CN106209742A - Safe verification method and system - Google Patents
Safe verification method and system Download PDFInfo
- Publication number
- CN106209742A CN106209742A CN201510229302.0A CN201510229302A CN106209742A CN 106209742 A CN106209742 A CN 106209742A CN 201510229302 A CN201510229302 A CN 201510229302A CN 106209742 A CN106209742 A CN 106209742A
- Authority
- CN
- China
- Prior art keywords
- user
- verification information
- side application
- ways
- dynamic verification
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Landscapes
- Storage Device Security (AREA)
- Information Transfer Between Computers (AREA)
Abstract
本申请提供了一种安全验证方法及系统,其中的安全验证方法包括:接收终端设备传送的用户输入的用户名和静态密码;基于所述用户名和静态密码进行第一安全验证;向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径;接收所述用户通过所述至少两种途径之一返回的动态验证信息;将所述用户通过所述至少两种途径之一返回的动态验证信息与本地生成的动态验证信息比较,从而进行第二安全验证。本申请避免了第一安全验证中静态密码易被破解带来的安全性问题,有效保证用户身份验证的安全可靠性。
The present application provides a security verification method and system, wherein the security verification method includes: receiving the user name and static password input by the user transmitted by the terminal device; performing the first security verification based on the user name and static password; providing the user with At least two ways to return the dynamic verification information generated by the user-side application; receiving the dynamic verification information returned by the user through one of the at least two ways; and receiving the dynamic verification information returned by the user through one of the at least two ways The verification information is compared with the locally generated dynamic verification information, so as to perform the second security verification. This application avoids the security problem caused by the static password being easily cracked in the first security verification, and effectively guarantees the safety and reliability of user identity verification.
Description
技术领域technical field
本申请涉及计算机领域,尤其涉及一种安全验证方法及系统。The present application relates to the field of computers, in particular to a safety verification method and system.
背景技术Background technique
随着互联网的迅速发展及应用,网络安全问题已成为网络提供商及用户最为关注的问题之一。对用户身份进行安全验证是保证网络安全的一种必要手段。目前,大多数网络服务都是通过用户名和静态密码对用户身份进行安全验证。为了保证安全性,静态密码需要设置的比较复杂,这样就使得密码难以记忆,且不方便输入。另外,静态密码还存在通过诸如暴力破解、撞库、拖库、窥视、木马等手段被破解的风险。With the rapid development and application of the Internet, network security issues have become one of the most concerned issues for network providers and users. Security verification of user identity is a necessary means to ensure network security. Currently, most network services use usernames and static passwords to securely authenticate user identities. In order to ensure security, the static password needs to be set more complicated, which makes the password difficult to remember and inconvenient to input. In addition, static passwords also have the risk of being cracked by means such as brute force cracking, credentialing, dragging, peeping, and Trojan horses.
因此,目前的基于用户名和静态密码对用户身份进行安全验证的手段存在静态密码易被破解的风险,因此,用户身份验证的安全性不够高。Therefore, there is a risk that the static password is easy to be cracked in the current means of securely verifying the user identity based on the user name and the static password. Therefore, the security of the user identity verification is not high enough.
发明内容Contents of the invention
本申请解决的技术问题之一是提供一种安全验证方法及系统,进一步提高用户身份验证的安全性。One of the technical problems solved by the present application is to provide a security verification method and system to further improve the security of user identity verification.
根据本申请一方面的一个实施例,提供了一种安全验证方法,包括:According to an embodiment of one aspect of the present application, a security verification method is provided, including:
接收终端设备传送的用户输入的用户名和静态密码;Receive the user name and static password input by the user transmitted by the terminal device;
基于所述用户名和静态密码进行第一安全验证;performing first security verification based on the username and static password;
向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径;Provide the user with at least two ways to return the dynamic verification information generated by the user-side application;
接收所述用户通过所述至少两种途径之一返回的动态验证信息;receiving the dynamic verification information returned by the user through one of the at least two ways;
将所述用户通过所述至少两种途径之一返回的动态验证信息与本地生成的动态验证信息比较,从而进行第二安全验证。The second security verification is performed by comparing the dynamic verification information returned by the user through one of the at least two ways with the locally generated dynamic verification information.
根据本申请另一方面的一个实施例,提供了一种安全验证系统,包括:According to an embodiment of another aspect of the present application, a security verification system is provided, including:
第一接收单元,用于接收终端设备传送的用户输入的用户名和静态密码;The first receiving unit is used to receive the user name and static password input by the user transmitted by the terminal device;
第一安全验证单元,用于基于所述用户名和静态密码进行第一安全验证;A first security verification unit, configured to perform first security verification based on the user name and static password;
提供单元,用于向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径;A providing unit, configured to provide the user with at least two ways to return the dynamic verification information generated by the user-side application;
第二接收单元,用于接收所述用户通过所述至少两种途径之一返回的动态验证信息;A second receiving unit, configured to receive the dynamic verification information returned by the user through one of the at least two ways;
第二安全验证单元,用于将所述用户通过所述至少两种途径之一返回的动态验证信息与本地生成的动态验证信息比较,从而进行第二安全验证。The second security verification unit is configured to compare the dynamic verification information returned by the user through one of the at least two ways with the locally generated dynamic verification information, so as to perform the second security verification.
本申请实施例在进行基于用户名和静态密码进行第一安全验证的基础上,进行基于动态验证信息的第二安全验证。由于动态验证信息是动态生成的,如果试图破解者未配置有与用户一样的生成动态验证信息的用户侧应用(动态验证信息应用),是很难破解的。因此,避免了第一安全验证中静态密码易被破解带来的安全性问题,有效保证用户身份验证的安全可靠性。且本实施例提供至少两种返回用于第二安全验证的用户侧应用生成的动态验证信息的途径,克服了在只提供一种返回用于第二安全验证的用户侧应用生成的动态验证信息的途径的情况下由于终端设备所处的网络环境和/或终端能力所限不能通过此途径返回动态验证信息、造成无法进行第二安全验证的问题,有效保证了及时准确地获取动态验证信息,从而进一步保证用户身份验证的可靠性。In the embodiment of the present application, on the basis of performing the first security verification based on the user name and the static password, the second security verification based on the dynamic verification information is performed. Because the dynamic verification information is dynamically generated, if the person trying to crack is not configured with the same user-side application (dynamic verification information application) that generates the dynamic verification information as the user, it is difficult to crack. Therefore, the safety problem caused by the static password being easily cracked in the first security verification is avoided, and the safety and reliability of user identity verification are effectively guaranteed. And this embodiment provides at least two ways to return the dynamic verification information generated by the user-side application for the second security verification, which overcomes the problem of only providing one way to return the dynamic verification information generated by the user-side application for the second security verification. In the case of the method, due to the limitation of the network environment of the terminal device and/or the terminal capability, the dynamic verification information cannot be returned through this method, resulting in the problem that the second security verification cannot be performed, which effectively ensures the timely and accurate acquisition of dynamic verification information. Thereby further ensuring the reliability of user authentication.
本领域普通技术人员将了解,虽然下面的详细说明将参考图示实施例、附图进行,但本申请并不仅限于这些实施例。而是,本申请的范围是广泛的,且意在仅通过后附的权利要求限定本申请的范围。Those of ordinary skill in the art will appreciate that although the following detailed description will refer to illustrated embodiments and accompanying drawings, the application is not limited to these embodiments. Rather, the scope of the application is broad and it is intended that the scope of the application be limited only by the appended claims.
附图说明Description of drawings
通过阅读参照以下附图所作的对非限制性实施例所作的详细描述,本申请的其它特征、目的和优点将会变得更明显:Other characteristics, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings:
图1a是根据本申请一个实施例的安全验证方法一种实施顺序的流程图。Fig. 1a is a flowchart of an implementation sequence of a security verification method according to an embodiment of the present application.
图1b是根据本申请一个实施例的安全验证方法另一种实施顺序的流程图。Fig. 1b is a flowchart of another implementation sequence of the security verification method according to an embodiment of the present application.
图2是根据本申请一个实施例的带有接收动态验证信息的输入框的界面示意图。Fig. 2 is a schematic diagram of an interface with an input box for receiving dynamic verification information according to an embodiment of the present application.
图3是根据本申请一个实施例的验证页面提示用户确认的界面示意图。Fig. 3 is a schematic diagram of an interface prompting a user to confirm on a verification page according to an embodiment of the present application.
图4是根据本申请一个实施例的用户侧应用提示用户确认的界面示意图。Fig. 4 is a schematic diagram of an interface where a user-side application prompts a user for confirmation according to an embodiment of the present application.
图5是根据本申请一个实施例的安全验证系统的框图。Fig. 5 is a block diagram of a security verification system according to an embodiment of the present application.
附图中相同或相似的附图标记代表相同或相似的部件。The same or similar reference numerals in the drawings represent the same or similar components.
具体实施方式detailed description
在更加详细地讨论示例性实施例之前应当提到的是,一些示例性实施例被描述成作为流程图描绘的处理或方法。虽然流程图将各项操作描述成顺序的处理,但是其中的许多操作可以被并行地、并发地或者同时实施。此外,各项操作的顺序可以被重新安排。当其操作完成时所述处理可以被终止,但是还可以具有未包括在附图中的附加步骤。所述处理可以对应于方法、函数、规程、子例程、子程序等等。Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe operations as sequential processing, many of the operations may be performed in parallel, concurrently, or simultaneously. In addition, the order of operations can be rearranged. The process may be terminated when its operations are complete, but may also have additional steps not included in the figure. The processing may correspond to a method, function, procedure, subroutine, subroutine, or the like.
所述计算机设备包括用户设备与网络设备。其中,所述用户设备包括但不限于电脑、智能手机、PDA等;所述网络设备包括但不限于单个网络服务器、多个网络服务器组成的服务器组或基于云计算(Cloud Computing)的由大量计算机或网络服务器构成的云,其中,云计算是分布式计算的一种,由一群松散耦合的计算机集组成的一个超级虚拟计算机。其中,所述计算机设备可单独运行来实现本申请,也可接入网络并通过与网络中的其他计算机设备的交互操作来实现本申请。其中,所述计算机设备所处的网络包括但不限于互联网、广域网、城域网、局域网、VPN网络等。The computer equipment includes user equipment and network equipment. Wherein, the user equipment includes, but is not limited to, computers, smart phones, PDAs, etc.; Or a cloud composed of network servers, among them, cloud computing is a kind of distributed computing, a super virtual computer composed of a group of loosely coupled computer sets. Wherein, the computer device can operate independently to realize the present application, and can also access the network and realize the present application by interacting with other computer devices in the network. Wherein, the network where the computer device is located includes, but is not limited to, the Internet, a wide area network, a metropolitan area network, a local area network, a VPN network, and the like.
需要说明的是,所述用户设备、网络设备和网络等仅为举例,其他现有的或今后可能出现的计算机设备或网络如可适用于本申请,也应包含在本申请保护范围以内,并以引用方式包含于此。It should be noted that the user equipment, network equipment, and network are only examples, and other existing or future computer equipment or networks that are applicable to this application should also be included in the scope of protection of this application, and Included herein by reference.
后面所讨论的方法(其中一些通过流程图示出)可以通过硬件、软件、固件、中间件、微代码、硬件描述语言或者其任意组合来实施。当用软件、固件、中间件或微代码来实施时,用以实施必要任务的程序代码或代码段可以被存储在机器或计算机可读介质(比如存储介质)中。(一个或多个)处理器可以实施必要的任务。The methods discussed below, some of which are illustrated by flowcharts, can be implemented by hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware or microcode, the program code or code segments to perform the necessary tasks may be stored in a machine or computer readable medium such as a storage medium. The processor(s) can perform the necessary tasks.
这里所公开的具体结构和功能细节仅仅是代表性的,并且是用于描述本申请的示例性实施例的目的。但是本申请可以通过许多替换形式来具体实现,并且不应当被解释成仅仅受限于这里所阐述的实施例。Specific structural and functional details disclosed herein are representative only and are for purposes of describing example embodiments of the present application. This application may, however, be embodied in many alternative forms and should not be construed as limited to only the embodiments set forth herein.
应当理解的是,虽然在这里可能使用了术语“第一”、“第二”等等来描述各个单元,但是这些单元不应当受这些术语限制。使用这些术语仅仅是为了将一个单元与另一个单元进行区分。举例来说,在不背离示例性实施例的范围的情况下,第一单元可以被称为第二单元,并且类似地第二单元可以被称为第一单元。这里所使用的术语“和/或”包括其中一个或更多所列出的相关联项目的任意和所有组合。It will be understood that although the terms "first", "second", etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term "and/or" includes any and all combinations of one or more of the associated listed items.
应当理解的是,当一个单元被称为“连接”或“耦合”到另一单元时,其可以直接连接或耦合到所述另一单元,或者可以存在中间单元。与此相对,当一个单元被称为“直接连接”或“直接耦合”到另一单元时,则不存在中间单元。应当按照类似的方式来解释被用于描述单元之间的关系的其他词语(例如“处于...之间”相比于“直接处于...之间”,“与...邻近”相比于“与...直接邻近”等等)。It will be understood that when an element is referred to as being "connected" or "coupled" to another element, it can be directly connected or coupled to the other element or intervening elements may be present. In contrast, when an element is referred to as being "directly connected" or "directly coupled" to another element, there are no intervening elements present. Other words used to describe the relationship between elements should be interpreted in a similar fashion (e.g., "between" as opposed to "directly between", "adjacent to" as opposed to than "directly adjacent to" etc.).
这里所使用的术语仅仅是为了描述具体实施例而不意图限制示例性实施例。除非上下文明确地另有所指,否则这里所使用的单数形式“一个”、“一项”还意图包括复数。还应当理解的是,这里所使用的术语“包括”和/或“包含”规定所陈述的特征、整数、步骤、操作、单元和/或组件的存在,而不排除存在或添加一个或更多其他特征、整数、步骤、操作、单元、组件和/或其组合。The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a", "an" and "an" are intended to include the plural unless the context clearly dictates otherwise. It should also be understood that the terms "comprising" and/or "comprising" as used herein specify the presence of stated features, integers, steps, operations, units and/or components, but do not exclude the presence or addition of one or more Other features, integers, steps, operations, units, components and/or combinations thereof.
还应当提到的是,在一些替换实现方式中,所提到的功能/动作可以按照不同于附图中标示的顺序发生。举例来说,取决于所涉及的功能/动作,相继示出的两幅图实际上可以基本上同时执行或者有时可以按照相反的顺序来执行。It should also be noted that in some alternative implementations, the functions/acts noted may occur out of the order noted in the figures. For example, two figures shown in succession may, in fact, be executed substantially concurrently or may sometimes be executed in the reverse order, depending upon the functionality/acts involved.
如前所述,由于基于用户名和静态密码对用户身份进行安全验证的方法存在静态密码易被破解的风险,因此安全性不高。本申请实施例为解决该问题,在基于用户名和静态密码进行安全验证的基础上,再进行基于动态验证信息的安全验证,有效提高了用户身份验证的安全可靠性。As mentioned above, since the method of securely verifying the user identity based on the user name and the static password has the risk that the static password is easily cracked, the security is not high. In order to solve this problem, the embodiments of the present application perform security verification based on dynamic verification information on the basis of security verification based on user names and static passwords, which effectively improves the security and reliability of user identity verification.
为描述方便本申请以下实施例将基于用户名和静态密码的安全验证称为第一安全验证,将基于动态验证信息的安全验证称为第二安全验证。For the convenience of description, in the following embodiments of the present application, the security verification based on the user name and the static password is called the first security verification, and the security verification based on the dynamic verification information is called the second security verification.
下面结合附图对本申请的技术方案作进一步详细描述。The technical solution of the present application will be described in further detail below in conjunction with the accompanying drawings.
图1a-1b是根据本申请一个实施例的安全验证方法的两种不同执行顺序的流程图。该安全验证方法可以由一个能够实现安全验证的服务器完成,也可以由一组服务器实现。该一组服务器例如可以为两台服务器,其中一台为用于实现第一安全验证的服务器,另一台为用于实现第二安全验证的服务器。该一组服务器还可以为包括多台服务器的云服务器组。如图1a-b中所示,该安全验证方法主要包括如下步骤:Figures 1a-1b are flowcharts of two different execution sequences of a security verification method according to an embodiment of the present application. The security authentication method can be implemented by a server capable of implementing security authentication, or can be implemented by a group of servers. The group of servers may be, for example, two servers, one of which is a server for implementing the first security verification, and the other is a server for implementing the second security verification. The group of servers may also be a cloud server group including multiple servers. As shown in Figure 1a-b, the security verification method mainly includes the following steps:
S10、接收终端设备传送的用户输入的用户名和静态密码;S10. Receive the user name and static password input by the user transmitted by the terminal device;
S11、基于所述用户名和静态密码进行第一安全验证;S11. Perform first security verification based on the user name and static password;
S12、向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径;S12. Provide the user with at least two ways to return the dynamic verification information generated by the user-side application;
S13、接收所述用户通过所述至少两种途径之一返回的动态验证信息;S13. Receive the dynamic verification information returned by the user through one of the at least two ways;
S14、将所述用户通过所述至少两种途径之一返回的动态验证信息与本地生成的动态验证信息比较,从而进行第二安全验证。S14. Perform a second security verification by comparing the dynamic verification information returned by the user through one of the at least two ways with the locally generated dynamic verification information.
下面对上述各步骤做进一步详细介绍。The above steps will be further described in detail below.
其中,步骤S10及S11为第一安全验证的实现过程,本申请实施例对第一安全验证方法不做具体限制,可采用已有技术实现。Wherein, steps S10 and S11 are the implementation process of the first security verification, and the embodiment of the present application does not specifically limit the first security verification method, which can be realized by using existing technologies.
步骤S12~S14为第二安全验证的实现过程。需要说明的是,本申请实施例的第二安全验证可以在第一安全验证通过后验证,如图1a所示,也可以和第一安全验证同时执行,也就是在基于用户名和静态密码进行第一安全验证的同时基于动态验证信息进行第二验证,如图1b所示。Steps S12-S14 are the implementation process of the second security verification. It should be noted that the second security verification in the embodiment of the present application can be verified after the first security verification is passed, as shown in FIG. During the first security verification, the second verification is performed based on the dynamic verification information, as shown in FIG. 1b.
所述用户侧应用是预先与用户的用户名(或称ID)绑定、能生成动态验证信息的应用,其可以承载于智能移动终端中。用户侧应用中通过如下算法生成动态验证信息:The user-side application is an application that is pre-bound with the user name (or ID) of the user and can generate dynamic verification information, and can be carried in the smart mobile terminal. The dynamic verification information is generated by the following algorithm in the user-side application:
动态验证信息=f(随机字符串、时间因子、口令长度)(1)Dynamic verification information = f (random character string, time factor, password length) (1)
服务器通过与上面一样的算法也生成一个动态验证信息。如果用户侧应用实时上报给服务器的动态验证信息与服务器实时生成的动态验证信息是一致的,就通过了第二安全验证。The server also generates a dynamic verification message through the same algorithm as above. If the dynamic verification information reported by the user-side application to the server in real time is consistent with the dynamic verification information generated by the server in real time, the second security verification is passed.
为实现基于动态验证信息的安全验证,本申请实施例可以由用户侧应用或用于实现第二安全验证的服务器(以下简称服务器)生成所述随机字符串,并在用户侧应用及服务器上同时保存该随机字符串,其中,该随机字符串与用户侧应用ID关联保存,而用户侧应用ID与安装该用户侧应用的终端的持有用户的用户名又是绑定的,这样,无论是在用户侧应用端,还是在服务器端,都能够通过用户的用户名找到该随机字符串,且对于同一用户找到的随机字符串是相同的。这样,保证了用户侧应用端和服务器端的上述算法(1)中的随机字符串变量是相同的。In order to realize the security verification based on the dynamic verification information, in the embodiment of the present application, the user-side application or the server (hereinafter referred to as the server) used to realize the second security verification can generate the random character string, and simultaneously use the user-side application and the server to generate the random character string. Save the random character string, wherein the random character string is stored in association with the user-side application ID, and the user-side application ID is bound to the user name of the user who owns the terminal where the user-side application is installed. The random character string can be found through the user's username on both the user side application side and the server side, and the random character strings found for the same user are the same. In this way, it is guaranteed that the random character string variables in the above algorithm (1) at the user side application side and the server side are the same.
在动态验证信息应用的初始配置时,让动态验证信息应用和服务器通信,得到服务器当前系统时间,然后在用户侧应用中保存服务器的系统时间与用户侧应用所在系统的系统时间的时间差值。当用户侧应用需要生成动态验证信息时,就用当前用户侧应用所在系统的系统时间加上该时间差值,作为时间因子(实际上就是计算出的当前服务器的系统时间),代入算法(1)。在服务器生成动态验证信息时,就用服务器当前的系统时间代入算法(1)。这样,保证了用户侧应用端和服务器端的上述算法(1)中的时间因子是相同的。During the initial configuration of the dynamic verification information application, let the dynamic verification information application communicate with the server to obtain the current system time of the server, and then save the time difference between the server's system time and the system time of the system where the user-side application is located in the user-side application. When the user-side application needs to generate dynamic verification information, the system time of the system where the current user-side application is located plus the time difference is used as the time factor (actually the calculated system time of the current server), and is substituted into the algorithm (1 ). When the server generates dynamic authentication information, the current system time of the server is used to substitute into algorithm (1). In this way, it is ensured that the time factor in the above algorithm (1) at the user side application side and the server side is the same.
在动态验证信息应用的初始配置时,也将动态验证信息应用在算法(1)中采用的口令长度与服务器在算法(1)中采用的口令长度配置成相同。During the initial configuration of the dynamic verification information application, the password length used by the dynamic verification information application in algorithm (1) is also configured to be the same as the password length used by the server in algorithm (1).
这样,对于同一时刻,用户侧应用通过上述算法(1)实时生成、上报给服务器的动态验证信息与服务器通过上述算法(1)实时生成的动态验证信息应是一致的。如果验证出用户侧应用实时上报给服务器的动态验证信息与服务器实时生成的动态验证信息是一致的,就通过了第二安全验证。In this way, at the same moment, the dynamic verification information generated by the user-side application in real time through the above algorithm (1) and reported to the server should be consistent with the dynamic verification information generated by the server in real time through the above algorithm (1). If it is verified that the dynamic verification information reported by the user-side application to the server in real time is consistent with the dynamic verification information generated by the server in real time, the second security verification is passed.
步骤S12中可提供的返回用户侧应用生成的动态验证信息的途径包括但不限于如下三种:The ways to return the dynamic verification information generated by the user-side application in step S12 include but are not limited to the following three ways:
途径一)向用户提供输入用户侧应用生成的动态验证信息的输入框。Approach 1) Provide the user with an input box for inputting dynamic verification information generated by the user-side application.
其中,该输入框可以为区别于接收静态密码的输入框,即,单独提供一输入框用于接收动态验证信息,如图2中所示,在验证页面中提供一用于接收动态验证信息的输入框;Wherein, the input box can be an input box different from receiving a static password, that is, an input box is provided separately for receiving dynamic verification information, as shown in FIG. 2 , an input box for receiving dynamic verification information is provided on the verification page. Input box;
该输入框也可以为与接收静态密码的输入框同一输入框,例如,对于outlook这样的不支持更改验证页面的场景,则直接将接收静态密码的输入框作为接收动态验证信息的输入框,并将通过该输入框接收的输入信息中后面指定位数的口令识别为用户输入的动态验证信息。本实施例即在静态密码输入框中输入静态口令后输入动态验证信息。The input box can also be the same input box as the input box that receives the static password. For example, for scenarios such as Outlook that do not support changing the verification page, the input box that receives the static password is directly used as the input box that receives the dynamic verification information, and Recognize the password with the specified number of digits in the input information received through the input box as the dynamic verification information input by the user. In this embodiment, the dynamic verification information is entered after the static password is entered in the static password input box.
具体实现中,可以直接将通过用于接收动态验证信息的输入框接收的动态验证信息传送给用于实现第二安全验证的服务器。也可以通过用于实现第一安全验证的服务器将该动态验证信息传送给用户实现第二安全验证的服务器(此为对应静态密码输入框与动态验证信息输入框为同一输入框的场景)。In a specific implementation, the dynamic verification information received through the input box for receiving the dynamic verification information may be directly transmitted to the server for implementing the second security verification. The dynamic verification information may also be transmitted to the user's second security verification server through the server for the first security verification (this is the scenario where the static password input box and the dynamic verification information input box are the same input box).
途径二)向所述用户的用户侧应用发送待确认消息,触发所述用户侧应用发送携带所述用户侧应用生成的动态验证信息的验证请求。Approach 2) Sending a pending confirmation message to the user-side application of the user, triggering the user-side application to send a verification request carrying the dynamic verification information generated by the user-side application.
向所述用户的用户侧应用发送待确认消息,即,向与该用户名绑定的用户侧应用发送待确认消息。该待确认消息中包含待确认的用户名及事件,例如,该待确认消息内容为:XX账号请求登录。Sending a pending confirmation message to the user-side application of the user, that is, sending a pending confirmation message to the user-side application bound to the username. The pending confirmation message includes the username and event to be confirmed, for example, the content of the pending confirmation message is: XX account requests login.
例如,向用户绑定的用户侧应用发送待确认消息,同时可在验证页面中提示用户到用户侧应用进行确认,如图3中所示,提示用户“请打开手机确认登录”。For example, send a pending confirmation message to the user-side application bound to the user, and at the same time prompt the user to go to the user-side application for confirmation on the verification page, as shown in Figure 3, prompting the user "Please turn on the mobile phone to confirm login".
用户侧应用中显示该待确认消息供用户确认,用户可选择接受或拒绝来进行确认,确认结果将连同用户侧应用生成的动态验证信息一起以验证请求的方式发送给服务器。The confirmation message is displayed in the user-side application for the user to confirm, and the user can choose to accept or reject to confirm, and the confirmation result will be sent to the server in the form of a verification request together with the dynamic verification information generated by the user-side application.
可以理解的是,用户侧应用发送的携带确认结果以及动态验证信息的验证请求中还可以包含该用户侧应用的ID。It can be understood that the verification request sent by the user-side application and carrying the confirmation result and dynamic verification information may also include the ID of the user-side application.
途径三)向所述用户提供二维码图片,以使得用户侧应用通过扫描所述二维码图片而触发发送携带所述用户侧应用生成的动态验证信息的验证请求。Approach 3) providing the user with a two-dimensional code picture, so that the user-side application triggers sending a verification request carrying dynamic verification information generated by the user-side application by scanning the two-dimensional code picture.
例如,可在验证页面显示二维码图片,并提示用户扫描二维码图片以完成验证,当用户通过用户侧应用扫描二维码后,用户侧应用上出现如图4中所示的界面。For example, a QR code picture can be displayed on the verification page, and the user is prompted to scan the QR code picture to complete the verification. After the user scans the QR code through the user-side application, the interface shown in Figure 4 appears on the user-side application.
其中,用户侧应用通过扫描所述二维码图片可获取该二维码图片中的待确认消息,所述待确认消息中包含待确认的用户名及事件,例如,该待确认消息内容为:XX账号请求登录。用户可在用户侧应用的界面(如图4)中选择接受或拒绝来进行确认,确认结果将连同用户侧应用生成的动态验证信息一起以验证请求的方式发送给服务器。Wherein, the application on the user side can obtain the message to be confirmed in the picture of the two-dimensional code by scanning the picture of the two-dimensional code, and the message to be confirmed includes the user name and event to be confirmed, for example, the content of the message to be confirmed is: XX account requests to log in. The user can choose to accept or reject in the user-side application interface (as shown in Figure 4) to confirm, and the confirmation result will be sent to the server in the form of a verification request together with the dynamic verification information generated by the user-side application.
可以理解的是,用户侧应用发送的携带确认结果以及动态验证信息的验证请求中还可以包含该用户侧应用的ID。It can be understood that the verification request sent by the user-side application and carrying the confirmation result and dynamic verification information may also include the ID of the user-side application.
由于上述三种途径单独提供其中一种均存在一定的弊端,例如,若单独提供途径一),则需要用户手工输入动态验证信息,用户体验较差;若单独提供途径二),则需要网络支持,在网络质量较差情况下,存在延迟;若单独提供途径三),则需要网络支持,且提供二维码图片需要一定的显示空间,对于不支持显示二维码图片的终端,如VPN(Virtual PrivateNetwork,虚拟专用网络)终端,或SSH(Secure Shell Protocol,安全外壳协议)终端则无法显示。Since one of the above three methods is provided separately, there are certain disadvantages. For example, if the method 1 is provided separately, the user needs to manually input dynamic verification information, and the user experience is poor; if the method 2 is provided separately, network support is required , in the case of poor network quality, there is a delay; if the method 3) is provided separately, network support is required, and providing a QR code image requires a certain display space. For terminals that do not support displaying QR code images, such as VPN ( Virtual PrivateNetwork (Virtual Private Network) terminal, or SSH (Secure Shell Protocol, secure shell protocol) terminal cannot be displayed.
本申请实施例通过同时提供至少两种返回动态验证信息的途径,可有效避免单一途径存在的问题,以便于及时获取动态验证信息,执行基于动态验证信息的第二安全验证,提升验证速度。The embodiment of the present application provides at least two ways to return dynamic verification information at the same time, which can effectively avoid the problems existing in a single way, so as to obtain dynamic verification information in time, perform second security verification based on dynamic verification information, and improve verification speed.
另外,需要说明的是,在另一实施例中,服务器可以根据终端设备所处的网络环境和/或终端设备的终端能力决定向用户返回哪些用户侧应用生成的动态验证信息的途径。即步骤S12可以包括:In addition, it should be noted that, in another embodiment, the server may determine which dynamic verification information generated by the user-side application is returned to the user according to the network environment of the terminal device and/or the terminal capability of the terminal device. That is, step S12 may include:
获取所述终端设备所处的网络环境和/或所述终端设备的终端能力;Obtaining the network environment where the terminal device is located and/or the terminal capability of the terminal device;
根据获取的所述终端设备所处的网络环境和/或所述终端设备的终端能力,向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径。According to the acquired network environment where the terminal device is located and/or the terminal capability of the terminal device, provide the user with at least two ways to return the dynamic verification information generated by the user-side application.
所述当前网络环境包括:是否连接网络、网速、网络信号强度等。所述终端能力包括:是否支持显示二维码、是否支持提供动态验证信息输入框等等。所述获取包括:接收和/或检测。接收的例子例如,可以在终端设备的验证界面上设置填写终端设备所处的网络环境和/或用户的终端能力的框,由用户进行输入,服务器通过获取用户填写的内容获知终端设备所处的网络环境和/或终端设备的终端能力。检测的例子例如,服务器检测终端设备当前所处的环境中有网络连接、或无网络连接,这在目前的技术中是可以实现的。The current network environment includes: whether to connect to the network, network speed, network signal strength, and the like. The terminal capabilities include: whether to support the display of two-dimensional codes, whether to support the provision of dynamic verification information input boxes, and so on. The acquiring includes: receiving and/or detecting. Examples of receiving For example, a box for filling in the network environment of the terminal device and/or the terminal capabilities of the user can be set on the verification interface of the terminal device, and the user can input, and the server can obtain the content filled in by the user to know the location of the terminal device. The network environment and/or terminal capabilities of the terminal device. An example of detection is, for example, that the server detects that the terminal device is currently connected to the network or not connected to the network, which is achievable in the current technology.
例如,服务器检测出终端设备所处的网络环境为有网络连接,但该终端不支持二维码显示,此时服务器仅向用户提供上述途径一)和途径二),而不是向用户提供所有途径。For example, the server detects that the network environment where the terminal device is located is connected to the network, but the terminal does not support the display of two-dimensional codes. At this time, the server only provides the above-mentioned method 1) and method 2) to the user instead of providing all the methods to the user. .
步骤S13为接收用户通过所述至少两种途径之一返回的动态验证信息,也就是用户可通过所述至少两种途径中的任一种来返回动态验证信息。例如,若同时提供上述三种途径,用户可直接通过途径二)在用户侧应用中对验证消息进行验证,并发送携带用户侧应用生成的动态验证信息的验证请求,此过程无需用户输入动态验证信息。当然也可通过途径一)或途径三)来返回动态验证信息。Step S13 is to receive the dynamic verification information returned by the user through one of the at least two ways, that is, the user can return the dynamic verification information through any one of the at least two ways. For example, if the above three methods are provided at the same time, the user can directly verify the verification message in the user-side application through method 2) and send a verification request carrying the dynamic verification information generated by the user-side application. This process does not require the user to enter dynamic verification information. Of course, the dynamic verification information can also be returned through approach 1) or approach 3).
步骤S14是将所述用户通过所述至少两种途径之一返回的动态验证信息与本地生成的动态验证信息比较,从而进行第二安全验证。Step S14 is to compare the dynamic verification information returned by the user through one of the at least two ways with the locally generated dynamic verification information, so as to perform a second security verification.
该第二安全验证的原理如前所述。所述本地生成的动态验证信息即执行第二安全验证的服务器本地生成的动态验证信息,该服务器为与用户侧应用绑定的服务器。The principle of the second security verification is as described above. The locally generated dynamic verification information is the dynamic verification information locally generated by the server performing the second security verification, and the server is a server bound to the user-side application.
本申请实施例在进行基于用户名和静态密码进行第一安全验证的基础上,进行基于动态验证信息的第二安全验证,避免了第一安全验证中静态密码易被破解带来的安全性问题,有效保证用户身份验证的安全可靠性。且本实施例提供至少两种返回用于第二安全验证的用户侧应用生成的动态验证信息的途径,有效保证了及时准确的获取动态验证信息,以保证第二安全验证的执行,从而进一步保证用户身份验证的可靠性。In the embodiment of the present application, on the basis of the first security verification based on the user name and static password, the second security verification based on the dynamic verification information is performed, which avoids the security problem caused by the static password being easily cracked in the first security verification. Effectively guarantee the safety and reliability of user authentication. And this embodiment provides at least two ways to return the dynamic verification information generated by the user-side application for the second security verification, which effectively ensures timely and accurate acquisition of dynamic verification information to ensure the execution of the second security verification, thereby further ensuring Reliability of user authentication.
本申请实施例还提供一种与上述安全验证方法对应的安全验证系统。该安全验证系统可以包括一组服务器,该一组服务器例如可以为两台服务器,其中一台为用于实现第一安全验证的服务器,另一台为用于实现第二安全验证的服务器。当然该一组服务器还可以为包括多台服务器的云服务器组。图5中所示的一种安全验证系统,包括:The embodiment of the present application also provides a security verification system corresponding to the above security verification method. The security verification system may include a group of servers. The group of servers may be, for example, two servers, one of which is a server for implementing the first security verification, and the other is a server for implementing the second security verification. Of course, the group of servers may also be a cloud server group including multiple servers. A kind of security verification system shown in Fig. 5, comprises:
第一接收单元20,用于接收终端设备传送的用户输入的用户名和静态密码;The first receiving unit 20 is configured to receive the user name and static password input by the user transmitted by the terminal device;
第一安全验证单元21,用于基于所述用户名和静态密码进行第一安全验证;The first security verification unit 21 is configured to perform first security verification based on the user name and static password;
提供单元22,用于向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径;A providing unit 22, configured to provide the user with at least two ways to return the dynamic verification information generated by the user-side application;
第二接收单元23,用于接收所述用户通过所述至少两种途径之一返回的动态验证信息;The second receiving unit 23 is configured to receive the dynamic verification information returned by the user through one of the at least two ways;
第二安全验证单元24,用于将所述用户通过所述至少两种途径之一返回的动态验证信息与本地生成的动态验证信息比较,从而进行第二安全验证。The second security verification unit 24 is configured to compare the dynamic verification information returned by the user through one of the at least two ways with the locally generated dynamic verification information, so as to perform the second security verification.
可选地,所述至少两种返回用户侧应用生成的动态验证信息的途径中的一种途径为:向用户提供输入用户侧应用生成的动态验证信息的输入框。Optionally, one of the at least two ways of returning the dynamic verification information generated by the user-side application is: providing an input box for the user to input the dynamic verification information generated by the user-side application.
可选地,所述至少两种返回用户侧应用生成的动态验证信息的途径中的一种途径为:向所述用户的用户侧应用发送待确认消息,触发所述用户侧应用发送携带所述用户侧应用生成的动态验证信息的验证请求。Optionally, one of the at least two ways of returning the dynamic verification information generated by the user-side application is: sending a message to be confirmed to the user-side application of the user, triggering the user-side application to send a message carrying the A verification request for dynamic verification information generated by the user-side application.
可选地,所述至少两种返回用户侧应用生成的动态验证信息的途径中的一种途径为:向所述用户提供二维码图片,以使得用户侧应用通过扫描所述二维码图片而触发发送携带所述用户侧应用生成的动态验证信息的验证请求。Optionally, one of the at least two ways of returning the dynamic verification information generated by the user-side application is: providing the user with a two-dimensional code picture, so that the user-side application scans the two-dimensional code picture And trigger sending a verification request carrying the dynamic verification information generated by the user-side application.
可选地,所述提供单元进一步被配置为:Optionally, the providing unit is further configured to:
获取所述终端设备所处的网络环境和/或所述终端设备的终端能力;Obtaining the network environment where the terminal device is located and/or the terminal capability of the terminal device;
根据获取的所述终端设备所处的网络环境和/或所述终端设备的终端能力,向所述用户提供至少两种返回用户侧应用生成的动态验证信息的途径。According to the acquired network environment where the terminal device is located and/or the terminal capability of the terminal device, provide the user with at least two ways to return the dynamic verification information generated by the user-side application.
需要注意的是,本申请可在软件和/或软件与硬件的组合体中被实施,例如,可采用专用集成电路(ASIC)、通用目的计算机或任何其他类似硬件设备来实现。在一个实施例中,本申请的软件程序可以通过处理器执行以实现上文所述步骤或功能。同样地,本申请的软件程序(包括相关的数据结构)可以被存储到计算机可读记录介质中,例如,RAM存储器,磁或光驱动器或软磁盘及类似设备。另外,本申请的一些步骤或功能可采用硬件来实现,例如,作为与处理器配合从而执行各个步骤或功能的电路。It should be noted that the present application can be implemented in software and/or a combination of software and hardware, for example, it can be implemented by using an application specific integrated circuit (ASIC), a general-purpose computer or any other similar hardware devices. In one embodiment, the software program of the present application can be executed by a processor to realize the steps or functions described above. Likewise, the software program (including associated data structures) of the present application can be stored in a computer-readable recording medium such as RAM memory, magnetic or optical drive or floppy disk and the like. In addition, some steps or functions of the present application may be implemented by hardware, for example, as a circuit that cooperates with a processor to execute each step or function.
另外,本申请的一部分可被应用为计算机程序产品,例如计算机程序指令,当其被计算机执行时,通过该计算机的操作,可以调用或提供根据本申请的方法和/或技术方案。而调用本申请的方法的程序指令,可能被存储在固定的或可移动的记录介质中,和/或通过广播或其他信号承载媒体中的数据流而被传输,和/或被存储在根据所述程序指令运行的计算机设备的工作存储器中。在此,根据本申请的一个实施例包括一个装置,该装置包括用于存储计算机程序指令的存储器和用于执行程序指令的处理器,其中,当该计算机程序指令被该处理器执行时,触发该装置运行基于前述根据本申请的多个实施例的方法和/或技术方案。In addition, a part of the present application can be applied as a computer program product, such as a computer program instruction. When it is executed by a computer, the method and/or technical solution according to the present application can be invoked or provided through the operation of the computer. The program instructions for invoking the method of the present application may be stored in a fixed or removable recording medium, and/or transmitted through a data stream in a broadcast or other signal-carrying medium, and/or stored in a in the working memory of the computer device on which the program instructions described above are executed. Here, an embodiment according to the present application includes an apparatus comprising a memory for storing computer program instructions and a processor for executing the program instructions, wherein when the computer program instructions are executed by the processor, triggering The operation of the device is based on the foregoing methods and/or technical solutions according to multiple embodiments of the present application.
对于本领域技术人员而言,显然本申请不限于上述示范性实施例的细节,而且在不背离本申请的精神或基本特征的情况下,能够以其他的具体形式实现本申请。因此,无论从哪一点来看,均应将实施例看作是示范性的,而且是非限制性的,本申请的范围由所附权利要求而不是上述说明限定,因此旨在将落在权利要求的等同要件的含义和范围内的所有变化涵括在本申请内。不应将权利要求中的任何附图标记视为限制所涉及的权利要求。此外,显然“包括”一词不排除其他单元或步骤,单数不排除复数。系统权利要求中陈述的多个单元或装置也可以由一个单元或装置通过软件或者硬件来实现。第一,第二等词语用来表示名称,而并不表示任何特定的顺序。It will be apparent to those skilled in the art that the present application is not limited to the details of the exemplary embodiments described above, but that the present application can be implemented in other specific forms without departing from the spirit or essential characteristics of the present application. Accordingly, the embodiments should be considered exemplary and non-restrictive in all points of view, and the scope of the application is defined by the appended claims rather than the foregoing description, and it is intended that the scope of the present application be defined by the appended claims rather than by the foregoing description. All changes within the meaning and range of equivalents of the elements are embraced in this application. Any reference sign in a claim should not be construed as limiting the claim concerned. In addition, it is obvious that the word "comprising" does not exclude other elements or steps, and the singular does not exclude the plural. A plurality of units or devices stated in the system claims may also be realized by one unit or device through software or hardware. The words first, second, etc. are used to denote names without implying any particular order.
Claims (10)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510229302.0A CN106209742B (en) | 2015-05-07 | 2015-05-07 | Security verification method and system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510229302.0A CN106209742B (en) | 2015-05-07 | 2015-05-07 | Security verification method and system |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN106209742A true CN106209742A (en) | 2016-12-07 |
| CN106209742B CN106209742B (en) | 2020-08-14 |
Family
ID=57459947
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201510229302.0A Active CN106209742B (en) | 2015-05-07 | 2015-05-07 | Security verification method and system |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN106209742B (en) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107341377A (en) * | 2017-06-16 | 2017-11-10 | 武汉斗鱼网络科技有限公司 | Time synchronization control method in one kind authentication |
| CN108600156A (en) * | 2018-03-07 | 2018-09-28 | 华为技术有限公司 | A kind of server and safety certifying method |
Citations (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1855810A (en) * | 2005-04-26 | 2006-11-01 | 上海盛大网络发展有限公司 | Dynamic code verificating system, method and use |
| CN100409685C (en) * | 1999-10-19 | 2008-08-06 | 汤姆森许可公司 | System and method for verifying rights to communicate protected content |
| CN101662364A (en) * | 2009-09-17 | 2010-03-03 | 北京飞天诚信科技有限公司 | Method and system for safe login |
| CN102946334A (en) * | 2012-11-28 | 2013-02-27 | 中国移动(深圳)有限公司 | Method and system for acquiring valid image verification code |
| US20130217374A1 (en) * | 2010-01-25 | 2013-08-22 | Research In Motion Limited | Error correction for dtmf corruption on uplink |
| CN103841130A (en) * | 2012-11-21 | 2014-06-04 | 深圳市腾讯计算机系统有限公司 | Verification information pushing method and device, and identity authentication method and device |
| CN103927464A (en) * | 2013-01-11 | 2014-07-16 | 深圳市腾讯计算机系统有限公司 | Common validation method, and method, device and system for generating two dimensional code |
| CN104038502A (en) * | 2014-06-24 | 2014-09-10 | 五八同城信息技术有限公司 | Verification method and system |
| CN104144058A (en) * | 2014-07-29 | 2014-11-12 | 诚迈科技(南京)股份有限公司 | Information verification method based on sound wave pairing |
-
2015
- 2015-05-07 CN CN201510229302.0A patent/CN106209742B/en active Active
Patent Citations (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN100409685C (en) * | 1999-10-19 | 2008-08-06 | 汤姆森许可公司 | System and method for verifying rights to communicate protected content |
| CN1855810A (en) * | 2005-04-26 | 2006-11-01 | 上海盛大网络发展有限公司 | Dynamic code verificating system, method and use |
| CN101662364A (en) * | 2009-09-17 | 2010-03-03 | 北京飞天诚信科技有限公司 | Method and system for safe login |
| US20130217374A1 (en) * | 2010-01-25 | 2013-08-22 | Research In Motion Limited | Error correction for dtmf corruption on uplink |
| CN103841130A (en) * | 2012-11-21 | 2014-06-04 | 深圳市腾讯计算机系统有限公司 | Verification information pushing method and device, and identity authentication method and device |
| CN102946334A (en) * | 2012-11-28 | 2013-02-27 | 中国移动(深圳)有限公司 | Method and system for acquiring valid image verification code |
| CN103927464A (en) * | 2013-01-11 | 2014-07-16 | 深圳市腾讯计算机系统有限公司 | Common validation method, and method, device and system for generating two dimensional code |
| CN104038502A (en) * | 2014-06-24 | 2014-09-10 | 五八同城信息技术有限公司 | Verification method and system |
| CN104144058A (en) * | 2014-07-29 | 2014-11-12 | 诚迈科技(南京)股份有限公司 | Information verification method based on sound wave pairing |
Non-Patent Citations (1)
| Title |
|---|
| 温浩宇,等: "《web网站设计与开发教程(HTML5、JSP版)》", 31 January 2014 * |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107341377A (en) * | 2017-06-16 | 2017-11-10 | 武汉斗鱼网络科技有限公司 | Time synchronization control method in one kind authentication |
| CN108600156A (en) * | 2018-03-07 | 2018-09-28 | 华为技术有限公司 | A kind of server and safety certifying method |
| CN108600156B (en) * | 2018-03-07 | 2021-05-07 | 华为技术有限公司 | Server and security authentication method |
Also Published As
| Publication number | Publication date |
|---|---|
| CN106209742B (en) | 2020-08-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN103609090B (en) | Identity login method and equipment | |
| US10050952B2 (en) | Smart phone login using QR code | |
| TWI706265B (en) | Third-party authorized login method and system | |
| US10735419B2 (en) | Techniques for authentication via a mobile device | |
| US9479499B2 (en) | Method and apparatus for identity authentication via mobile capturing code | |
| CN104902028B (en) | A kind of a key login authentication method, apparatus and system | |
| US10878212B2 (en) | Two-dimensional code scanning interaction methods and apparatuses | |
| US11038870B2 (en) | Quick response (QR) code for secure provisioning | |
| CN105227536A (en) | A kind of Quick Response Code login method and equipment | |
| CN110574350B (en) | Method and system for performing preferentially generated second factor authentication | |
| CN107623690A (en) | Login method, device and storage medium | |
| US20230186304A1 (en) | Transaction Validation Service | |
| US11777942B2 (en) | Transfer of trust between authentication devices | |
| EP3982614A1 (en) | Resource security integration platform | |
| CN106452738A (en) | Authentication method, device and system for logging in equipment | |
| CN104618356B (en) | Auth method and device | |
| CN104079527A (en) | Information processing method and electronic equipment | |
| US12445487B2 (en) | Anti-phishing based on wrong flow detection | |
| US11050743B2 (en) | Systems and methods of enabling fast user access to remote desktops | |
| US11134077B2 (en) | User-controlled transaction annotation for authentication events across multiple user devices | |
| CN106209742B (en) | Security verification method and system | |
| CN119853977A (en) | Cloud application login preliminary authentication method and device and electronic equipment | |
| CN106161338A (en) | For verifying the method and device of user identity | |
| CN108282472A (en) | A kind of WIFI authentication methods, device, server and storage medium | |
| WO2018024252A1 (en) | Virtual reality-based information verification method, device, data storage medium, and virtual reality apparatus |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant |