[go: up one dir, main page]

WO2016206090A1 - Dispositif, appareil et procédé d'authentification à deux facteurs - Google Patents

Dispositif, appareil et procédé d'authentification à deux facteurs Download PDF

Info

Publication number
WO2016206090A1
WO2016206090A1 PCT/CN2015/082495 CN2015082495W WO2016206090A1 WO 2016206090 A1 WO2016206090 A1 WO 2016206090A1 CN 2015082495 W CN2015082495 W CN 2015082495W WO 2016206090 A1 WO2016206090 A1 WO 2016206090A1
Authority
WO
WIPO (PCT)
Prior art keywords
picture
user
factor
account
password
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/082495
Other languages
English (en)
Chinese (zh)
Inventor
徐志贤
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to PCT/CN2015/082495 priority Critical patent/WO2016206090A1/fr
Priority to CN201580029554.7A priority patent/CN106489155A/zh
Publication of WO2016206090A1 publication Critical patent/WO2016206090A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V10/00Arrangements for image or video recognition or understanding
    • G06V10/20Image preprocessing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols

Definitions

  • the present invention relates to the field of identity authentication, and in particular, to a two-factor authentication method, apparatus, and device.
  • Two-factor authentication refers to the use of two independent and irrelevant evidence to prove identity.
  • a secret known to the person being authenticated for example, a password or a Personal Identification Number (PIN);
  • the two-factor authentication required by the network application is an enhanced way of matching the user name and password authentication mode, that is, the above 1+2 or 1+3 mode.
  • the embodiment of the invention provides a two-factor authentication method, device and device, and the authentication process is simple and the user is convenient to operate.
  • a two-factor authentication method comprising:
  • User login authentication is performed according to the account number, the password, and the picture factor.
  • the method before the receiving a password and a picture factor that are input when the user logs in, the method further includes:
  • the updated interference picture information is displayed
  • the receiving the password and picture factor input when the user logs in including:
  • the password input when the user logs in and the picture factor selected from the updated interference picture information when the user logs in are received.
  • the method before the acquiring an account that is input when the user logs in, the method further includes:
  • the receiving a password and a picture factor that are input when the user is registered include:
  • the picture selected by the user is taken as the picture factor.
  • the receiving a password and a picture factor that are input when the user registers include:
  • the user uploading the image as a picture factor includes:
  • the user uploaded images are tailored according to uniform specifications
  • the method further includes:
  • the user uploaded the image is a signature picture drawn by the user
  • the receiving the password and picture factor input when the user logs in including:
  • Performing user login authentication according to the account number, the password, and the picture factor including:
  • the method further includes:
  • User login authentication is performed according to the account number and the password.
  • the method further includes:
  • the user After the user logs in, the user is queried according to the user's instruction whether the picture factor authentication function is enabled.
  • the picture factor authentication function is enabled on the account according to the user's instruction
  • the method further includes:
  • the user After the user logs in, the user is queried according to the user's instruction whether the picture factor authentication function is enabled.
  • the picture factor authentication function is cancelled according to the user's instruction
  • the method further includes:
  • the user retrieves the password authentication according to the account number, the verification code, and the picture factor.
  • the performing user login authentication according to the account, the password, and the picture factor includes:
  • the authentication failure is confirmed, and the login authentication result of the authentication failure is displayed.
  • the method further includes:
  • a two-factor authentication method comprising:
  • the user retrieves the password authentication according to the account number, the verification code, and the picture factor.
  • the method before the receiving the verification code and the picture factor that are input when the user retrieves the password, the method further includes:
  • the updated interference picture information is displayed
  • the verification code and the picture factor input when the user receives the password including:
  • the method before the acquiring the account that is input when the user retrieves the password, the method further includes:
  • the receiving a password and a picture factor that are input when the user is registered include:
  • the user uploading the image as a picture factor includes:
  • the user uploaded images are tailored according to uniform specifications
  • the method further includes:
  • the user uploaded the image is a signature picture drawn by the user
  • Performing user password recovery authentication according to the account number, the verification code, and the picture factor including:
  • a two-factor authentication apparatus comprising:
  • a query unit configured to query whether an account factor obtained by the obtaining unit is enabled with a picture factor authentication function
  • a display unit configured to display prompt information of the input picture factor when the query result of the query unit is that the picture factor authentication function is enabled for the account;
  • a receiving unit configured to receive a password and a picture factor input when the user logs in
  • the authentication unit is configured to perform user login authentication according to the account acquired by the acquiring unit, the password received by the receiving unit, and a picture factor.
  • the device further includes:
  • a determining unit configured to determine whether the interference picture information is updated before the receiving unit receives the password and the picture factor input when the user logs in;
  • the display unit is further configured to display the updated interference picture information when the judgment result of the determining unit is that the interference picture information is updated;
  • the receiving unit is specifically configured to receive a password input when the user logs in and a picture factor selected from the updated interference picture information when the user logs in.
  • the display unit is further configured to display prompt information of the input picture factor when an instruction for enabling the picture factor authentication function for the account is obtained;
  • the receiving unit is further configured to receive a password and a picture factor input when the user registers;
  • a registration unit configured to perform user registration according to the account acquired by the acquiring unit, the password received by the receiving unit, and a picture factor, and generate interference picture information including the picture factor for the account.
  • the receiving unit includes:
  • a receiving subunit configured to receive a password input when the user registers
  • a display subunit configured to randomly generate a picture list, and display the picture list
  • the receiving subunit is further configured to receive an instruction for selecting a picture from the picture list when the user registers;
  • a picture factor confirmation subunit is configured to use a picture selected by the user by the receiving subunit as a picture factor.
  • the receiving unit includes:
  • the receiving subunit is further configured to receive an instruction that a user uploads a picture
  • the picture factor confirmation subunit is configured to use the user uploaded picture received by the receiving subunit as a picture factor.
  • the picture factor confirmation subunit is specifically configured to The grid is cropped; the cropped image is used as the image factor.
  • the display unit is further configured to display prompt information for sharing a picture uploaded by a user;
  • the receiving unit is further configured to receive an instruction of the user, and share the uploaded image of the user according to the instruction, so that the interference picture information can be generated for the other account according to the picture uploaded by the user.
  • the receiving unit is specifically configured to receive a password input by the user when logging in and a picture factor drawn by the user;
  • the authentication unit is specifically configured to verify, by using the account acquired by the acquiring unit, whether the password received by the receiving unit is correct, and by comparing the picture factor received by the receiving unit with the signature picture received by the receiving subunit. Similarity, user login authentication.
  • the receiving unit is further configured to: when the obtaining unit acquires an account that is input when the user logs in, the query unit queries whether the image factor authentication function is enabled in the account, and the query result of the query unit is the account When the picture factor authentication function is not enabled, the password input by the user is received;
  • the authentication unit is further configured to perform user login authentication according to the account acquired by the acquiring unit and the password received by the receiving unit.
  • the query unit is further configured to: after the user logs in, query whether the account factor authentication function is enabled by the account according to an instruction of the user;
  • the device also includes:
  • An enabling unit configured to: when the query result of the query unit is that the account factor is not enabled When the authentication function is performed, the picture factor authentication function is enabled for the account according to the user's instruction;
  • the display unit is further configured to display prompt information of an input picture factor
  • the receiving unit is further configured to receive a picture factor input by the user
  • the registration unit is further configured to re-register the user according to the account, the password, and the picture factor, and generate interference picture information including the picture factor for the account.
  • the query unit is further configured to: after the user logs in, query whether the account factor authentication function is enabled by the account according to an instruction of the user;
  • the device also includes:
  • a canceling unit configured to cancel a picture factor authentication function on the account according to a user instruction when the query result of the query unit is that the picture factor authentication function is enabled on the account;
  • the registration unit is further configured to perform user registration again according to the account number and the password.
  • the obtaining unit is further configured to acquire an account that is input when the user retrieves the password;
  • the query unit is further configured to query whether an account factor obtained by the obtaining unit is enabled with a picture factor authentication function
  • the display unit is further configured to: when the query result of the query unit is that the image factor authentication function is enabled for the account, display prompt information of the input picture factor;
  • the receiving unit is further configured to receive a verification code and a picture factor input by the user;
  • the authentication unit is further configured to perform user recovery password authentication according to the account number, the verification code, and the picture factor.
  • the authenticating unit is specifically configured to:
  • the authentication failure is confirmed, and the login authentication result of the authentication failure is displayed.
  • the device further includes:
  • the locking unit is configured to lock the account when the number of consecutive authentication failures of the authentication unit exceeds a preset number of times.
  • a two-factor authentication apparatus comprising:
  • the obtaining unit is configured to obtain an account entered when the user retrieves the password
  • a query unit configured to query whether an account factor obtained by the obtaining unit is enabled with a picture factor authentication function
  • a display unit configured to display prompt information of the input picture factor when the query result of the query unit is that the picture factor authentication function is enabled for the account;
  • a receiving unit configured to receive a verification code and a picture factor input when the user retrieves the password
  • the authentication unit is configured to perform user recovery password authentication according to the account acquired by the acquiring unit, the verification code received by the receiving unit, and the picture factor.
  • the device further includes:
  • a determining unit configured to determine whether the interference picture information is updated before the receiving unit receives the verification code and the picture factor input when the user retrieves the password
  • the display unit is further configured to display the updated interference picture information when the judgment result of the determining unit is that the interference picture information is updated;
  • the receiving unit is specifically configured to receive a verification code input when the user retrieves the password and a picture factor selected from the updated interference picture information when the user retrieves the password.
  • the acquiring unit is further configured to input when acquiring a password for the user to retrieve Before the account number, obtain the account number entered when the user registers;
  • the display unit is further configured to display prompt information of the input picture factor when an instruction for enabling the picture factor authentication function for the account is obtained;
  • the receiving unit is further configured to receive a password and a picture factor input when the user registers;
  • the device also includes:
  • a registration unit configured to perform user registration according to the account acquired by the acquiring unit, the password received by the receiving unit, and a picture factor, and generate interference picture information including the picture factor for the account.
  • the receiving unit includes:
  • a receiving subunit configured to receive a password input when the user registers
  • the receiving subunit is further configured to receive an instruction that a user uploads a picture
  • the picture factor confirmation sub-unit is used to use the picture uploaded by the user as a picture factor.
  • the picture factor confirmation sub-unit is specifically configured to perform, according to a unified specification, a user-uploaded picture;
  • the cropped image acts as a picture factor.
  • the display unit is further configured to display prompt information for sharing a user-uploaded picture
  • the receiving unit is further configured to receive an instruction of the user, and share the uploaded image of the user according to the instruction, so that the interference picture information can be generated for the other account according to the picture uploaded by the user.
  • the user-uploaded picture received by the receiving sub-unit is a signature picture drawn by the user
  • the receiving unit is specifically configured to receive a verification code input by the user when the password is retrieved and a picture factor drawn by the user;
  • the authentication unit is specifically configured to verify, by using the account acquired by the acquiring unit, whether the verification code received by the receiving unit is correct, and by comparing the picture factor received by the receiving unit with the receiving subunit.
  • the similarity of the signature image is used to retrieve the password for the user.
  • the memory is configured to store program instructions
  • the processor is configured to perform the following operations according to program instructions stored in the memory:
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory:
  • the updated interference picture information is displayed
  • the processor performs an operation of receiving a password and a picture factor input when the user logs in, including:
  • the password input when the user logs in and the picture factor selected from the updated interference picture information when the user logs in are received.
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory :
  • the performing, by the processor, the operation of receiving the password and the picture factor input when the user registers includes:
  • the picture selected by the user is taken as the picture factor.
  • the performing, by the processor, the operation of receiving the password and the picture factor input when the user registers includes:
  • the performing, by the processor, the performing a user-uploaded picture as a picture factor includes:
  • the user uploaded images are tailored according to uniform specifications
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory :
  • the user uploaded the image is a signature picture drawn by the user
  • the processor performs the operation of receiving the password and the picture factor input when the user logs in, including:
  • the processor performs the operation of performing user login authentication according to the account, the password, and the picture factor, including:
  • User login authentication is performed by verifying the account number, whether the password is correct, and by comparing the similarity between the picture factor and the signature picture.
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory:
  • User login authentication is performed according to the account number and the password.
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory:
  • the user After the user logs in, the user is queried according to the user's instruction whether the picture factor authentication function is enabled.
  • the picture factor authentication function is enabled on the account according to the user's instruction
  • the processor is further configured to use the memory
  • the program instructions stored in it do the following:
  • the user After the user logs in, the user is queried according to the user's instruction whether the picture factor authentication function is enabled.
  • the picture factor authentication function is cancelled according to the user's instruction
  • the processor is further configured to Program instructions stored in memory perform the following operations:
  • the user retrieves the password authentication according to the account number, the verification code, and the picture factor.
  • the performing, by the processor, the performing user login authentication according to the account, the password, and the picture factor including:
  • the processor is further configured to perform The program instructions stored in the memory perform the following operations:
  • the memory is configured to store program instructions
  • the processor is configured to perform the following operations according to program instructions stored in the memory:
  • the user retrieves the password authentication according to the account number, the verification code, and the picture factor.
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory:
  • the processor performs the operation of receiving the verification code and the picture factor input when the user retrieves the password, including:
  • the performing, by the processor, the operation of receiving the password and the picture factor input when the user registers includes:
  • the performing, by the processor, the performing a user-uploaded picture as a picture factor includes:
  • the processor is further configured to perform the following operations according to the program instructions stored in the memory :
  • the sixth possible implementation in the sixth aspect In the current mode, the picture uploaded by the user is a signature picture drawn by the user;
  • the processor performs the operation of receiving the verification code and the picture factor input when the user retrieves the password, including:
  • Performing user password recovery authentication according to the account number, the verification code, and the picture factor including:
  • the user retrieves the password authentication by verifying the account number, whether the verification code is correct, and by comparing the similarity between the picture factor and the signature picture.
  • the embodiment of the invention provides a two-factor authentication method, first obtaining an account input when a user logs in, and then querying whether the account factor authentication function is enabled for the account, and when the query result is that the image factor authentication function is enabled for the account, the user is Display the prompt information of the input picture factor, receive the password and picture factor input when the user logs in, and perform user login authentication according to the account number, password and picture factor.
  • the password is used as the first authentication factor
  • the picture is used as the second authentication factor, because the picture has the characteristics that the user can easily remember, and can be performed in the account server.
  • the storage does not need to be carried by the user, so the authentication process is simple and the user operates conveniently.
  • FIG. 1 is a system architecture diagram on which a two-factor authentication method according to an embodiment of the present invention is based;
  • FIG. 3 is a signal flow diagram of a registration method in a two-factor authentication method according to Embodiment 2 of the present invention.
  • FIG. 5 is a signal flow diagram of a method for setting a picture factor in a two-factor authentication method according to Embodiment 4 of the present invention.
  • FIG. 6 is a signal flow diagram of a method for canceling a picture factor in a two-factor authentication method according to Embodiment 5 of the present invention.
  • FIG. 7 is a flowchart of a two-factor authentication method according to Embodiment 6 of the present invention.
  • FIG. 8 is a signal flow diagram of an authentication method for retrieving a password in a two-factor authentication method according to Embodiment 7 of the present invention.
  • FIG. 10 is a structural diagram of a two-factor authentication apparatus according to Embodiment 9 of the present invention.
  • the account client module is responsible for generating a human-computer interaction interface, so that the user inputs the account, password, and picture factor through the human-computer interaction interface, and displays the authentication result.
  • the account client module is usually a child in the client application system. Module.
  • the account server module is responsible for the account, password, picture factor storage, verification, interference picture generation, account, password and picture factor input correctness authentication. Among them, the correctness verification verifies whether the account number, password and picture factor are input correctly, and can confirm that the picture factor input is correct when the picture factor input by the user is completely consistent with the stored picture factor; also can input the picture factor and storage in the user When the similarity of the picture factor is greater than the preset threshold, confirm that the picture factor input is correct. For example, when the picture factor is a signature picture, the account server module can also determine the correctness of the input of the picture factor by handwriting comparison or picture similarity comparison.
  • the execution body of the method may be A physical device including an account server module and an account client module, or when applied to the system architecture shown in FIG. 1(b), the execution body of the method may be a physical device including only the account client module. Specifically, it is applied to authentication during the login process, and the method includes:
  • Step 202 Query whether the account factor authentication function is enabled on the account.
  • the image factor authentication function may be locally queried in the account, and the other device may be queried whether the image factor authentication function is enabled.
  • the registration process may include: obtaining an account input when the user is registered; and when obtaining an instruction to enable the picture factor authentication function for the account, displaying the input picture factor a prompt information; receiving a password and a picture factor input when the user registers; performing user registration according to the account number, the password, and the picture factor, and generating interference picture information including the picture factor for the account.
  • the interference picture information may be specifically presented to the user in the form of a list for the user to select a picture factor from the list.
  • the user receives the picture factor input by the user, but is not limited to the following two methods: the first way, receiving the password input by the user; randomly generating the picture list, displaying the picture list; receiving the user from the The instruction for selecting a picture in the picture list is used as a picture factor for the picture selected by the user.
  • the second method the password input by the user is received; the instruction for uploading the image by the user is received, and the image uploaded by the user is used as the picture factor.
  • the using the image uploaded by the user as a picture factor may include: cutting a picture uploaded by the user according to a unified specification; and using the cut picture as a picture factor.
  • the picture factor set when the user is registered may be stored, so that when the user performs login authentication, the picture factor input when the user logs in is compared with the picture factor set when the user registers, when the two are consistent. To confirm that the picture factor entered when the user logs in is the correct picture factor.
  • the method may further include: displaying prompt information for sharing a picture uploaded by the user; receiving an instruction of the user, sharing the picture uploaded by the user according to the instruction, so as to be able to be according to the user
  • the uploaded image generates interference image information for other accounts.
  • the registration process may include: obtaining an account entered when the user registers; receiving an input when receiving an instruction that does not enable the picture factor authentication function for the account. Password; user registration based on the account number and the password.
  • the picture factor authentication function or the picture factor authentication function can be enabled through the account management, and the picture factor can be set, changed, or cancelled.
  • the process of enabling the picture factor authentication function may include: after the user logs in, querying whether the account is enabled with the picture factor authentication function according to the user's instruction; when the query result is that the picture factor authentication function is not enabled for the account, according to the user's instruction Enabling a picture factor authentication function for the account; displaying prompt information for inputting a picture factor; receiving a picture factor input by the user; re-registering the user according to the account number, the password, and the picture factor, and generating an inclusion for the account Interference picture information of the picture factor.
  • the process of canceling the picture factor authentication function may include: after the user logs in, querying whether the account is enabled with the picture factor authentication function according to the user's instruction; when the query result is that the picture factor authentication function is enabled for the account, according to the user's instruction Deactivating the picture factor authentication function for the account; re-registering the user according to the account number and the password.
  • Step 203 When the query result is that the picture factor authentication function is enabled for the account, the prompt information of the input picture factor is displayed.
  • Step 204 Receive a password and a picture factor input when the user logs in.
  • the interference picture information may be displayed through the user interface, and the picture factor selected by the user from the interference picture information is received.
  • the method further includes: determining whether the interference picture information is updated; and when the judgment result is that the interference picture information is updated, displaying the updated interference picture information to the user; and receiving the password and picture factor input by the user, The method includes: receiving a password input by the user and a picture factor selected by the user from the updated interference picture information.
  • Step 205 Perform user login authentication according to the account number, the password, and the picture factor.
  • the account number, the password, and the picture factor are all correct, confirming that the authentication is successful, displaying a successful login authentication result; when at least one of the account number, the password, and the picture factor is incorrect When the authentication fails, the login authentication result of the authentication failure is displayed.
  • the account is locked.
  • the time for locking the account can be configured, and the short message alarm notification can be sent to the user according to the mobile phone number bound to the account, or the email alert notification can be sent to the user according to the email address bound to the account.
  • the performing the user login authentication may include: verifying the account, whether the password is correct, and performing user login authentication by comparing the similarity between the picture factor and the signature picture. For example, when the account number and the password are correct, and the similarity between the picture factor and the signature picture is greater than a preset threshold, the authentication is confirmed to be successful.
  • step 202 When the result of the query in step 202 is that the account factor authentication function is not enabled on the account, the account is authenticated by the single factor authentication method, and specifically, the password input by the user is received; and the account and the password are used according to the account and the password. User login authentication.
  • the account is locked.
  • the embodiment of the invention provides a two-factor authentication method, first obtaining an account input when a user logs in, and then querying whether the account factor authentication function is enabled for the account, and when the query result is that the image factor authentication function is enabled for the account, the user is Display the prompt information of the input picture factor, receive the password and picture factor input by the user, and perform user login authentication according to the account number, password and picture factor.
  • the password is used as the first authentication factor
  • the picture is used as the second authentication factor, because the picture has the characteristics that the user can easily remember, and can be performed in the account server.
  • the storage does not need to be carried by the user, so the authentication process is simple and the user operates conveniently.
  • step 301 the account client obtains a registration request of the user.
  • Step 302 The account client displays a prompt message requesting the user to input an account, a password, selecting a picture, or newly uploading a picture through the user interface.
  • Step 303 The account client submits a registration request to the account server, where the registration request carries an account, a password, a selected picture information, or a picture uploaded by the user.
  • Step 304 The account server registers the account, saves the input picture information, and generates a list of interference pictures with multiple other pictures for the account.
  • step 305 the account server returns the registration result to the account client.
  • the picture factor authentication function may not be enabled, and the image or password registration is not required to be selected or loaded.
  • the image factor is subsequently selected by the user.
  • the account When not set, the account only performs password single factor authentication.
  • the user When the user selects to enable the image two-factor authentication when registering, the user is from the N pictures provided by the system. Select a picture as the picture factor, or upload a picture yourself (either a device local picture or a camera photo or software to draw a picture) as a picture factor. You can also ask the user to draw a signature image through the drawing software.
  • the login method includes a message interaction process that requires a user to select a picture factor, and the method includes:
  • step 401 the account client obtains a login request for the account.
  • Step 403 The account server queries whether the account factor authentication function is enabled in the account, and generates a query result.
  • the query information sent by the account client may also carry the previously cached interference picture list that is locally cached.
  • the account server needs to query the current interference picture list and the received interference. Whether the picture list is consistent. If they are consistent, the query result carries the identifier information of the interference picture list without updating; if not, the current interference picture list is carried in the query result.
  • the interference picture list includes a picture factor set by the user, and the interference picture list may specifically be a picture identifier or a digital abstract or a complete picture information.
  • step 404 the account server returns the query result of step 403 to the account client.
  • step 406 the account client displays a list of interference pictures, and asks the user to select a picture set by himself.
  • Step 407 The account client sends a login authentication request to the account server, where the login authentication request carries the account, the password, and the selected picture information.
  • Step 408 The correctness of the account server authentication account, the password, and the selected picture information is correct.
  • the login authentication result is confirmed as successful. Otherwise, the login authentication result is confirmed as the authentication failure.
  • the account server By selecting the picture factor, when the account server authenticates the picture factor, it compares the identifier (ID) or the digital digest or the complete picture information of the input picture information to determine whether the picture factor is selected and input correctly.
  • ID identifier
  • the account server By selecting the picture factor, when the account server authenticates the picture factor, it compares the identifier (ID) or the digital digest or the complete picture information of the input picture information to determine whether the picture factor is selected and input correctly.
  • step 409 the account server returns the login authentication result to the account client.
  • step 410 the account client displays the login authentication result.
  • the method of selecting a picture factor is mainly described. If the method of signing pictures is adopted, the specific process is different: after the account client sends the query information to the account server, the account server only returns the picture to the account client. Whether the factor authentication function is enabled or not; the account client requires the user to re-use the drawing software to draw the signature picture; the account server determines whether the picture factor is input correctly by comparing the similarity between the signature picture and the picture factor stored in the user registration.
  • FIG. 5 is a signal flow diagram of a method for setting a picture factor in a two-factor authentication method according to Embodiment 4 of the present invention.
  • the setting method includes a message interaction process for setting a picture factor after an account with no picture factor is set, and the method includes:
  • the account management interface is entered.
  • Step 502 The account client sends an inquiry to the account server according to the account management request. begging.
  • Step 503 The account server queries whether the account factor authentication function is enabled according to the query request, and obtains the query result that the account factor authentication function is not enabled for the account.
  • step 504 the account server returns the query result to the account client.
  • Step 505 The account client enables the picture factor authentication function according to the user's instruction.
  • Step 506 The account client requests the account server to obtain the interference picture list.
  • step 507 the account server returns an interference picture list to the account client.
  • the account server can randomly generate an interference picture list and then return an interference picture list to the account client.
  • Step 508 The account client displays an interference picture list, prompting the user to select a picture or upload a picture by itself, and submit a set picture factor.
  • the user When receiving the picture factor set by the user, the user may also be required to enter a password to enhance security.
  • the request can carry an account, selected pictures or newly uploaded pictures; it can also carry a password to enhance security.
  • step 510 the account server sets a picture factor for the account, and generates a list of interference pictures with multiple other pictures for the account.
  • Passwords can also be verified in this step to enhance security.
  • step 512 the account client displays the result of the successful setting of the picture factor.
  • the picture factor is selected by the user in the interference picture list, and the picture factor can also be set by using the signature picture mode.
  • FIG. 6 is a signal flow diagram of a method for canceling a picture factor in a two-factor authentication method according to Embodiment 5 of the present invention.
  • the method includes the message exchange process of canceling the picture factor after the account with the picture factor is set to be registered, and the method includes:
  • the account management interface is entered.
  • step 604 the account server sends the query result to the account client.
  • Step 606 The account client sends a request for canceling the picture factor to the account server.
  • the request can carry an account; it can also carry a password to enhance security.
  • Passwords can also be verified in this step to enhance security.
  • the password and the picture factor that are input when the user is registered may include: receiving a password input by the user when registering; receiving an instruction for uploading a picture by the user; and using the picture uploaded by the user as a picture factor.
  • the user-uploaded image is clipped according to a uniform specification; the clipped image is used as a picture factor.
  • the following process may be further included: displaying prompt information for sharing a picture uploaded by the user; receiving an instruction of the user, sharing the picture uploaded by the user according to the instruction, so as to be able to The picture uploaded by the user generates interference picture information for other accounts.
  • the uploaded picture of the user is a signature picture drawn by the user; correspondingly, in the authentication process of the user retrieving the password, the verification code input by the user when the password is retrieved and the user-drawn a picture factor; performing user recovery password authentication by verifying whether the account number, the verification code is correct, and by comparing the similarity between the picture factor and the signature picture.
  • step 704 it may first determine whether the interference picture information is updated; when the judgment result is that the interference picture information is updated, the updated interference picture information is displayed; and the verification code input when the user retrieves the password is received. And a picture factor selected from the updated interference picture information when the user retrieves the password.
  • step 804 the account server returns the query result of step 703 to the account client.
  • Step 806 The account client sends a request for obtaining a verification code to the account server.
  • step 809 the account client asks the user to input a verification code and a new password, and displays a list of interference pictures, and asks the user to select a picture set by himself.
  • the password, the verification code, and the picture factor can also be used to prevent brute force cracking, that is, after consecutive errors N times, the account is locked, and the lock time can be configured.
  • step 813 the account client displays the authentication result.
  • FIG. 9 is a structural diagram of a two-factor authentication apparatus according to Embodiment 8 of the present invention.
  • the apparatus is used to perform the two-factor authentication method provided by the embodiment of the present invention.
  • the method is applied to authentication in a login process, and the apparatus includes:
  • the query unit 902 is configured to query whether the account factor acquired by the obtaining unit 901 is enabled with the picture factor authentication function;
  • the display unit 903 is configured to display prompt information of the input picture factor when the query result of the query unit 902 is that the picture factor authentication function is enabled on the account;
  • the receiving unit 904 is configured to receive a password and a picture factor that are input when the user logs in;
  • the authentication unit 905 is configured to perform user login authentication according to the account acquired by the acquiring unit 901, the password received by the receiving unit 904, and a picture factor.
  • the device further includes:
  • the determining unit 906 is configured to determine whether the interference picture information is updated before the receiving unit 904 receives the password and the picture factor input when the user logs in;
  • the display unit 903 is further configured to: when the determination result of the determining unit 906 is that the interference picture information is updated, display the updated interference picture information;
  • the receiving unit 904 is specifically configured to receive a password input when the user logs in and a picture factor selected from the updated interference picture information when the user logs in.
  • the obtaining unit 901 is further configured to: obtain an account that is input when the user registers, before acquiring an account that is input when the user logs in;
  • the display unit 903 is further configured to: when the instruction for enabling the picture factor authentication function on the account is acquired, displaying prompt information of the input picture factor;
  • the receiving unit 904 is further configured to receive a password and a picture factor input when the user registers;
  • the device also includes:
  • the registration unit 907 is configured to perform user registration according to the account acquired by the obtaining unit 901, the password and the picture factor received by the receiving unit 904, and generate the picture due to the account Sub-interference picture information.
  • the receiving unit 904 includes:
  • a receiving subunit configured to receive a password input when the user registers
  • a display subunit configured to randomly generate a picture list, and display the picture list
  • the receiving subunit is further configured to receive an instruction for selecting a picture from the picture list when the user registers;
  • a picture factor confirmation subunit is configured to use a picture selected by the user by the receiving subunit as a picture factor.
  • the receiving unit 904 includes:
  • a receiving subunit configured to receive a password input when the user registers
  • the receiving subunit is further configured to receive an instruction that a user uploads a picture
  • the picture factor confirmation subunit is configured to use the user uploaded picture received by the receiving subunit as a picture factor.
  • the picture factor confirmation subunit is specifically configured to cut a picture uploaded by the user according to a unified specification; and the cut picture is used as a picture factor.
  • the display unit 903 is further configured to display prompt information for sharing a picture uploaded by the user;
  • the receiving unit 904 is further configured to receive an instruction of the user, and share the uploaded image of the user according to the instruction, so that the interference picture information can be generated for the other account according to the picture uploaded by the user.
  • the user-uploaded picture received by the receiving sub-unit is a signature picture drawn by the user
  • the receiving unit 904 is specifically configured to receive a password input by the user when logging in and a picture factor drawn by the user;
  • the authentication unit 905 is specifically configured to verify whether the account number acquired by the acquiring unit 901, the password received by the receiving unit 904 is correct, and the picture factor received by the receiving unit 904 and the receiver. The similarity of the signature pictures received by the unit, and the user login authentication is performed.
  • the receiving unit 904 is further configured to: when the acquiring unit 901 acquires an account that is input when the user logs in, the query unit 902 queries whether the account is enabled with the picture factor authentication function, and when the query unit The query result of 902 is that when the account factor authentication function is not enabled for the account, the password input by the user is received;
  • the authentication unit 905 is further configured to perform user login authentication according to the account acquired by the acquiring unit 901 and the password received by the receiving unit 904.
  • the querying unit 902 is further configured to: after the user logs in, query whether the account factor is enabled by the account according to an instruction of the user;
  • the device also includes:
  • the enabling unit 908 is configured to enable the picture factor authentication function on the account according to an instruction of the user when the query result of the query unit 902 is that the account factor is not enabled by the account;
  • the display unit 903 is further configured to display prompt information of the input picture factor
  • the receiving unit 904 is further configured to receive a picture factor input by the user;
  • the registration unit 907 is further configured to re-register the user according to the account, the password, and the picture factor, and generate interference picture information including the picture factor for the account.
  • the querying unit 902 is further configured to: after the user logs in, query whether the account factor is enabled by the account according to an instruction of the user;
  • the device also includes:
  • the canceling unit 909 is configured to cancel the picture factor authentication function on the account according to the instruction of the user when the query result of the query unit 902 is that the picture factor authentication function is enabled on the account;
  • the registration unit 907 is further configured to perform user registration again according to the account number and the password.
  • the obtaining unit 901 is further configured to acquire an account that is input when the user retrieves the password;
  • the query unit 902 is further configured to query whether the account factor acquired by the obtaining unit 901 is enabled with the picture factor authentication function;
  • the display unit 903 is further configured to: when the query result of the query unit 902 is that the image factor authentication function is enabled for the account, display prompt information of the input picture factor;
  • the receiving unit 904 is further configured to receive a verification code and a picture factor input by the user;
  • the authentication unit 905 is further configured to perform user recovery password authentication according to the account number, the verification code, and the picture factor.
  • the authentication unit 905 is specifically configured to:
  • the authentication failure is confirmed, and the login authentication result of the authentication failure is displayed.
  • the device further includes:
  • the locking unit 910 is configured to lock the account when the number of consecutive authentication failures of the authentication unit 905 exceeds a preset number of times.
  • FIG. 10 is a structural diagram of a two-factor authentication apparatus according to Embodiment 9 of the present invention.
  • the apparatus is used to perform the two-factor authentication method provided by the embodiment of the present invention.
  • the method is applied to the authentication in the process of retrieving a password, and the apparatus includes:
  • the obtaining unit 1001 is configured to obtain an account that is input when the user retrieves the password;
  • the query unit 1002 is configured to query whether the account obtained by the obtaining unit 1001 enables the picture factor authentication function;
  • the display unit 1003 is configured to display prompt information of the input picture factor when the query result of the query unit 1002 is that the picture factor authentication function is enabled for the account;
  • the receiving unit 1004 is configured to receive a verification code and a picture factor that are input when the user retrieves the password;
  • the authentication unit 1005 is configured to perform user recovery password authentication according to the account acquired by the acquiring unit 1001, the verification code received by the receiving unit 1004, and the picture factor.
  • the device further includes:
  • the determining unit 1006 is configured to determine whether the interference picture information is updated before the receiving unit 1004 receives the verification code and the picture factor input when the user retrieves the password;
  • the display unit 1003 is further configured to: when the determining unit 1006 determines that the interference result is an interference picture When the information is updated, the updated interference picture information is displayed;
  • the receiving unit 1004 is specifically configured to receive a verification code input when the user retrieves the password and a picture factor selected from the updated interference picture information when the user retrieves the password.
  • the obtaining unit 1001 is further configured to acquire an account that is input when the user registers, before acquiring an account that is input when the user retrieves the password;
  • the display unit 1003 is further configured to: when the instruction for enabling the picture factor authentication function on the account is acquired, displaying prompt information of the input picture factor;
  • the receiving unit 1004 is further configured to receive a password and a picture factor input when the user registers;
  • the device also includes:
  • the registration unit 1007 is configured to perform user registration according to the account acquired by the obtaining unit 1001, the password and the picture factor received by the receiving unit 1004, and generate interference picture information including the picture factor for the account.
  • the receiving unit 1004 includes:
  • a receiving subunit configured to receive a password input when the user registers
  • the receiving subunit is further configured to receive an instruction that a user uploads a picture
  • the picture factor confirmation sub-unit is used to use the picture uploaded by the user as a picture factor.
  • the picture factor confirmation subunit is specifically configured to cut a picture uploaded by the user according to a unified specification; and the cut picture is used as a picture factor.
  • the display unit 1003 is further configured to display prompt information for sharing a picture uploaded by the user;
  • the receiving unit 1004 is further configured to receive an instruction of the user, and share the uploaded image of the user according to the instruction, so that the interference picture information can be generated for the other account according to the picture uploaded by the user.
  • the user-uploaded picture received by the receiving sub-unit is a signature picture drawn by the user
  • the receiving unit 1004 is specifically configured to receive a verification code input by the user when the password is retrieved and a picture factor drawn by the user;
  • the authentication unit 1005 is specifically configured to verify whether the account number acquired by the acquiring unit 1001, the verification code received by the receiving unit 1004 is correct, and the ratio of the picture factor received by the receiving unit 1004 to the receiving.
  • the similarity of the signature pictures received by the subunits is performed by the user to retrieve the password authentication.
  • FIG. 11 is a structural diagram of a two-factor authentication device according to Embodiment 10 of the present invention.
  • the device is used to perform the two-factor authentication method provided by the embodiment of the present invention.
  • the method is applied to the authentication in the login process, and the device includes:
  • the processor 1102 The processor 1102;
  • the memory 1101 is configured to store program instructions
  • the processor 1102 is configured to perform the following operations according to the program instructions stored in the memory 1101:
  • the updated interference picture information is displayed
  • the password input when the user logs in and the picture factor selected from the updated interference picture information when the user logs in are received.
  • the processor 1102 performs the operation of receiving the password and the picture factor input when the user registers, including:
  • the user uploaded images are tailored according to uniform specifications
  • processor 1102 is further configured to perform the following operations according to the program instructions stored in the memory 1101:
  • the picture uploaded by the user is a signature picture drawn by the user
  • the processor 1102 performs the operation of performing user login authentication according to the account, the password, and the picture factor, including:
  • User login authentication is performed by verifying the account number, whether the password is correct, and by comparing the similarity between the picture factor and the signature picture.
  • processor 1102 is further configured to perform the following operations according to the program instructions stored in the memory 1101:
  • processor 1102 is further configured to perform the following operations according to the program instructions stored in the memory 1101:
  • the picture factor authentication function is enabled on the account according to the user's instruction
  • processor 1102 is further configured to perform the following operations according to the program instructions stored in the memory 1101:
  • the user After the user logs in, the user is queried according to the user's instruction whether the picture factor authentication function is enabled.
  • processor 1102 is further configured to perform the following operations according to the program instructions stored in the memory 1101:
  • the authentication failure is confirmed, and the login authentication result of the authentication failure is displayed.
  • FIG. 12 is a structural diagram of a two-factor authentication device according to Embodiment 11 of the present invention, where the device is used to perform the two-factor authentication method provided by the embodiment of the present invention, and the method is applied to the process of retrieving a password.
  • the card includes:
  • the processor 1202 The processor 1202;
  • the user retrieves the password authentication according to the account number, the verification code, and the picture factor.
  • the processor 1202 is further configured to perform the following operations according to the program instructions stored in the memory 1201:
  • the processor 1202 performs the operation of receiving the verification code and the picture factor input when the user retrieves the password, including:
  • the processor 1202 is further configured to perform the following operations according to the program instructions stored in the memory 1201:
  • the processor 1202 performs the operation of receiving the password and the picture factor input when the user registers, including:
  • the performing, by the processor 1202, the performing, by using the user-uploaded picture as a picture factor includes:
  • the user uploaded images are tailored according to uniform specifications
  • the processor 1202 is further configured to perform the following operations according to the program instructions stored in the memory 1201:

Landscapes

  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Multimedia (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Facsimiles In General (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)

Abstract

La présente invention concerne un dispositif, un appareil et un procédé d'authentification à deux facteurs. Le procédé comprend les étapes consistant : à acquérir un compte saisi par un utilisateur lors de sa connexion; à vérifier si oui ou non le compte permet une fonction d'authentification de facteur d'image; si le résultat de la vérification montre que le compte permet la fonction d'authentification de facteur d'image, à afficher un message d'invite pour entrer un facteur d'image; à recevoir un mot de passe et le facteur d'image saisi par l'utilisateur lors de sa connexion; et à effectuer une authentification de connexion utilisateur en fonction du compte, du mot de passe et du facteur d'image. Comme on peut le voir, le procédé d'authentification à deux facteurs fournis par la présente invention utilise le mot de passe comme un premier facteur d'authentification et l'image comme un second facteur d'authentification, et est avantageux en ce qu'il est facile pour l'utilisateur de se souvenir de l'image et peut être stockée au niveau d'une extrémité de serveur de compte sans nécessiter d'être transportée par l'utilisateur, permettant ainsi un processus d'authentification facile et une exploitation pratique pour l'utilisateur.
PCT/CN2015/082495 2015-06-26 2015-06-26 Dispositif, appareil et procédé d'authentification à deux facteurs Ceased WO2016206090A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2015/082495 WO2016206090A1 (fr) 2015-06-26 2015-06-26 Dispositif, appareil et procédé d'authentification à deux facteurs
CN201580029554.7A CN106489155A (zh) 2015-06-26 2015-06-26 双因子认证方法、装置和设备

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/082495 WO2016206090A1 (fr) 2015-06-26 2015-06-26 Dispositif, appareil et procédé d'authentification à deux facteurs

Publications (1)

Publication Number Publication Date
WO2016206090A1 true WO2016206090A1 (fr) 2016-12-29

Family

ID=57584481

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/082495 Ceased WO2016206090A1 (fr) 2015-06-26 2015-06-26 Dispositif, appareil et procédé d'authentification à deux facteurs

Country Status (2)

Country Link
CN (1) CN106489155A (fr)
WO (1) WO2016206090A1 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111359221A (zh) * 2020-03-08 2020-07-03 北京智明星通科技股份有限公司 一种用于手机游戏账号的防盗方法、系统及服务器
CN111611565A (zh) * 2020-05-11 2020-09-01 叶春林 自主达意式安全验证系统
US20230247026A1 (en) * 2022-01-31 2023-08-03 Citizens Financial Group, Inc. Systems and methods for secure and remote onboarding

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107818504A (zh) * 2017-09-27 2018-03-20 上海维信荟智金融科技有限公司 合同的自动化签署方法及系统
CN111695910B (zh) * 2020-06-12 2023-11-21 中国银行股份有限公司 一种安全认证的方法、装置、存储介质及电子设备
CN119783074A (zh) * 2024-12-11 2025-04-08 苏州中析生物信息有限公司 一种基于多因素认证、区块链和网络安全可视化的图像识别系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070074119A1 (en) * 2005-09-27 2007-03-29 Nec Nexsolutions, Ltd. Image array authentication system
CN101309147A (zh) * 2008-06-13 2008-11-19 兰州大学 一种基于图像口令身份认证方法
CN101663672A (zh) * 2007-02-21 2010-03-03 维杜普有限责任公司 用于图形图像认证的方法和系统
CN102354354A (zh) * 2011-09-28 2012-02-15 辽宁国兴科技有限公司 一种基于信息指纹技术的图片密码生成认证方法
CN103548031A (zh) * 2011-05-24 2014-01-29 微软公司 图片手势认证

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103067371A (zh) * 2012-12-24 2013-04-24 广州杰赛科技股份有限公司 云终端身份认证方法和系统
CN103313246B (zh) * 2013-06-05 2016-02-03 中国科学院计算技术研究所 一种无线传感网双因子认证方法和装置及其网络

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070074119A1 (en) * 2005-09-27 2007-03-29 Nec Nexsolutions, Ltd. Image array authentication system
CN101663672A (zh) * 2007-02-21 2010-03-03 维杜普有限责任公司 用于图形图像认证的方法和系统
CN101309147A (zh) * 2008-06-13 2008-11-19 兰州大学 一种基于图像口令身份认证方法
CN103548031A (zh) * 2011-05-24 2014-01-29 微软公司 图片手势认证
CN102354354A (zh) * 2011-09-28 2012-02-15 辽宁国兴科技有限公司 一种基于信息指纹技术的图片密码生成认证方法

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111359221A (zh) * 2020-03-08 2020-07-03 北京智明星通科技股份有限公司 一种用于手机游戏账号的防盗方法、系统及服务器
CN111611565A (zh) * 2020-05-11 2020-09-01 叶春林 自主达意式安全验证系统
US20230247026A1 (en) * 2022-01-31 2023-08-03 Citizens Financial Group, Inc. Systems and methods for secure and remote onboarding
US12438860B2 (en) * 2022-01-31 2025-10-07 Citizens Financial Group, Inc. Systems and methods for secure and remote onboarding

Also Published As

Publication number Publication date
CN106489155A (zh) 2017-03-08

Similar Documents

Publication Publication Date Title
US12294655B2 (en) Method of using one device to unlock another device
US10735196B2 (en) Password-less authentication for access management
US10735182B2 (en) Apparatus, system, and methods for a blockchain identity translator
US8955076B1 (en) Controlling access to a protected resource using multiple user devices
US8752145B1 (en) Biometric authentication with smart mobile device
US11184353B2 (en) Trusted status transfer between associated devices
US20210377244A1 (en) Systems and methods for identity verification via third party accounts
CN103119975B (zh) 用户账户恢复
CN111433770B (zh) 用于用户认证的方法和装置以及计算机可读介质
US20170126733A1 (en) Protection against end user account locking denial of service (dos)
WO2016206090A1 (fr) Dispositif, appareil et procédé d'authentification à deux facteurs
EP3206329A1 (fr) Procédé, dispositif, terminal et serveur de contrôle de sécurité
CN105141427A (zh) 一种基于声纹识别的登录认证方法、装置及系统
WO2019134234A1 (fr) Procédé d'ouverture de session avec prévention contre un enracinement, dispositif, appareil terminal et support d'informations
US11777942B2 (en) Transfer of trust between authentication devices
CN108121904B (zh) 解锁方法、装置、电子设备及服务器
JP2003099404A (ja) 認証サーバ装置、クライアント装置およびそれらを用いたユーザ認証システム、並びにユーザ認証方法、そのコンピュータ・プログラムおよびそのプログラムを記録した記録媒体
CN113826095A (zh) 单击登录过程
JP2025509902A (ja) 情報アクセスハンドオーバ
JP3974070B2 (ja) ユーザ認証装置、端末装置、プログラム及びコンピュータ・システム
CN115623478B (zh) 信息传输方法、装置、电子设备及可读存储介质
JP2025027754A (ja) プログラム、情報処理装置および情報処理方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15895989

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15895989

Country of ref document: EP

Kind code of ref document: A1