S108: If the second terminal device receives an authorization credential sent in response to the user performing the authentication operation, then the user is determined to have passed identity authentication based on the authorization credential, and the target service is executed; otherwise, the target service is refused to be executed.
[0067] As mentioned earlier, the first terminal device is equipped with an app or mini-program capable of initiating authentication requests. The app or mini-program provides the ability to receive operations and has an interface. When the app or mini-program in the first terminal device receives authorization credentials from the server, it determines that the current user has passed authentication based on the authorization credentials and executes the target service; otherwise, it refuses to execute the target service.
[0068] The above describes one or more embodiments of the authentication method provided in this specification. Based on the same idea, this specification also provides corresponding authentication devices, such as... Figure 4 As shown, the device is applied to a first terminal device, and the device includes: Response module 401 is used to respond to an authentication request initiated for a target service and determine the authentication operation corresponding to the authentication request; The description text generation module 402 is used to generate a first description text, which is used to describe the authentication operation and the purpose of the authentication operation. A machine-readable encoding generation module 403 is used to generate machine-readable encoding based on the first descriptive text; Display module 404 is used to display the machine-readable code and the first description text in the verification interface and show the verification interface to the user so that the user can use the second terminal device that has been authenticated to scan the machine-readable code to obtain the second description text and verify the consistency between the second description text and the first description text. The identity authentication module 405 is used to determine that the user has passed identity authentication and execute the target service based on the authorization credential sent by the second terminal device in response to the user performing the authentication operation; otherwise, it refuses to execute the target service.
[0069] Optionally, the machine-readable encoding generation module is specifically used to convert the first description text into a string according to a preset encoding rule, convert the string into the machine-readable encoding, so that the user can use the second terminal device to scan the machine-readable encoding to obtain the string, and decode the string into the second description text according to a preset decoding rule corresponding to the encoding rule.
[0070] Optionally, the machine-readable encoding can be any one of a one-dimensional barcode, a two-dimensional barcode, or a barcode-like barcode.
[0071] Optionally, after scanning the machine-readable code, the second terminal device displays the second description text in the authentication interface; if the user performs the authentication operation in the authentication interface, the authorization credential is sent to the first terminal device.
[0072] Optionally, the authentication operation includes: performing a target action in the target area of the authentication interface; or, entering specified verification data in the authentication interface.
[0073] Optionally, the target action includes at least one of the following actions performed in the target area: clicking, touching, and swiping.
[0074] Optionally, the verification data includes at least one of a verification code and the user's physiological characteristic data.
[0075] This specification also provides a computer-readable storage medium storing a computer program that can be used to execute the above-described... Figure 1 The provided identity authentication method.
[0076] This instruction manual also provides Figure 5 The diagram shows the structure of the electronic device. Figure 5 As shown, at the hardware level, this electronic device includes a processor, internal bus, network interface, memory, and non-volatile memory, and may also include other hardware required for business operations. The processor reads the corresponding computer program from the non-volatile memory into memory and then runs it to achieve the above. Figure 1 The authentication method described herein. Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to individual logic units, but can also be hardware or logic devices.
[0077] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many improvements to the methodology today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that an improvement to the methodology cannot be implemented using hardware physical modules.
[0078] For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is an integrated circuit whose logic function is determined by the user programming the device. Designers program a digital system onto a PLD themselves, eliminating the need for chip manufacturers to design and fabricate dedicated integrated circuit chips. Furthermore, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented using "logic compiler" software, similar to the software compiler used in program development. The source code before compilation must be written in a specific programming language called a Hardware Description Language (HDL). There are many types of HDLs, such as ABEL. Various hardware description languages are available, including Advanced Boolean Expression Language (AHDL), Altera Hardware Description Language (AHDL), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog are the most commonly used. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these languages and then programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0079] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0080] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0081] For ease of description, the above devices are described in terms of function, divided into various units. Of course, in implementing this specification, the functions of each unit can be implemented in one or more software and / or hardware components.
[0082] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0083] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0084] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0085] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0086] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0087] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0088] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0089] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0090] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0091] This specification can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This specification can also be practiced in distributed computing environments, where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0092] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0093] The above description is merely an embodiment of this specification and is not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this application.
Claims
1. An identity authentication method, the method being applied to a first terminal device, the method comprising: In response to an authentication request initiated for a target service, determine the authentication operation corresponding to the authentication request; Generate a first description text, which is used to describe the authentication operation and the purpose of the authentication operation; Generate machine-readable encoding based on the first descriptive text; The machine-readable code and the first description text are displayed in the verification interface, and the verification interface is shown to the user so that the user can use a second terminal device that has been authenticated to scan the machine-readable code to obtain the second description text and verify the consistency between the second description text and the first description text. If the server receives an authorization credential in response to the user performing the authentication operation, the user is determined to have passed identity authentication based on the authorization credential, and the target service is executed. Otherwise, the target service will not be executed.
2. The method according to claim 1, wherein generating the machine-readable code based on the first descriptive text specifically includes: The first description text is converted into a string according to a preset encoding rule; Convert the string into the machine-readable encoding; The second terminal device scans the machine-readable code to obtain the second descriptive text, specifically including: The second terminal device scans the machine-readable code to obtain the string; The second terminal device decodes the string into the second description text according to a preset decoding rule corresponding to the encoding rule.
3. The method according to claim 2, wherein the machine-readable encoding is any one of a one-dimensional code, a two-dimensional code, and a QR code-like code.
4. The method according to claim 2, further comprising: After scanning the machine-readable code, the second terminal device displays the second description text in the authentication interface; If the user performs the authentication operation on the authentication interface, the server sends the authorization credential to the first terminal device.
5. The method according to claim 4, wherein the authentication operation comprises: Perform the target action in the target area of the authentication interface; or Enter the specified verification data in the authentication interface.
6. The method according to claim 5, wherein the target action includes at least one of clicking, touching, and swiping performed in the target area.
7. The method according to claim 5, wherein the verification data includes at least one of a verification code and the user's physiological characteristic data.
8. The method according to claim 1, wherein the target service includes account registration or account login.
9. An identity authentication device, the device being applied to a first terminal device, the device comprising: The response module is used to respond to an authentication request initiated for the target business and determine the authentication operation corresponding to the authentication request; A description text generation module is used to generate a first description text, which is used to describe the authentication operation and the purpose of the authentication operation. A machine-readable encoding generation module is used to generate machine-readable encoding based on the first descriptive text; The display module is used to display the machine-readable code and the first description text in the verification interface and show the verification interface to the user so that the user can use the second terminal device that has been authenticated to scan the machine-readable code to obtain the second description text and verify the consistency between the second description text and the first description text. The identity authentication module is used to determine that the user has passed identity authentication and execute the target service based on the authorization credential sent by the server in response to the user performing the authentication operation; otherwise, it refuses to execute the target service.
10. The apparatus according to claim 9, wherein the machine-readable encoding generation module is specifically configured to convert the first description text into a string according to a preset encoding rule, convert the string into the machine-readable encoding, so that the user can use the second terminal device to scan the machine-readable encoding to obtain the string, and decode the string into the second description text according to a preset decoding rule corresponding to the encoding rule.
11. The apparatus of claim 10, wherein the machine-readable code is any one of a one-dimensional code, a two-dimensional code, and a QR code-like code.
12. The apparatus according to claim 10, wherein after the second terminal device scans the machine-readable code, it displays the second descriptive text in the authentication interface; if the user performs the authentication operation in the authentication interface, the server sends the authorization credential to the first terminal device.
13. The apparatus of claim 12, wherein the authentication operation comprises: Perform the target action in the target area of the authentication interface; or Enter the specified verification data in the authentication interface.
14. The apparatus of claim 13, wherein the target action includes at least one of clicking, touching, and swiping performed in the target area.
15. The apparatus according to claim 13, wherein the verification data includes at least one of a verification code and the user's physiological characteristic data.
16. The apparatus according to claim 9, wherein the target service includes account registration or account login.
17. A computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in any one of claims 1 to 8.
18. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method described in any one of claims 1 to 8.
Citation Information
Patent Citations
Multi-application login method and device
CN109413096A
Authorization authentication method and device, storage medium and computer program product
CN121012682A