A remote multi-factor identity authentication method and device of a border security device, an electronic device, and a storage medium
Patent Information
- Application Number
- CN202610899225.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-18
- Publication Date
- 2026-09-22
AI Technical Summary
[0003]本发明提供了一种边界安全装置的远程多因子身份认证方法、装置、电子设备及存储介质,能够解决现有技术中用户身份被冒用和用户账户被非法访问的风险较大的问题
本发明提供了一种边界安全装置的远程多因子身份认证方法,所述方法包括:将用于身份认证的多因子远程认证信息拆分为若干种因子认证信息,为每种因子认证信息关联一台唯一的输入移动设备,并将各所述因子认证信息、每种因子认证信息所关联的输入移动设备的设备编号,以及每种因子认证信息的输入顺序打包为对应的多因子认证信息包;将所述多因子认证信息包发送至对应的接收移动设备,以使用户根据接收移动设备中多因子认证信息包的信息,按照每种因子认证信息的输入顺序,在各输入移动设备中上传对应关联的因子认证信息;当接收到各输入移动设备上传的因子认证信息后,将所接收到的各输入移动设备的设备编号、所上传的因子认证信息以及上传顺序与所述多因子认证信息包中的信息进行比对,若比对一致,则判定各输入移动设备的身份认证通过,否则判定不通过。
Smart Images

Figure CN122802206A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of remote authentication technology, and in particular to a remote multi-factor authentication method, device, electronic device, and storage medium for a boundary security device. Background Technology
[0002] User authentication methods based on mobile devices inputting multi-factor authentication information to border security devices offer convenient remote multi-factor authentication, making them widely applicable. Existing related solutions typically rely on a network-connected mobile device inputting multi-factor authentication information to a border security device for remote user authentication. In this method, the mobile device is independent, with each device corresponding to a fixed set of multi-factor authentication information. Each authentication attempt involves a single mobile device inputting this fixed information to the border security device. However, if the mobile device in this existing solution is compromised by a cyber attacker, the attacker may remotely control the device to input multi-factor authentication information to the border security device, leading to the risk of user identity theft and unauthorized access to user accounts. Summary of the Invention
[0003] This invention provides a remote multi-factor authentication method, device, electronic device, and storage medium for boundary security devices, which can solve the problem of high risk of user identity misuse and unauthorized access to user accounts in the prior art.
[0004] To address the aforementioned technical problems, embodiments of the present invention provide a remote multi-factor authentication method for a boundary security device, comprising: The multi-factor remote authentication information used for identity authentication is split into several types of factor authentication information. Each type of factor authentication information is associated with a unique input mobile device. The factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information are packaged into a corresponding multi-factor authentication information package. The multi-factor authentication information package is sent to the corresponding receiving mobile device so that the user can upload the corresponding associated factor authentication information in each input mobile device according to the input order of each factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. Upon receiving the factor authentication information uploaded by each input mobile device, the device number, uploaded factor authentication information, and upload order of each input mobile device are compared with the information in the multi-factor authentication information package. If the comparison matches, the identity authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0005] As a preferred embodiment, the input mobile device is connected to the network only when uploading factor authentication information, while the receiving mobile device is always connected to the network. When the authentication of the input mobile device fails, disconnect the network connection of each input mobile device.
[0006] As a preferred option, it also includes: If no factor authentication information is received from the input mobile device within the preset time period, the network connection status of each input mobile device will be checked. If an abnormal network connection is detected, the network connection of the input mobile device with the abnormal network connection will be enabled until the network connection status of each input mobile device is found to be normal.
[0007] As a preferred embodiment, when the device number, uploaded factor authentication information, and upload order of each input mobile device received satisfy the following formula with the information in the multi-factor authentication information packet, it is determined that the comparison is consistent and the identity authentication of each input mobile device is successful: ; in, For the received first Remote authentication information data of seed factors It is a positive integer. , The total number of types of multi-factor remote authentication information; The upload order of the received multi-factor authentication information; For the first Input the mobile device's serial number data for seed factor authentication information; To receive the first received by the mobile device Multiple factor authentication information in the factor authentication information package It is a positive integer. , The total number of types of multi-factor remote authentication information received by the receiving mobile device; The input order for receiving multiple factor authentication information received by the mobile device; It is a constant; For the first Input the mobile device's serial number data for seed factor authentication information; To take the absolute value; It is the natural logarithm function.
[0008] Based on the above embodiments, another embodiment of the present invention provides a remote multi-factor authentication device for a boundary security device, including: a multi-factor authentication information packet generation module, a factor authentication information uploading module, and an input mobile device authentication module; The multi-factor authentication information package generation module is used to split the multi-factor remote authentication information used for identity authentication into several types of factor authentication information, associate each type of factor authentication information with a unique input mobile device, and package each type of factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information into a corresponding multi-factor authentication information package. The factor authentication information uploading module is used to send the multi-factor authentication information package to the corresponding receiving mobile device, so that the user can upload the corresponding associated factor authentication information in each input mobile device according to the input order of each factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. The input mobile device authentication module is used to compare the device number, uploaded factor authentication information, and upload order of each input mobile device with the information in the multi-factor authentication information package after receiving factor authentication information uploaded by each input mobile device. If the comparison is consistent, the authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0009] As a preferred embodiment, the input mobile device is connected to the network only when uploading factor authentication information, while the receiving mobile device is always connected to the network. When the authentication of the input mobile device fails, disconnect the network connection of each input mobile device.
[0010] As a preferred option, it also includes: If no factor authentication information is received from the input mobile device within the preset time period, the network connection status of each input mobile device will be checked. If an abnormal network connection is detected, the network connection of the input mobile device with the abnormal network connection will be enabled until the network connection status of each input mobile device is found to be normal.
[0011] As a preferred embodiment, when the device number, uploaded factor authentication information, and upload order of each input mobile device received satisfy the following formula with the information in the multi-factor authentication information packet, it is determined that the comparison is consistent and the identity authentication of each input mobile device is successful: ; in, For the received first Remote authentication information data of seed factors It is a positive integer. , The total number of types of multi-factor remote authentication information; The upload order of the received multi-factor authentication information; For the first Input the mobile device's serial number data for seed factor authentication information; To receive the first received by the mobile device Multiple factor authentication information in the factor authentication information package It is a positive integer. , The total number of types of multi-factor remote authentication information received by the receiving mobile device; The input order for receiving multiple factor authentication information received by the mobile device; It is a constant; For the first Input the mobile device's serial number data for seed factor authentication information; To take the absolute value; It is the natural logarithm function.
[0012] Based on the above embodiments, another embodiment of the present invention provides an electronic device, the device including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the remote multi-factor authentication method of the boundary security device described in the above embodiments of the invention.
[0013] Based on the above embodiments, another embodiment of the present invention provides a storage medium, the storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the storage medium is located to execute the remote multi-factor authentication method of the boundary security device described in the above embodiments of the invention.
[0014] Compared with the prior art, the embodiments of the present invention have the following beneficial effects: This invention provides a remote multi-factor authentication method for a boundary security device. The method includes: splitting multi-factor remote authentication information for identity authentication into several types of factor authentication information; associating each type of factor authentication information with a unique input mobile device; and packaging each type of factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information into a corresponding multi-factor authentication information package; sending the multi-factor authentication information package to the corresponding receiving mobile device, so that the user uploads the corresponding associated factor authentication information to each input mobile device according to the input order of each type of factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device; upon receiving the factor authentication information uploaded by each input mobile device, comparing the received device number of each input mobile device, the uploaded factor authentication information, and the upload order with the information in the multi-factor authentication information package; if the comparison matches, the identity authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0015] Therefore, this invention associates each type of authentication information with a unique input mobile device. By using multiple independent input mobile devices to input the associated multiple authentication information in the order of each type of authentication information, network attackers must break through the defenses of multiple input mobile devices in a very short time to impersonate a user. This greatly increases the difficulty of network attackers' attacks, thereby reducing the risk of user identity theft, realizing real-time remote authentication of user identity, improving the accuracy of remote authentication of user identity, and effectively reducing the risk of unauthorized access to user accounts. Attached Figure Description
[0016] Figure 1 This is a flowchart illustrating a remote multi-factor authentication method for a boundary security device according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a remote multi-factor authentication device for a boundary security device provided in an embodiment of the present invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.
[0019] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.
[0020] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0021] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0022] In the description of the embodiments of this application, the terms "multiple" and "several" refer to two or more (including two), similarly, "multiple groups" refer to two or more (including two groups), and "multiple pieces" refer to two or more (including two pieces).
[0023] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.
[0024] Example 1 Please refer to Figure 1 To address the significant risks of user identity misuse and unauthorized access to user accounts in existing technologies, an embodiment of the present invention provides a flowchart of a remote multi-factor authentication method for a boundary security device, comprising the following specific steps: S1. The multi-factor remote authentication information used for identity authentication is split into several types of factor authentication information, each type of factor authentication information is associated with a unique input mobile device, and the factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information are packaged into a corresponding multi-factor authentication information package. In a preferred embodiment, for step S1 above, the mobile device remotely connected to the network and the boundary security device is first divided into a receiving mobile device and an input mobile device, and the connection between the input mobile device and the network is disconnected, while the receiving mobile device maintains its connection with the network.
[0025] All mobile devices that are remotely connected to network and border security devices are divided into two roles: Receiving mobile device: It is only responsible for receiving authentication task instructions, maintaining a connection with the network throughout the process, and does not participate in the input of authentication information; Input mobile device: Specifically used for inputting authentication factor information. It immediately disconnects from the network in the initial state and only connects to the network as needed for a short period of time when inputting information, reducing the risk of being attacked by the network.
[0026] Then, a unique number is set for each input mobile device, the real-time multi-factor remote authentication information of the user identity is split into multiple factor authentication information, a unique input mobile device is assigned to each factor authentication information, and the multiple factor authentication information, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multiple factor authentication information are packaged into a multi-factor authentication information package.
[0027] Specifically, the real-time multi-factor remote authentication information used for user identity authentication (such as password, dynamic verification code, biometric verification value, hardware binding code, etc.) needs to be split into two or more independent factor authentication information (such as factor 1: dynamic verification code, factor 2: biometric verification value, factor 3: hardware binding code).
[0028] The multi-factor authentication information package includes the following information: (1) All factor authentication information after splitting; (2) The unique identifier of the input mobile device corresponding to each factor; (3) Input order of factor authentication information (e.g., input factor 1 first → input factor 2 then input factor 3 last).
[0029] S2. Send the multi-factor authentication information package to the corresponding receiving mobile device so that the user can upload the corresponding associated factor authentication information in each input mobile device according to the input order of each factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. In a preferred embodiment, for step S2 above, the multi-factor authentication information, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information are packaged into a multi-factor authentication information packet, and the multi-factor authentication information packet is sent to the receiving mobile device through the boundary security device.
[0030] When the receiving mobile device receives the multi-factor authentication information packet, it disassembles the multi-factor authentication information packet. After disassembly, the following key information is clearly displayed in a visual interface (such as an APP pop-up, SMS notification, or dedicated authentication interface) for the user to view: (1) The specific type of authentication information for each factor (e.g., Factor 1: 6-digit dynamic verification code; Factor 2: fingerprint biometric verification; Factor 3: hardware binding code). (12) The unique mobile device number corresponding to each factor (e.g., factor 2 needs to be entered on mobile input device number D1; factor 2 needs to be entered on mobile input device number D2). (3) Input order of factor authentication information.
[0031] Then, based on the visual information on the receiving mobile device, the user views the displayed content on the receiving mobile device, obtains the input requirements, and manually performs the operation on the corresponding input mobile device, inputting each factor authentication information into the input mobile device in the input order of the multiple factor authentication information.
[0032] For example, if the factor is a dynamic verification code, the user will view the verification code on the receiving mobile device and then manually enter it into the input mobile device corresponding to the number; if the factor is a biometric feature, the user will directly register their fingerprint / face on the designated input mobile device according to the prompts (no data transmission from the receiving mobile device is required, only the user needs to explicitly enter the device); if the factor is a hardware binding code, the user will view the binding code format / requirements displayed on the receiving mobile device and then enter the preset binding code on the designated input mobile device.
[0033] Finally, the multi-factor remote authentication information, formed by the user inputting authentication information through each of the input mobile devices according to the input order of each factor authentication information, is remotely sent to the border security device.
[0034] It should be noted that the input mobile device only serves as an input carrier, passively receiving manual input from the user. It does not establish any data connection with the receiving mobile device, nor does it directly receive factor authentication information data from the receiving mobile device. After input is completed, the input mobile device temporarily restores its connection to the network, integrates its own ID, the input factor information, and the input sequence marker to form complete multi-factor remote authentication information, and remotely sends it to the boundary security device. The network connection is immediately disconnected after the upload is completed (the disconnection will be confirmed again after subsequent authentication).
[0035] S3. After receiving the factor authentication information uploaded by each input mobile device, compare the device number, uploaded factor authentication information and upload order of each input mobile device with the information in the multi-factor authentication information package. If the comparison is consistent, the identity authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0036] In a preferred embodiment, regarding step S3 above, after receiving the authentication information uploaded by each input mobile device, the boundary security device verifies whether the received multi-factor remote authentication information, the order of each factor authentication information in the multi-factor remote authentication information, and the number of the input mobile device that inputs each factor authentication information are consistent with the multi-factor authentication information received by the receiving mobile device in the multi-factor authentication information packet, the input order of the multi-factor authentication information, and the unique number of the input mobile device that inputs each factor authentication information. If so, the user's identity for this real-time multi-factor remote authentication information is authenticated as successful; otherwise, the user's identity for this real-time multi-factor remote authentication information is authenticated as unsuccessful.
[0037] Specifically, after receiving the uploaded authentication information, the boundary security device verifies its consistency with the previously distributed multi-factor authentication information package in three dimensions: information content, input order, and device number, to ensure that the authentication has not been tampered with or impersonated. Verification dimensions: (1) Whether the content of each factor authentication information uploaded is completely consistent with the factor information in the authentication information package (such as whether the dynamic verification code and biometric verification value match). (2) Whether the input order of the uploaded factor information is completely consistent with the input order specified in the authentication information package (e.g., whether it is uploaded in the order of factor 1 → factor 2 → factor 3). (3) Whether the input mobile device number corresponding to the uploaded information is completely consistent with the device number bound in the authentication information package (e.g., whether factor 1 is indeed uploaded by device number D1).
[0038] In this embodiment of the remote multi-factor authentication method for the boundary security device, multiple input mobile devices only connect to the network for a short period of time when inputting factor authentication information. Furthermore, multiple independent mobile devices input multiple factor authentication information in real time. Therefore, network attackers must break through the defenses of multiple mobile devices in a very short time, which greatly increases the difficulty of network attackers and reduces the risk of user identity being impersonated. Furthermore, the real-time multi-factor remote authentication information used to verify a user's identity can be set to be completely different each time a user accesses an account. This not only achieves real-time remote authentication of the user's identity but also improves the accuracy of remote authentication, thereby effectively reducing the risk of unauthorized access to the user's account.
[0039] In a preferred embodiment, the input mobile device is connected to the network only when uploading factor authentication information, while the receiving mobile device is always connected to the network; when the authentication of the input mobile device fails, the network connection of each input mobile device is disconnected.
[0040] Specifically, in order to promptly disconnect the mobile device from the network after it has completed the input of multi-factor authentication information, thereby reducing the opportunity for network attackers to compromise the mobile device and further lowering the risk of user identity theft when users input multi-factor authentication information via mobile devices, the following steps may also be included: When the multi-factor authentication information received by the boundary security device, the number corresponding to the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information are completely consistent with the multi-factor authentication information in the multi-factor authentication information packet, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information, the connection between the input mobile device that inputs each factor authentication information and the network is disconnected.
[0041] To further reduce the risk of user identity theft and ensure the security of user accounts with high security requirements, the following steps may also be included: When the user's account security level exceeds a preset value, the number of different types of multi-factor authentication information in the multi-factor remote authentication information used to authenticate the user's identity is increased.
[0042] In a preferred embodiment, the method further includes: if no factor authentication information uploaded by the input mobile device is received within a preset time period, the network connection status of each input mobile device is detected; when an abnormal network connection of an input mobile device is detected, the network connection of the input mobile device with the abnormal network connection is enabled, until the network connection status of each input mobile device is detected to be normal.
[0043] Specifically, to ensure that all mobile devices inputting multi-factor authentication information have a normal connection to the network, the following steps may also be included: When the boundary security device does not receive the multi-factor authentication information remotely sent by the input mobile device within a certain period of time, it checks whether the connection between each input mobile device that inputs each type of authentication information and the network is normal. When it is detected that the connection between the input mobile device that inputs the multi-factor authentication information and the network is abnormal, it re-establishes the connection between the input mobile device with the abnormal connection and the network, and repeats this step until it is detected that the connection between each input mobile device that inputs each type of authentication information and the network is normal.
[0044] To accurately detect whether each input mobile device that inputs each type of authentication information has a normal connection to the network within a certain time frame, a remote multi-factor authentication method for a mobile device-based boundary security device includes the following expression: When the boundary security device does not receive the multi-factor authentication information remotely sent by the input mobile device within a certain time frame, it checks whether the connection between each input mobile device that inputs each type of authentication information and the network is normal. When it detects that any input mobile device that inputs the multi-factor authentication information has an abnormal connection to the network, it re-establishes the connection between the abnormal input mobile device and the network, and repeats this step until it is detected that the connection between each input mobile device that inputs each type of authentication information and the network is normal. ; In the formula, This indicates a set time period; This indicates the number of types of multi-factor authentication information remotely sent by the input mobile device; This indicates the amount of multi-factor authentication information data remotely sent by the input mobile device; This indicates the speed at which the input mobile device sends data; This represents the sine function.
[0045] In a preferred embodiment, when the device number of each input mobile device, the uploaded factor authentication information, and the upload order of the received information satisfy the following formula with the information in the multi-factor authentication information packet, it is determined that the comparison is consistent and the identity authentication of each input mobile device is successful: ; in, For the received first Remote authentication information data of seed factors It is a positive integer. , The total number of types of multi-factor remote authentication information; The upload order of the received multi-factor authentication information; For the first Input the mobile device's serial number data for seed factor authentication information; To receive the first received by the mobile device Multiple factor authentication information in the factor authentication information package It is a positive integer. , The total number of types of multi-factor remote authentication information received by the receiving mobile device; The input order for receiving multiple factor authentication information received by the mobile device; It is a constant; For the first Input the mobile device's serial number data for seed factor authentication information; To take the absolute value; It is the natural logarithm function.
[0046] Therefore, this embodiment provides a remote multi-factor authentication method for a boundary security device. The method includes: splitting the multi-factor remote authentication information used for authentication into several types of factor authentication information; associating each type of factor authentication information with a unique input mobile device; and packaging each type of factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information into a corresponding multi-factor authentication information package; sending the multi-factor authentication information package to the corresponding receiving mobile device, so that the user uploads the corresponding associated factor authentication information to each input mobile device according to the input order of each type of factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device; after receiving the factor authentication information uploaded by each input mobile device, comparing the received device number of each input mobile device, the uploaded factor authentication information, and the upload order with the information in the multi-factor authentication information package; if the comparison is consistent, the authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0047] This embodiment associates each type of authentication information with a unique input mobile device. By using multiple independent input mobile devices to input the associated multiple authentication information in the order of each type of authentication information, network attackers must break through the defenses of multiple input mobile devices in a very short time to impersonate the user. This greatly increases the difficulty of the attack for network attackers, thereby reducing the risk of user identity being impersonated, realizing real-time remote authentication of user identity, improving the accuracy of remote authentication of user identity, and effectively reducing the risk of unauthorized access to user accounts.
[0048] Example 2 Please refer to Figure 2 This is a schematic diagram of the structure of a remote multi-factor authentication device for a boundary security device according to an embodiment of the present invention. The device includes: a multi-factor authentication information packet generation module, a factor authentication information uploading module, and an input mobile device authentication module. The multi-factor authentication information package generation module is used to split the multi-factor remote authentication information used for identity authentication into several types of factor authentication information, associate each type of factor authentication information with a unique input mobile device, and package each type of factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information into a corresponding multi-factor authentication information package. The factor authentication information uploading module is used to send the multi-factor authentication information package to the corresponding receiving mobile device, so that the user can upload the corresponding associated factor authentication information in each input mobile device according to the input order of each factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. The input mobile device authentication module is used to compare the device number, uploaded factor authentication information, and upload order of each input mobile device with the information in the multi-factor authentication information package after receiving factor authentication information uploaded by each input mobile device. If the comparison is consistent, the authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0049] In a preferred embodiment, the multi-factor authentication packet generation module is used to first divide the mobile device remotely connected to the network and the border security device into a receiving mobile device and an input mobile device, and disconnect the input mobile device from the network, while the receiving mobile device maintains its connection with the network.
[0050] All mobile devices that are remotely connected to network and border security devices are divided into two roles: Receiving mobile device: It is only responsible for receiving authentication task instructions, maintaining a connection with the network throughout the process, and does not participate in the input of authentication information; Input mobile device: Specifically used for inputting authentication factor information. It immediately disconnects from the network in the initial state and only connects to the network as needed for a short period of time when inputting information, reducing the risk of being attacked by the network.
[0051] Then, a unique number is set for each input mobile device, the real-time multi-factor remote authentication information of the user identity is split into multiple factor authentication information, a unique input mobile device is assigned to each factor authentication information, and the multiple factor authentication information, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multiple factor authentication information are packaged into a multi-factor authentication information package.
[0052] Specifically, the real-time multi-factor remote authentication information used for user identity authentication (such as password, dynamic verification code, biometric verification value, hardware binding code, etc.) needs to be split into two or more independent factor authentication information (such as factor 1: dynamic verification code, factor 2: biometric verification value, factor 3: hardware binding code).
[0053] The multi-factor authentication information package includes the following information: (1) All factor authentication information after splitting; (2) The unique identifier of the input mobile device corresponding to each factor; (3) Input order of factor authentication information (e.g., input factor 1 first → input factor 2 then input factor 3 last).
[0054] In a preferred embodiment, the factor authentication information uploading module is used to package the multiple factor authentication information, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multiple factor authentication information into a multi-factor authentication information package, and send the multi-factor authentication information package to the receiving mobile device through the boundary security device.
[0055] When the receiving mobile device receives the multi-factor authentication information packet, it disassembles the multi-factor authentication information packet. After disassembly, the following key information is clearly displayed in a visual interface (such as an APP pop-up, SMS notification, or dedicated authentication interface) for the user to view: (1) The specific type of authentication information for each factor (e.g., Factor 1: 6-digit dynamic verification code; Factor 2: fingerprint biometric verification; Factor 3: hardware binding code). (12) The unique mobile device number corresponding to each factor (e.g., factor 2 needs to be entered on mobile input device number D1; factor 2 needs to be entered on mobile input device number D2). (3) Input order of factor authentication information.
[0056] Then, based on the visual information on the receiving mobile device, the user views the displayed content on the receiving mobile device, obtains the input requirements, and manually performs the operation on the corresponding input mobile device, inputting each factor authentication information into the input mobile device in the input order of the multiple factor authentication information.
[0057] For example, if the factor is a dynamic verification code, the user will view the verification code on the receiving mobile device and then manually enter it into the input mobile device corresponding to the number; if the factor is a biometric feature, the user will directly register their fingerprint / face on the designated input mobile device according to the prompts (no data transmission from the receiving mobile device is required, only the user needs to explicitly enter the device); if the factor is a hardware binding code, the user will view the binding code format / requirements displayed on the receiving mobile device and then enter the preset binding code on the designated input mobile device.
[0058] Finally, the multi-factor remote authentication information, formed by the user inputting authentication information through each of the input mobile devices according to the input order of each factor authentication information, is remotely sent to the border security device.
[0059] It should be noted that the input mobile device only serves as an input carrier, passively receiving manual input from the user. It does not establish any data connection with the receiving mobile device, nor does it directly receive factor authentication information data from the receiving mobile device. After input is completed, the input mobile device temporarily restores its connection to the network, integrates its own ID, the input factor information, and the input sequence marker to form complete multi-factor remote authentication information, and remotely sends it to the boundary security device. The network connection is immediately disconnected after the upload is completed (the disconnection will be confirmed again after subsequent authentication).
[0060] In a preferred embodiment, the input mobile device authentication module is configured to, after receiving authentication information uploaded by each input mobile device, verify whether the received multi-factor remote authentication information, the order of each factor authentication information in the multi-factor remote authentication information, and the number of the input mobile device inputting each factor authentication information are consistent with the multi-factor authentication information received by the receiving mobile device in the multi-factor authentication information packet, the input order of the multi-factor authentication information, and the unique number of the input mobile device inputting each factor authentication information. If so, the user's current real-time multi-factor remote authentication information is authenticated as successful; otherwise, the user's current real-time multi-factor remote authentication information is authenticated as unsuccessful.
[0061] Specifically, after receiving the uploaded authentication information, the boundary security device verifies its consistency with the previously distributed multi-factor authentication information package in three dimensions: information content, input order, and device number, to ensure that the authentication has not been tampered with or impersonated. Verification dimensions: (1) Whether the content of each factor authentication information uploaded is completely consistent with the factor information in the authentication information package (such as whether the dynamic verification code and biometric verification value match). (2) Whether the input order of the uploaded factor information is completely consistent with the input order specified in the authentication information package (e.g., whether it is uploaded in the order of factor 1 → factor 2 → factor 3). (3) Whether the input mobile device number corresponding to the uploaded information is completely consistent with the device number bound in the authentication information package (e.g., whether factor 1 is indeed uploaded by device number D1).
[0062] In this embodiment of the remote multi-factor authentication method for the boundary security device, multiple input mobile devices only connect to the network for a short period of time when inputting factor authentication information. Furthermore, multiple independent mobile devices input multiple factor authentication information in real time. Therefore, network attackers must break through the defenses of multiple mobile devices in a very short time, which greatly increases the difficulty of network attackers and reduces the risk of user identity being impersonated. Furthermore, the real-time multi-factor remote authentication information used to verify a user's identity can be set to be completely different each time a user accesses an account. This not only achieves real-time remote authentication of the user's identity but also improves the accuracy of remote authentication, thereby effectively reducing the risk of unauthorized access to the user's account.
[0063] In another preferred embodiment, the remote multi-factor authentication device of the boundary security device may further include: The network connection disconnection module is used to disconnect the connection between the input mobile device that inputs each factor authentication information and the network when the multi-factor authentication information received by the boundary security device, the number corresponding to the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information are completely consistent with the multi-factor authentication information in the multi-factor authentication information packet, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information.
[0064] Preferably, the input mobile device is connected to the network only when uploading factor authentication information, while the receiving mobile device is always connected to the network. When the authentication of the input mobile device fails, disconnect the network connection of each input mobile device.
[0065] Specifically, in order to promptly disconnect the mobile device from the network after it has completed the input of multi-factor authentication information, thereby reducing the opportunity for network attackers to compromise the mobile device and further lowering the risk of user identity theft when users input multi-factor authentication information via mobile devices, the following steps may also be included: When the multi-factor authentication information received by the boundary security device, the number corresponding to the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information are completely consistent with the multi-factor authentication information in the multi-factor authentication information packet, the unique number of the input mobile device that inputs each factor authentication information, and the input order of the multi-factor authentication information, the connection between the input mobile device that inputs each factor authentication information and the network is disconnected.
[0066] In another preferred embodiment, the remote multi-factor authentication device of the boundary security device may further include: The category quantity increase module is used to increase the number of categories of multi-factor authentication information in the multi-factor remote authentication information for authenticating user identity when the user's account security level value exceeds a preset value.
[0067] To further reduce the risk of user identity theft and ensure the security of user accounts with high security requirements, the following steps may also be included: When the user's account security level exceeds a preset value, the number of different types of multi-factor authentication information in the multi-factor remote authentication information used to authenticate the user's identity is increased.
[0068] In another preferred embodiment, the remote multi-factor authentication device of the boundary security device may further include: The input mobile device network connection detection module is used to detect whether the connection between each input mobile device that receives each type of input factor authentication information and the network is normal when the boundary security device does not receive the multiple factor authentication information remotely sent by the input mobile device within a certain period of time.
[0069] When it is detected that one of the input mobile devices that input the various factor authentication information has an abnormal connection with the network, the connection between the input mobile device with the abnormal connection and the network is re-established, and this step is repeated until it is detected that the connection between each input mobile device that inputs each factor authentication information and the network is normal.
[0070] Preferred options also include: If no factor authentication information is received from the input mobile device within the preset time period, the network connection status of each input mobile device will be checked. If an abnormal network connection is detected, the network connection of the input mobile device with the abnormal network connection will be enabled until the network connection status of each input mobile device is found to be normal.
[0071] Preferably, when the device number, uploaded factor authentication information, and upload order of each input mobile device received satisfy the following formula with the information in the multi-factor authentication information package, it is determined that the comparison is consistent and the identity authentication of each input mobile device is successful: ; in, For the received first Remote authentication information data of seed factors It is a positive integer. , The total number of types of multi-factor remote authentication information; The upload order of the received multi-factor authentication information; For the first Input the mobile device's serial number data for seed factor authentication information; To receive the first received by the mobile device Multiple factor authentication information in the factor authentication information package It is a positive integer. , The total number of types of multi-factor remote authentication information received by the receiving mobile device; The input order for receiving multiple factor authentication information received by the mobile device; It is a constant; For the first Input the mobile device's serial number data for seed factor authentication information; To take the absolute value; It is the natural logarithm function.
[0072] Specifically, to ensure that all mobile devices inputting multi-factor authentication information have a normal connection to the network, the following steps may also be included: When the boundary security device does not receive the multi-factor authentication information remotely sent by the input mobile device within a certain period of time, it checks whether the connection between each input mobile device that inputs each type of authentication information and the network is normal. When it is detected that the connection between the input mobile device that inputs the multi-factor authentication information and the network is abnormal, it re-establishes the connection between the input mobile device with the abnormal connection and the network, and repeats this step until it is detected that the connection between each input mobile device that inputs each type of authentication information and the network is normal.
[0073] In order to set an appropriate time period to accurately detect whether each input mobile device that inputs each type of authentication information has a normal connection with the network, the aforementioned remote multi-factor authentication method for a mobile device-based boundary security device detects whether the connection between each input mobile device that inputs each type of authentication information and the network is normal when the boundary security device does not receive the multi-factor authentication information remotely sent by the input mobile device within a certain time period.
[0074] When it is detected that one of the input mobile devices that input the various factor authentication information has an abnormal connection with the network, the connection between the input mobile device with the abnormal connection and the network is re-established, and this step is repeated until it is detected that the connection between each input mobile device that inputs each factor authentication information and the network is normal. In this step, the method for setting a certain period of time includes the following expression: ; In the formula, This indicates a set time period; This indicates the number of types of multi-factor authentication information remotely sent by the input mobile device; This indicates the amount of multi-factor authentication information data remotely sent by the input mobile device; This indicates the speed at which the input mobile device sends data; This represents the sine function.
[0075] Therefore, this embodiment provides a remote multi-factor authentication device for a boundary security device. The device includes: a multi-factor authentication information package generation module, a factor authentication information uploading module, and an input mobile device authentication module. The multi-factor authentication information package generation module is used to split the multi-factor remote authentication information used for identity authentication into several types of factor authentication information, associate each type of factor authentication information with a unique input mobile device, and package each type of factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information into a corresponding multi-factor authentication information package. The factor authentication information uploading module is used to send the multi-factor authentication information package to the corresponding receiving mobile device, so that the user can upload the corresponding associated factor authentication information to each input mobile device according to the input order of each type of factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. The input mobile device authentication module is used to compare the received device number of each input mobile device, the uploaded factor authentication information, and the upload order with the information in the multi-factor authentication information package after receiving the factor authentication information uploaded by each input mobile device. If the comparison is consistent, the identity authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
[0076] This embodiment associates each type of authentication information with a unique input mobile device. By using multiple independent input mobile devices to input the associated multiple authentication information in the order of each type of authentication information, network attackers must break through the defenses of multiple input mobile devices in a very short time to impersonate the user. This greatly increases the difficulty of the attack for network attackers, thereby reducing the risk of user identity being impersonated, realizing real-time remote authentication of user identity, improving the accuracy of remote authentication of user identity, and effectively reducing the risk of unauthorized access to user accounts.
[0077] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0078] Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any inventive effort.
[0079] Those skilled in the art will clearly understand that, for convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0080] Example 3 Accordingly, embodiments of the present invention provide an electronic device, the device including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the remote multi-factor authentication method of the boundary security device described in the above embodiments of the invention.
[0081] The electronic device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The device may include, but is not limited to, a processor and a memory.
[0082] The processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0083] The general-purpose processor can be a microprocessor or any conventional processor, etc. The processor is the control center of the device and connects various parts of the device through various interfaces and lines.
[0084] Example 4 Accordingly, embodiments of the present invention provide a storage medium, the storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the storage medium is located to execute the remote multi-factor authentication method of the boundary security device described in the above embodiments of the invention.
[0085] The memory can be used to store the computer program, and the processor implements various functions of the device by running or executing the computer program stored in the memory and calling data stored in the memory.
[0086] The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function, etc.; the data storage area may store data created based on the use of the mobile phone, etc.
[0087] In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0088] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-described method embodiments.
[0089] The computer program includes computer program code, which may be in the form of source code, object code, executable file, or some intermediate form.
[0090] The computer-readable medium may include any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0091] It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the content as required by the legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium may not include electrical carrier signals and telecommunication signals.
[0092] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A remote multi-factor authentication method for a boundary security device, characterized in that, include: The multi-factor remote authentication information used for identity authentication is split into several types of factor authentication information. Each type of factor authentication information is associated with a unique input mobile device. The factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information are packaged into a corresponding multi-factor authentication information package. The multi-factor authentication information package is sent to the corresponding receiving mobile device so that the user can upload the corresponding associated factor authentication information in each input mobile device according to the input order of each factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. Upon receiving the factor authentication information uploaded by each input mobile device, the device number, uploaded factor authentication information, and upload order of each input mobile device are compared with the information in the multi-factor authentication information package. If the comparison matches, the identity authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
2. The remote multi-factor authentication method for the boundary security device as described in claim 1, characterized in that, The input mobile device is connected to the network only when uploading factor authentication information, while the receiving mobile device is always connected to the network. When the authentication of the input mobile device fails, disconnect the network connection of each input mobile device.
3. The remote multi-factor authentication method for the boundary security device as described in claim 1, characterized in that, Also includes: If no factor authentication information is received from the input mobile device within the preset time period, the network connection status of each input mobile device will be checked. If an abnormal network connection is detected, the network connection of the input mobile device with the abnormal network connection will be enabled until the network connection status of each input mobile device is found to be normal.
4. The remote multi-factor authentication method for the boundary security device as described in claim 1, characterized in that, When the device number, uploaded factor authentication information, and upload order of each input mobile device received satisfy the following formula with the information in the multi-factor authentication information packet, it is determined that the comparison is consistent and the identity authentication of each input mobile device is successful: ; in, For the received first Remote authentication information data of seed factors It is a positive integer. , The total number of types of multi-factor remote authentication information; The order in which the received multi-factor authentication information is uploaded; For the first Input the mobile device's serial number data for seed factor authentication information; To receive the first received by the mobile device Multiple factor authentication information in the factor authentication information package It is a positive integer. , The total number of types of multi-factor remote authentication information received by the receiving mobile device; The input order for receiving multiple factor authentication information received by the mobile device; It is a constant; For the first The input of the seed factor authentication information is the serial number data of the mobile device; To take the absolute value; It is the natural logarithm function.
5. A remote multi-factor authentication device for a boundary security system, characterized in that, include: The module includes a multi-factor authentication information package generation module, a factor authentication information uploading module, and an input mobile device identity authentication module. The multi-factor authentication information package generation module is used to split the multi-factor remote authentication information used for identity authentication into several types of factor authentication information, associate each type of factor authentication information with a unique input mobile device, and package each type of factor authentication information, the device number of the input mobile device associated with each type of factor authentication information, and the input order of each type of factor authentication information into a corresponding multi-factor authentication information package. The factor authentication information uploading module is used to send the multi-factor authentication information package to the corresponding receiving mobile device, so that the user can upload the corresponding associated factor authentication information in each input mobile device according to the input order of each factor authentication information based on the information in the multi-factor authentication information package in the receiving mobile device. The input mobile device authentication module is used to compare the device number, uploaded factor authentication information, and upload order of each input mobile device with the information in the multi-factor authentication information package after receiving factor authentication information uploaded by each input mobile device. If the comparison is consistent, the authentication of each input mobile device is determined to be successful; otherwise, it is determined to be unsuccessful.
6. The remote multi-factor authentication method for a boundary security device as described in claim 1, characterized in that, The input mobile device is connected to the network only when uploading factor authentication information, while the receiving mobile device is always connected to the network. When the authentication of the input mobile device fails, disconnect the network connection of each input mobile device.
7. The remote multi-factor authentication method for a boundary security device as described in claim 1, characterized in that, Also includes: If no factor authentication information is received from the input mobile device within the preset time period, the network connection status of each input mobile device will be checked. If an abnormal network connection is detected, the network connection of the input mobile device with the abnormal network connection will be enabled until the network connection status of each input mobile device is found to be normal.
8. The remote multi-factor authentication method for the boundary security device as described in claim 1, characterized in that, When the device number, uploaded factor authentication information, and upload order of each input mobile device received satisfy the following formula with the information in the multi-factor authentication information packet, it is determined that the comparison is consistent and the identity authentication of each input mobile device is successful: ; in, For the received first Remote authentication information data of seed factors It is a positive integer. , The total number of types of multi-factor remote authentication information; The order in which the received multi-factor authentication information is uploaded; For the first The input of the seed factor authentication information is the serial number data of the mobile device; To receive the first received by the mobile device Multiple factor authentication information in the factor authentication information package It is a positive integer. , The total number of types of multi-factor remote authentication information received by the receiving mobile device; The input order for receiving multiple factor authentication information received by the mobile device; It is a constant; For the first The input of the seed factor authentication information is the serial number data of the mobile device; To take the absolute value; It is the natural logarithm function.
9. An electronic device, characterized in that, The device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements a remote multi-factor authentication method for a boundary security device as described in any one of claims 1 to 4.
10. A storage medium, characterized in that, The storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to perform a remote multi-factor authentication method for a boundary security device as described in any one of claims 1 to 4.