CN109918892A - Verification code generation method, device and storage medium, computer equipment - Google Patents

Verification code generation method, device and storage medium, computer equipment Download PDF

Info

Publication number
CN109918892A
CN109918892A CN201910112933.2A CN201910112933A CN109918892A CN 109918892 A CN109918892 A CN 109918892A CN 201910112933 A CN201910112933 A CN 201910112933A CN 109918892 A CN109918892 A CN 109918892A
Authority
CN
China
Prior art keywords
pixel
risk class
terminal device
feature
product value
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201910112933.2A
Other languages
Chinese (zh)
Other versions
CN109918892B (en
Inventor
黎立桂
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Ping An Technology Shenzhen Co Ltd
Original Assignee
Ping An Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Ping An Technology Shenzhen Co Ltd filed Critical Ping An Technology Shenzhen Co Ltd
Priority to CN201910112933.2A priority Critical patent/CN109918892B/en
Publication of CN109918892A publication Critical patent/CN109918892A/en
Priority to PCT/CN2019/117236 priority patent/WO2020164268A1/en
Application granted granted Critical
Publication of CN109918892B publication Critical patent/CN109918892B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/36User authentication by graphic or iconic representation
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Collating Specific Patterns (AREA)

Abstract

The present invention provides a kind of verification code generation method, device and storage medium, computer equipment, which comprises obtains the browser feature of terminal device;According to the browser feature generating device finger print information;By the device-fingerprint information input to disaggregated model, the risk class of the terminal device is obtained;The disaggregated model is used to characterize the incidence relation of the device-fingerprint information and the risk class;The identifying code of corresponding difficulty degree value is generated according to the risk class.The above method can access the risk class of network with automated analysis terminal device, and different identifying codes is generated according to different risk class, to enhance the safety of system verifying.

Description

Verification code generation method, device and storage medium, computer equipment
Technical field
The present invention relates to online verification technique fields, specifically, the present invention relates to a kind of verifyings based on terminal device Code generating method, device and storage medium, computer equipment.
Background technique
With the development of internet technology, hacker is attacked certain operation platforms using automation by software program, such as Malice brush ticket, forum pour water.Alternatively, rival can be used software program the product platform of opponent is carried out it is constantly automatic Change access, causes the avalanche of the product operation platform of opponent.In order to avoid Machine automated attack, at present using identifying code to visit Ask that the user of platform verifies.Identifying code can be figure, text or English alphabet etc..
Pattern identifying code on the market is all the identical graphical verification code of display relative to user, and is easy to crack, even if Increase distortion and background interference, as depth learning technology develops, cracking also becomes increasingly simpler, another aspect user experience It is poor.
Summary of the invention
The present invention proposes a kind of verification code generation method based on terminal device, device and storage medium, computer equipment, With the risk class of automated analysis terminal device access network, different identifying codes is generated according to different risk class, from And enhance the safety of system verifying.
The present invention provides following scheme:
A kind of verification code generation method based on terminal device, comprising: obtain the browser feature of terminal device;According to institute State browser feature generating device finger print information;By the device-fingerprint information input to disaggregated model, obtains the terminal and set Standby risk class;The disaggregated model is used to characterize the incidence relation of the device-fingerprint information and the risk class;Root The identifying code of corresponding difficulty degree value is generated according to the risk class.
In one embodiment, the browser feature for obtaining terminal device, comprising: obtain the device screen of terminal device The pixel x1 of the horizontal direction of resolution ratio, vertical direction pixel y1, the horizontal direction of maximum screen resolution ratio can be used The pixel y2 of pixel x2, vertical direction;The first product value after calculating the pixel x1 and the pixel y1 product, The pixel x2 and the second product value after the pixel y2 product;Obtain first product value and second product The difference of value;The pixel x1, pixel y1, pixel x2, pixel y2, first product value, described second are multiplied Product value and the difference are as the browser feature.
In one embodiment, described according to the browser feature generating device finger print information, comprising: according to the pixel Point x1, pixel y1, pixel x2, pixel y2, first product value, second product value and the difference generate Resolution ratio nonlinear combination feature;According to the resolution ratio nonlinear combination feature, first product value and described second Product value generating device finger print information.
In one embodiment, the browser feature further include equipment can touch-control point number, whether support can touch-control, Verifying equipment can touch-control points and operating system it is whether consistent, verify equipment can touch-control points with whether support can touch-control be No consistent, facility information lacks one or more in degree feature.
In one embodiment, the browser feature for obtaining terminal device, according to the browser feature generating device Finger print information, comprising: obtain the browser feature of the terminal device;Judge whether system is giving birth in set period of time for the first time At identifying code;If so, obtain equipment in the browser feature can touch-control point number, whether support can touch-control, verifying Equipment can touch-control points and whether operating system consistent, verifying equipment can touch-control points with whether support can touch-control whether one It causes, at least three feature in facility information missing degree feature, the device-fingerprint information is generated according at least three feature; Otherwise, it obtains the pixel x1 of the horizontal direction of the device screen resolution ratio of terminal device, the pixel y1 of vertical direction, can be used The pixel y2 of the pixel x2 of the horizontal direction of maximum screen resolution ratio, vertical direction;Calculate the pixel x1 with it is described The second product value after the first product value after pixel y1 product, the pixel x2 and the pixel y2 product;It obtains The difference of first product value and second product value;By the pixel x1, pixel y1, pixel x2, pixel Y2, first product value, second product value and the difference are as the browser feature.
In one embodiment, the browser feature for obtaining terminal device, according to the browser feature generating device The device-fingerprint information input to disaggregated model is obtained the risk class of the terminal device, comprising: obtain by finger print information Take the browser feature of the terminal device of multiple verification time points in preset time period;According to each verification time point The browser feature generate corresponding device-fingerprint information;Each verification time point and verification time point is corresponding It is input to the disaggregated model described in device-fingerprint information input, obtains the corresponding risk class of each verification time point;Statistics The corresponding risk class of each verification time point, obtains the risk class of the terminal device in the preset time period.
In one embodiment, the risk class include the first risk class arranged from low to high according to risk class, Second risk class, third risk class and the 4th risk class;It is described that corresponding difficulty journey is generated according to the risk class The identifying code of angle value, comprising: if the risk class is first risk class, generate the identifying code of clicking operation;If institute Stating risk class is second risk class, generates the identifying code of slider type;If the risk class is the third wind Dangerous grade generates the identifying code of point selection operation;If the risk class is the 4th risk class, voice vocal print type is generated Identifying code.
A kind of identifying code generating means based on terminal device, comprising: first obtains module, for obtaining terminal device Browser feature;First generation module, for according to the browser feature generating device finger print information;Second obtains module, For obtaining the risk class of the terminal device for the device-fingerprint information input to disaggregated model;The disaggregated model For characterizing the incidence relation of the device-fingerprint information and the risk class;Second generation module, according to described risk etc. Grade generates the identifying code of corresponding difficulty degree value.
A kind of storage medium, is stored thereon with computer program;The computer program is suitable for being loaded and being held by processor Verification code generation method based on terminal device described in any of the above-described embodiment of row.
A kind of computer equipment comprising: one or more processors;Memory;One or more application program, wherein One or more of application programs are stored in the memory and are configured as being held by one or more of processors Row, one or more of application programs are configured to carry out the testing based on terminal device according to any of the above-described embodiment Demonstrate,prove code generating method.
Verification code generation method provided by the above embodiment based on terminal device sets the browser feature generation of front end After standby finger print information, by device-fingerprint information input into disaggregated model, device-fingerprint information is differentiated by disaggregated model, According to the incidence relation of device-fingerprint information and risk class, the risk etc. of the corresponding terminal device of device-fingerprint information is exported Grade.Finally, system generates corresponding identifying code according to the risk class of terminal device.Therefore, above method automated analysis is whole End equipment accesses the risk class of network, and different identifying codes is generated according to different risk class, to enhance system verifying Safety.
The additional aspect of the present invention and advantage will be set forth in part in the description, these will become from the following description Obviously, or practice through the invention is recognized.
Detailed description of the invention
Above-mentioned and/or additional aspect and advantage of the invention will become from the following description of the accompanying drawings of embodiments Obviously and it is readily appreciated that, in which:
Interaction schematic diagram of the Fig. 1 in the embodiment between server provided by the invention and terminal device;
Fig. 2 is the method stream in an a kind of embodiment of the verification code generation method based on terminal device provided by the invention Cheng Tu;
Fig. 3 is the interaction signaling diagram in an embodiment of terminal device provided by the invention and server;
Fig. 4 is the method flow diagram in an embodiment of step S100 provided by the invention;
Fig. 5 is the part side in an a kind of embodiment of the verification code generation method based on terminal device provided by the invention Method flow chart;
Fig. 6 is the structural frames in an a kind of embodiment of the identifying code generating means based on terminal device provided by the invention Figure;
Fig. 7 is the structural schematic diagram in an a kind of embodiment of computer equipment provided by the invention.
Specific embodiment
The embodiment of the present invention is described below in detail, examples of the embodiments are shown in the accompanying drawings, wherein from beginning to end Same or similar label indicates same or similar element or element with the same or similar functions.Below with reference to attached The embodiment of figure description is exemplary, and for explaining only the invention, and is not construed as limiting the claims.
Those skilled in the art of the present technique are appreciated that unless expressly stated, singular " one " used herein, " one It is a ", " described " and "the" may also comprise plural form, " first " used herein, " second " are only used for distinguishing same technology special Sign, is not limited the sequence of the technical characteristic and quantity etc..It is to be further understood that in specification of the invention The wording " comprising " used refers to that there are the feature, integer, step, operation, element and/or component, but it is not excluded that depositing Or add other one or more features, integer, step, operation, element, component and/or their group.
Those skilled in the art of the present technique are appreciated that unless otherwise defined, all terms used herein (including technology art Language and scientific term), there is meaning identical with the general understanding of those of ordinary skill in fields of the present invention.Should also Understand, those terms such as defined in the general dictionary, it should be understood that have in the context of the prior art The consistent meaning of meaning, and unless idealization or meaning too formal otherwise will not be used by specific definitions as here To explain.
A kind of verification code generation method based on terminal device provided by the invention is used for server end.Suitable for service After the network request that device is initiated according to terminal device, according to risk class, front end shows the identifying codes of different difficulty or ease again.It is real one It applies in example, should be applied in application environment as shown in Figure 1 based on the verification code generation method of terminal device.
As shown in Figure 1, server 100 and terminal device 300 are located in same 200 environment of network, server 100 and end End equipment 300 carries out the interaction of data information by network 200.In the present embodiment, terminal device 300 and server 100 into Row network communication.Server 100 and the quantity of terminal device 300 are not construed as limiting, and are only used as illustrating shown in Fig. 1.Terminal is set Standby 300 are equipped with client, for carrying out network access to server 100.User can pass through the client of terminal device 300 Information exchange is carried out with corresponding server 100.Client is corresponding with server (Server) end, follows same tricks jointly According to agreement, server 100 is enabled to parse the related data of client (such as browser) in terminal device 300, thus really Make the network access risk class of terminal device 300.
Server 100 may be, but not limited to, network server, management server, apps server, database Server, cloud server etc..Terminal device 300 may be, but not limited to, smart phone, PC (personal Computer, PC), tablet computer, personal digital assistant (personal digital assistant, PDA), mobile Internet access set Standby (mobile Internet device, MID) etc..The operating system of terminal device 300 may be, but not limited to, Android (Android) system, IOS (IPhone operating system) system, Windows phone system, Windows system Deng.
The present invention provides a kind of verification code generation method based on terminal device.It in one embodiment, as shown in Fig. 2, should Verification code generation method based on terminal device, comprising the following steps:
S100 obtains the browser feature of terminal device.
In the present embodiment, as shown in figure 3, server passes through the net that front end receiver is initiated to terminal device by browser When network access request, the browser feature of terminal device is obtained by front end.Specifically, server by utilizing front end collection terminal is set Standby browser feature include browser language, pixel ratio, color depth, device screen resolution ratio x, device screen resolution ratio y, Equipment can with screen resolution x, equipment can with screen resolution y, equipment can number, the equipment of point of touch-control whether support to touch Control, equipment can touch-control points and the whether consistent verification result of operating system, equipment can touch-control points and support can touch-control Whether consistent verification result, whether cpu class unknown, whether browser plug-in lacks, the font that is detected using JS/CSS is arranged Whether table lack, operating system whether be unknown, WebGL supplier whether lack, browser production firm whether be Whether other, operating system production firm are other, whether browser type is robot, browser plug-in, browser plug-in Whether sum, the font detected using JS/CSS sum, operating system are consistent with system platform, whether audio stack fingerprinting mentions For, the parameter information of audio stack fingerprinting, system to user agent available logic processor sum, whether install AdBlock, Whether user has distorted language, whether user has distorted screen resolution, whether user has distorted operating system, browser production Manufacturer, operating system production firm, access equipment type, operating system family and combine features described above, calculate data it is very poor, Quartile, quartile are very poor, five numbers summarize (minimum value, upper quartile, median, lower quartile, maximum in order Value) etc..
In addition, the browser characteristic information may also include the facility information missing degree feature of the terminal device.Tool Body, facility information lacks corresponding user and uses unit exception.User's validity can be carried out according to facility information missing degree to sentence Disconnected and classification judge etc..Such as lack high, normal, basic, the low middle height of correspondence user's validity.
S200, according to the browser feature generating device finger print information.
In the present embodiment, as shown in figure 3, server is believed according to the device-fingerprint that the browser feature generates terminal device Breath.Wherein, device-fingerprint information can be by number, any one of letter or multinomial form.In a specific embodiment, 32 character strings that device-fingerprint information is formed using number and lowercase.
The device-fingerprint information input to disaggregated model is obtained the risk class of the terminal device by S300;It is described Disaggregated model is used to characterize the incidence relation of the device-fingerprint information and the risk class.
In the present embodiment, as shown in figure 3, server by device-fingerprint information input into disaggregated model, by classification mould Type analyzes device-fingerprint information.For disaggregated model according to the incidence relation of device-fingerprint information and risk class, output should The risk class of the corresponding terminal device of device-fingerprint information.Wherein, disaggregated model includes the simple pattra leaves based on Gaussian Profile This disaggregated model.
In one embodiment, the browser feature for obtaining terminal device, according to the browser feature generating device The device-fingerprint information input to disaggregated model is obtained the risk class of the terminal device, comprising: obtain by finger print information Take the browser feature of the terminal device of multiple verification time points in preset time period;According to each verification time point The browser feature generate corresponding device-fingerprint information;Each verification time point and verification time point is corresponding It is input to the disaggregated model described in device-fingerprint information input, obtains the corresponding risk class of each verification time point;Statistics The corresponding risk class of each verification time point, obtains the risk class of the terminal device in the preset time period.
In this embodiment, the browser characteristic present in different time periods risk class of terminal device.Such as, it determines The excavation feature (such as -5 terminal devices of 2:00 AM probably abnormal) of 24 hours systems 12 months months excavation feature, is It is no be festivals or holidays (Spring Festival, 11 festivals or holidays etc.), whether be working day, whether be weekend.The verification time body of preset time period Whether abnormal reveal user behavior.Meanwhile user behavior can be monitored according to verification time and number.Therefore, when herein will be default Between duration in section be divided into multiple verification time points, the device-fingerprint information that each verification time point is obtained and verification time Point is input in disaggregated model together.Disaggregated model carries out risk point according to different verification time points, to device-fingerprint information Class, to export the corresponding risk class of verification time point.Further, the risk class for counting each verification time point, can be true Make the risk class of the terminal device in preset time period, so as to according to different preset time periods determine terminal this when Between risk class in section.
S400 generates the identifying code of corresponding difficulty degree value according to the risk class.
In the present embodiment, as shown in figure 3, server determines that terminal device accesses the risk of network by disaggregated model After grade, the identifying code of corresponding difficulty degree value is generated according to determining risk class.Specifically, server is by terminal device The risk for accessing network carries out grade classification, and different grades of risk corresponds to the identifying code of different difficulty degree values.According to classification The risk class of module output can match the corresponding identifying code of the risk class from system, and sending to terminal device should Corresponding identifying code.
In one embodiment, the risk class include the first risk class arranged from low to high according to risk class, Second risk class, third risk class and the 4th risk class.Step S400, comprising: if the risk class is described First risk class generates the identifying code of clicking operation;If the risk class is second risk class, sliding block class is generated The identifying code of type;If the risk class is the third risk class, the identifying code of point selection operation is generated;If described risk etc. Grade is the 4th risk class, generates the identifying code of voice vocal print type.
In a particular embodiment, server forward end sends the identifying code of different risk class.Front end is according to risk Grade shows the identifying code of different difficulty or ease.For example, the calm grade LEV1 that tests shows " clicking identifying code ", low risk level LEV2 is aobvious Show " sliding block identifying code ", risk grade LEV3 shows " clicking identifying code " that high-risk grade LEV4 shows " voice voice print verification Code ".By the equipment for surfing the net progress risk anticipation to request is sent, friendly credible equipment and malicious access are treated with a certain discrimination, from And promote user experience.
Verification code generation method provided by the above embodiment based on terminal device sets the browser feature generation of front end After standby finger print information, by device-fingerprint information input into disaggregated model, device-fingerprint information is differentiated by disaggregated model, According to the incidence relation of device-fingerprint information and risk class, the risk etc. of the corresponding terminal device of device-fingerprint information is exported Grade.Finally, system generates corresponding identifying code according to the risk class of terminal device.Therefore, above method automated analysis is whole End equipment accesses the risk class of network, and different identifying codes is generated according to different risk class, to enhance system verifying Safety.
In one embodiment, as shown in figure 4, step S100, comprising the following steps:
S110 obtains the pixel x1 of the horizontal direction of the device screen resolution ratio of terminal device, the pixel of vertical direction Point y1, the pixel x2 of the horizontal direction of maximum screen resolution ratio, the pixel y2 of vertical direction can be used.
S120, the first product value after calculating the pixel x1 and the pixel y1 product, the pixel x2 with The second product value after the pixel y2 product.
S130 obtains the difference of first product value and second product value.
S140, by the pixel x1, pixel y1, pixel x2, pixel y2, first product value, described Two product values and the difference are as the browser feature.
In this embodiment, the screen resolution of terminal device includes the screen resolution and reality that equipment itself has Maximum screen resolution ratio can be used in.It can determine that screen by the pixel in screen level direction and the pixel of vertical direction Curtain resolution ratio.The pixel x1 of the horizontal direction of device screen resolution ratio is multiplied by the embodiment with the pixel y1 of vertical direction After obtain the first product value, will can use the pixel x2 of the horizontal direction of maximum screen resolution ratio and the pixel y2 of vertical direction The second product value is obtained after multiplication.Further, the first product value and the second product value are made the difference, obtains difference.Finally, by terminal The pixel x1 of the horizontal direction of the device screen resolution ratio of equipment, vertical direction pixel y1, can be differentiated with maximum screen The pixel x2 of the horizontal direction of rate, the pixel y2 of vertical direction and the first product value, the second product value and difference conduct The browser feature.
Further, it in an embodiment of the embodiment, " is generated according to the browser feature in step S200 Device-fingerprint information ", comprising: according to the pixel x1, pixel y1, pixel x2, pixel y2, first product The resolution ratio nonlinear combination feature that value, second product value and the difference generate;It is non-linear according to the resolution ratio Assemblage characteristic, first product value and the second product value generating device finger print information.
Specifically, the product value of pixel x1 and pixel y1 are resolution_multi.Pixel x2 and pixel Y2 product value is available_resolution_multi.The difference of above-mentioned two product value is D-value.By pixel X1, pixel y1, pixel x2, pixel y2, resolution_multi, available_resolution_multi and These features of D-value generate the nonlinear combination feature based on resolution ratio as browser feature, according to these features, and will Nonlinear combination feature and product resolution_multi based on resolution ratio, product available_resolution_ Multi generating device finger print information, in the device-fingerprint information input disaggregated model that will be generated.
In addition, in an embodiment of the implementation, the browser feature further include equipment can touch-control point Number, whether support can touch-control, verifying equipment can touch-control points and whether operating system consistent, verifying equipment can touch-control points With whether support can whether touch-control consistent, one or more in facility information missing degree feature.At this point, as shown in figure 5, " the browser feature for obtaining terminal device, according to the browser feature generating device finger print information " may also include following Step:
S101 obtains the browser feature of the terminal device.
S103 judges whether system is generation identifying code for the first time in set period of time.
S201, if so, obtain equipment in the browser feature can touch-control point number, whether support can touch-control, Verifying equipment can touch-control points and operating system it is whether consistent, verify equipment can touch-control points with whether support can touch-control be No consistent, in facility information missing degree feature at least three feature, generates the device-fingerprint according at least three feature Information.
Otherwise S203 obtains the pixel x1 of the horizontal direction of the device screen resolution ratio of terminal device, vertical direction Pixel y1, the pixel x2 of the horizontal direction of maximum screen resolution ratio, the pixel y2 of vertical direction can be used;Calculate the picture Second after vegetarian refreshments x1 and the first product value after the pixel y1 product, the pixel x2 and the pixel y2 product Product value;Obtain the difference of first product value and second product value;By the pixel x1, pixel y1, pixel Point x2, pixel y2, first product value, second product value and the difference are as the browser feature.
In this embodiment, when server gets the browser feature of terminal device, first determine whether it is current whether For the generation identifying code for the first time of system in the set time period.If so, obtain browser feature in equipment can touch-control point Number, whether support can touch-control, verifying equipment can touch-control points and whether operating system consistent, verifying equipment can touch-control Points with whether support can whether touch-control consistent, at least three feature in facility information missing degree feature, according to this at least 3 A feature generates the device-fingerprint information.If it is not, then as described in above-described embodiment, according to the pixel x1, pixel y1, The resolution ratio that pixel x2, pixel y2, first product value, second product value and the difference generate is non-linear Assemblage characteristic;According to the resolution ratio nonlinear combination feature, first product value and the second product value generating device Finger print information.Therefore, server is by the embodiment, in the network access request for receiving terminal device, if for the first time Identifying code is generated, the device-fingerprint information of the terminal device can be generated according to multiple hardware conditions of terminal device, is guaranteed for the first time The property of terminal device can be recognized accurately in the identifying code of generation, enhance the safety verification of system.If it is non-generate for the first time test Code is demonstrate,proved, the device-fingerprint information of terminal device can be generated by the screen resolution of terminal device, to generate identifying code again When, shorten the time for generating identifying code, improves the efficiency for generating identifying code.
The identifying code generating means based on terminal device that the present invention also provides a kind of.In one embodiment, as shown in fig. 6, The identifying code generating means based on terminal device include the first acquisition module 10, the first generation module 20, second acquisition module 30 and second generation module 40.
First acquisition module 10 is used to obtain the browser feature of terminal device.In the present embodiment, as shown in figure 3, clothes When the network access request that business device is initiated to terminal device by browser by front end receiver, terminal device is obtained by front end Browser feature.Specifically, the browser feature of server by utilizing front end collection terminal equipment includes browser language, pixel Than, color depth, device screen resolution ratio x, device screen resolution ratio y, equipment can use screen with screen resolution x, equipment Resolution ratio y, equipment can touch-control point number, equipment whether support can touch-control, equipment can touch-control points and operating system be No consistent verification result, equipment can touch-control points and support can the whether consistent verification result of touch-control, cpu class whether not Know, whether browser plug-in lacks, whether the list of fonts that is detected using JS/CSS is lacked, operating system whether be Whether unknown, WebGL supplier lack, whether browser production firm is other, operating system production firm whether be The font that whether other, browser type are robot, browser plug-in, browser plug-in are total, are detected using JS/CSS Sum, whether operating system consistent with system platform, whether audio stack fingerprinting provides, the parameter information of audio stack fingerprinting, System is total to the available logic processor of user agent, whether install AdBlock, whether user has distorted language, Yong Hushi It is no distorted screen resolution, whether user has distorted operating system, browser production firm, operating system production firm, visit Ask device type, operating system family and combine features described above, calculate the very poor of data, quartile, quartile it is very poor, five Number summarizes (minimum value, upper quartile, median, lower quartile, maximum value in order) etc..In addition, the browser feature Information may also include the facility information missing degree feature of the terminal device.Specifically, facility information lacks corresponding user and makes Use unit exception.User's Effective judgement and classification judge etc. can be carried out by lacking degree according to facility information.Such as missing senior middle school It is low, correspond to the low middle height of user's validity.
First generation module 20 is used for according to the browser feature generating device finger print information.In the present embodiment, such as Shown in Fig. 3, server generates the device-fingerprint information of terminal device according to the browser feature.Wherein, device-fingerprint information can By number, any one of letter or multinomial to form.In a specific embodiment, device-fingerprint information using number and 32 character strings of lowercase composition.
Second, which obtains module 30, is used to the device-fingerprint information input to disaggregated model obtaining the terminal device Risk class;The disaggregated model is used to characterize the incidence relation of the device-fingerprint information and the risk class.In this reality Apply in example, as shown in figure 3, server by device-fingerprint information input into disaggregated model, by disaggregated model to device-fingerprint believe Breath is analyzed.Disaggregated model exports the device-fingerprint information pair according to the incidence relation of device-fingerprint information and risk class The risk class for the terminal device answered.Wherein, disaggregated model includes the Naive Bayes Classification Model based on Gaussian Profile.
Second generation module 40 generates the identifying code of corresponding difficulty degree value according to the risk class.In the present embodiment In, as shown in figure 3, after server determines the risk class that terminal device accesses network by disaggregated model, according to determination Risk class generate the identifying code of corresponding difficulty degree value.Specifically, server by terminal device access network risk into Row grade classification, different grades of risk correspond to the identifying code of different difficulty degree values.According to the risk etc. of categorization module output Grade, can match the corresponding identifying code of the risk class, and send the corresponding identifying code to terminal device from system.
In other embodiments, the modules in the identifying code generating means provided by the invention based on terminal device are also For executing in the verification code generation method of the present invention based on terminal device, the operation that corresponding each step executes, This is no longer described in detail.
The present invention also provides a kind of storage mediums.Computer program is stored on the storage medium;The computer program When being executed by processor, the verification code generation method described in any of the above-described embodiment based on terminal device is realized.The storage is situated between Matter can be memory.For example, built-in storage or external memory, or including both built-in storage and external memory.Interior storage Device may include read-only memory (ROM), programming ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory or random access memory.External memory may include hard disk, floppy disk, ZIP disk, USB flash disk, magnetic Band etc..Storage medium disclosed in this invention includes but is not limited to the memory of these types.Memory disclosed in this invention It is only used as example rather than as restriction.
The present invention also provides a kind of computer equipments.A kind of computer equipment includes: one or more processors;Storage Device;One or more application program.Wherein one or more of application programs are stored in the memory and are configured To be executed by one or more of processors, one or more of application programs are configured to carry out any of the above-described embodiment The verification code generation method based on terminal device.
Fig. 7 is the structural schematic diagram of the computer equipment in one embodiment of the invention.Computer equipment described in the present embodiment It can be server, personal computer and the network equipment.As shown in fig. 7, equipment include processor 703, it is memory 705, defeated Enter the devices such as unit 707 and display unit 709.It will be understood by those skilled in the art that the device structure device shown in Fig. 7 is simultaneously The restriction to all devices is not constituted, may include than illustrating more or fewer components, or the certain components of combination.Memory 705 can be used for storing application program 701 and each functional module, and processor 703 runs the application program for being stored in memory 705 701, thereby executing the various function application and data processing of equipment.Memory can be built-in storage or external memory, or Person includes both built-in storage and external memory.Built-in storage may include read-only memory (ROM), programming ROM (PROM), Electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory or random access memory.External storage Device may include hard disk, floppy disk, ZIP disk, USB flash disk, tape etc..Memory disclosed in this invention includes but is not limited to these types Memory.Memory disclosed in this invention is only used as example rather than as restriction.
Input unit 707 is used to receive the input of signal, and receives the keyword of user's input.Input unit 707 can Including touch panel and other input equipments.Touch panel collects the touch operation of user on it or nearby and (for example uses Family uses the operations of any suitable object or attachment on touch panel or near touch panel such as finger, stylus), and root According to the corresponding attachment device of preset driven by program;Other input equipments can include but is not limited to physical keyboard, function One of key (such as broadcasting control button, switch key etc.), trace ball, mouse, operating stick etc. are a variety of.Display unit 709 can be used for showing the information of user's input or be supplied to the information of user and the various menus of computer equipment.Display is single The forms such as liquid crystal display, Organic Light Emitting Diode can be used in member 709.Processor 703 is the control centre of computer equipment, benefit With the various pieces of various interfaces and the entire computer of connection, by running or executing the software being stored in memory 705 Program and/or module, and the data being stored in memory are called, perform various functions and handle data.
In one embodiment, equipment includes one or more processors 703, and one or more memories 705, and one A or multiple application programs 701.Wherein one or more of application programs 701 are stored in memory 705 and are configured To be executed by one or more of processors 703, one or more of application programs 701 are configured to carry out the above implementation Verification code generation method based on terminal device described in example.
It, can also be in addition, each functional unit in each embodiment of the present invention can integrate in a processing module It is that each unit physically exists alone, can also be integrated in two or more units in a module.Above-mentioned integrated mould Block both can take the form of hardware realization, can also be realized in the form of software function module.The integrated module is such as Fruit is realized and when sold or used as an independent product in the form of software function module, also can store in a computer In read/write memory medium.
Those of ordinary skill in the art will appreciate that realizing that all or part of the steps of above-described embodiment can pass through hardware It completes, relevant hardware can also be instructed to complete by program, which can store in a computer-readable storage medium In matter, storage medium may include memory, disk or CD etc..
The above is only some embodiments of the invention, it is noted that for the ordinary skill people of the art For member, various improvements and modifications may be made without departing from the principle of the present invention, these improvements and modifications are also answered It is considered as protection scope of the present invention.
It should be understood that each functional unit in various embodiments of the present invention can be integrated in a processing module, It can be physically existed alone, can also be integrated in two or more units in a module with each unit.It is above-mentioned integrated Module both can take the form of hardware realization, can also be realized in the form of software function module.
The above is only some embodiments of the invention, it is noted that for the ordinary skill people of the art For member, various improvements and modifications may be made without departing from the principle of the present invention, these improvements and modifications are also answered It is considered as protection scope of the present invention.

Claims (10)

1. a kind of verification code generation method based on terminal device characterized by comprising
Obtain the browser feature of terminal device;
According to the browser feature generating device finger print information;
By the device-fingerprint information input to disaggregated model, the risk class of the terminal device is obtained;The disaggregated model For characterizing the incidence relation of the device-fingerprint information and the risk class;
The identifying code of corresponding difficulty degree value is generated according to the risk class.
2. the method according to claim 1, wherein the browser feature for obtaining terminal device, comprising:
It obtains the pixel x1 of the horizontal direction of the device screen resolution ratio of terminal device, the pixel y1 of vertical direction, can be used The pixel y2 of the pixel x2 of the horizontal direction of maximum screen resolution ratio, vertical direction;
The first product value after calculating the pixel x1 and the pixel y1 product, the pixel x2 and the pixel The second product value after y2 product;
Obtain the difference of first product value and second product value;
By the pixel x1, pixel y1, pixel x2, pixel y2, first product value, second product value with And the difference is as the browser feature.
3. according to the method described in claim 2, it is characterized in that, described believe according to the browser feature generating device fingerprint Breath, comprising:
According to the pixel x1, pixel y1, pixel x2, pixel y2, first product value, second product value And the resolution ratio nonlinear combination feature that the difference generates;
Believed according to the resolution ratio nonlinear combination feature, first product value and the second product value generating device fingerprint Breath.
4. according to the method described in claim 2, it is characterized in that, the browser feature further include equipment can touch-control point Number, whether support can touch-control, verifying equipment can touch-control points and whether operating system consistent, verifying equipment can touch-control point Number with whether support can whether touch-control consistent, one or more in facility information missing degree feature.
5. according to the method described in claim 4, it is characterized in that, it is described obtain terminal device browser feature, according to institute State browser feature generating device finger print information, comprising:
Obtain the browser feature of the terminal device;
Judge whether system is generation identifying code for the first time in set period of time;
If so, obtain equipment in the browser feature can touch-control point number, whether support can touch-control, verifying equipment can Whether the points of touch-control and operating system consistent, verifying equipment can touch-control points with whether support can touch-control whether unanimously, set At least three feature in standby loss of learning degree feature generates the device-fingerprint information according at least three feature;
Otherwise, obtain the pixel x1 of the horizontal direction of the device screen resolution ratio of terminal device, the pixel y1 of vertical direction, The pixel x2 of the horizontal direction of maximum screen resolution ratio, the pixel y2 of vertical direction can be used;Calculate the pixel x1 with The second product value after the first product value after the pixel y1 product, the pixel x2 and the pixel y2 product; Obtain the difference of first product value and second product value;By the pixel x1, pixel y1, pixel x2, as Vegetarian refreshments y2, first product value, second product value and the difference are as the browser feature.
6. the method according to claim 1, wherein it is described obtain terminal device browser feature, according to institute Browser feature generating device finger print information is stated, by the device-fingerprint information input to disaggregated model, the terminal is obtained and sets Standby risk class, comprising:
Obtain the browser feature of the terminal device of multiple verification time points in preset time period;
Corresponding device-fingerprint information is generated according to the browser feature of each verification time point;
The classification will be input to described in each verification time point and the corresponding device-fingerprint information input of verification time point Model obtains the corresponding risk class of each verification time point;
The corresponding risk class of each verification time point is counted, the risk etc. of the terminal device in the preset time period is obtained Grade.
7. the method according to claim 1, wherein the risk class include according to risk class from low to high The first risk class, the second risk class, third risk class and the 4th risk class of arrangement;
The identifying code that corresponding difficulty degree value is generated according to the risk class, comprising:
If the risk class is first risk class, the identifying code of clicking operation is generated;
If the risk class is second risk class, the identifying code of slider type is generated;
If the risk class is the third risk class, the identifying code of point selection operation is generated;
If the risk class is the 4th risk class, the identifying code of voice vocal print type is generated.
8. a kind of identifying code generating means based on terminal device characterized by comprising
First obtains module, for obtaining the browser feature of terminal device;
First generation module, for according to the browser feature generating device finger print information;
Second obtains module, for obtaining the risk of the terminal device for the device-fingerprint information input to disaggregated model Grade;The disaggregated model is used to characterize the incidence relation of the device-fingerprint information and the risk class;
Second generation module generates the identifying code of corresponding difficulty degree value according to the risk class.
9. a kind of storage medium, which is characterized in that be stored thereon with computer program;The computer program is suitable for by processor The verification code generation method based on terminal device described in any one of loading and execute the claims 1 to 7.
10. a kind of computer equipment, characterized in that it comprises:
One or more processors;
Memory;
One or more application program, wherein one or more of application programs are stored in the memory and are configured To be executed by one or more of processors, one or more of application programs are configured to carry out according to claim 1 To 7 described in any item verification code generation methods based on terminal device.
CN201910112933.2A 2019-02-13 2019-02-13 Verification code generation method and device, storage medium and computer equipment Active CN109918892B (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201910112933.2A CN109918892B (en) 2019-02-13 2019-02-13 Verification code generation method and device, storage medium and computer equipment
PCT/CN2019/117236 WO2020164268A1 (en) 2019-02-13 2019-11-11 Verification code generation method and apparatus, and storage medium and computer device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910112933.2A CN109918892B (en) 2019-02-13 2019-02-13 Verification code generation method and device, storage medium and computer equipment

Publications (2)

Publication Number Publication Date
CN109918892A true CN109918892A (en) 2019-06-21
CN109918892B CN109918892B (en) 2023-11-21

Family

ID=66961571

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910112933.2A Active CN109918892B (en) 2019-02-13 2019-02-13 Verification code generation method and device, storage medium and computer equipment

Country Status (2)

Country Link
CN (1) CN109918892B (en)
WO (1) WO2020164268A1 (en)

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110362985A (en) * 2019-07-16 2019-10-22 北京天融信网络安全技术有限公司 A kind of verification method and device
CN110460993A (en) * 2019-08-21 2019-11-15 广州大学 A kind of authentication method and system based on gesture verifying
CN110472407A (en) * 2019-08-21 2019-11-19 广州大学 A kind of access authentication method and system based on gesture identifying code
CN110572700A (en) * 2019-09-19 2019-12-13 湖南快乐阳光互动娱乐传媒有限公司 Client risk identification method and system
CN110598392A (en) * 2019-09-12 2019-12-20 同盾控股有限公司 Man-machine verification method and device, storage medium and electronic equipment
WO2020164268A1 (en) * 2019-02-13 2020-08-20 平安科技(深圳)有限公司 Verification code generation method and apparatus, and storage medium and computer device
CN112131551A (en) * 2020-09-25 2020-12-25 平安国际智慧城市科技股份有限公司 Verification code verification method and device, computer equipment and readable storage medium
CN112187702A (en) * 2019-07-02 2021-01-05 北京京东尚科信息技术有限公司 Method and device for verifying client
CN112422488A (en) * 2019-08-23 2021-02-26 钉钉控股(开曼)有限公司 Screen projection method and device
CN112818340A (en) * 2021-01-20 2021-05-18 北京顶象技术有限公司 Control method and device of prevention and control system and electronic equipment
CN112948812A (en) * 2021-03-29 2021-06-11 天津车之家数据信息技术有限公司 Verification code distribution method, computing device and storage medium
CN114048449A (en) * 2022-01-11 2022-02-15 北京顶象技术有限公司 Method and device for improving security of verification code by combining cache information

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105323227A (en) * 2014-07-30 2016-02-10 腾讯科技(深圳)有限公司 Verification code image generation method and device and electronic equipment
CN106446202A (en) * 2016-09-30 2017-02-22 福建北卡科技有限公司 Anti-interference browser fingerprint generation method based on implicit characteristic acquisition
CN107046516A (en) * 2016-02-05 2017-08-15 上海行邑信息科技有限公司 A kind of air control control method and device for recognizing mobile terminal identity
CN107066974A (en) * 2017-04-17 2017-08-18 东南大学 The terminal device recognition methods that a kind of anti-browser fingerprint changes
CN107749844A (en) * 2017-10-16 2018-03-02 维沃移动通信有限公司 Auth method and mobile terminal
CN109104456A (en) * 2018-06-07 2018-12-28 北京本邦科技股份有限公司 A kind of user tracking based on browser fingerprint and propagating statistics analysis method
CN109165840A (en) * 2018-08-20 2019-01-08 平安科技(深圳)有限公司 Risk profile processing method, device, computer equipment and medium
CN109255230A (en) * 2018-09-29 2019-01-22 武汉极意网络科技有限公司 Recognition methods, system, user equipment and the storage medium of abnormal verifying behavior

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108460268A (en) * 2017-02-20 2018-08-28 阿里巴巴集团控股有限公司 Verification method and device
CN108513267A (en) * 2017-02-27 2018-09-07 中国移动通信集团浙江有限公司 Safe verification method, authentication server and the service terminal of communication service
CN109918892B (en) * 2019-02-13 2023-11-21 平安科技(深圳)有限公司 Verification code generation method and device, storage medium and computer equipment

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105323227A (en) * 2014-07-30 2016-02-10 腾讯科技(深圳)有限公司 Verification code image generation method and device and electronic equipment
CN107046516A (en) * 2016-02-05 2017-08-15 上海行邑信息科技有限公司 A kind of air control control method and device for recognizing mobile terminal identity
CN106446202A (en) * 2016-09-30 2017-02-22 福建北卡科技有限公司 Anti-interference browser fingerprint generation method based on implicit characteristic acquisition
CN107066974A (en) * 2017-04-17 2017-08-18 东南大学 The terminal device recognition methods that a kind of anti-browser fingerprint changes
CN107749844A (en) * 2017-10-16 2018-03-02 维沃移动通信有限公司 Auth method and mobile terminal
CN109104456A (en) * 2018-06-07 2018-12-28 北京本邦科技股份有限公司 A kind of user tracking based on browser fingerprint and propagating statistics analysis method
CN109165840A (en) * 2018-08-20 2019-01-08 平安科技(深圳)有限公司 Risk profile processing method, device, computer equipment and medium
CN109255230A (en) * 2018-09-29 2019-01-22 武汉极意网络科技有限公司 Recognition methods, system, user equipment and the storage medium of abnormal verifying behavior

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
任俊玲;王兴芬;王承权;: "面向电子商务的新一代验证码系统分析", 网络空间安全, no. 12, pages 34 - 39 *

Cited By (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020164268A1 (en) * 2019-02-13 2020-08-20 平安科技(深圳)有限公司 Verification code generation method and apparatus, and storage medium and computer device
CN112187702A (en) * 2019-07-02 2021-01-05 北京京东尚科信息技术有限公司 Method and device for verifying client
CN110362985A (en) * 2019-07-16 2019-10-22 北京天融信网络安全技术有限公司 A kind of verification method and device
CN110460993A (en) * 2019-08-21 2019-11-15 广州大学 A kind of authentication method and system based on gesture verifying
CN110472407A (en) * 2019-08-21 2019-11-19 广州大学 A kind of access authentication method and system based on gesture identifying code
CN112422488A (en) * 2019-08-23 2021-02-26 钉钉控股(开曼)有限公司 Screen projection method and device
CN110598392A (en) * 2019-09-12 2019-12-20 同盾控股有限公司 Man-machine verification method and device, storage medium and electronic equipment
CN110572700A (en) * 2019-09-19 2019-12-13 湖南快乐阳光互动娱乐传媒有限公司 Client risk identification method and system
CN112131551A (en) * 2020-09-25 2020-12-25 平安国际智慧城市科技股份有限公司 Verification code verification method and device, computer equipment and readable storage medium
CN112818340A (en) * 2021-01-20 2021-05-18 北京顶象技术有限公司 Control method and device of prevention and control system and electronic equipment
CN112948812A (en) * 2021-03-29 2021-06-11 天津车之家数据信息技术有限公司 Verification code distribution method, computing device and storage medium
CN114048449A (en) * 2022-01-11 2022-02-15 北京顶象技术有限公司 Method and device for improving security of verification code by combining cache information
CN114048449B (en) * 2022-01-11 2022-05-13 北京顶象技术有限公司 Method and device for improving security of verification code by combining cache information

Also Published As

Publication number Publication date
CN109918892B (en) 2023-11-21
WO2020164268A1 (en) 2020-08-20

Similar Documents

Publication Publication Date Title
CN109918892A (en) Verification code generation method, device and storage medium, computer equipment
US11736478B2 (en) Device, system, and method of user authentication based on user-specific characteristics of task performance
CN108229130B (en) Verification method and device
CN104408341B (en) Smart phone user identity identifying method based on gyroscope behavioural characteristic
Buschek et al. Improving accuracy, applicability and usability of keystroke biometrics on mobile touchscreen devices
US9298912B2 (en) System and method for distinguishing human swipe input sequence behavior and using a confidence value on a score to detect fraudsters
CN108595519A (en) Focus incident sorting technique, device and storage medium
Stanciu et al. On the effectiveness of sensor-enhanced keystroke dynamics against statistical attacks
Khan et al. Augmented reality-based mimicry attacks on behaviour-based smartphone authentication
CN105681351B (en) Verification method and system based on interactive operation, user equipment and server
CN106572049A (en) Identity verifying apparatus and method
Weng et al. Towards understanding the security of modern image captchas and underground captcha-solving services
CN103873455B (en) A kind of method and device of information checking
CN109981567A (en) Sending method, device, storage medium and the server of network authorization data
US9202035B1 (en) User authentication based on biometric handwriting aspects of a handwritten code
CN105323073A (en) Identity authentication method, identity authentication device and identity authentication system
CN109995576A (en) Recognition methods, device and the storage medium of equipment for surfing the net, computer equipment
CN104820924A (en) Online safe payment system based on handwriting authentication
CN103473492A (en) Method and user terminal for recognizing permission
CN106778151A (en) Method for identifying ID and device based on person's handwriting
CN109902459A (en) Man-machine identification verification method, system, equipment and the storage medium of WEB page
Masood et al. Touch and you’re trapp (ck) ed: Quantifying the uniqueness of touch gestures for tracking
CN108400980B (en) User identity authentication method and device, computer equipment and storage medium
CN109495513A (en) Unsupervised encryption malicious traffic stream detection method, device, equipment and medium
CN110008670A (en) Identity identifying method and device based on hand-written password

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant