WO2016019804A1 - 一种校验方法和装置 - Google Patents
一种校验方法和装置 Download PDFInfo
- Publication number
- WO2016019804A1 WO2016019804A1 PCT/CN2015/084884 CN2015084884W WO2016019804A1 WO 2016019804 A1 WO2016019804 A1 WO 2016019804A1 CN 2015084884 W CN2015084884 W CN 2015084884W WO 2016019804 A1 WO2016019804 A1 WO 2016019804A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- verification
- client
- server
- mode
- verification mode
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
Definitions
- the present application relates to the field of communications technologies, and in particular, to a verification method and apparatus.
- robot registration There are many robot behaviors on the various clients of the terminal. For example: robot registration, robot login, etc. These client-side robot behaviors have many impacts on users, servers, and so on. Taking the client robot registration as an example, if malicious registration is frequent, it may cause great pressure on the server. At the same time, after the registration of the client robot, the forum will frequently publish advertisements and other issues affecting the normal management of the forum.
- verification code is often used to identify client robot behavior. For example, when the user registers, the server randomly generates a set of check codes for the user to input and verify. This approach is less experienced for normal registered users. At the same time, there is also the possibility of being recognized by the client robot, and the effect is not good.
- the present application provides a verification method and apparatus capable of effectively identifying a robot behavior of a client.
- a verification method comprising:
- the verification mode is a sensor verification of the terminal
- the acquiring the state parameter of the terminal includes: acquiring a state parameter from a sensor of the terminal.
- the verification manner includes at least one of a gravity sensor verification, a light sensor verification, and a touch sensor verification.
- the generating the prompt information according to the verification manner returned by the server includes:
- the user interface is generated according to the verification manner returned by the server, and the verification manner is included in the user interface.
- the status parameter of the terminal is re-acquired, and the status parameter is sent to the server.
- a verification method comprising:
- the generating the verification manner according to the verification mode request includes:
- the sensor verification mode supported by the model of the terminal is randomly generated.
- the generating the verification manner according to the verification mode request further includes:
- the method further includes:
- the status parameter of the terminal sent by the client When the status parameter of the terminal sent by the client is received, it is determined whether the current time exceeds the timestamp corresponding to the verification mode. If not, it is determined whether the status parameter matches the verification mode.
- the method further includes:
- a calibration device comprising:
- the request sending unit sends a verification mode request to the server
- the prompt generating unit generates prompt information according to the verification manner returned by the server, to prompt the user to input the verification mode;
- the parameter sending unit acquires the status parameter of the terminal, and sends the status parameter to the server, so that the server verifies that the verification is passed when the status parameter matches the verification mode.
- the verification mode is a sensor verification of the terminal
- the parameter sending unit specifically acquires a state parameter from a sensor of the terminal.
- the verification manner includes at least one of a gravity sensor verification, a light sensor verification, and a touch sensor verification.
- the prompt generating unit generates a user interface according to a check mode returned by the server, and the user interface includes the check mode.
- the parameter sending unit re-acquires the state parameter of the terminal, and sends the status parameter to the server.
- a calibration device comprising:
- a verification generating unit configured to generate a verification mode according to the verification manner
- the mode sending unit sends the verification mode to the client, so that the client generates the prompt information according to the verification manner;
- a parameter receiving unit receiving a status parameter of the terminal sent by the client
- the parameter check unit determines whether the state parameter matches the check mode, and when the state parameter matches the check mode, confirms that the check passes.
- the verification generating unit specifically acquires the model of the terminal where the client is located
- the sensor verification mode supported by the model of the terminal is randomly generated.
- the verification generating unit further generates a timestamp corresponding to the verification mode
- the parameter checking unit determines whether the current time exceeds the timestamp corresponding to the verification mode, and the current time does not exceed the timestamp corresponding to the verification mode. And determining whether the state parameter matches the verification mode.
- the parameter verification unit sends a message that the matching fails to the client.
- the server when the behavior of the robot behavior recognition needs to be performed, the server returns a random verification manner to the client according to the request of the client, so that the user changes the state of the terminal according to the verification manner. If the status parameter of the terminal matches the verification mode, it can be confirmed that the current behavior of the client is not the behavior of the robot, and the verification is passed.
- the behavior of the client robot can be effectively avoided, thereby improving the accuracy of the verification without reducing the user experience.
- FIG. 1 is a schematic flow chart of a verification method in an embodiment of the present application.
- FIG. 2 is a schematic flow chart of a verification method in another embodiment of the present application.
- FIG. 3 is a schematic flow chart of a verification method in another embodiment of the present application.
- FIG. 4 is a schematic diagram of a user interface for generating prompt information by a client in an embodiment of the present application.
- FIG. 5 is a schematic structural diagram of a client in an embodiment of the present application.
- FIG. 6 is a schematic structural diagram of a calibration apparatus according to an embodiment of the present application.
- FIG. 7 is a schematic structural diagram of a server in an embodiment of the present application.
- FIG. 8 is a schematic structural diagram of a calibration apparatus according to another embodiment of the present application.
- first, second, third, etc. may be used to describe various information in this application, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other.
- first information may also be referred to as the second information without departing from the scope of the present application.
- second information may also be referred to as the first information.
- word "if” as used herein may be interpreted as "when” or “when” or “in response to a determination.”
- the present application provides a verification scheme, in which a random sensor verification method is sent by the server, and after the client prompts the user to verify the sensor, the state parameter of the terminal is obtained, and the state parameter is obtained. Send to the server for verification, to identify and judge the behavior of the client robot, and enhance the user experience.
- the application provides a verification method, which is applied to the client and the server respectively.
- the verification method applied on the client includes the following steps:
- Step 101 Send a verification mode request to the server.
- the client when the client needs to perform the behavior of the robot behavior recognition, the client sends a verification mode request to the server to request the server to send a random verification mode.
- the behavior that needs to perform the robot behavior recognition can be set by the developer, such as registration, login, and the like.
- Step 102 Generate prompt information according to a verification manner returned by the server, to prompt the user to input the verification mode.
- the client generates prompt information for the user according to the verification manner returned by the server.
- the client may present the prompt information to the user by using a text, a picture, or the like through the user interface.
- the client may also broadcast the prompt information to the user by using a voice. This application does not limit this.
- step 103 the status parameter of the terminal is obtained, and the status parameter is sent to the server, so that the server verifies that the verification is passed when the status parameter matches the verification mode.
- the client after generating the prompt information, the client obtains the state parameter of the terminal, and then sends the state parameter to the server for the server to perform verification. Taking the verification of the sensor as an example, the client obtains the status parameter from the sensor of the terminal where it is located.
- the server when an action that requires robot behavior recognition occurs, the server returns a random check mode to the client according to the request of the client, so that the user changes the state of the terminal according to the check mode, if the terminal If the status parameter matches the verification mode, it can be confirmed that the current behavior of the client is not the behavior of the robot, and the verification is passed.
- the behavior of the client robot can be effectively avoided, thereby improving the accuracy of the verification without reducing the user experience.
- the verification method applied on the server includes the following steps:
- Step 201 Receive a verification mode request sent by the client.
- Step 202 Generate a verification mode according to the verification mode request.
- Step 203 Send the verification mode to the client, so that the client generates the prompt information according to the verification manner.
- the server after receiving the verification mode request sent by the client, the server randomly generates a verification mode, and returns the verification mode to the client.
- the verification method includes, but is not limited to, a verification method in which the robot behavior such as sensor verification and biometric verification is difficult to recognize.
- the verification method is implemented by means of sensor verification.
- the sensor verification includes: gravity sensor verification, light sensor verification, touch sensor verification, and the like.
- gravity sensor verification it may include: shaking the terminal N times, flipping the terminal, and the like.
- light sensor verification it may include: blocking light, for example, the user may block the light sensor of the terminal with a finger.
- touch sensor verification it may include: inputting a preset slip on the touch screen Move gestures, such as drawing two circles.
- the server may first acquire the model of the terminal where the client is located, determine the sensor that the terminal has according to the model, and then select a verification mode associated with the sensor.
- the server generates a timestamp corresponding to the verification mode, and the timestamp is a timeout period of the verification, that is, if the timestamp expires, the client sends the verification time.
- the terminal status parameter still cannot match the verification mode, and the behavior of the client is most likely the behavior of the robot, confirming that the verification fails.
- the timestamp is usually set by the developer, for example: 10 seconds, which is not limited in this application.
- Step 204 Receive a status parameter of the terminal sent by the client.
- Step 205 Determine whether the state parameter matches the verification mode, and when the state parameter matches the verification mode, confirm that the verification is passed.
- the server determines whether the status parameter of the terminal sent by the client matches the verification mode issued by the client. When the status parameter matches the verification mode, it is confirmed that the behavior of the current client is not the behavior of the robot, and the verification is passed.
- the server returns a random check mode to the client according to the request of the client, so that the user changes the state of the terminal according to the check mode, if the state parameter of the terminal Matching the verification method, it can be confirmed that the current behavior of the client is not a robot behavior, and the verification is passed.
- the behavior of the client robot can be effectively avoided, thereby improving the accuracy of the verification without reducing the user experience.
- the method includes the following steps:
- step 301 the client sends a verification mode request to the server.
- the client sends a verification mode request to the server when a preset behavior requiring robot behavior recognition occurs.
- the behavior of performing robot behavior recognition as described is an example of registration.
- the client sends a verification method. Request to the server.
- the client can also send a verification mode request to the server when the user fills in the registration information and clicks the confirmation. This application does not limit this.
- Step 302 The server receives the verification mode request sent by the client.
- Step 303 The server requests to generate a verification mode according to the verification mode.
- Step 304 The server sends the verification mode to the client.
- the server can first obtain the model of the terminal where the client is located.
- the terminal where the client is located is Iphone 5s, and the Iphone 5s includes a gravity sensor, a light sensor, and a touch sensor.
- the server can randomly generate a gravity sensor calibration mode, a light sensor verification mode, or a touch sensor verification mode, and simultaneously generate a timestamp corresponding to the verification mode.
- the verification method generated by the client is: shaking the mobile phone, the time stamp is 10 seconds.
- the client sends the generated verification method to the client and starts timing.
- Step 305 The client generates prompt information according to the verification manner returned by the server, to prompt the user to input the verification mode.
- the client After receiving the verification mode sent by the server, the client generates a prompt message to the user. Specifically, the client may prompt the user for the verification mode through a user interface.
- a user interface for generating prompt information by a client in an embodiment of the present application, in which the user can display the verification mode to the user by using a text, and can also be more imaged by using a picture or the like. The method prompts the user to the verification mode.
- Step 306 The client acquires a state parameter of the terminal, and sends the state parameter to the server.
- the client after generating the prompt information, the client obtains the state parameter of the terminal from the sensor specified by the verification mode through an API (Application Programming Interface).
- the verification method as a shaking method
- the client obtains the state parameter of the mobile phone from the gravity sensor of the Iphone 5s, and the state parameter is usually the acceleration of the mobile phone in three dimensions of the space, and then the state parameter is Sent to the server.
- Step 307 The server receives the status parameter of the terminal sent by the client, and determines whether the current time exceeds the timestamp corresponding to the verification mode. If not, step 308 is performed. If yes, then Go to step 312.
- Step 308 The server determines whether the status parameter matches the verification mode. If yes, step 309 is performed. If no, step 310 is performed.
- the mobile phone is still shaken in the verification mode, and the server determines whether the acceleration of the mobile phone in the three dimensions of the space matches the preset “shake” acceleration.
- the specific implementation method may be implemented. The related art is not described herein again.
- Step 309 the server confirms that the verification is passed, and returns a message that the verification passes to the client.
- Step 310 The server determines whether the current time exceeds the timestamp corresponding to the verification mode. If yes, step 312 is performed. If no, step 311 is performed.
- Step 311 The server returns a message that the matching fails to the client.
- the client After receiving the message that the matching fails, the client performs step 306, re-acquires the state parameter of the terminal, and sends the status parameter to the server.
- the server For the server to re-verify. This is because, after the client generates the prompt information, the user may not perform the verification mode immediately, so the status parameter acquired by the client does not match the verification mode.
- the retransmission mechanism is designed in this application. When the timestamp corresponding to the verification mode does not expire, the client can re-acquire the status parameter and send it to the server for verification to improve the accuracy of the verification.
- step 312 the server sends a message that the verification fails to the client.
- the server verifies that the status parameter sent by the client does not match the verification mode, it confirms that the registration fails.
- the server returns a random check mode to the client according to the request of the client, so that the user changes the state of the terminal according to the check mode, if the state parameter of the terminal Matching the verification method, it can be confirmed that the current behavior of the client is not a robot behavior, and the verification is passed.
- the behavior of the client robot can be effectively avoided, thereby improving the accuracy of the verification without reducing the user experience.
- the present application also provides an embodiment of a verification device.
- the embodiments of the verification device of the present application can be applied to the client and the server respectively.
- the device may be implemented by software, or may be implemented by hardware or a combination of hardware and software.
- the verification device of the present application is formed by a processor of the device in which the corresponding computer program instruction in the non-volatile memory is read into the memory.
- a verification apparatus 500 is provided, which is applied to a client, where the apparatus 500 includes: a request sending unit 501, a prompt generating unit 502, and a parameter sending. Unit 503.
- the request sending unit 501 sends a verification mode request to the server
- the prompt generating unit 502 generates prompt information according to the verification manner returned by the server, to prompt the user to input the verification mode;
- the parameter sending unit 503 is configured to obtain a status parameter of the terminal, and send the status parameter to the server, so that the server verifies that the verification is passed when the status parameter matches the verification mode.
- the verification mode is a sensor verification of the terminal
- the parameter sending unit 503 specifically acquires a state parameter from a sensor of the terminal.
- the verification manner includes at least one of a gravity sensor verification, a light sensor verification, and a touch sensor verification.
- the prompt generating unit 502 generates a user interface according to the check mode returned by the server, and the user interface includes the check mode.
- the parameter sending unit 503 re-acquires the state parameter of the terminal, and sends the status parameter to the server.
- a verification apparatus 700 is provided, which is applied to a server, where the apparatus 700 includes: a request receiving unit 701, a check generating unit 702, and a manner.
- the request receiving unit 701 receives a verification mode request sent by the client.
- the check generating unit 702 requests to generate a check mode according to the check mode
- the sending unit 703 sends the verification mode to the client, so that the client generates prompt information according to the verification manner;
- the parameter receiving unit 704 receives a status parameter of the terminal sent by the client.
- the parameter verification unit 705 determines whether the status parameter matches the verification mode, and confirms that the verification is passed when the status parameter matches the verification mode.
- the verification generating unit 702 specifically acquires the model of the terminal where the client is located;
- the sensor verification mode supported by the model of the terminal is randomly generated.
- check generating unit 702 further generates a timestamp corresponding to the check mode
- the parameter verification unit 705 determines whether the current time exceeds the timestamp corresponding to the verification mode, and the current time does not exceed the time corresponding to the verification mode. When stamping, it is determined whether the state parameter matches the check mode.
- the parameter verification unit 705 sends a message indicating that the matching fails to the client.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Telephonic Communication Services (AREA)
Abstract
本申请提供一种校验方法和装置。所述方法包括:发送校验方式请求给服务端;根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式;获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。通过本申请的技术方案可以有效避免客户端机器人行为,从而提高校验的准确性,同时不降低用户体验。
Description
本申请涉及通信技术领域,尤其涉及一种校验方法和装置。
终端的各种客户端上存在着诸多机器人行为。比如:机器人注册、机器人登录等。这些客户端机器人行为给用户、服务端等带来诸多影响。以客户端机器人注册为例,如果恶意频繁注册,将可能给服务端造成巨大压力。同时,客户端机器人在注册完成之后,还会在论坛上频繁发布广告等影响论坛的正常管理。
目前,通常采用验证码的方式来识别客户端机器人行为。比如:用户在注册的时候,服务端随机生成一组校验码以供用户输入并校验。这种方式对于正常的注册用户而言,体验较差。同时,也存在着被客户端机器人识别的可能,效果欠佳。
发明内容
有鉴于此,本申请提供一种校验方法和装置,能够有效地识别客户端的机器人行为。
具体地,本申请是通过如下技术方案实现的:
一种校验方法,所述方法包括:
发送校验方式请求给服务端;
根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式;
获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。
进一步地,所述校验方式为终端的传感器校验;
所述获取终端的状态参数包括:从所述终端的传感器上获取状态参数。
进一步地,所述校验方式包括:重力传感器校验、光线传感器校验和触摸传感器校验中的至少一种。
进一步地,所述根据服务端返回的校验方式生成提示信息包括:
根据服务端返回的校验方式生成用户界面,所述用户界面中包括所述校验方式。
进一步地,在接收到服务端返回的匹配失败消息后,重新获取所述终端的状态参数,并将所述状态参数发送给服务端。
一种校验方法,所述方法包括:
接收客户端发送的校验方式请求;
根据所述校验方式请求生成校验方式;
将所述校验方式发送给客户端,以供客户端根据所述校验方式生成提示信息;
接收客户端发送的终端的状态参数;
判断所述状态参数是否匹配所述校验方式,在所述状态参数匹配所述校验方式时,确认校验通过。
进一步地,所述根据所述校验方式请求生成校验方式包括:
获取客户端所在的终端的型号;
随机生成所述终端的型号支持的传感器校验方式。
进一步地,所述根据所述校验方式请求生成校验方式还包括:
生成所述校验方式对应的时间戳;
所述方法还包括:
在接收到客户端发送的终端的状态参数时,判断当前时间是否超过所述校验方式对应的时间戳,如果否,则判断所述状态参数是否匹配所述校验方式。
进一步地,所述方法还包括:
在所述状态参数不匹配所述校验方式,且当前时间没有超过所述校验方式对应的时间戳时,发送匹配失败的消息给客户端。
一种校验装置,所述装置包括:
请求发送单元,发送校验方式请求给服务端;
提示生成单元,根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式;
参数发送单元,获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。
进一步地,所述校验方式为终端的传感器校验;
所述参数发送单元,具体从所述终端的传感器上获取状态参数。
进一步地,所述校验方式包括:重力传感器校验、光线传感器校验和触摸传感器校验中的至少一种。
进一步地,所述提示生成单元,具体根据服务端返回的校验方式生成用户界面,所述用户界面中包括所述校验方式。
进一步地,在接收到服务端返回的匹配失败消息后,所述参数发送单元重新获取所述终端的状态参数,并将所述状态参数发送给服务端。
一种校验装置,所述装置包括:
请求接收单元,接收客户端发送的校验方式请求;
校验生成单元,根据所述校验方式请求生成校验方式;
方式发送单元,将所述校验方式发送给客户端,以供客户端根据所述校验方式生成提示信息;
参数接收单元,接收客户端发送的终端的状态参数;
参数校验单元,判断所述状态参数是否匹配所述校验方式,在所述状态参数匹配所述校验方式时,确认校验通过。
进一步地,所述校验生成单元,具体获取客户端所在的终端的型号;
随机生成所述终端的型号支持的传感器校验方式。
进一步地,所述校验生成单元,还生成所述校验方式对应的时间戳;
在接收到客户端发送的终端的状态参数时,所述参数校验单元判断当前时间是否超过所述校验方式对应的时间戳,在所述当前时间没有超过所述校验方式对应的时间戳时,判断所述状态参数是否匹配所述校验方式。
进一步地,在所述状态参数不匹配所述校验方式,且当前时间没有超过所述校验方式对应的时间戳时,所述参数校验单元发送匹配失败的消息给客户端。
由以上描述可以看出,本申请在发生需要进行机器人行为识别的行为时,服务端根据客户端的请求向客户端返回随机的校验方式,以使用户根据所述校验方式改变终端的状态,如果终端的状态参数匹配所述校验方式,则可以确认客户端的当前行为不是机器人行为,校验通过。通过本申请的技术方案,可以有效避免客户端机器人行为,从而提高校验的准确性,同时不降低用户体验。
图1是本申请一实施例中校验方法的流程示意图。
图2是本申请另一实施例中校验方法的流程示意图。
图3是本申请另一实施例中校验方法的流程示意图。
图4是本申请一实施例中客户端生成提示信息的用户界面示意图。
图5是本申请一实施例中客户端的结构示意图。
图6是本申请一实施例中校验装置的结构示意图。
图7是本申请一实施例中服务端的结构示意图。
图8是本申请另一实施例中校验装置的结构示意图。
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本申请相一致的所
有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本申请的一些方面相一致的装置和方法的例子。
在本申请使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本申请。在本申请和所附权利要求书中所使用的单数形式的“一种”、“所述”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本申请可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本申请范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”可以被解释成为“在……时”或“当……时”或“响应于确定”。
针对上述问题,本申请提供一种校验方案,由服务端下发随机的传感器校验方式,客户端将该传感器校验方式提示给用户后,获取终端的状态参数,并将所述状态参数发送给服务端进行校验,以进行客户端机器人行为的识别判断,同时提升用户体验。
下面结合具体的实施例来描述本申请的实现过程。
本申请提供一种校验方法,分别应用在客户端和服务端上。请参考图1,应用在客户端上的校验方法包括以下步骤:
步骤101,发送校验方式请求给服务端。
在本申请实施例中,客户端在发生需要进行机器人行为识别的行为时,发送校验方式请求给服务端,以请求服务端下发随机的校验方式。其中,所述需要进行机器人行为识别的行为可以由开发人员进行设置,比如:注册、登录等。
步骤102,根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式。
在本申请实施例中,客户端根据服务端返回的校验方式生成面向用户的提示信息。具体地,客户端可以将所述提示信息通过用户界面以文字、图片等方式呈现给用户,当然客户端也可以将所述提示信息通过语音的方式播报给用户。本申请对此不做限制。
步骤103,获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。
在本申请实施例中,客户端在生成提示信息后,获取终端的状态参数,然后将所述状态参数发送给服务端以供服务端进行校验。以所述校验方式为传感器校验为例,客户端从其所在的终端的传感器上获取所述状态参数。
由上述实施例可见,在发生需要进行机器人行为识别的行为时,服务端根据客户端的请求向客户端返回随机的校验方式,以使用户根据所述校验方式改变终端的状态,如果终端的状态参数匹配所述校验方式,则可以确认客户端的当前行为不是机器人行为,校验通过。通过本申请的技术方案,可以有效避免客户端机器人行为,从而提高校验的准确性,同时不降低用户体验。
请参考图2,应用在服务端上的校验方法包括以下步骤:
步骤201,接收客户端发送的校验方式请求。
步骤202,根据所述校验方式请求生成校验方式。
步骤203,将所述校验方式发送给客户端,以供客户端根据所述校验方式生成提示信息。
在本申请实施例中,服务端在接收到客户端发送的校验方式请求后,随机生成校验方式,并将该校验方式返回给客户端。所述校验方式包括但不限于传感器校验、生物校验等机器人行为难以识别的校验方式。
在本申请一种优选的实施方式中,所述校验方式采用传感器校验的方式来实现。所述传感器校验包括:重力传感器校验、光线传感器校验、触摸传感器校验等。对于重力传感器校验可以包括:摇动终端N次、翻转终端等。对于光线传感器校验可以包括:遮挡光线,比如,用户可以用手指遮挡住终端的光线传感器。对于触摸传感器校验可以包括:在触摸屏上输入预设的滑
动手势,比如:画两个圈等。
进一步地,服务端在生成校验方式之前,可以先获取客户端所在的终端的型号,根据所述型号判断终端具有的传感器,然后选择与所述传感器相关的校验方式。
更进一步地,服务端在生成校验方式的同时还会生成所述校验方式对应的时间戳,所述时间戳是校验的超时时间,即如果在所述时间戳超时时,客户端发送的终端状态参数还是不能匹配所述校验方式,则客户端的行为极有可能是机器人行为,确认校验失败。所述时间戳通常由开发人员进行设置,比如:10秒钟,本申请对此不做限制。
步骤204,接收客户端发送的终端的状态参数。
步骤205,判断所述状态参数是否匹配所述校验方式,在所述状态参数匹配所述校验方式时,确认校验通过。
在本申请中,服务端判断客户端发送的终端的状态参数是否匹配其下发的校验方式,在状态参数匹配所述校验方式时,确认当前客户端的行为不是机器人行为,校验通过。
由上述实施例可见,在需要进行机器人行为识别的场景,服务端根据客户端的请求向客户端返回随机的校验方式,以使用户根据所述校验方式改变终端的状态,如果终端的状态参数匹配所述校验方式,则可以确认客户端的当前行为不是机器人行为,验证通过。通过本申请的技术方案,可以有效避免客户端机器人行为,从而提高校验的准确性,同时不降低用户体验。
下面结合具体的实施例描述实现本申请校验方法中客户端和服务端的交互过程。
请参考图3,所述方法包括以下步骤:
步骤301,客户端发送校验方式请求给服务端。
具体地,在本步骤中,客户端在预设的需要进行机器人行为识别的行为发生时,发送校验方式请求给服务端。以所述需要进行机器人行为识别的行为是注册为例,当用户点击客户端提供的注册按钮时,客户端发送校验方式
请求给服务端。当然,在实际应用中,客户端也可以在用户填写好注册信息后点击确认的时候发送校验方式请求给服务端。本申请对此不做限制。
步骤302,服务端接收客户端发送的校验方式请求。
步骤303,服务端根据所述校验方式请求生成校验方式。
步骤304,服务端将所述校验方式发送给客户端。
在本步骤中,服务端可以先获取客户端所在的终端的型号,比如:客户端所在的终端为Iphone 5s,Iphone 5s包括重力传感器、光线传感器以及触摸传感器。服务端可以随机生成一种重力传感器校验方式、光线传感器校验方式或者触摸传感器校验方式,并同时生成所述校验方式对应的时间戳。比如:客户端生成的校验方式为:摇一摇手机,所述时间戳为10秒。客户端将生成的所述校验方式发送给客户端,并开始计时。
步骤305,客户端根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式。
在本步骤中,客户端在接收到服务端发送的校验方式后,生成提示信息给用户。具体地,客户端可以通过用户界面来提示用户所述校验方式。请参考图4,在本申请一种实施例中客户端生成提示信息的用户界面示意图,在所述用户界面中除了可以使用文字显示所述校验方式给用户,还可以通过图片等更形象的方式将所述校验方式提示给用户。
步骤306,客户端获取终端的状态参数,并将所述状态参数发送给服务端。
具体地,客户端在生成提示信息后,通过API(Application Programming Interface,应用程序编程接口)从所述校验方式指定的传感器上获取终端的状态参数。以所述校验方式为摇一摇为例,客户端从Iphone 5s的重力传感器上获取手机的状态参数,所述状态参数通常为手机在空间三个维度上的加速度,然后将所述状态参数发送给服务端。
步骤307,服务端接收客户端发送的终端的状态参数,判断当前时间是否超过所述校验方式对应的时间戳,如果否,则执行步骤308。如果是,则
执行步骤312。
步骤308,服务端判断所述状态参数是否匹配所述校验方式,如果是,则执行步骤309。如果否,则执行步骤310。
在本步骤中,仍以所述校验方式为手机摇一摇为例,服务端判断手机在空间三个维度上的加速度是否匹配预设的“摇一摇”的加速度,具体的实现方法可以参考相关技术,本申请在此不再赘述。
步骤309,服务端确认校验通过,返回校验通过的消息给客户端。
步骤310,服务端判断当前时间是否超过所述校验方式对应的时间戳,如果是,则执行步骤312。如果否,则执行步骤311。
步骤311,服务端返回匹配失败的消息给客户端,客户端在接收到所述匹配失败的消息后,执行步骤306,重新获取所述终端的状态参数,并将所述状态参数发送给服务端,以供服务端重新校验。这是因为,客户端在生成提示信息后,用户可能没有马上执行校验方式,所以就会导致客户端获取的状态参数不匹配所述校验方式。本申请设计重传机制,在所述校验方式对应的时间戳没有超时时,客户端可以重新获取状态参数,并发送给服务端进行校验,以提高校验的准确性。
步骤312,服务端发送校验失败的消息给客户端。
具体地,以注册行为为例,当服务端校验客户端发送的状态参数不匹配所述校验方式时,确认注册失败。
由上述实施例可见,在需要进行机器人行为识别的场景,服务端根据客户端的请求向客户端返回随机的校验方式,以使用户根据所述校验方式改变终端的状态,如果终端的状态参数匹配所述校验方式,则可以确认客户端的当前行为不是机器人行为,验证通过。通过本申请的技术方案,可以有效避免客户端机器人行为,从而提高校验的准确性,同时不降低用户体验。
与本申请校验方法的实施例相对应,本申请还提供了一种校验装置的实施例。
本申请校验装置的实施例可以分别应用在客户端和服务端上。本申请所
述装置可以通过软件实现,也可以通过硬件或者软硬件结合的方式实现。以软件实现为例,本申请校验装置作为一个逻辑意义上的装置,是通过其所在设备的处理器将非易失性存储器中对应的计算机程序指令读取到内存中运行形成的。
请参考图5和图6,在本申请另一实施例中,提供一种校验装置500,应用在客户端上,所述装置500包括有:请求发送单元501、提示生成单元502以及参数发送单元503。
其中,所述请求发送单元501,发送校验方式请求给服务端;
提示生成单元502,根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式;
参数发送单元503,获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。
进一步地,所述校验方式为终端的传感器校验;
所述参数发送单元503,具体从所述终端的传感器上获取状态参数。
进一步地,所述校验方式包括:重力传感器校验、光线传感器校验和触摸传感器校验中的至少一种。
进一步地,所述提示生成单元502,具体根据服务端返回的校验方式生成用户界面,所述用户界面中包括所述校验方式。
进一步地,在接收到服务端返回的匹配失败消息后,所述参数发送单元503重新获取所述终端的状态参数,并将所述状态参数发送给服务端。
请参考图7和图8,在本申请另一实施例中,提供一种校验装置700,应用在服务端上,所述装置700包括有:请求接收单元701、校验生成单元702、方式发送单元703、参数接收单元704以及参数校验单元705。
其中,所述请求接收单元701,接收客户端发送的校验方式请求;
所述校验生成单元702,根据所述校验方式请求生成校验方式;
所述方式发送单元703,将所述校验方式发送给客户端,以供客户端根据所述校验方式生成提示信息;
所述参数接收单元704,接收客户端发送的终端的状态参数;
所述参数校验单元705,判断所述状态参数是否匹配所述校验方式,在所述状态参数匹配所述校验方式时,确认校验通过。
进一步地,所述校验生成单元702,具体获取客户端所在的终端的型号;
随机生成所述终端的型号支持的传感器校验方式。
进一步地,所述校验生成单元702,还生成所述校验方式对应的时间戳;
在接收到客户端发送的终端的状态参数时,所述参数校验单元705判断当前时间是否超过所述校验方式对应的时间戳,在所述当前时间没有超过所述校验方式对应的时间戳时,判断所述状态参数是否匹配所述校验方式。
进一步地,在所述状态参数不匹配所述校验方式,且当前时间没有超过所述校验方式对应的时间戳时,所述参数校验单元705发送匹配失败的消息给客户端。
上述装置中各个单元的功能和作用的实现过程具体详见上述方法中对应步骤的实现过程,在此不再赘述。
以上所述仅为本申请的较佳实施例而已,并不用以限制本申请,凡在本申请的精神和原则之内,所做的任何修改、等同替换、改进等,均应包含在本申请保护的范围之内。
Claims (11)
- 一种校验方法,其特征在于,所述方法包括:发送校验方式请求给服务端;根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式;获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。
- 根据权利要求1所述的方法,其特征在于,所述校验方式为终端的传感器校验;所述获取终端的状态参数包括:从所述终端的传感器上获取状态参数。
- 根据权利要求2所述的方法,其特征在于,所述校验方式包括:重力传感器校验、光线传感器校验和触摸传感器校验中的至少一种。
- 根据权利要求1所述的方法,其特征在于,所述根据服务端返回的校验方式生成提示信息包括:根据服务端返回的校验方式生成用户界面,所述用户界面中包括所述校验方式。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:在接收到服务端返回的匹配失败消息后,重新获取所述终端的状态参数,并将所述状态参数发送给服务端。
- 一种校验方法,其特征在于,所述方法包括:接收客户端发送的校验方式请求;根据所述校验方式请求生成校验方式;将所述校验方式发送给客户端,以供客户端根据所述校验方式生成提示信息;接收客户端发送的终端的状态参数;判断所述状态参数是否匹配所述校验方式,在所述状态参数匹配所述校验方式时,确认校验通过。
- 根据权利要求6所述的方法,其特征在于,所述根据所述校验方式请求生成校验方式包括:获取客户端所在的终端的型号;随机生成所述终端的型号支持的传感器校验方式。
- 根据权利要求7所述的方法,其特征在于,所述根据所述校验方式请求生成校验方式还包括:生成所述校验方式对应的时间戳;所述方法还包括:在接收到客户端发送的终端的状态参数时,判断当前时间是否超过所述校验方式对应的时间戳,如果否,则判断所述状态参数是否匹配所述校验方式。
- 根据权利要求8所述的方法,其特征在于,所述方法还包括:在所述状态参数不匹配所述校验方式,且当前时间没有超过所述校验方式对应的时间戳时,发送匹配失败的消息给客户端。
- 一种校验装置,其特征在于,所述装置包括:请求发送单元,发送校验方式请求给服务端;提示生成单元,根据服务端返回的校验方式生成提示信息,以提示用户输入所述校验方式;参数发送单元,获取终端的状态参数,并将所述状态参数发送给服务端,以供服务端在校验所述状态参数匹配所述校验方式时,确认校验通过。
- 一种校验装置,其特征在于,所述装置包括:请求接收单元,接收客户端发送的校验方式请求;校验生成单元,根据所述校验方式请求生成校验方式;方式发送单元,将所述校验方式发送给客户端,以供客户端根据所述校验方式生成提示信息;参数接收单元,接收客户端发送的终端的状态参数;参数校验单元,判断所述状态参数是否匹配所述校验方式,在所述状态参数匹配所述校验方式时,确认校验通过。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201410384480.6A CN105450410A (zh) | 2014-08-06 | 2014-08-06 | 一种校验方法和装置 |
| CN201410384480.6 | 2014-08-06 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016019804A1 true WO2016019804A1 (zh) | 2016-02-11 |
Family
ID=55263130
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2015/084884 Ceased WO2016019804A1 (zh) | 2014-08-06 | 2015-07-23 | 一种校验方法和装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105450410A (zh) |
| WO (1) | WO2016019804A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112732755A (zh) * | 2020-12-30 | 2021-04-30 | 招商局金融科技有限公司 | 基于客户分群的标签值匹配联合校验方法、装置及计算机设备 |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107920044A (zh) * | 2016-10-09 | 2018-04-17 | 中国移动通信有限公司研究院 | 一种安全验证方法及装置 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20110159842A1 (en) * | 2009-02-06 | 2011-06-30 | Research In Motion Limited | Motion-Based Disabling of Messaging On A Wireless Communications Device By Differentiating A Driver From A Passenger |
| CN103036680A (zh) * | 2012-12-10 | 2013-04-10 | 中国科学院计算机网络信息中心 | 基于生物特征识别的域名认证系统及方法 |
| CN103140857A (zh) * | 2010-09-28 | 2013-06-05 | 乐天株式会社 | 认证系统、认证方法、认证装置、信息终端、程序以及信息记录介质 |
| CN103493059A (zh) * | 2010-02-12 | 2014-01-01 | 奥森泰克公司 | 用于人类存在检测的生物测定传感器及相关方法 |
| CN103685195A (zh) * | 2012-09-21 | 2014-03-26 | 华为技术有限公司 | 用户验证处理方法、用户设备和服务器 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102281138B (zh) * | 2010-06-12 | 2014-05-07 | 国民技术股份有限公司 | 一种提高验证码安全性的方法和系统 |
| CN103023638B (zh) * | 2011-09-22 | 2016-03-30 | 阿里巴巴集团控股有限公司 | 一种基于移动终端的身份验证方法及装置 |
| CN103457991B (zh) * | 2013-05-29 | 2017-03-15 | 北京奇虎科技有限公司 | 一种终端安全保护方法和系统 |
| CN103516726A (zh) * | 2013-09-22 | 2014-01-15 | 小米科技有限责任公司 | 基于终端行为的验证方法、装置、客户端、服务器及设备 |
-
2014
- 2014-08-06 CN CN201410384480.6A patent/CN105450410A/zh active Pending
-
2015
- 2015-07-23 WO PCT/CN2015/084884 patent/WO2016019804A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20110159842A1 (en) * | 2009-02-06 | 2011-06-30 | Research In Motion Limited | Motion-Based Disabling of Messaging On A Wireless Communications Device By Differentiating A Driver From A Passenger |
| CN103493059A (zh) * | 2010-02-12 | 2014-01-01 | 奥森泰克公司 | 用于人类存在检测的生物测定传感器及相关方法 |
| CN103140857A (zh) * | 2010-09-28 | 2013-06-05 | 乐天株式会社 | 认证系统、认证方法、认证装置、信息终端、程序以及信息记录介质 |
| CN103685195A (zh) * | 2012-09-21 | 2014-03-26 | 华为技术有限公司 | 用户验证处理方法、用户设备和服务器 |
| CN103036680A (zh) * | 2012-12-10 | 2013-04-10 | 中国科学院计算机网络信息中心 | 基于生物特征识别的域名认证系统及方法 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112732755A (zh) * | 2020-12-30 | 2021-04-30 | 招商局金融科技有限公司 | 基于客户分群的标签值匹配联合校验方法、装置及计算机设备 |
| CN112732755B (zh) * | 2020-12-30 | 2024-03-22 | 招商局金融科技有限公司 | 基于客户分群的标签值匹配联合校验方法、装置及计算机设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105450410A (zh) | 2016-03-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| TWI706265B (zh) | 第三方授權登錄方法及系統 | |
| CN103988169B (zh) | 基于策略符合性的安全数据访问 | |
| US20190124076A1 (en) | Method and system for verifying an account operation | |
| CN109787989B (zh) | 一种密码修改方法、系统及目标服务器和存储介质 | |
| US10116649B2 (en) | P2P connecting and establishing method and communication system using the same | |
| WO2016165536A1 (zh) | 一种身份验证方法和设备 | |
| US8453220B2 (en) | Device association | |
| CN110574350B (zh) | 执行优先生成第二因素认证的方法和系统 | |
| CN109039990B (zh) | 基于验证码进行行为验证的方法及装置 | |
| JP2015521813A (ja) | デバイス間でのアカウントの転送 | |
| EP3272093B1 (en) | Method and system for anti-phishing using smart images | |
| JP2018508858A (ja) | ユーザ端末で少なくとも1つの車両の機能を制御するサービスにユーザをサインアップする方法 | |
| CN104935438A (zh) | 用于身份验证的方法和装置 | |
| JP7078707B2 (ja) | 情報処理方法、情報処理装置、プログラム、及び情報処理端末 | |
| CN104426835B (zh) | 一种登录检测的方法、服务器、登录检测装置及其系统 | |
| CN109379193B (zh) | 一种动态防重放攻击认证方法及装置 | |
| CN103139182A (zh) | 一种允许用户访问的方法、客户端、服务器以及系统 | |
| CN103634935B (zh) | 基于wps或qss的网络接入方法和装置 | |
| WO2014086222A1 (zh) | 设置视频通话参数、和发送能力参数的方法及装置 | |
| JP2018129791A5 (zh) | ||
| CN104125267A (zh) | 账号保护方法、装置及终端设备 | |
| TW201603576A (zh) | 應用於遠端連線的驗證方法、驗證系統及其網路攝影機 | |
| US20150381366A1 (en) | Methods and apparatuses for binding token key to account | |
| WO2016019804A1 (zh) | 一种校验方法和装置 | |
| US11050743B2 (en) | Systems and methods of enabling fast user access to remote desktops |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15830279 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15830279 Country of ref document: EP Kind code of ref document: A1 |