Authentication method, apparatus and device, and storage medium

By converting the initial authentication parameters into a parameter type recognizable by the pass key authenticator on the user terminal, and directly using the target authenticator for authentication, the inefficiency caused by external browser calls is solved, and a more efficient authentication process is achieved.

WO2026092066A1PCT designated stage Publication Date: 2026-05-07BEIJING XINWANG RUIJIE NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING XINWANG RUIJIE NETWORK TECH CO LTD
Filing Date
2025-10-09
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

In existing technologies, calling the access key authenticator through an external browser is inefficient, resulting in an inefficient authentication process.

Method used

The initial authentication parameters are converted from the parameter type of the web page view to the parameter type of the pass key authenticator on the user terminal, and the authentication process is performed directly through the target authenticator, avoiding calls from external browsers.

Benefits of technology

It improves the efficiency of certification and reduces the time and resource consumption of the certification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025126601_07052026_PF_FP_ABST
    Figure CN2025126601_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application are an authentication method, apparatus and device, and a storage medium. The method comprises: receiving an initial authentication parameter corresponding to an authentication request, wherein the authentication request is used for requesting login to a target account of an application program; converting the initial authentication parameter of a first parameter type into a target authentication parameter of a second parameter type, wherein the first parameter type is a parameter type corresponding to a webpage view, and the second parameter type is a parameter type of a target authenticator corresponding to a passkey; by means of the target authenticator, performing authentication processing on the target authentication parameter to obtain an authentication response parameter of the target account; and on the basis of the authentication response parameter, acquiring an authentication result of the target account.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication methods, devices, equipment and storage media

[0001] Cross-references to related applications

[0002] This application claims priority to Chinese Patent Application No. 202411545398.7, filed on October 31, 2024, entitled "Authentication Method, Apparatus, Device and Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of communication technology, and in particular to an authentication method, apparatus, device and storage medium. Background Technology

[0004] Passkeys protocols utilize public-key cryptography to enable users to authenticate themselves through their devices without needing to remember complex passwords. Passkeys offer a more secure and user-friendly authentication experience.

[0005] In related technologies, applications (abbreviated as APP) can implement access key authentication in an external browser by redirecting the user to the external browser. Summary of the Invention

[0006] This application provides an authentication method, apparatus, device, and storage medium to improve authentication efficiency.

[0007] In a first aspect, embodiments of this application provide an authentication method applied to a user terminal, comprising:

[0008] Receive the initial authentication parameters corresponding to the authentication request, which is used to request the target account for logging into the application;

[0009] The initial authentication parameters of the first parameter type are transformed into target authentication parameters of the second parameter type, where the first parameter type is the parameter type corresponding to the webpage view, and the second parameter type is the parameter type of the target authenticator corresponding to the pass key;

[0010] The target authentication parameters are processed by the target authenticator to obtain the authentication response parameters of the target account.

[0011] Based on the authentication response parameters, obtain the authentication result of the target account.

[0012] In one possible implementation, the target authentication parameters are authenticated using the target authenticator to obtain the authentication response parameters for the target account, including:

[0013] The login credentials for the target account are obtained through the target authenticator.

[0014] The target authenticator performs login authentication processing on the target authentication parameters and the login credentials to obtain the authentication response parameters of the target account.

[0015] In one possible implementation, obtaining the login credentials for the target account through the target authenticator includes:

[0016] The target authenticator determines at least one authentication method, which includes: fingerprint authentication, facial authentication, Universal Serial Bus (USB) authentication, and Bluetooth authentication.

[0017] Receive login credentials corresponding to at least one of the authentication methods.

[0018] In one possible implementation, before receiving the initial parameters corresponding to the authentication request, the method further includes:

[0019] Generate an authentication request for the target account;

[0020] The application corresponding to the authentication request is subjected to a first permission verification through a preset interface to obtain a first verification result.

[0021] If the first verification result is successful, then the authentication request is sent.

[0022] In one possible implementation, before authenticating the target parameters through the target authenticator to obtain the authentication parameters of the target account, the method further includes:

[0023] Perform a second permission verification on the domain name of the webpage view to obtain a second verification result;

[0024] If the second verification result is successful, then the target authenticator is invoked.

[0025] In one possible implementation, converting the initial authentication parameter of the first parameter type into a target authentication parameter of the second parameter type includes:

[0026] Obtain the target structure template corresponding to the second parameter type;

[0027] Based on the target structure template, the initial authentication parameters are subjected to structural transformation processing to obtain the target authentication parameters.

[0028] In one possible implementation, before generating the authentication request for the target account, the method further includes:

[0029] Receive the initial registration parameters corresponding to the registration request, wherein the registration request is used to request the registration of the target account;

[0030] The initial registration parameters of the first parameter type are converted into target registration parameters of the second parameter type;

[0031] The target registration parameters are authenticated using the target authenticator to obtain the registration response parameters for the target account.

[0032] Based on the registration response parameters, the registration result of the target account is obtained.

[0033] In one possible implementation, obtaining the authentication result of the target account based on the authentication response parameters includes:

[0034] Convert the authentication response parameter of the second parameter type into the first response parameter of the first parameter type;

[0035] Send the first response parameter to the server and receive the authentication result of the target account.

[0036] Secondly, an authentication device provided in this application includes a receiving module, a conversion processing module, an authentication processing module, and an acquisition module:

[0037] The receiving module is used to receive the initial authentication parameters corresponding to the authentication request, wherein the authentication request is used to request the target account of the login application.

[0038] The conversion processing module is used to convert the initial authentication parameters of the first parameter type into target authentication parameters of the second parameter type, wherein the first parameter type is the parameter type corresponding to the webpage view, and the second parameter type is the parameter type of the target authenticator corresponding to the pass key;

[0039] The authentication processing module performs authentication processing on the target authentication parameters through the target authenticator to obtain the authentication response parameters of the target account;

[0040] The acquisition module is used to obtain the authentication result of the target account based on the authentication response parameters.

[0041] In one possible implementation, the authentication processing module is specifically used for:

[0042] The login credentials for the target account are obtained through the target authenticator.

[0043] The target authenticator performs login authentication processing on the target authentication parameters and the login credentials to obtain the authentication response parameters of the target account.

[0044] In one possible implementation, the authentication processing module is specifically used for:

[0045] The target authenticator determines at least one authentication method, which includes: fingerprint authentication, facial authentication, Universal Serial Bus (USB) authentication, and Bluetooth authentication.

[0046] Receive login credentials corresponding to at least one of the authentication methods.

[0047] In one possible implementation, the device further includes:

[0048] Generate an authentication request for the target account;

[0049] The application corresponding to the authentication request is subjected to a first permission verification through a preset interface to obtain a first verification result.

[0050] If the first verification result is successful, then the authentication request is sent.

[0051] In one possible implementation, the device is further used for:

[0052] Perform a second permission verification on the domain name of the webpage view to obtain a second verification result;

[0053] If the second verification result is successful, then the target authenticator is invoked.

[0054] In one possible implementation, the device is further used for:

[0055] Obtain the target structure template corresponding to the second parameter type;

[0056] Based on the target structure template, the initial authentication parameters are subjected to structural transformation processing to obtain the target authentication parameters.

[0057] In one possible implementation, the device is further used for:

[0058] Receive the initial registration parameters corresponding to the registration request, wherein the registration request is used to request the registration of the target account;

[0059] Transform the initial registration parameters of the first parameter type into target registration parameters of the second parameter type;

[0060] The target registration parameters are authenticated using the target authenticator to obtain the registration response parameters for the target account.

[0061] Based on the registration response parameters, the registration result of the target account is obtained.

[0062] In one possible implementation, the acquisition module has the following functions:

[0063] Convert the authentication response parameter of the second parameter type into the first response parameter of the first parameter type;

[0064] Send the first response parameter to the server and receive the authentication result of the target account.

[0065] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0066] The memory stores computer-executed instructions;

[0067] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0068] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0069] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0070] The authentication method, apparatus, device, and storage medium provided in this application embodiment can convert the initial login parameters of the first parameter type corresponding to the authentication request into target authentication parameters of the second parameter type after receiving the authentication request from the target account. The second parameter type is the parameter type of the target authenticator corresponding to the pass key. The target authenticator can authenticate the target authentication parameters without needing to call the target authenticator through an external browser for authentication processing, which can improve authentication efficiency. Attached Figure Description

[0071] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0072] Figure 1 is a schematic diagram of the application scenario provided in the embodiments of this application;

[0073] Figure 2 is a flowchart illustrating an authentication method provided in an embodiment of this application;

[0074] Figure 3 is a flowchart illustrating a registration request method provided in an embodiment of this application;

[0075] Figure 4A is a schematic diagram of the structure of a device providing authentication services according to an embodiment of this application;

[0076] Figure 4B is a schematic diagram of another device for providing authentication services provided in an embodiment of this application;

[0077] Figure 5 is a schematic diagram of an authentication request interaction provided in an embodiment of this application;

[0078] Figure 6 is a schematic diagram of an interactive registration and authentication process provided in an embodiment of this application;

[0079] Figure 7 is a schematic diagram of an authentication architecture provided in an embodiment of this application;

[0080] Figure 8 is a schematic diagram of an authorization verification architecture provided in an embodiment of this application;

[0081] Figure 9 is a schematic diagram of an authentication device provided in an embodiment of this application;

[0082] Figure 10 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0083] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concepts of this application to those skilled in the art through reference to specific embodiments. Those skilled in the art will be able to obtain drawings of other embodiments based on these drawings without any inventive effort. Detailed Implementation

[0084] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0085] In this application, the use of ordinal terms such as "first", "second", etc. to modify elements does not indicate any priority, position, or order of one element relative to another element, or the temporal order of actions in a method of execution. Unless otherwise specifically stated, such ordinal numbers are used only as labels to distinguish one element with a particular name from another element with the same name (other than the ordinal number).

[0086] When using the terms "comprising," "having," and "including" as described in this application, another component may be added unless explicit qualifying terms such as "only," "consisting of," etc. are used. Unless otherwise stated, singular terms may include plural forms and should not be construed as having a quantity of only one.

[0087] Figure 1 is a schematic diagram of an application scenario provided by an embodiment of this application. Referring to Figure 1, it may include a user terminal 101 and a server 102. An application (APP) may be installed on the user terminal 101. The target user can log in to their user account through the application via the user terminal 101. The application may include a web view component. After the target user clicks the login button on the application's login interface, the web view interface is displayed on the user terminal 101. After the user enters their user identifier on the web view interface via the user terminal 101, the user terminal 101 can generate an authentication request.

[0088] Server 102 can receive authentication requests and generate initial authentication parameters based on the requests. Server 102 can then send these initial authentication parameters to user terminal 101. User terminal 101 can convert the initial authentication parameters (of type 1) into target authentication parameters (of type 2). User terminal 101 can then use the target authenticator to process the authentication request based on the target authentication parameters, obtaining the authentication response parameters for the target account. User terminal 101 can then obtain the authentication result for the target account based on the authentication response parameters.

[0089] In related technologies, applications can redirect to an external browser, which then calls the target authenticator corresponding to the access key to achieve access key authentication. However, using an external browser for access key authentication of the target account results in low authentication efficiency.

[0090] The authentication method provided in this application, after receiving the initial authentication parameters corresponding to the authentication request, can convert the initial authentication parameters of the first parameter type into target authentication parameters of the second parameter type. The second parameter type is the parameter type of the target authenticator corresponding to the pass key. The authentication request can be directly authenticated through the target authenticator without the need to call the target authenticator through an external browser for authentication processing, which can improve authentication efficiency.

[0091] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0092] Figure 2 is a flowchart illustrating an authentication method provided in an embodiment of this application. Referring to Figure 2, the method may include:

[0093] S201. Receive the initial authentication parameters corresponding to the authentication request.

[0094] The execution entity of this application embodiment can be a user terminal or an authentication device set in the user terminal. The authentication device can be implemented by software or by a combination of software and hardware.

[0095] The application can be installed on the target user's terminal, and web page view components can be installed within the application.

[0096] After entering the login interface of the login application, the user can click the login button on the login interface. At this time, the web view interface in the application can be opened through the web view component. The user can enter the user identifier on the web view interface. After entering the user identifier, the user can click login to generate an authentication request for the target account. The authentication request can be used to request the target account to log in to the user application.

[0097] An authentication request can be sent to the server, which may include the domain name of the webpage view and the user ID of the target user.

[0098] The server can generate initial authentication parameters based on the authentication request. The initial authentication parameters may include login challenge value, domain name of web page view, user ID and credential list, etc. The credential list may include at least one registration credential.

[0099] S202. Convert the initial authentication parameter of the first parameter type into the target authentication parameter of the second parameter type.

[0100] The first parameter type can be the parameter type of the Web Authentication (WebAuthn) protocol corresponding to the web view.

[0101] The second parameter type can be the parameter type of the target authenticator corresponding to the Passkeys protocol.

[0102] The target authenticator can be a Fast IDentity Online (FIDO) authenticator or an execution module used for authentication. It can execute Passkeys protocol authentication, which can be divided into two parts: Client to Authenticator Protocol (CTAP) and WebAuthn protocol.

[0103] The CTAP protocol can be used to standardize the communication protocol between the WebAuthn protocol and the target authenticator. The WebAuthn protocol can be used to implement authentication functions on the browser side.

[0104] While WebAuthn can be implemented through web views within an application, CTAP cannot. This means the first parameter type of the initial authentication parameters cannot be recognized by the target authenticator. However, the first parameter type can be converted to a second parameter type that the target authenticator can recognize, thus enabling the call to the target authenticator. In essence, by transforming the first parameter type of the initial authentication parameters into a second parameter type that the target authenticator can recognize, the CTAP protocol functionality is achieved.

[0105] Furthermore, the target structure template corresponding to the second parameter type can be obtained; based on the target structure template, the initial authentication parameters are structurally transformed to obtain the target authentication parameters.

[0106] In some possible embodiments, the software development kit (SDK) of the target authenticator can be obtained, and the type of the second parameter corresponding to the target authenticator can be determined based on the SDK of the target authenticator.

[0107] For example, assuming the SDK corresponding to the target authenticator is SDK1, and the parameter type corresponding to SDK1 is parameter type 1, then parameter type 1 can be determined as the second parameter type.

[0108] In some possible embodiments, the second parameter type corresponding to the target authenticator can be stored, and the second parameter type can be obtained directly after obtaining the initial authentication parameters.

[0109] It can store multiple structure templates corresponding to multiple parameter types, and can determine the target structure template from multiple structure templates based on the second parameter type.

[0110] The parameter type can be used to indicate the data format, data type, etc. of the corresponding parameters of the protocol executed by the target authenticator.

[0111] Structure templates can be used to indicate the data format and data type examples of their corresponding parameter types.

[0112] The target authentication parameters can be obtained by converting the data types of each parameter in the initial authentication parameters through the target structure template and storing each parameter in the corresponding position of the target structure template.

[0113] S203. The target authentication parameters are processed by the target authenticator to obtain the authentication response parameters of the target account.

[0114] Furthermore, the login credentials of the target account can be obtained through the target authenticator; the target authenticator can then be used to perform login authentication processing on the target authentication parameters and login credentials to obtain the authentication response parameters of the target account.

[0115] In some possible embodiments, the target authenticator can determine at least one authentication method, which may include fingerprint authentication, facial authentication, Universal Serial Bus (USB) authentication, and Bluetooth authentication, and receive login credentials corresponding to at least one authentication method.

[0116] The target authenticator can display at least one authentication method on the user terminal interface. The target user can choose any authentication method and enter the login credentials corresponding to that authentication method. The login credentials can be fingerprints, facial images, USB information, Bluetooth information, etc.

[0117] For example, if the authentication method is fingerprint authentication, then the login credential is the fingerprint information of the target user corresponding to the target account.

[0118] In some possible embodiments, to enhance the security of the authentication process, the user terminal can select two or more authentication methods and enter the login credentials corresponding to each authentication method. The login credentials can be fingerprints, facial images, USB information, Bluetooth information, etc.

[0119] The target authenticator can be used to obtain the list of credentials in the target authentication request. The list of credentials includes at least one registration credential. If a login credential is present among the at least one registration credential, the authentication is successful, and authentication response parameters can be generated.

[0120] Authentication response parameters may include credential identifier, signature data, authenticator identifier, etc.

[0121] S204. Based on the authentication response parameters, obtain the authentication result of the target account.

[0122] Furthermore, the second parameter type corresponding to the authentication response parameter can be converted into the first parameter type to obtain the target response parameter; the target response parameter is sent to the server, and the authentication result of the target account is received.

[0123] The process of converting the second parameter type corresponding to the authentication response parameter into the first parameter type can be performed in parameter S202, which will not be elaborated here.

[0124] When a user terminal sends authentication response parameters to the server, it can perform permission verification on the authentication response parameters. If the permission verification is successful and the authentication response parameters indicate successful authentication, then the login of the target user's account will be executed.

[0125] After a target user registers through the target authenticator, the target authenticator can generate a registration password. The registration password can be a pair of public and private keys. The target authenticator can store the private key, and the server can store the public key.

[0126] The target authenticator can encrypt the login challenge value using a private key to obtain the signature data in the authentication response parameters. The server can receive the authentication response parameters, which include the signature data. The server can decrypt the signature data to obtain the first decryption challenge value. If the first decryption challenge value is the login challenge value, then the authentication response parameters can be determined as the response parameters corresponding to the authentication request.

[0127] The server can determine the authentication result based on the authentication response parameters and send the authentication result to the user terminal.

[0128] The login challenge value can be data randomly generated by the server when generating the initial authentication parameters corresponding to the authentication request.

[0129] The server can also check whether the target user's current state allows authentication, so that if the authentication response parameter indicates successful authentication, the server can log in to the target user's account.

[0130] The authentication method provided in this application, after receiving the initial authentication parameters corresponding to the authentication request, can convert the first parameter type of the initial authentication parameters into the second parameter type to obtain the target authentication parameters. The target authentication parameters can be authenticated through the target authenticator without needing to call the target authenticator through an external browser for authentication processing, which can improve authentication efficiency.

[0131] The above embodiment describes a target user logging into a target account through a target authenticator. Before logging into a target account through a target authenticator, the target user needs to register through the target authenticator. The following, with reference to Figure 3, describes the execution process of a target user registering a target account through a target authenticator provided in this embodiment.

[0132] Figure 3 is a flowchart illustrating a registration request method provided in an embodiment of this application. Referring to Figure 3, the method may include:

[0133] S301. Receive the initial registration parameters corresponding to the registration request.

[0134] A registration request can be used to request the registration of a target user's account.

[0135] Initial registration parameters may include a randomly generated registration challenge value from WebAuthn, a user identifier, and information about the encryption algorithms that the server can use (pubkeyCredParams). The information about the encryption algorithms that the server can use may include various parameters required for the generation and verification of public key credentials.

[0136] S302. Convert the initial registration parameter of the first parameter type into the target registration parameter of the second parameter type.

[0137] The execution process of S302 can be found in the execution process of S202, and will not be repeated here.

[0138] S303. The target registration parameters are authenticated by the target authenticator to obtain the registration response parameters of the target account.

[0139] Registration response parameters may include a registration credential identifier, a proof object indicating the target user's identity authentication information, and signature data. The proof object may include a public key, and the signature data may be data encrypted with a private key using the registration challenge value.

[0140] S304. Based on the registration response parameters, obtain the registration result of the target account.

[0141] The user terminal can send registration authentication parameters to the server, and the server can receive registration response parameters. The server can verify the validity of the signature data using the public key. If the signature data is processed using the public key to obtain a second decryption challenge value, and the second decryption challenge value matches the registration challenge value, then the registration response parameters are valid, and the server can store the registration response parameters corresponding to the target account.

[0142] The registration challenge value can be data randomly generated by the server when generating the initial registration parameters corresponding to the registration request.

[0143] The server may also include a registration identifier list. After a target account is successfully registered, the user identifier of the target account can be stored in the registration identifier list so that the server can determine whether the target account has been registered.

[0144] The authentication method provided in this application embodiment can convert the initial registration parameters of the first parameter type into target registration parameters of the second parameter type after receiving the initial registration parameters. The target registration parameters can be registered and authenticated by the target authenticator without the need to call the target authenticator through an external browser for authentication processing, which can improve authentication efficiency.

[0145] Based on the above embodiments, the execution process of information transmission for authentication and registration provided in the embodiments of this application will be described below with reference to Figures 4A and 4B.

[0146] Figure 4A is a schematic diagram of the structure of a device providing authentication services according to an embodiment of this application. Referring to Figure 4A, it may include a web layer, a web view layer, and a target authenticator. A web view component can be installed in an application (e.g., a client), allowing the application to implement the WebAuthn protocol of the web layer. The target authenticator adapts both the CTAP protocol and the WebAuthn protocol. In Figure 4A, the CTAP protocol cannot be implemented through the web view, and the web view layer and the target authenticator cannot exchange information.

[0147] Figure 4B is a schematic diagram of another device providing authentication services according to an embodiment of this application. Referring to Figure 4B, an adhesive layer can be configured between the webpage view layer and the target authenticator. The adhesive layer can be used to convert the first parameter type of the webpage view into the second parameter type of the target authenticator, thereby realizing the interaction between the webpage layer and the target authenticator.

[0148] The web page layer can send authentication requests / registration requests to the web page view layer. The glue layer can obtain the initial authentication parameters / initial registration parameters from the web page view layer. The glue layer can convert the initial authentication parameters / initial registration parameters into target authentication parameters / target registration parameters. The glue layer can achieve information interaction with the web page view layer through a preset interface, which can be a JavaScript Application Programming Interface (JSAPI).

[0149] The glue layer can invoke the target authenticator, which can process the target authentication parameters and obtain the authentication response parameters. The glue layer can obtain the authentication response parameters and reply to the web page view layer with the authentication response parameters through a preset interface. The web page view layer can return the authentication response parameters corresponding to the authentication request to the web page layer.

[0150] In some possible embodiments, a first permission verification can be performed on the application corresponding to the authentication request through a preset interface to obtain a first verification result; if the first verification result is successful, an authentication request is sent; if the first verification result is unsuccessful, the authentication request fails.

[0151] By using a pre-defined interface to verify the permissions of the application corresponding to the authentication request, access by malicious software can be prevented, thereby improving authentication security.

[0152] The web page layer can obtain navigator credentials (navigator.credentials.get) by sending an authentication request to the web page view layer, and the web page layer can create navigator credentials (navigator.credentials.create) by sending a registration request to the web page view layer. `navigator.credentials.get` and `navigator.credentials.Create` are core functions of the WebAuthn protocol, used to implement a more secure and streamlined user authentication process.

[0153] Figure 5 is an interactive schematic diagram of an authentication request provided by an embodiment of this application. Referring to Figure 5, the system may include a server and a user terminal. The user terminal may include an application and a target authenticator. The user terminal can generate an authentication request through the application, and can send the authentication request to the server. The server can generate initial authentication parameters based on the authentication request and send the initial authentication request to the user terminal. The user terminal can convert the initial authentication parameters of a first parameter type into target authentication parameters of a second parameter type. The application can send the target authentication parameters to the target authenticator, and the target authenticator can send at least one authentication method corresponding to the target account to the user terminal. The user terminal can obtain the login credentials entered by the target user, and the target authenticator can perform authentication processing on the target authentication parameters and the login credentials to obtain the authentication response parameters of the target account.

[0154] The user terminal can use the application to convert the second parameter type corresponding to the authentication response parameter into the first parameter type to obtain the first response parameter, and then send the first response parameter to the server. The server verifies the permissions based on the first response parameter. If the permission verification is successful, the server determines the authentication result based on the first response parameter and sends the authentication result back to the user. If the authentication result is successful, the server proceeds to log in to the target user's account.

[0155] Figure 6 is a schematic diagram of an interaction for registration and authentication provided in an embodiment of this application. Referring to Figure 6, it includes a server and a user terminal. The user terminal may include an application and a target authenticator. The user terminal can generate a registration request through the application, and can send the registration request to the server. The server can generate initial registration parameters based on the registration request and send the initial registration request to the user terminal. The user terminal can convert the initial registration parameters of a first parameter type into target registration parameters of a second parameter type. The target authenticator can obtain the target registration parameters. The application can obtain at least one authentication method through the target authenticator. The application can obtain the registration credentials entered by the target user. The target authenticator can perform registration processing on the target registration parameters and registration credentials to obtain the registration response parameters of the target account.

[0156] The application can obtain the registration response parameters, convert the second parameter type corresponding to the registration response parameters into the first parameter type, and obtain the second response parameter. The user terminal can then send the second response parameter to the server. The server verifies the permissions of the second response parameter. If the permission verification is successful, and the second response parameter indicates successful authentication, the server saves the second response parameter of the target account in the server, generates the registration result, and sends the registration result to the user terminal.

[0157] Figure 7 is a schematic diagram of an authentication architecture provided in an embodiment of this application. Referring to Figure 7, the user terminal can generate an authentication request. The user terminal can send the authentication request to the server via JSAPI. The JSAPI can perform permission verification on the authentication request. After successful verification, the server can receive the authentication request of the target account, obtain the registration identifier list based on the authentication request, and determine whether the target account has registered a pass key based on the registration identifier list.

[0158] If not, the application can be authorized through the Passkey registration interface. Upon successful verification, initial registration parameters can be obtained, and these parameters (first parameter type) can be converted into target registration parameters (second parameter type). The target authenticator corresponding to the passkey can be called to create an authentication method for the target account. Through this authentication method, registration credentials corresponding to the target registration parameters can be obtained, leading to the registration response parameters. These response parameters can then be sent to the server, where the server can perform authorization verification on them.

[0159] If so, the application's permissions can be verified through the Passkey authentication interface. Upon successful verification, the initial login parameters can be obtained. The first parameter type corresponding to the initial login parameters can be converted to the second parameter type to obtain the target authentication parameters. The target authenticator corresponding to the passkey can be called. Through the target authenticator, the authentication method corresponding to the target account can be determined. Based on the authentication method, the login credentials corresponding to the target authentication parameters can be obtained. Authentication processing can be performed based on the target authentication parameters and login credentials to obtain authentication response parameters. These authentication response parameters can then be sent to the server, where the server can perform permission verification on the authentication response parameters.

[0160] The authentication method improved in this application embodiment can determine whether the target account has been registered based on the registration identifier list when logging into the target account, and then make a registration request or authentication request to the target account, which can improve the authentication efficiency.

[0161] Figure 8 is a schematic diagram of an authorization verification architecture provided in an embodiment of this application. Referring to Figure 6, when a target account is authenticated or registered, the user terminal can perform a second authorization verification on the domain name of the webpage view to determine whether the domain name of the webpage view is valid. If the domain name of the webpage view is invalid, the second verification result is verification failure. If the domain name of the webpage view is valid, the second verification result is verification success, and the target authenticator can be called. The target authenticator can obtain the first hash value of the application and determine whether the application is valid through the first hash value of the application's signing certificate. If the application is invalid, the authorization verification fails; if the application is valid, the target authenticator can be called for registration or authentication.

[0162] The server can receive authentication or registration response parameters from the user terminal. It can obtain the second hash value of the application's signature certificate corresponding to the authentication or registration response parameters. The server uses this second hash value to determine the application's legitimacy. If the application is illegitimate, the authorization verification fails. If the application is legitimate, the verification passes. The server then determines the authentication result corresponding to the authentication response parameters or the registration result corresponding to the registration response parameters. The server can send the authentication result to the user device. If the registration result is successful, the server prompts that registration and authentication are complete and login is possible. If the authentication result is successful, the user terminal logs in to the target user's target account.

[0163] The authentication method provided in this application embodiment can perform permission verification on the application corresponding to the authentication request or registration request when information is exchanged between the server and the user terminal, and can detect maliciously accessed applications, thereby improving the security of authentication.

[0164] Figure 9 is a schematic diagram of an authentication device provided in an embodiment of this application. Referring to Figure 9, the authentication device 10 may include a receiving module 11, a conversion processing module 12, and an authentication processing module 13.

[0165] The receiving module 11 is used to receive the initial authentication parameters corresponding to the authentication request, which is used to request the target account of the login application.

[0166] The conversion processing module 12 is used to convert the initial authentication parameters of the first parameter type into the target authentication parameters of the second parameter type. The first parameter type is the parameter type corresponding to the web page view, and the second parameter type is the parameter type of the target authenticator corresponding to the pass key.

[0167] The authentication processing module 13 is used to perform authentication processing on the target authentication parameters through the target authenticator to obtain the authentication response parameters of the target account.

[0168] The acquisition module 14 is used to obtain the authentication result of the target account based on the authentication response parameters.

[0169] The authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0170] In one possible implementation, the authentication processing module 13 is specifically used for:

[0171] Obtain the login credentials for the target account through the target authenticator;

[0172] The target authenticator processes the target authentication parameters and login credentials to obtain the authentication response parameters for the target account.

[0173] In one possible implementation, the authentication processing module 13 is specifically used for:

[0174] The target authenticator determines at least one authentication method, which includes: fingerprint authentication, facial recognition, Universal Serial Bus (USB) authentication, and Bluetooth authentication.

[0175] Receive login credentials corresponding to at least one authentication method.

[0176] In one possible implementation, the device further includes:

[0177] Generate an authentication request for the target account;

[0178] The application corresponding to the authentication request is subjected to the first permission verification through the preset interface, and the first verification result is obtained.

[0179] If the first verification result is successful, then an authentication request is sent.

[0180] In one possible implementation, the device is also used for:

[0181] Perform a second permission verification on the domain name of the webpage view to obtain a second verification result;

[0182] If the second verification result is successful, then the target authenticator is invoked.

[0183] In one possible implementation, the device is also used for:

[0184] Obtain the target structure template corresponding to the type of the second parameter;

[0185] Based on the target structure template, the initial authentication parameters are structurally transformed to obtain the target authentication parameters.

[0186] In one possible implementation, the device is also used for:

[0187] Receive the initial registration parameters corresponding to the registration request. The registration request is used to request the target account for the target account to be registered.

[0188] Convert the initial registration parameters of the first parameter type into the target registration parameters of the second parameter type;

[0189] The target registration parameters are authenticated by the target authenticator to obtain the registration response parameters of the target account.

[0190] Based on the registration response parameters, obtain the registration result of the target account.

[0191] In one possible implementation, the acquisition module 14 has the following functions:

[0192] Convert the second parameter type corresponding to the authentication response parameter to the first parameter type to obtain the first response parameter;

[0193] Send the first response parameters to the server and receive the authentication result of the target account.

[0194] The authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0195] Figure 10 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Referring to Figure 10, the electronic device 20 may include a processor 21 and a memory 22. Exemplarily, the processor 21 and the memory 22 are interconnected via a bus 23.

[0196] Memory 22 stores instructions executed by the computer;

[0197] The processor 21 executes computer execution instructions stored in the memory 22, causing the processor 21 to perform the authentication method as shown in the above method embodiment.

[0198] Accordingly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the authentication method of the above-described method embodiments.

[0199] Accordingly, embodiments of this application may also provide a computer program product, including a computer program, which, when executed by a processor, can implement the authentication method shown in the above-described method embodiments.

[0200] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0201] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.

[0202] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0203] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0204] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0205] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0206] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0207] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0208] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. An authentication method applied to a user terminal, comprising: Receive initial authentication parameters sent by the server, the initial authentication parameters corresponding to the authentication request, the authentication request being used to request the target account for logging into the application; The initial authentication parameters of the first parameter type are transformed into target authentication parameters of the second parameter type, where the first parameter type is the parameter type corresponding to the webpage view, and the second parameter type is the parameter type of the target authenticator corresponding to the pass key; The target authentication parameters are processed by the target authenticator to obtain the authentication response parameters of the target account. as well as, Based on the authentication response parameters, the authentication result of the target account is obtained.

2. The method according to claim 1, wherein, The target authentication parameters are processed by the target authenticator to obtain the authentication response parameters of the target account, including: The login credentials for the target account are obtained through the target authenticator; and, The target authenticator performs login authentication processing on the target authentication parameters and the login credentials to obtain the authentication response parameters of the target account.

3. The method according to claim 2, wherein, The step of obtaining the login credentials for the target account through the target authenticator includes: The target authenticator obtains a list of credentials from the authentication request, wherein the list of credentials includes at least one registration credential; and The login credential is obtained based on at least one of the registration credentials.

4. The method according to claim 2 or 3, wherein, The step of obtaining the login credentials for the target account through the target authenticator includes: The target authenticator determines at least one authentication method, including at least one of: fingerprint authentication, facial recognition, Universal Serial Bus (USB) authentication, or Bluetooth authentication; and Receive login credentials corresponding to at least one of the authentication methods.

5. The method according to any one of claims 1-4, wherein, The target authenticator is either a fast online authenticator or an execution module used for authentication.

6. The method according to any one of claims 1-5, wherein, Before receiving the initial parameters corresponding to the authentication request, the method further includes: Generate an authentication request for the target account; The application corresponding to the authentication request is subjected to a first permission verification through a preset interface to obtain a first verification result; and... If the first verification result is successful, then the authentication request is sent to the server.

7. The method according to any one of claims 1-6, wherein, The authentication request includes: the domain name of the webpage view and the user identifier of the target account.

8. The method according to any one of claims 1-7, wherein, The initial authentication parameters include at least one of the following: login challenge value, domain name of the webpage view, user ID or list of credentials.

9. The method according to any one of claims 1-8, wherein, Before obtaining the authentication response parameters of the target account by authenticating the target authentication parameters through the target authenticator, the method further includes: A second permission verification is performed on the domain name of the webpage view to obtain a second verification result; and, If the second verification result is successful, then the target authenticator is invoked.

10. The method according to any one of claims 1-9, wherein, The step of converting the initial authentication parameters of the first parameter type into target authentication parameters of the second parameter type includes: Obtain the target structure template corresponding to the second parameter type; and Based on the target structure template, the initial authentication parameters are subjected to structural transformation processing to obtain the target authentication parameters.

11. The method according to claim 6, wherein, Before generating the authentication request for the target account, the method further includes: Receive the initial registration parameters corresponding to the registration request, wherein the registration request is used to request the registration of the target account; Convert the initial registration parameters of the first parameter type into target registration parameters of the second parameter type; The target registration parameters are authenticated using the target authenticator to obtain the registration response parameters for the target account; and, Based on the registration response parameters, the registration result of the target account is obtained.

12. The method according to claim 11, wherein, After obtaining the registration result of the target account based on the registration response parameters, the method further includes: After the registration of the target account is completed, the target authenticator generates a registration password, which includes a public key and a private key pair, and the target authenticator stores the private key.

13. The method according to claim 12, wherein, After the target account registration is completed and the target authenticator generates the registration password, the method further includes: The target authenticator encrypts the login challenge value using the private key to obtain signature data, and the authentication response parameters include the signature data.

14. The method according to claim 8 or 13, wherein, The initial authentication parameters include the login challenge value, which is data randomly generated by the server when generating the initial authentication parameters.

15. The method according to any one of claims 1-14, wherein, The step of obtaining the authentication result of the target account based on the authentication response parameters includes: Convert the authentication response parameter of the second parameter type into a first response parameter of the first parameter type; and... Send the first response parameter to the server and receive the authentication result of the target account.

16. The method according to claim 15, wherein, Before sending the first response parameter to the server, the method further includes: Perform third-party authorization verification on the authentication response parameters; and If the third permission verification is successful and the authentication response parameter indicates successful authentication, then the login of the target user's account will be executed.

17. The method according to claim 16, wherein, The authentication response parameters include at least one of the following: credential identifier, signature data, or authenticator identifier.

18. An authentication device, wherein, It includes a receiving module, a conversion processing module, an authentication processing module, and an acquisition module: The receiving module is used to receive the initial authentication parameters corresponding to the authentication request, the authentication request being used to request the target account of the login application. The conversion processing module is used to convert the initial authentication parameters of the first parameter type into target authentication parameters of the second parameter type, wherein the first parameter type is the parameter type corresponding to the webpage view, and the second parameter type is the parameter type of the target authenticator corresponding to the pass key; The authentication processing module performs authentication processing on the target authentication parameters through the target authenticator to obtain the authentication response parameters of the target account; The acquisition module is used to obtain the authentication result of the target account based on the authentication response parameters.

19. An electronic device comprising: Memory and processor The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the authentication method as described in any one of claims 1 to 17.

20. A computer-readable storage medium storing a computer program that, when executed by a processor, implements the authentication method according to any one of claims 1 to 17.