Movatterモバイル変換


[0]ホーム

URL:


CN104066085A - Safety protection method applied for mobile terminal and system thereof - Google Patents

Safety protection method applied for mobile terminal and system thereof
Download PDF

Info

Publication number
CN104066085A
CN104066085ACN201410019174.2ACN201410019174ACN104066085ACN 104066085 ACN104066085 ACN 104066085ACN 201410019174 ACN201410019174 ACN 201410019174ACN 104066085 ACN104066085 ACN 104066085A
Authority
CN
China
Prior art keywords
user
sign
authentication
mobile terminal
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201410019174.2A
Other languages
Chinese (zh)
Inventor
林俊佑
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Suzhou Tian Ming Information Technology Co Ltd
Original Assignee
Suzhou Tian Ming Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Suzhou Tian Ming Information Technology Co LtdfiledCriticalSuzhou Tian Ming Information Technology Co Ltd
Priority to CN201410019174.2ApriorityCriticalpatent/CN104066085A/en
Publication of CN104066085ApublicationCriticalpatent/CN104066085A/en
Pendinglegal-statusCriticalCurrent

Links

Landscapes

Abstract

The invention relates to a safety protection method applied for a mobile terminal and a system thereof. The method comprises the steps of registering a user authentication identifier after login information is registered, wherein the user authentication identifier comprises an international mobile equipment identity and a mobile user identify label of the mobile terminal; while the user is logining, automatically acquiring the user authentication identifier and authenticating the international mobile equipment identity and the mobile user identify label one by one after the authentication of the logining information is completed, and successfully logining an application program if the international mobile equipment identity and the mobile user identify label are correct; meanwhile, updating or cancelling the user authentication identifier according to the demand. According to the method and the system provided by the invention, the authentication is carried out by the exclusive international mobile equipment identity and the mobile user identify label taken by the mobile terminal, therefore, the safety problem caused by the stolen logining information by a user under a single register condition can be solved; meanwhile, the demand that the user needs to update or cancel the user authentication identifier under different conditions can be met.

Description

A kind of method for security protection and system thereof of mobile terminal application
Technical field
The present invention relates to information security field, particularly through International Mobile Equipment Identity code and user, move method for security protection and the system thereof that identify label realizes a kind of mobile terminal application.
Background technology
Along with network technology, apply in daily life more and more extensively, people have more and more relied on network and have carried out a lot of daily routines, and such as utilizing, network is done shopping, office, amusement and contact etc.Also just because of the reinforcement of network application, also arise at the historic moment in the website of various convenient services, and the quantity of website is constantly increased.Each website, in order to distinguish client's identity, generally can require user to register own identity information.User can login website by the identity information of registration.
So, once illegal molecule is stolen the identity information of user's registration, can unhinderedly login website and user cannot discover, so, some personal information of user may be stolen and cause user's important information to be leaked.
Therefore; the inventor is because commonly use the method for security protection of mobile terminal application and the necessity that system has its improvement really; then with it, be engaged in for many years design and the professional manufacturing experience of association area; for relating to, through International Mobile Equipment Identity code and user, move method for security protection and the system thereof that identify label realizes mobile terminal application and study improvement energetically, under the discretion consideration of each side's condition, finally develop the present invention.
Summary of the invention
The present invention's main purpose, be to provide a kind of method for security protection and system thereof of mobile terminal application, make full use of unique International Mobile Equipment Identity code that mobile terminal itself carries and user and move identify label and know as user rs authentication, improve user's terminal applies fail safe; Meanwhile, more frequent if user changes mobile terminal, user is renewable or cancel user rs authentication and identify to facilitate and log in application program.
The embodiment one of according to the present invention, the present invention discloses a kind of method for security protection of mobile terminal application, and application with between mobile terminal and server, is characterized in that, comprises the following steps:
S10. user is sent to server registration by logon information, and logon information at least comprises and logs in account number and password;
S11. user logs in application program in mobile terminal, and whether authentication of users logon information is correct, if so, enters next step;
S12. point out user whether to need International Mobile Equipment Identity code, the mobile subscriber identifier of setting mobile terminal to be designated user rs authentication sign; If so, enter next step;
S13. the International Mobile Equipment Identity code of mobile terminal, mobile subscriber identifier sign are sent to server and register, and by International Mobile Equipment Identity code, the binding of mobile subscriber identifier sign, i.e. user rs authentication sign;
S14. user logs in application program in mobile terminal, and whether authentication of users logon information is correct, if so, enters next step;
S15. obtain current user rs authentication sign;
S16. verify that whether current International Mobile Equipment Identity code is consistent with the former International Mobile Equipment Identity code in server, if so, enter next step;
S17. verify that whether current mobile subscriber identifier sign is consistent with the former mobile subscriber identifier sign in server, if so, enters next step;
S18. successfully log on this application program.
The embodiment one of according to the present invention, in step S11 and S14, if authentication of users logon information is incorrect, logs in this application program failure.
The embodiment one of according to the present invention, in step S12, if user selects not set user rs authentication sign, successfully logs in this application program.
The embodiment one of according to the present invention, in step S16, if verify, the former International Mobile Equipment Identity code in current International Mobile Equipment Identity code and server is inconsistent, logs in application program failure.
The embodiment one of according to the present invention, in step S17, if verify, current mobile subscriber identifier sign is inconsistent with the former mobile subscriber identifier sign in server, perform step S19, point out user whether to upgrade user rs authentication sign, if, point out user to input original subscriber and verify sign, whether correctly check, if so, upgrade user rs authentication sign.
The embodiment one of according to the present invention, in step S19, if user selects not upgrade user rs authentication sign, performs step S20, and the original subscriber who points out user whether to cancel in the server of having set verifies sign.
The embodiment one of according to the present invention, in step S20, if user selects to cancel and sets user rs authentication sign, perform step S21, point out user to input original subscriber and verify sign, whether correctly check, if eliminate the original subscriber who has recorded in server, verify sign.
The embodiment one of according to the present invention, the present invention discloses again a kind of safety system of mobile terminal application, comprising:
Registering modules is registered in order to logon information is sent to server, and logon information at least comprises and logs in account number and password;
Whether the first logon information authentication module is correct in order to verify logon information, if so, enters next step; If not, log in application program failure;
Checking sign setting module is in order to point out user whether to need to set user rs authentication sign, if, obtain International Mobile Equipment Identity code, the mobile subscriber identifier sign of mobile terminal as user rs authentication sign, and user rs authentication sign is sent to server registers; If not, successfully log on the application program of website;
Whether the second logon information authentication module is correct in order to authentication of users logon information equally, if so, enters next step;
If not; Log in failure;
Checking identifier acquisition module is in order to obtain current user rs authentication sign;
Mobile equipment identity code authentication module in order to verify current International Mobile Equipment Identity code whether with server in former state
Border mobile equipment identity code is identical, if so, enters next step, if not, logs in application program failure;
Identify label authentication module in order to verify current mobile subscriber identifier sign whether with server in former mobile subscriber's body
Part sign is identical, if so, successfully logs in application program.
The embodiment one of according to the present invention, more comprise a checking identification renewal module, when identify label authentication module verifies current mobile subscriber identifier sign, identify not identical with the former mobile subscriber identifier in server, whether checking identification renewal module prompting user needs to upgrade user rs authentication sign, if, point out user to input original subscriber and verify sign, check whether correct, if upgrade user rs authentication sign.
The embodiment one of according to the present invention, more comprise a checking sign cancellation module, if user selects not upgrade user rs authentication sign, the original subscriber who points out user whether will cancel in server verifies sign, if so, point out user to input original subscriber and verify sign, whether correctly check, if so, eliminate the original subscriber who has recorded in server and verify sign.
In sum, in practice, by unique International Mobile Equipment Identity code that mobile terminal is carried and mobile subscriber identifier, be identified at while logging in and verify, solved the stolen safety problem of bringing of user's logon information under single registration scenarios, meanwhile, also having met user's needs different in the situation that upgrades user rs authentication sign or cancels the demand that user rs authentication identifies.
Accompanying drawing explanation
Fig. 1 is the system architecture diagram of safety system of the present invention's mobile terminal application.
Fig. 2 is the flow chart of steps of method for security protection of the present invention's mobile terminal application.
Embodiment
This exposure book mainly provides a kind of method for security protection and system thereof of mobile terminal application; by the present invention; by unique International Mobile Equipment Identity code that mobile terminal is carried and mobile subscriber identifier, be identified at while logging in and verify; solved the stolen safety problem of bringing of user's logon information under single registration scenarios; meanwhile, also having met user's needs different in the situation that upgrades user rs authentication sign or cancels the demand that user rs authentication identifies.
Below, with reference to graphic one of shown preferred embodiment, describe cooperation in detail feature of the present invention and effect; Please refer to Fig. 1, the system architecture diagram of the safety system of the mobile terminal application that Fig. 1 is the present invention.As shown in Figure 1, the invention provides a kind of safety system of mobile terminal application, this system mainly comprises following:
Registering modules is registered in order to logon information is sent to server, and this logon information at least comprises and logs in account number and password;
Whether the first logon information authentication module is correct in order to the logon information of authentication of users input when user logins website by input logon information, if so, enters next step; If not, log in failure; The first logon information authentication module comprises that limiting module can not input logon information after the number of times of input error logon information at most continuously again in order to limited subscriber simultaneously, when the number of times of the continuous input error logon information of user reaches maximum number of times, limiting module by limited subscriber at logon information corresponding position input character.
Checking sign setting module is in order to point out user whether to need to set user rs authentication sign, if, checking sign setting module obtains the International Mobile Equipment Identity code, mobile subscriber identifier sign of mobile terminal as user rs authentication sign, and user rs authentication sign is sent to server registers; If not, successfully log on the application program of website;
Whether the second logon information authentication module is correct in order to verify logon information equally, if so, enters next step; If not, log in failure; Need restriction, when user is in registered website input logon information, the second logon information authentication module is only carried out the whether correct step of checking login user logon information in the situation that user has set user rs authentication sign.
The current user rs authentication sign of active obtaining mobile terminal after checking identifier acquisition module is correct in order to the logon information in the second logon information authentication module authentication of users input;
Mobile equipment identity code authentication module is in order to verify that whether current International Mobile Equipment Identity code is identical with the former International Mobile Equipment Identity code in server, if so, verify that International Mobile Equipment Identity code is correct, enter next step, if not, log in failure;
Identify label authentication module, in order to verify that whether current mobile subscriber identifier sign is identical with the former mobile subscriber identifier sign in server, if so, verifies that mobile subscriber identifier sign is correct, logs in successfully.
It is to be noted, the International Mobile Equipment Identity code of each mobile terminal, mobile subscriber identifier sign is all unique, therefore, when user sets user rs authentication sign, only when user uses when having International Mobile Equipment Identity code that this original subscriber verifies that sign comprises and identifying with mobile subscriber identifier, it is identical with the former International Mobile Equipment Identity code in server that mobile equipment identity code authentication module just can verify current International Mobile Equipment Identity code, it is identical with the former mobile subscriber identifier sign in server that identify label authentication module just can verify current mobile subscriber identifier sign, user just can set user rs authentication successful login application program of sign in the situation that.
Furthermore, this safety system more comprises a checking identification renewal module, when identify label authentication module verifies current mobile subscriber identifier sign, identify not identical with the former mobile subscriber identifier in server, whether checking identification renewal module prompting user needs to upgrade user rs authentication sign, if so, point out user to input original subscriber and verify sign, whether correctly check, if so, upgrade user rs authentication sign; If not, do not upgrade user rs authentication sign.When user changes mobile terminal, log in website, can synchronously upgrade user rs authentication and identify the fail safe that guarantees that user logins.
Furthermore, this safety system more comprises a checking sign cancellation module, if user selects not upgrade user rs authentication sign, the original subscriber who points out user whether will cancel in server verifies sign, if so, point out user to input original subscriber and verify sign, whether correctly check, if so, eliminate the original subscriber who has recorded in server and verify sign; If not, the original subscriber who has recorded in reservation server verifies sign.When user cancels original subscriber, verify after sign, user is logging in the application of this application program, only needs correct input logon information just can log in successfully.Frequent when different mobile terminals logs in as user, if all need at every turn, set user rs authentication sign or upgrade user rs authentication sign and will make troubles, if therefore user cancels user rs authentication sign, just can better simply step login website.
Please refer to Fig. 2, the flow chart of steps of the method for security protection of the mobile terminal that Fig. 2 is the present invention.As shown in Figure 2, the present invention more provides a kind of method for security protection of mobile terminal application, and as can be seen from Figure, the method mainly comprises the following steps:
S10: logon information is registered on server;
When user's first passage mobile terminal starts application program for mobile terminal, logon information need be sent to server and register, this logon information at least comprises and logs in account number, password.
S11. verify that whether logon information is correct, if so, enter step S12;
User logs in application program in mobile terminal, inputs and send logon information to server, and server end will be verified
Whether the logon information of user's input is correct; If so, enter step S12; If not, show and log in application program failure.In this step S12, by the maximum number of times of the logon information of limit erroneous, when user sends wrong logon information, reach maximum number of times, by limited subscriber at logon information corresponding position input character.The situation of logon information mistake comprise log in one of account number, password be wrong be all wrong with both.
S12. whether prompting needs to set user rs authentication sign;
Do not setting user rs authentication sign, when user in this application program send logon information to server to enter application program,
All can point out International Mobile Equipment Identity code, the mobile subscriber identifier sign whether user needs to set mobile terminal to identify as user rs authentication, if so, enter step S13; If not, successfully log in application program.In the present embodiment, the English full name of International Mobile Equipment Identity code is International Mobile Equipment Identity, referred to as IMEI, mobile subscriber identifier sign can be international mobile subscriber identity, the English full name of international mobile subscriber identity is International Mobile Subscriber Identification Number, referred to as IMSI, so, the present invention is not limited to this.
S13. obtain user rs authentication and identify and be sent to server registers;
The International Mobile Equipment Identity code of mobile terminal, mobile subscriber identifier sign are sent to server and register, and will
International Mobile Equipment Identity code, the binding of mobile subscriber identifier sign, i.e. user rs authentication sign.
S14. verify that whether logon information is correct, if so, enter step S15;
User logs in application program in mobile terminal after setting user rs authentication sign, and whether authentication of users logon information is correct,
If so, enter step S15; If not, log in application program failure.
S15. obtain current user rs authentication sign;
Obtain International Mobile Equipment Identity code, the current mobile subscriber identifier code of current mobile terminal and be sent to server.
S16. verify that whether current International Mobile Equipment Identity code is consistent with the former International Mobile Equipment Identity code in server,
If so, enter step S17; If not, log in application program failure.
S17. verify that whether current mobile subscriber identifier sign is consistent with the former mobile subscriber identifier sign in server, if
To enter step S18;
S18. successfully log on this application program.
You need to add is that, in step S17, if verify former in current mobile subscriber identifier sign and server
Mobile subscriber identifier sign is inconsistent, performs step S19, points out user whether to upgrade user rs authentication sign, if point out user to input original subscriber, verify sign, check whether correct, if, upgrade user rs authentication sign, if incorrect, do not upgrade user rs authentication sign.In step S19, if user selects not upgrade user rs authentication sign, perform step S20, the original subscriber who points out user whether to cancel in the server of having set verifies sign, if user selects to cancel the user rs authentication sign of having set, performs step S21, point out user to input original subscriber and verify sign, whether correctly check, if so, eliminate the original subscriber who has recorded in server and verify sign; If user selects not cancel the user rs authentication sign of having set, do not eliminate the original subscriber who has recorded in server and verify sign.
The present invention can realize following advantage:
By the present invention, by unique International Mobile Equipment Identity code that mobile terminal is carried and mobile subscriber identifier, be identified at while logging in and verify, solved the stolen safety problem of bringing of user's logon information under single registration scenarios, meanwhile, also having met user's needs different in the situation that upgrades user rs authentication sign or cancels the demand that user rs authentication identifies.
Only the foregoing is only the present invention's preferred embodiment, the non-scope of patent protection that is intended to limit to the present invention, therefore such as use specification of the present invention and the equivalence variation for it of graphic content institute, is all in like manner all contained within the scope of the present invention's rights protection, closes and gives Chen Ming.

Claims (10)

CN201410019174.2A2014-01-162014-01-16Safety protection method applied for mobile terminal and system thereofPendingCN104066085A (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201410019174.2ACN104066085A (en)2014-01-162014-01-16Safety protection method applied for mobile terminal and system thereof

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201410019174.2ACN104066085A (en)2014-01-162014-01-16Safety protection method applied for mobile terminal and system thereof

Publications (1)

Publication NumberPublication Date
CN104066085Atrue CN104066085A (en)2014-09-24

Family

ID=51553573

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201410019174.2APendingCN104066085A (en)2014-01-162014-01-16Safety protection method applied for mobile terminal and system thereof

Country Status (1)

CountryLink
CN (1)CN104066085A (en)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN105991280A (en)*2015-02-022016-10-05中国移动通信集团湖北有限公司User authentication method and system
CN107026814A (en)*2016-01-292017-08-08中国移动通信集团陕西有限公司A kind of login validation method and device through point attendant application
CN109151820A (en)*2018-08-242019-01-04安徽讯飞智能科技有限公司One kind being based on the safety certifying method and device of " one machine of a people, one card No.1 "
CN109168165A (en)*2018-11-122019-01-08北京云狐时代科技有限公司Mobile terminal application login method and device
CN111385313A (en)*2020-05-282020-07-07支付宝(杭州)信息技术有限公司Method and system for verifying object request validity
CN112187736A (en)*2020-09-102021-01-05珠海格力电器股份有限公司Supply chain account login method and device based on mobile terminal

Citations (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN102143482A (en)*2011-04-132011-08-03中国工商银行股份有限公司Method and system for authenticating mobile banking client information, and mobile terminal
CN102299930A (en)*2011-09-192011-12-28北京无限新锐网络科技有限公司Method for ensuring security of client software
US20120052842A1 (en)*2005-12-162012-03-01Research In Motion LimitedSystem And Method For Wireless Messaging In A Wireless Communication System
CN103124266A (en)*2013-02-072013-05-29百度在线网络技术(北京)有限公司Mobile terminal, method and system for logging in through mobile terminal and cloud server
CN103188668A (en)*2011-12-272013-07-03方正国际软件(北京)有限公司Security protection method and security protection system for mobile terminal application

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20120052842A1 (en)*2005-12-162012-03-01Research In Motion LimitedSystem And Method For Wireless Messaging In A Wireless Communication System
CN102143482A (en)*2011-04-132011-08-03中国工商银行股份有限公司Method and system for authenticating mobile banking client information, and mobile terminal
CN102299930A (en)*2011-09-192011-12-28北京无限新锐网络科技有限公司Method for ensuring security of client software
CN103188668A (en)*2011-12-272013-07-03方正国际软件(北京)有限公司Security protection method and security protection system for mobile terminal application
CN103124266A (en)*2013-02-072013-05-29百度在线网络技术(北京)有限公司Mobile terminal, method and system for logging in through mobile terminal and cloud server

Cited By (8)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN105991280A (en)*2015-02-022016-10-05中国移动通信集团湖北有限公司User authentication method and system
CN107026814A (en)*2016-01-292017-08-08中国移动通信集团陕西有限公司A kind of login validation method and device through point attendant application
CN107026814B (en)*2016-01-292020-01-03中国移动通信集团陕西有限公司Login verification method and device of sub-service application program
CN109151820A (en)*2018-08-242019-01-04安徽讯飞智能科技有限公司One kind being based on the safety certifying method and device of " one machine of a people, one card No.1 "
CN109168165A (en)*2018-11-122019-01-08北京云狐时代科技有限公司Mobile terminal application login method and device
CN111385313A (en)*2020-05-282020-07-07支付宝(杭州)信息技术有限公司Method and system for verifying object request validity
CN111385313B (en)*2020-05-282020-09-11支付宝(杭州)信息技术有限公司Method and system for verifying object request validity
CN112187736A (en)*2020-09-102021-01-05珠海格力电器股份有限公司Supply chain account login method and device based on mobile terminal

Similar Documents

PublicationPublication DateTitle
CN103188668B (en)Security protection method and security protection system for mobile terminal application
CN104066085A (en)Safety protection method applied for mobile terminal and system thereof
CN105246073B (en)The access authentication method and server of wireless network
CN104254069B (en)Network registry system and method without SIM card mobile phone
CN109906623A (en)A kind of profile method for down loading and equipment
CN104954383A (en)Application program login method and system
CN105554037A (en)Identity identification processing method and service platform
US20140141751A1 (en)Registration and login method and mobile terminal
CN106453234A (en)Identity authentication method, relevant server and client
CN105791262A (en)APP real name authentication secure login system and method based on mobile phone IMSI
CN104579671B (en)Auth method and system
CN108990047B (en) Test method, device and medium for contract relationship management data preparation platform
CN106293816B (en) A method for increasing the stickiness between users and Apps installed on mobile smart terminals
US10291613B1 (en)Mobile device authentication
CN108076056A (en)Cloud server login method and device
CN103634328A (en)Authentication method, device and system for network platform authentication server
CN104468457A (en)User logging-in method based on unified user system and registering method
CN104580237A (en)Method for logging into website, server used in method for logging into website, client terminal used in method for logging into website and peripheral used in method for logging into website
CN113672887A (en)Account management method, server, terminal and processor
CN105100022A (en)Cipher processing method, server and system
CN111817999A (en)User login method and device
CN107645726A (en)A kind of method and system for mobile terminal user identity certification
CN107508784B (en) Application login method and terminal device
CN107241362A (en)Recognize the method and apparatus that identifying code inputs user identity
US9946860B1 (en)Systems and methods for allowing administrative access

Legal Events

DateCodeTitleDescription
C06Publication
PB01Publication
C10Entry into substantive examination
SE01Entry into force of request for substantive examination
RJ01Rejection of invention patent application after publication
RJ01Rejection of invention patent application after publication

Application publication date:20140924


[8]ページ先頭

©2009-2025 Movatter.jp