WO2019200799A1 - 短信验证码的推送方法、电子装置及可读存储介质 - Google Patents
短信验证码的推送方法、电子装置及可读存储介质 Download PDFInfo
- Publication number
- WO2019200799A1 WO2019200799A1 PCT/CN2018/102098 CN2018102098W WO2019200799A1 WO 2019200799 A1 WO2019200799 A1 WO 2019200799A1 CN 2018102098 W CN2018102098 W CN 2018102098W WO 2019200799 A1 WO2019200799 A1 WO 2019200799A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- mobile phone
- verification code
- preset
- phone number
- short message
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/18—Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/55—Push-based network services
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/12—Messaging; Mailboxes; Announcements
- H04W4/14—Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD]
Definitions
- the present application relates to the field of computer technologies, and in particular, to a method for pushing a short message verification code, an electronic device, and a readable storage medium.
- SMS verification codes there are many business scenarios that use SMS verification codes.
- the method for generating SMS verification codes is generally that as long as the user applies, the SMS verification code can be obtained, that is, the existing SMS verification code is generated.
- the method does not set any security mechanism, and the security is not high.
- the existing technology is pushed to the user after generating the short message verification code, the short message verification code is pushed by the synchronous method, and the short message pushing time is slow and the efficiency is low, resulting in poor user experience.
- the purpose of the present application is to provide a method for pushing a short message verification code, an electronic device, and a readable storage medium, which are intended to improve the security and push efficiency of the short message verification code.
- a first aspect of the present application provides an electronic device, where the electronic device includes a memory and a processor, where the memory stores a push system of a short message verification code that can be run on the processor, When the push verification system of the short message verification code is executed by the processor, the following steps are implemented:
- the preset short message pushing platform is configured to push the short message verification code for the mobile phone number of the user.
- the second aspect of the present application further provides a method for pushing a short message verification code, where the method for pushing the short message verification code includes:
- the preset short message pushing platform is configured to push the short message verification code for the mobile phone number of the user.
- a third aspect of the present application further provides a computer readable storage medium, where the computer readable storage medium stores a push system of a short message verification code, and the push system of the short message verification code can be at least A processor executes the step of causing the at least one processor to perform the push method of the short message verification code as described above.
- the method for pushing the short message verification code and the electronic device and the readable storage medium proposed by the application obtain the mobile phone number of the user after receiving the request for generating the short message verification code sent by the user; and determining whether the mobile phone number of the user is in a preset blacklist If the mobile phone number of the user is not in the preset blacklist, generate a short message verification code corresponding to the mobile phone number of the user, and put the generated short message verification code into the preset queue; start a preset number of threads, press
- the preset multi-thread push rule uses a preset number of threads to read the short message verification code in the preset queue, and pushes the read short message verification code and the corresponding user mobile phone number to the preset short message pushing platform.
- the blacklist security mechanism is set, only the mobile phone number that is not in the blacklist will generate the SMS verification code, which improves the security of generating the SMS verification code.
- multi-threading is started to push the SMS verification code, which can efficiently and efficiently.
- the generated SMS verification code is quickly pushed, and the user's mobile phone receives the SMS verification code faster and improves the user experience.
- FIG. 1 is a schematic diagram of an operating environment of a preferred embodiment of a push system 10 for a short message verification code of the present application;
- FIG. 2 is a schematic diagram of multi-thread push of a short message verification code in an embodiment of a push verification system 10 of the short message verification code of the present application;
- FIG. 3 is a schematic flowchart of an embodiment of a method for pushing a short message verification code according to an embodiment of the present invention.
- FIG. 1 is a schematic diagram of an operating environment of a preferred embodiment of a push system 10 for a short message verification code of the present application.
- the push verification system 10 of the short message verification code is installed and runs in the electronic device 1.
- the electronic device 1 may include, but is not limited to, a memory 11, a processor 12, and a display 13.
- Figure 1 shows only the electronic device 1 with components 11-13, but it should be understood that not all illustrated components may be implemented, and more or fewer components may be implemented instead.
- the memory 11 is at least one type of readable computer storage medium, which in some embodiments may be an internal storage unit of the electronic device 1, such as a hard disk or memory of the electronic device 1.
- the memory 11 may also be an external storage device of the electronic device 1 in other embodiments, such as a plug-in hard disk equipped on the electronic device 1, a smart memory card (SMC), and a secure digital device. (Secure Digital, SD) card, flash card, etc.
- the memory 11 may also include both an internal storage unit of the electronic device 1 and an external storage device.
- the memory 11 is configured to store application software installed on the electronic device 1 and various types of data, such as program codes of the push system 10 of the short message verification code.
- the memory 11 can also be used to temporarily store data that has been output or is about to be output.
- the processor 12 may be a central processing unit (CPU), a microprocessor or other data processing chip for running program code or processing data stored in the memory 11, for example The push system 10 or the like that executes the short message verification code.
- CPU central processing unit
- microprocessor or other data processing chip for running program code or processing data stored in the memory 11, for example The push system 10 or the like that executes the short message verification code.
- the display 13 in some embodiments may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, an OLED (Organic Light-Emitting Diode) touch sensor, or the like.
- the display 13 is configured to display information processed in the electronic device 1 and a user interface for displaying visualization, such as a generated short message verification code, feedback information indicating whether the short message verification code is successfully pushed, and the like.
- the components 11-13 of the electronic device 1 communicate with one another via a system bus.
- the short message verification code push system 10 includes at least one computer readable instruction stored in the memory 11, the at least one computer readable instruction being executable by the processor 12 to implement various embodiments of the present application.
- the push system 10 of the short message verification code is executed by the processor 12 to implement the following steps:
- Step S1 After receiving the SMS verification code generation request sent by the user, obtain the mobile phone number of the user.
- the push system of the short message verification code receives the short message verification code generation request sent by the user, including the user's mobile phone number, for example, receiving the short message verification code generation request sent by the user through the mobile phone, the tablet computer, the self-service terminal device, and the like, such as Receiving a short message verification code generation request sent by a user on a pre-installed client in a mobile phone, a tablet computer, a self-service terminal device, or the like, or receiving the user to send on a browser system in a terminal such as a mobile phone, a tablet computer, or a self-service terminal device
- the incoming SMS verification code generation request For example, after the user inputs the mobile phone number in the specified location, click the “Get SMS verification code” button to trigger the SMS verification code generation request.
- step S2 it is determined whether the mobile phone number of the user is in a preset blacklist.
- Step S3 If the mobile phone number of the user is not in the preset blacklist, generate a short message verification code corresponding to the mobile phone number of the user, and put the generated short message verification code into the preset queue.
- a blacklist security mechanism is set, and a blacklist is set to restrict access by a part of malicious or illegal users.
- the credit score of the evaluation user is calculated according to the setting rule.
- the user ie, his mobile phone number
- the success rate x of the user's SMS verification code verification is calculated every day, and the user's credit score r is calculated by the following formula:
- the trigger frequency of the user can also be detected at the same time, for example, clicking the “Get SMS verification code” button to trigger the frequency of the SMS verification code generation request. If the trigger frequency is higher than the preset frequency threshold, it is considered that there is a short frequency high frequency request SMS. If the verification code is suspected of malicious or illegal access, the calculated credit score r of the user is lowered by a preset value (for example, 20% can be lowered), and the final credit score of each user is obtained, and the final credit score will be suspected malicious. Or users who illegally access the behavior are blacklisted. For example, each user has an initial credit score of 100. If a user finally calculates a credit score lower than 80, the user (ie, his mobile phone number) is added to the blacklist.
- the entire process ends, and there is no need to proceed to the next step. To limit access by some malicious or illegal users.
- the token token of the mobile phone number of the user is further detected.
- a token security policy is configured, and the number of consecutive authentication errors is limited by setting a token. For example, it can be determined whether the token of the mobile phone number of the user meets the condition for generating a short message verification code. Specifically, if it is detected that the user sends the SMS verification code generation request on the system for the first time, the user is assigned a new token token, and the initialization count is 0; if a user fails to authenticate after applying the SMS verification code once, Then, the user's token token count will be incremented by one.
- the user's token token count is continuously incremented by one. If the user successfully authenticates after applying for the short message verification code once, the user's token token is initialized, that is, recounted from 0. If the user's token token count reaches the preset maximum number of token counts n, it indicates that the number of consecutive authentication errors of the user reaches the maximum number of counts n, and the token token of the user is automatically locked for m minutes. When it is detected that the token token of the current user's mobile phone number is locked, it is determined that the token of the mobile phone number of the user does not meet the condition for generating the short message verification code. This avoids wasting too much system resources on users with excessive number of consecutive authentication errors (possibly malicious or illegal users) to save system resources to process requests from other normal users.
- the entire process ends without going to the next step.
- a blacklist security mechanism and a token security policy are set, so as to limit the user who applies for generating the short message verification code, only if the user's mobile phone number is not in the blacklist, and the user's mobile phone If the token of the number meets the condition for generating the SMS verification code, that is, if the mobile phone number of the user does not have multiple consecutive authentication errors, the SMS verification code corresponding to the mobile phone number of the user is generated, and the generated SMS verification code is put into the pre- Set the queue to ensure the security of generating SMS verification code.
- Step S4 starting a preset number of threads, using a preset multi-thread push rule and using a preset number of threads to read the short message verification code in the preset queue, and the read short message verification code and the corresponding user mobile phone The number is pushed to the preset SMS push platform to push the SMS verification code for the mobile phone number of the user.
- the short message verification code is generated (for example, the token token of the user's mobile phone number and preset parameters such as a preset variable factor may be generated.
- the signature factor in the user request is calculated, and the generated SMS verification code of the user's mobile phone number is put into the preset queue.
- HASH processing is performed according to the mobile phone number of the user, and the HASH processed number is mapped to a preset number of partitions (for example, corresponding to 0 to 31 partitions), and at least a preset number is automatically started when the preset multi-thread processing application is started ( For example, 32 threads use a preset number (such as 32) of threads to extract the HASH number in the corresponding partition, and use a preset number (such as 32) of threads to read the preset queue corresponding to the number.
- the SMS verification code finally pushes the number extracted from the corresponding partition and the short message verification code corresponding to the number in the read preset queue to the preset short message platform, so as to send the short message verification code for the number.
- the multi-thread push of the short message verification code is realized, and the short message push time is effectively shortened.
- FIG. 2 is a schematic diagram of multi-thread push of the short message verification code in an embodiment of the push verification system 10 of the short message verification code.
- the preset multi-thread processing application includes three instances of A, B, and C, and first performs HASH processing according to the mobile phone number to obtain a number corresponding to each mobile phone number.
- the HASH value can be recorded as HASH (phone), and the HASH value corresponding to each mobile phone number is mapped to 0 to 31 partitions. If three instances of A, B, and C are currently enabled, each instance will start 32 threads to process the data of the corresponding partition, that is, the number HASH value.
- the user's mobile phone number is used to send the SMS verification code.
- a blacklist security mechanism and a token security policy are set, so as to limit the users who apply for generating the short message verification code, and the blacklist can effectively limit the malicious or illegal users. Access, by setting a token can effectively limit the number of consecutive authentication errors for users, thereby improving the security of generating SMS verification codes.
- multi-threading is started to push the short message verification code, and the generated short message verification code can be quickly and efficiently transmitted, and the user mobile phone receives the short message verification code faster and improves the user experience. .
- FIG. 3 is a schematic flowchart of a method for pushing a short message verification code according to an embodiment of the present invention.
- the method for pushing a short message verification code includes the following steps:
- Step S10 After receiving the SMS verification code generation request sent by the user, obtain the mobile phone number of the user.
- the push system of the short message verification code receives the short message verification code generation request sent by the user, including the user's mobile phone number, for example, receiving the short message verification code generation request sent by the user through the mobile phone, the tablet computer, the self-service terminal device, and the like, such as Receiving a short message verification code generation request sent by a user on a pre-installed client in a mobile phone, a tablet computer, a self-service terminal device, or the like, or receiving the user to send on a browser system in a terminal such as a mobile phone, a tablet computer, or a self-service terminal device
- the incoming SMS verification code generation request For example, after the user enters the mobile phone number in the specified location, click the “Get SMS Verification Code” button to trigger the SMS verification code generation request.
- step S20 it is determined whether the mobile phone number of the user is in a preset blacklist.
- Step S30 If the mobile phone number of the user is not in the preset blacklist, generate a short message verification code corresponding to the mobile phone number of the user, and put the generated short message verification code into the preset queue.
- a blacklist security mechanism is set, and a blacklist is set to restrict access by a part of malicious or illegal users.
- the credit score of the evaluation user is calculated according to the setting rule.
- the user ie, his mobile phone number
- the success rate x of the user's SMS verification code verification is calculated every day, and the user's credit score r is calculated by the following formula:
- the trigger frequency of the user can also be detected at the same time, for example, clicking the “Get SMS verification code” button to trigger the frequency of the SMS verification code generation request. If the trigger frequency is higher than the preset frequency threshold, it is considered that there is a short frequency high frequency request SMS. If the verification code is suspected of malicious or illegal access, the calculated credit score r of the user is lowered by a preset value (for example, 20% can be lowered), and the final credit score of each user is obtained, and the final credit score will be suspected malicious. Or users who illegally access the behavior are blacklisted. For example, each user has an initial credit score of 100. If a user finally calculates a credit score lower than 80, the user (ie, his mobile phone number) is added to the blacklist.
- the entire process ends, and there is no need to proceed to the next step. To limit access by some malicious or illegal users.
- the token token of the mobile phone number of the user is further detected.
- a token security policy is configured, and the number of consecutive authentication errors is limited by setting a token. For example, whether the token of the mobile phone number of the user is consistent with the condition for generating the short message verification code. Specifically, if it is detected that the user sends the SMS verification code generation request on the system for the first time, the user is assigned a new token token, and the initialization count is 0; if a user fails to authenticate after applying the SMS verification code once, Then, the user's token token count will be incremented by one.
- the user's token token count is continuously incremented by one. If the user successfully authenticates after applying for the short message verification code once, the user's token token is initialized, that is, recounted from 0. If the user's token token count reaches the preset maximum number of token counts n, it indicates that the number of consecutive authentication errors of the user reaches the maximum number of counts n, and the token token of the user is automatically locked for m minutes. When it is detected that the token token of the current user's mobile phone number is locked, it is determined that the token of the mobile phone number of the user does not meet the condition for generating the short message verification code. This avoids wasting too much system resources on users with excessive number of consecutive authentication errors (possibly malicious or illegal users) to save system resources to process requests from other normal users.
- the entire process ends without going to the next step.
- a blacklist security mechanism and a token security policy are set, so as to limit the user who applies for generating the short message verification code, only if the user's mobile phone number is not in the blacklist, and the user's mobile phone If the token of the number meets the condition for generating the SMS verification code, that is, if the mobile phone number of the user does not have multiple consecutive authentication errors, the SMS verification code corresponding to the mobile phone number of the user is generated, and the generated SMS verification code is put into the pre- Set the queue to ensure the security of generating SMS verification code.
- Step S40 starting a preset number of threads, using a preset multi-thread push rule and using a preset number of threads to read the short message verification code in the preset queue, and the read short message verification code and the corresponding user mobile phone The number is pushed to the preset SMS push platform to push the SMS verification code for the mobile phone number of the user.
- the short message verification code is generated (for example, the token token of the user's mobile phone number and preset parameters such as a preset variable factor may be generated.
- the signature factor in the user request is calculated, and the generated SMS verification code of the user's mobile phone number is put into the preset queue.
- HASH processing is performed according to the mobile phone number of the user, and the HASH processed number is mapped to a preset number of partitions (for example, corresponding to 0 to 31 partitions), and at least a preset number is automatically started when the preset multi-thread processing application is started ( For example, 32 threads use a preset number (such as 32) of threads to extract the HASH number in the corresponding partition, and use a preset number (such as 32) of threads to read the preset queue corresponding to the number.
- the SMS verification code finally pushes the number extracted from the corresponding partition and the short message verification code corresponding to the number in the read preset queue to the preset short message platform, so as to send the short message verification code for the number.
- the multi-thread push of the short message verification code is realized, and the short message push time is effectively shortened.
- the preset multi-thread processing application includes three instances of A, B, and C, and first performs HASH processing according to the mobile phone number, and obtains each The HASH value corresponding to the mobile phone number can be recorded as HASH (phone), and the HASH value corresponding to each mobile phone number is mapped to 0 to 31 partition. If three instances of A, B, and C are currently enabled, each instance will start 32 threads to process the data of the corresponding partition, that is, the number HASH value.
- the user's mobile phone number is used to send the SMS verification code.
- a blacklist security mechanism and a token security policy are set, so as to limit the users who apply for generating the short message verification code, and the blacklist can effectively limit the malicious or illegal users. Access, by setting a token can effectively limit the number of consecutive authentication errors for users, thereby improving the security of generating SMS verification codes.
- multi-threading is started to push the short message verification code, and the generated short message verification code can be quickly and efficiently transmitted, and the user mobile phone receives the short message verification code faster and improves the user experience. .
- the present application further provides a computer readable storage medium storing a push verification system of a short message verification code, the push verification system of the short message verification code being executable by at least one processor to enable the The at least one processor performs the steps of the method for pushing the short message verification code in the foregoing embodiment, and the specific implementation processes of the steps S10, S20, and S30 of the method for pushing the short message verification code are as described above, and details are not described herein again.
- the foregoing embodiment method can be implemented by means of software plus a necessary general hardware platform, and can also be implemented by hardware, but in many cases, the former is A better implementation.
- the technical solution of the present application which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a storage medium (such as ROM/RAM, disk,
- the optical disc includes a number of instructions for causing a terminal device (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to perform the methods described in various embodiments of the present application.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Telephonic Communication Services (AREA)
- Telephone Function (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请涉及一种短信验证码的推送方法、电子装置及可读存储介质,该方法包括:收到用户发出的短信验证码生成请求后,获取用户手机号码;判断用户手机号码是否在预设的黑名单中;若用户手机号码不在预设的黑名单中,则生成用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台。本申请提高了生成短信验证码的安全性,同时,启动多线程来进行短信验证码的推送,能高效率地快速推送出生成的短信验证码,用户手机接收到短信验证码的速度更快,提高用户体验。
Description
优先权申明
本申请基于巴黎公约申明享有2018年04月17日递交的申请号为CN 2018103450291、名称为“短信验证码的推送方法、电子装置及可读存储介质”中国专利申请的优先权,该中国专利申请的整体内容以参考的方式结合在本申请中。
本申请涉及计算机技术领域,尤其涉及一种短信验证码的推送方法、电子装置及可读存储介质。
目前,对于大型互联网金融企业,有很多业务场景都会使用到短信验证码,现有技术中生成短信验证码的方法一般是只要用户申请,均能获取到短信验证码,即现有生成短信验证码的方法都没有设置任何安全机制,安全性不高。而且,现有技术在生成短信验证码后推送给用户时,采用等同步方式推送短信验证码,短信推送时间缓慢,效率低下,造成用户体验不佳。
发明内容
本申请的目的在于提供一种短信验证码的推送方法、电子装置及可读存储介质,旨在提高短信验证码的安全性及推送效率。
为实现上述目的,本申请第一方面提供一种电子装置,所述电子装置包括存储器、处理器,所述存储器上存储有可在所述处理器上运行的短信验证码的推送系统,所述短信验证码的推送系统被所述处理器执行时实现如下步骤:
收到用户发出的短信验证码生成请求后,获取用户手机号码;
判断所述用户手机号码是否在预设的黑名单中;
若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;
启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
此外,为实现上述目的,本申请第二方面还提供一种短信验证码的推送方法,所述短信验证码的推送方法包括:
收到用户发出的短信验证码生成请求后,获取用户手机号码;
判断所述用户手机号码是否在预设的黑名单中;
若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;
启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
进一步地,为实现上述目的,本申请第三方面还提供一种计算机可读存储介质,所述计算机可读存储介质存储有短信验证码的推送系统,所述短信验证码的推送系统可被至少一个处理器执行,以使所述至少一个处理器执行如上述的短信验证码的推送方法的步骤。
本申请提出的短信验证码的推送方法、电子装置及可读存储介质,在收到用户发出的短信验证码生成请求后,获取用户手机号码;判断所述用户手机号码是否在预设的黑名单中;若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台。由于设置了黑名单安全机制,只有不在黑名单中的手机号码才会生成短信验证码,提高了生成短信验证码的安全性,同时,启动多线程来进行短信验证码的推送,能高效率地快速推送出生成的短信验证码,用户手机接收到短信验证码的速度更快,提高用户体验。
图1为本申请短信验证码的推送系统10较佳实施例的运行环境示意图;
图2为本申请短信验证码的推送系统10一实施例中短信验证码的多线程推送示意图;
图3为本申请短信验证码的推送方法一实施例的流程示意图。
为了使本申请的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本申请进行进一步详细说明。应当理解,此处所描述的具体实施例仅用以解释本申请,并不用于限定本申请。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
需要说明的是,在本申请中涉及“第一”、“第二”等的描述仅 用于描述目的,而不能理解为指示或暗示其相对重要性或者隐含指明所指示的技术特征的数量。由此,限定有“第一”、“第二”的特征可以明示或者隐含地包括至少一个该特征。另外,各个实施例之间的技术方案可以相互结合,但是必须是以本领域普通技术人员能够实现为基础,当技术方案的结合出现相互矛盾或无法实现时应当认为这种技术方案的结合不存在,也不在本申请要求的保护范围之内。
本申请提供一种短信验证码的推送系统。请参阅图1,是本申请短信验证码的推送系统10较佳实施例的运行环境示意图。
在本实施例中,所述的短信验证码的推送系统10安装并运行于电子装置1中。该电子装置1可包括,但不仅限于,存储器11、处理器12及显示器13。图1仅示出了具有组件11-13的电子装置1,但是应理解的是,并不要求实施所有示出的组件,可以替代的实施更多或者更少的组件。
所述存储器11为至少一种类型的可读计算机存储介质,所述存储器11在一些实施例中可以是所述电子装置1的内部存储单元,例如该电子装置1的硬盘或内存。所述存储器11在另一些实施例中也可以是所述电子装置1的外部存储设备,例如所述电子装置1上配备的插接式硬盘,智能存储卡(Smart Media Card,SMC),安全数字(Secure Digital,SD)卡,闪存卡(Flash Card)等。进一步地,所述存储器11还可以既包括所述电子装置1的内部存储单元也包括外部存储设备。所述存储器11用于存储安装于所述电子装置1的应用软件及各类数据,例如所述短信验证码的推送系统10的程序代码等。所述存储器11还可以用于暂时地存储已经输出或者将要输出的数据。
所述处理器12在一些实施例中可以是一中央处理器(Central Processing Unit,CPU),微处理器或其他数据处理芯片,用于运行所述存储器11中存储的程序代码或处理数据,例如执行所述短信验证码的推送系统10等。
所述显示器13在一些实施例中可以是LED显示器、液晶显示器、触控式液晶显示器以及OLED(Organic Light-Emitting Diode,有机发光二极管)触摸器等。所述显示器13用于显示在所述电子装置1中处理的信息以及用于显示可视化的用户界面,例如生成的短信验证码、短信验证码是否推送成功的反馈信息等。所述电子装置1的部件11-13通过系统总线相互通信。
短信验证码的推送系统10包括至少一个存储在所述存储器11中的计算机可读指令,该至少一个计算机可读指令可被所述处理器12执行,以实现本申请各实施例。
其中,上述短信验证码的推送系统10被所述处理器12执行时实 现如下步骤:
步骤S1,收到用户发出的短信验证码生成请求后,获取用户手机号码。
本实施例中,短信验证码的推送系统接收用户发出的包含用户手机号码的短信验证码生成请求,例如,接收用户通过手机、平板电脑、自助终端设备等终端发送的短信验证码生成请求,如接收用户在手机、平板电脑、自助终端设备等终端中预先安装的客户端上发送来的短信验证码生成请求,或接收用户在手机、平板电脑、自助终端设备等终端中的浏览器系统上发送来的短信验证码生成请求。例如,用户在指定位置输入手机号码后,点击“获取短信验证码”按钮,从而触发短信验证码生成请求。
步骤S2,判断所述用户手机号码是否在预设的黑名单中。
步骤S3,若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
本实施例中设置有黑名单安全机制,通过设置黑名单来限制部分恶意或者非法用户的访问。具体地,根据设定规则计算评估用户的信用评分,当计算出用户的信用评分低于预先设定的评分阈值时,则将该用户(即其手机号码)加入黑名单中。例如,为每个用户设定初始信用分100,统计用户每天进行短信验证码验证的成功率x,并通过如下公式计算得到用户的信用评分r:
r=(2/(1+e^ax))-1
其中,0≤x≤1,a为根据经验预先设置的常数,例如,本实施例中根据经验可设置a=-6。此外,还可同时检测用户的触发频率,例如点击“获取短信验证码”按钮来触发短信验证码生成请求的频率,若触发频率高于预设频率阈值,则认为存在短时间内高频率请求短信验证码的疑似恶意或非法访问行为,则将计算得到的该用户的信用评分r下调预设值(例如可下调20%),得到每个用户最终的信用评分,根据最终信用评分将有疑似恶意或非法访问行为的用户加入黑名单。例如,每个用户初始信用分100,如果有用户最终计算得到的信用分低于80,则将该用户(即其手机号码)加入黑名单中。
若判断当前发出短信验证码生成请求的用户手机号码在预设的黑名单中,则整个流程结束,无需进入下一步操作。以限制部分恶意或者非法用户的访问。
若判断当前发出短信验证码生成请求的用户手机号码不在预设的黑名单中,则进一步地,检测该用户手机号码的令牌token。本实施例中配置有令牌安全策略,通过设置令牌来限制用户连续认证错误次数,如可判断该用户手机号码的令牌是否符合生成短信验证码的条 件。具体地,如果检测到用户是第一次在系统上发出短信验证码生成请求,则为用户分配一个新的令牌token,初始化计数为0;如果一个用户在一次申请短信验证码后认证失败,则将会对该用户的令牌token计数加1,若接着连续认证失败,则将该用户的令牌token计数连续加1。如果用户在一次申请短信验证码后认证成功,则将该用户的令牌token初始化,即从0开始重新计数。若有用户的令牌token计数达到预先设定的token最大计数次数n,则说明该用户连续认证错误次数达到最大计数次数n,将会对该用户的令牌token自动锁定m分钟。在检测到当前用户手机号码的令牌token为被锁定的状态时,则判断该用户手机号码的令牌不符合生成短信验证码的条件。从而避免在连续认证错误次数过多的用户(可能为恶意或非法用户)上浪费太多系统资源,以节省系统资源来处理其他正常用户的请求。
若判断当前用户手机号码的令牌不符合生成短信验证码的条件(即该用户手机号码连续认证错误次数达到最大计数次数n),则整个流程结束,无需进入下一步操作。
本实施例中在生成短信验证码时,设置有黑名单安全机制和令牌安全策略,以此来对申请生成短信验证码的用户进行限制,只有在用户手机号码不在黑名单中,且用户手机号码的令牌符合生成短信验证码的条件即该用户手机号码没有多次连续认证错误的情况下,才会生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列,保证了生成短信验证码的安全性。
步骤S4,启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
本实施例中,为所述用户手机号码生成对应的短信验证码后,对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
具体的,若判断当前用户手机号码的令牌符合生成短信验证码的条件,则生成短信验证码(例如,可利用该用户手机号码的令牌token及预设参数如预先设定的可变因子,用户请求中的签名因子等计算得到),并将生成的该用户手机号码的短信验证码放入预设队列。同时,根据用户手机号码进行HASH处理,将HASH处理后的号码映射到预设数量的分区(如对应0到31分区)中,在预设多线程处理应用 程序启动时自动启动至少预设数量(如32个)的线程,利用预设数量(如32个)的线程提取对应分区中HASH后的号码,并利用预设数量(如32个)的线程读取预设队列中与该号码对应的短信验证码,最后将从对应分区中提取的号码和读取的预设队列中与该号码对应的短信验证码一起推送到预设的短信平台,以针对该号码进行短信验证码的发送。从而实现短信验证码的多线程推送,有效地缩短短信推送时间。
如图2所示,图2为本申请短信验证码的推送系统10一实施例中短信验证码的多线程推送示意图。在图2中一种具体的短信验证码推送应用场景中,预设多线程处理应用程序中包括A、B、C三个实例,首先根据手机号码进行HASH处理,得到每个手机号码对应的号码HASH值如可记为HASH(phone),将每个手机号码对应的号码HASH值映射到0到31分区。如果当前启动了A、B、C三个实例,每个实例将会启动32个线程分别处理对应分区的数据即号码HASH值。提取到对应分区中的号码HASH值后,读取预设队列中与各个手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
本实施例中在生成短信验证码时,设置有黑名单安全机制和令牌安全策略,以此来对申请生成短信验证码的用户进行限制,通过设置黑名单可有效限制部分恶意或者非法用户的访问,通过设置令牌可有效限制用户连续认证错误次数,从而提高生成短信验证码的安全性。同时,在推送生成的短信验证码时,启动多线程来进行短信验证码的推送,能高效率地快速推送出生成的短信验证码,用户手机接收到短信验证码的速度更快,提高用户体验。
如图3所示,图3为本申请短信验证码的推送方法一实施例的流程示意图,该短信验证码的推送方法包括以下步骤:
步骤S10,收到用户发出的短信验证码生成请求后,获取用户手机号码。
本实施例中,短信验证码的推送系统接收用户发出的包含用户手机号码的短信验证码生成请求,例如,接收用户通过手机、平板电脑、自助终端设备等终端发送的短信验证码生成请求,如接收用户在手机、平板电脑、自助终端设备等终端中预先安装的客户端上发送来的短信验证码生成请求,或接收用户在手机、平板电脑、自助终端设备等终端中的浏览器系统上发送来的短信验证码生成请求。例如,用户在指定位置输入手机号码后,点击“获取短信验证码”按钮,从而触 发短信验证码生成请求。
步骤S20,判断所述用户手机号码是否在预设的黑名单中。
步骤S30,若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
本实施例中设置有黑名单安全机制,通过设置黑名单来限制部分恶意或者非法用户的访问。具体地,根据设定规则计算评估用户的信用评分,当计算出用户的信用评分低于预先设定的评分阈值时,则将该用户(即其手机号码)加入黑名单中。例如,为每个用户设定初始信用分100,统计用户每天进行短信验证码验证的成功率x,并通过如下公式计算得到用户的信用评分r:
r=(2/(1+e^ax))-1
其中,0≤x≤1,a为根据经验预先设置的常数,例如,本实施例中根据经验可设置a=-6。此外,还可同时检测用户的触发频率,例如点击“获取短信验证码”按钮来触发短信验证码生成请求的频率,若触发频率高于预设频率阈值,则认为存在短时间内高频率请求短信验证码的疑似恶意或非法访问行为,则将计算得到的该用户的信用评分r下调预设值(例如可下调20%),得到每个用户最终的信用评分,根据最终信用评分将有疑似恶意或非法访问行为的用户加入黑名单。例如,每个用户初始信用分100,如果有用户最终计算得到的信用分低于80,则将该用户(即其手机号码)加入黑名单中。
若判断当前发出短信验证码生成请求的用户手机号码在预设的黑名单中,则整个流程结束,无需进入下一步操作。以限制部分恶意或者非法用户的访问。
若判断当前发出短信验证码生成请求的用户手机号码不在预设的黑名单中,则进一步地,检测该用户手机号码的令牌token。本实施例中配置有令牌安全策略,通过设置令牌来限制用户连续认证错误次数,如可判断该用户手机号码的令牌是否符合生成短信验证码的条件。具体地,如果检测到用户是第一次在系统上发出短信验证码生成请求,则为用户分配一个新的令牌token,初始化计数为0;如果一个用户在一次申请短信验证码后认证失败,则将会对该用户的令牌token计数加1,若接着连续认证失败,则将该用户的令牌token计数连续加1。如果用户在一次申请短信验证码后认证成功,则将该用户的令牌token初始化,即从0开始重新计数。若有用户的令牌token计数达到预先设定的token最大计数次数n,则说明该用户连续认证错误次数达到最大计数次数n,将会对该用户的令牌token自动锁定m分钟。在检测到当前用户手机号码的令牌token为被锁定的状态时,则判断该用户手机号码的令牌不符合生成短信验证码的条件。从而避 免在连续认证错误次数过多的用户(可能为恶意或非法用户)上浪费太多系统资源,以节省系统资源来处理其他正常用户的请求。
若判断当前用户手机号码的令牌不符合生成短信验证码的条件(即该用户手机号码连续认证错误次数达到最大计数次数n),则整个流程结束,无需进入下一步操作。
本实施例中在生成短信验证码时,设置有黑名单安全机制和令牌安全策略,以此来对申请生成短信验证码的用户进行限制,只有在用户手机号码不在黑名单中,且用户手机号码的令牌符合生成短信验证码的条件即该用户手机号码没有多次连续认证错误的情况下,才会生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列,保证了生成短信验证码的安全性。
步骤S40,启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
本实施例中,为所述用户手机号码生成对应的短信验证码后,对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
具体的,若判断当前用户手机号码的令牌符合生成短信验证码的条件,则生成短信验证码(例如,可利用该用户手机号码的令牌token及预设参数如预先设定的可变因子,用户请求中的签名因子等计算得到),并将生成的该用户手机号码的短信验证码放入预设队列。同时,根据用户手机号码进行HASH处理,将HASH处理后的号码映射到预设数量的分区(如对应0到31分区)中,在预设多线程处理应用程序启动时自动启动至少预设数量(如32个)的线程,利用预设数量(如32个)的线程提取对应分区中HASH后的号码,并利用预设数量(如32个)的线程读取预设队列中与该号码对应的短信验证码,最后将从对应分区中提取的号码和读取的预设队列中与该号码对应的短信验证码一起推送到预设的短信平台,以针对该号码进行短信验证码的发送。从而实现短信验证码的多线程推送,有效地缩短短信推送时间。
如图2所示,在图2中一种具体的短信验证码推送应用场景中,预设多线程处理应用程序中包括A、B、C三个实例,首先根据手机号码进行HASH处理,得到每个手机号码对应的号码HASH值如可 记为HASH(phone),将每个手机号码对应的号码HASH值映射到0到31分区。如果当前启动了A、B、C三个实例,每个实例将会启动32个线程分别处理对应分区的数据即号码HASH值。提取到对应分区中的号码HASH值后,读取预设队列中与各个手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
本实施例中在生成短信验证码时,设置有黑名单安全机制和令牌安全策略,以此来对申请生成短信验证码的用户进行限制,通过设置黑名单可有效限制部分恶意或者非法用户的访问,通过设置令牌可有效限制用户连续认证错误次数,从而提高生成短信验证码的安全性。同时,在推送生成的短信验证码时,启动多线程来进行短信验证码的推送,能高效率地快速推送出生成的短信验证码,用户手机接收到短信验证码的速度更快,提高用户体验。
此外,本申请还提供一种计算机可读存储介质,所述计算机可读存储介质存储有短信验证码的推送系统,所述短信验证码的推送系统可被至少一个处理器执行,以使所述至少一个处理器执行如上述实施例中的短信验证码的推送方法的步骤,该短信验证码的推送方法的步骤S10、S20、S30等具体实施过程如上文所述,在此不再赘述。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件来实现,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
以上参照附图说明了本申请的优选实施例,并非因此局限本申请的权利范围。上述本申请实施例序号仅仅为了描述,不代表实施例的 优劣。另外,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。
本领域技术人员不脱离本申请的范围和实质,可以有多种变型方案实现本申请,比如作为一个实施例的特征可用于另一实施例而得到又一实施例。凡在运用本申请的技术构思之内所作的任何修改、等同替换和改进,均应在本申请的权利范围之内。
Claims (20)
- 一种电子装置,其特征在于,所述电子装置包括存储器、处理器,所述存储器上存储有可在所述处理器上运行的短信验证码的推送系统,所述短信验证码的推送系统被所述处理器执行时实现如下步骤:收到用户发出的短信验证码生成请求后,获取用户手机号码;判断所述用户手机号码是否在预设的黑名单中;若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
- 如权利要求1所述的电子装置,其特征在于,在所述判断所述用户手机号码是否在预设的黑名单中的步骤之前,所述处理器还用于执行所述短信验证码的推送系统,以实现以下步骤:统计申请短信验证码的每个手机号码每天进行短信验证码验证的成功率x,根据成功率x计算每个手机号码的信用评分,公式如下:r=(2/(1+e^ax))-1其中,0≤x≤1,a为预设常数参数,r为信用评分,若有手机号码的信用评分低于预设评分阈值,则将该手机号码加入预设的黑名单中。
- 如权利要求2所述的电子装置,其特征在于,在所述判断所述用户手机号码是否在预设的黑名单中的步骤之前,所述处理器还用于执行所述短信验证码的推送系统,以实现以下步骤:检测每个手机号码触发短信验证码生成请求的频率;若有手机号码触发短信验证码生成请求的频率高于预设频率阈值,则将该手机号码的信用评分下调预设值,若下调预设值后的信用评分低于预设评分阈值,则将该手机号码加入预设的黑名单中。
- 如权利要求1所述的电子装置,其特征在于,所述短信验证码的推送系统被所述处理器执行实现所述启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台的步骤时,包括:对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读 取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
- 如权利要求2所述的电子装置,其特征在于,所述短信验证码的推送系统被所述处理器执行实现所述启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台的步骤时,包括:对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
- 如权利要求3所述的电子装置,其特征在于,所述短信验证码的推送系统被所述处理器执行实现所述启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台的步骤时,包括:对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
- 如权利要求1所述的电子装置,其特征在于,所述处理器还用于执行所述短信验证码的推送系统,以实现以下步骤:为申请短信验证码的每个手机号码分配一个令牌,若手机号码为首次申请短信验证码,则为首次申请短信验证码的手机号码分配的令牌计数为0;若手机号码在申请短信验证码后认证失败,则对该认证失败手机号码的令牌计数加1,若该手机号码连续认证失败,则对该手机号码的令牌计数连续加1;若该手机号码在申请短信验证码后认证成功,则对该手机号码的令牌计数初始化为0;监测申请短信验证码的每个手机号码的令牌计数,若有手机号码的令牌计数达到预设计数阈值,则将令牌计数达到预设计数阈值的手机号码的令牌在预设时间内进行锁定;所述若所述用户手机号码不在预设的黑名单中,则生成所述用户 手机号码对应的短信验证码,并将生成的短信验证码放入预设队列的步骤包括:若所述用户手机号码不在预设的黑名单中,则分析所述用户手机号码的令牌状态;若分析所述用户手机号码的令牌没有被锁定,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
- 如权利要求2所述的电子装置,其特征在于,所述处理器还用于执行所述短信验证码的推送系统,以实现以下步骤:为申请短信验证码的每个手机号码分配一个令牌,若手机号码为首次申请短信验证码,则为首次申请短信验证码的手机号码分配的令牌计数为0;若手机号码在申请短信验证码后认证失败,则对该认证失败手机号码的令牌计数加1,若该手机号码连续认证失败,则对该手机号码的令牌计数连续加1;若该手机号码在申请短信验证码后认证成功,则对该手机号码的令牌计数初始化为0;监测申请短信验证码的每个手机号码的令牌计数,若有手机号码的令牌计数达到预设计数阈值,则将令牌计数达到预设计数阈值的手机号码的令牌在预设时间内进行锁定;所述若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列的步骤包括:若所述用户手机号码不在预设的黑名单中,则分析所述用户手机号码的令牌状态;若分析所述用户手机号码的令牌没有被锁定,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
- 如权利要求3所述的电子装置,其特征在于,所述处理器还用于执行所述短信验证码的推送系统,以实现以下步骤:为申请短信验证码的每个手机号码分配一个令牌,若手机号码为首次申请短信验证码,则为首次申请短信验证码的手机号码分配的令牌计数为0;若手机号码在申请短信验证码后认证失败,则对该认证失败手机号码的令牌计数加1,若该手机号码连续认证失败,则对该手机号码的令牌计数连续加1;若该手机号码在申请短信验证码后认证成功,则对该手机号码的令牌计数初始化为0;监测申请短信验证码的每个手机号码的令牌计数,若有手机号码的令牌计数达到预设计数阈值,则将令牌计数达到预设计数阈值的手机号码的令牌在预设时间内进行锁定;所述若所述用户手机号码不在预设的黑名单中,则生成所述用户 手机号码对应的短信验证码,并将生成的短信验证码放入预设队列的步骤包括:若所述用户手机号码不在预设的黑名单中,则分析所述用户手机号码的令牌状态;若分析所述用户手机号码的令牌没有被锁定,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
- 一种短信验证码的推送方法,其特征在于,所述短信验证码的推送方法包括:收到用户发出的短信验证码生成请求后,获取用户手机号码;判断所述用户手机号码是否在预设的黑名单中;若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
- 如权利要求10所述的短信验证码的推送方法,其特征在于,在判断所述用户手机号码是否在预设的黑名单中的步骤之前,还包括:统计申请短信验证码的每个手机号码每天进行短信验证码验证的成功率x,根据成功率x计算每个手机号码的信用评分,公式如下:r=(2/(1+e^ax))-1其中,0≤x≤1,a为预设常数参数,r为信用评分,若有手机号码的信用评分低于预设评分阈值,则将该手机号码加入预设的黑名单中。
- 如权利要求11所述的短信验证码的推送方法,其特征在于,在判断所述用户手机号码是否在预设的黑名单中的步骤之前,还包括:检测每个手机号码触发短信验证码生成请求的频率;若有手机号码触发短信验证码生成请求的频率高于预设频率阈值,则将该手机号码的信用评分下调预设值,若下调预设值后的信用评分低于预设评分阈值,则将该手机号码加入预设的黑名单中。
- 如权利要求10所述的短信验证码的推送方法,其特征在于,所述启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台的步骤包括:对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量 的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
- 如权利要求11所述的短信验证码的推送方法,其特征在于,所述启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台的步骤包括:对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
- 如权利要求12所述的短信验证码的推送方法,其特征在于,所述启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台的步骤包括:对所述用户手机号码进行HASH函数处理,得到号码HASH值;将所述号码HASH值映射到预设数量的分区,并启动预设数量的线程,利用预设数量的线程提取对应分区中的号码HASH值,读取所述预设队列中与所述用户手机号码对应的短信验证码,将提取的号码HASH值和短信验证码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的发送。
- 如权利要求10所述的短信验证码的推送方法,其特征在于,还包括:为申请短信验证码的每个手机号码分配一个令牌,若手机号码为首次申请短信验证码,则为首次申请短信验证码的手机号码分配的令牌计数为0;若手机号码在申请短信验证码后认证失败,则对该认证失败手机号码的令牌计数加1,若该手机号码连续认证失败,则对该手机号码的令牌计数连续加1;若该手机号码在申请短信验证码后认证成功,则对该手机号码的令牌计数初始化为0;监测申请短信验证码的每个手机号码的令牌计数,若有手机号码的令牌计数达到预设计数阈值,则将令牌计数达到预设计数阈值的手机号码的令牌在预设时间内进行锁定;所述若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列的 步骤包括:若所述用户手机号码不在预设的黑名单中,则分析所述用户手机号码的令牌状态;若分析所述用户手机号码的令牌没有被锁定,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
- 如权利要求11所述的短信验证码的推送方法,其特征在于,还包括:为申请短信验证码的每个手机号码分配一个令牌,若手机号码为首次申请短信验证码,则为首次申请短信验证码的手机号码分配的令牌计数为0;若手机号码在申请短信验证码后认证失败,则对该认证失败手机号码的令牌计数加1,若该手机号码连续认证失败,则对该手机号码的令牌计数连续加1;若该手机号码在申请短信验证码后认证成功,则对该手机号码的令牌计数初始化为0;监测申请短信验证码的每个手机号码的令牌计数,若有手机号码的令牌计数达到预设计数阈值,则将令牌计数达到预设计数阈值的手机号码的令牌在预设时间内进行锁定;所述若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列的步骤包括:若所述用户手机号码不在预设的黑名单中,则分析所述用户手机号码的令牌状态;若分析所述用户手机号码的令牌没有被锁定,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
- 如权利要求12所述的短信验证码的推送方法,其特征在于,还包括:为申请短信验证码的每个手机号码分配一个令牌,若手机号码为首次申请短信验证码,则为首次申请短信验证码的手机号码分配的令牌计数为0;若手机号码在申请短信验证码后认证失败,则对该认证失败手机号码的令牌计数加1,若该手机号码连续认证失败,则对该手机号码的令牌计数连续加1;若该手机号码在申请短信验证码后认证成功,则对该手机号码的令牌计数初始化为0;监测申请短信验证码的每个手机号码的令牌计数,若有手机号码的令牌计数达到预设计数阈值,则将令牌计数达到预设计数阈值的手机号码的令牌在预设时间内进行锁定;所述若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列的 步骤包括:若所述用户手机号码不在预设的黑名单中,则分析所述用户手机号码的令牌状态;若分析所述用户手机号码的令牌没有被锁定,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列。
- 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储有短信验证码的推送系统,所述短信验证码的推送系统被处理器执行时实现如下步骤:收到用户发出的短信验证码生成请求后,获取用户手机号码;判断所述用户手机号码是否在预设的黑名单中;若所述用户手机号码不在预设的黑名单中,则生成所述用户手机号码对应的短信验证码,并将生成的短信验证码放入预设队列;启动预设数量的线程,按预设的多线程推送规则并利用预设数量的线程读取所述预设队列中的短信验证码,将读取的短信验证码及对应的用户手机号码推送至预设的短信推送平台,以针对所述用户手机号码进行短信验证码的推送。
- 如权利要求19所述的计算机可读存储介质,其特征在于,在判断所述用户手机号码是否在预设的黑名单中的步骤之前,还包括:统计申请短信验证码的每个手机号码每天进行短信验证码验证的成功率x,根据成功率x计算每个手机号码的信用评分,公式如下:r=(2/(1+e^ax))-1其中,0≤x≤1,a为预设常数参数,r为信用评分,若有手机号码的信用评分低于预设评分阈值,则将该手机号码加入预设的黑名单中。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201810345029.1 | 2018-04-17 | ||
| CN201810345029.1A CN108810831B (zh) | 2018-04-17 | 2018-04-17 | 短信验证码的推送方法、电子装置及可读存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2019200799A1 true WO2019200799A1 (zh) | 2019-10-24 |
Family
ID=64094307
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/102098 Ceased WO2019200799A1 (zh) | 2018-04-17 | 2018-08-24 | 短信验证码的推送方法、电子装置及可读存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN108810831B (zh) |
| WO (1) | WO2019200799A1 (zh) |
Cited By (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111417122A (zh) * | 2020-03-25 | 2020-07-14 | 杭州迪普科技股份有限公司 | 一种防范攻击方法及装置 |
| CN115379402A (zh) * | 2022-08-09 | 2022-11-22 | 深圳中网讯通技术有限公司 | 一种上行短信推送的控制方法及装置 |
| CN115412850A (zh) * | 2022-08-18 | 2022-11-29 | 南京鼎山信息科技有限公司 | 基于5g通信的短信消息管控服务系统及方法 |
| US20220414698A1 (en) * | 2019-07-29 | 2022-12-29 | TapText llc | System and methods for using enhanced qr codes in a call to action |
| CN115706941A (zh) * | 2021-08-06 | 2023-02-17 | 腾讯科技(深圳)有限公司 | 信息处理方法、装置、电子设备及计算机可读存储介质 |
| CN115941213A (zh) * | 2021-08-04 | 2023-04-07 | 京东科技控股股份有限公司 | 平台邀请激活方法及装置 |
| CN117131086A (zh) * | 2023-08-28 | 2023-11-28 | 中国联合网络通信集团有限公司 | 一种验证码查询方法、装置、设备及存储介质 |
| CN117651277A (zh) * | 2024-01-30 | 2024-03-05 | 北京国舜科技股份有限公司 | 一种基于安全组件的短信炸弹防护方法和装置 |
| CN118093734A (zh) * | 2024-03-01 | 2024-05-28 | 湖南微趣互动科技有限公司 | 一种大数据黑名单过滤方法 |
| CN119603258A (zh) * | 2024-11-30 | 2025-03-11 | 中国农业银行股份有限公司 | 业务快捷短语消息推送方法及相关装置 |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109862562A (zh) * | 2019-01-02 | 2019-06-07 | 武汉极意网络科技有限公司 | 一种动态验证码选取方法及系统 |
| CN109618349B (zh) * | 2019-01-08 | 2022-08-12 | 中国联合网络通信集团有限公司 | 一种数据传输方法和服务器 |
| CN110032864B (zh) * | 2019-03-08 | 2023-10-17 | 平安科技(深圳)有限公司 | 动态码生成方法、装置、计算机设备和存储介质 |
| CN110113758A (zh) * | 2019-05-21 | 2019-08-09 | 深圳壹账通智能科技有限公司 | 一种基于手机号码发送验证消息的控制方法及相关装置 |
| CN110457206A (zh) * | 2019-07-09 | 2019-11-15 | 深圳壹账通智能科技有限公司 | 短信平台测试方法、装置、计算机设备及存储介质 |
| CN111049822B (zh) * | 2019-12-10 | 2022-04-22 | 北京达佳互联信息技术有限公司 | 短信验证码发送方法、装置、短信服务器及存储介质 |
| CN111918224B (zh) * | 2020-07-28 | 2022-03-04 | 广州市百果园信息技术有限公司 | 短信验证方法、装置、设备及存储介质 |
| CN112804399B (zh) * | 2021-01-06 | 2022-03-01 | 北京小米移动软件有限公司 | 验证码接收方法、装置及介质 |
| CN119676711B (zh) * | 2025-02-20 | 2025-06-03 | 广州赛讯信息技术有限公司 | 一种基于零信任机制的网络安全短信息发送方法及系统 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104768139A (zh) * | 2015-02-28 | 2015-07-08 | 北京奇艺世纪科技有限公司 | 一种短信发送的方法及装置 |
| CN106851602A (zh) * | 2017-03-31 | 2017-06-13 | 武汉票据交易中心有限公司 | 一种交易系统短信验证方法及系统 |
| CN106850608A (zh) * | 2017-01-23 | 2017-06-13 | 山东浪潮商用系统有限公司 | 一种短信验证码发送次数频率控制方法 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9392456B2 (en) * | 2013-09-24 | 2016-07-12 | Telesign Corporation | Call center SMS verification system and method |
| CN106230597A (zh) * | 2016-07-28 | 2016-12-14 | 努比亚技术有限公司 | 短信验证码验证装置及方法 |
| CN106878967A (zh) * | 2017-03-10 | 2017-06-20 | 北京百悟科技有限公司 | 短信发送方法及装置 |
| CN107241336B (zh) * | 2017-06-19 | 2020-05-19 | 广州市百果园信息技术有限公司 | 身份验证方法和装置 |
-
2018
- 2018-04-17 CN CN201810345029.1A patent/CN108810831B/zh active Active
- 2018-08-24 WO PCT/CN2018/102098 patent/WO2019200799A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104768139A (zh) * | 2015-02-28 | 2015-07-08 | 北京奇艺世纪科技有限公司 | 一种短信发送的方法及装置 |
| CN106850608A (zh) * | 2017-01-23 | 2017-06-13 | 山东浪潮商用系统有限公司 | 一种短信验证码发送次数频率控制方法 |
| CN106851602A (zh) * | 2017-03-31 | 2017-06-13 | 武汉票据交易中心有限公司 | 一种交易系统短信验证方法及系统 |
Cited By (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12067587B2 (en) * | 2019-07-29 | 2024-08-20 | TapText llc | System and methods for using enhanced QR codes in a call to action |
| US20220414698A1 (en) * | 2019-07-29 | 2022-12-29 | TapText llc | System and methods for using enhanced qr codes in a call to action |
| CN111417122B (zh) * | 2020-03-25 | 2024-03-01 | 杭州迪普科技股份有限公司 | 一种防范攻击方法及装置 |
| CN111417122A (zh) * | 2020-03-25 | 2020-07-14 | 杭州迪普科技股份有限公司 | 一种防范攻击方法及装置 |
| CN115941213A (zh) * | 2021-08-04 | 2023-04-07 | 京东科技控股股份有限公司 | 平台邀请激活方法及装置 |
| CN115706941A (zh) * | 2021-08-06 | 2023-02-17 | 腾讯科技(深圳)有限公司 | 信息处理方法、装置、电子设备及计算机可读存储介质 |
| CN115379402A (zh) * | 2022-08-09 | 2022-11-22 | 深圳中网讯通技术有限公司 | 一种上行短信推送的控制方法及装置 |
| CN115379402B (zh) * | 2022-08-09 | 2024-05-28 | 深圳中网讯通技术有限公司 | 一种上行短信推送的控制方法及装置 |
| CN115412850B (zh) * | 2022-08-18 | 2023-07-28 | 南京鼎山信息科技有限公司 | 基于5g通信的短信消息管控服务系统及方法 |
| CN115412850A (zh) * | 2022-08-18 | 2022-11-29 | 南京鼎山信息科技有限公司 | 基于5g通信的短信消息管控服务系统及方法 |
| CN117131086A (zh) * | 2023-08-28 | 2023-11-28 | 中国联合网络通信集团有限公司 | 一种验证码查询方法、装置、设备及存储介质 |
| CN117651277A (zh) * | 2024-01-30 | 2024-03-05 | 北京国舜科技股份有限公司 | 一种基于安全组件的短信炸弹防护方法和装置 |
| CN117651277B (zh) * | 2024-01-30 | 2024-05-03 | 北京国舜科技股份有限公司 | 一种基于安全组件的短信炸弹防护方法和装置 |
| CN118093734A (zh) * | 2024-03-01 | 2024-05-28 | 湖南微趣互动科技有限公司 | 一种大数据黑名单过滤方法 |
| CN119603258A (zh) * | 2024-11-30 | 2025-03-11 | 中国农业银行股份有限公司 | 业务快捷短语消息推送方法及相关装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN108810831A (zh) | 2018-11-13 |
| CN108810831B (zh) | 2020-03-10 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2019200799A1 (zh) | 短信验证码的推送方法、电子装置及可读存储介质 | |
| US10223524B1 (en) | Compromised authentication information clearing house | |
| US10073916B2 (en) | Method and system for facilitating terminal identifiers | |
| EP3044987B1 (en) | Method and system for verifying an account operation | |
| US9491182B2 (en) | Methods and systems for secure internet access and services | |
| CN108199852B (zh) | 一种鉴权方法、鉴权系统和计算机可读存储介质 | |
| CN105591743B (zh) | 通过用户终端的设备运行特征进行身份鉴权的方法及装置 | |
| CN111814133A (zh) | 移动应用统一登录方法及装置 | |
| TWI528301B (zh) | 操作處理方法和裝置 | |
| CN109492378A (zh) | 一种基于设备识别码的身份验证方法、服务器及介质 | |
| WO2020181809A1 (zh) | 基于接口校验的数据处理的方法、系统和计算机设备 | |
| CN110268406B (zh) | 密码安全性 | |
| WO2017076193A1 (zh) | 一种处理客户端请求的方法和装置 | |
| EP3270318B1 (en) | Dynamic security module terminal device and method for operating same | |
| CN105610810A (zh) | 一种数据处理方法、客户端和服务器 | |
| WO2013156531A1 (en) | Secure password-based authentication for cloud computing services | |
| WO2022073340A1 (zh) | 移动终端应用程序安全检测方法、系统、终端及存储介质 | |
| CN104202345A (zh) | 验证码生成方法、装置及系统 | |
| CN111382422B (zh) | 在非法访问用户数据的威胁下更改账户记录的密码的系统和方法 | |
| CN107294931B (zh) | 调整限制访问频率的方法和装置 | |
| CN106559386A (zh) | 一种认证方法及装置 | |
| CN111949363B (zh) | 业务访问的管理方法、计算机设备、存储介质及系统 | |
| CN111651749A (zh) | 基于密码找回账号的方法、装置、计算机设备及存储介质 | |
| CN111666567A (zh) | 恶意修改应用程序的检测方法、装置、计算机程序和介质 | |
| CN106507300A (zh) | 一种找回丢失终端的方法、装置及终端 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18915729 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 21.01.2021.) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18915729 Country of ref document: EP Kind code of ref document: A1 |