IP Library Granted Patent US 11,652,818
Granted Patent B2
US 11,652,818 · App. 16/875,619 · Granted May 16, 2023

Method and apparatus for accessing service system

Inventors: Hongdong Zheng (Hangzhou, CN); Long Chen (Hangzhou, CN); Hanxiao Xiao (Hangzhou, CN); Zixi Liu (Hangzhou, CN); Biao Zhang (Hangzhou, CN); Zihao Zeng (Hangzhou, CN); Yujiang Liu (Hangzhou, CN); Xing Yao (Hangzhou, CN); Fengxiang Ding (Hangzhou, CN); Yuanchao Zhang (Hangzhou, CN); Lu Jin (Hangzhou, CN)
Assignee: ADVANCED NEW TECHNOLOGIES CO., LTD.
H04L63/0869H04L63/0861H04L63/0876H04L63/10H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,818
App. No.
16/875,619
Granted
May 16, 2023
Kind
B2
Abstract

A method for accessing a service system includes: receiving fingerprint information of a to-be-verified terminal device and identification information of a to-be-verified user from a login computer system based on a service access instruction to access the service server; verifying, according to the fingerprint information of the to-be-verified terminal device and the identification information of the to-be-verified user, whether the to-be-verified terminal device is a specified device of the to-be-verified user based on a specified device database, the specified device database comprising identification information of each user and fingerprint information of a specified device of each user; determining, according to a result of the verifying, whether to allow the login computer system to access the service server according to the service access instruction; and if yes, sending a notification to the login computer system to enable the login computer system to access the service server.

Claims (45)

1. A method for accessing a service server, comprising:

receiving a service access instruction to access the service server from a login computer system, the service access instruction comprising fingerprint information of a to-be-verified terminal device, identification information of a to-be-verified user, and a first trusted identifier previously generated by the login computer system according to data of the to-be-verified terminal device and the identification information of the to-be-verified user in combination with a preset calculation rule, wherein the first trusted identifier indicates that the to-be-verified terminal device and the to-be-verified user are trusted, and the service access instruction is initiated by the to-be-verified user using the to-be-verified terminal device;

parsing the service access instruction to obtain the fingerprint information of the to-be-verified terminal device, the identification information of the to-be-verified user, and the trusted identifier;

calculating, according to the preset calculation rule, a second trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user using the fingerprint information of the to-be-verified terminal device and the identification information of the to-be-verified user received in the service access instruction;

determining whether the first trusted identifier matches the second trusted identifier;

determining the login computer system is allowed to access the service server according to the service access instruction responsive to determining the first trusted identifier matches the second trusted identifier; and

in response to determining that the login computer system is allowed to access the service server, sending a notification to the login computer system to enable the login computer system to access the service server.

2. The method according to claim 1 , wherein the method further comprises: forwarding the service access instruction by an access management server to the login computer system responsive to determining the first trusted identifier does not match the second trusted identifier.

3. The method according to claim 2 , wherein the method further comprises:

determining whether the to-be-verified terminal device is a specified device of the to-be-verified user; and

sending a verification success notification to the login computer system, to enable the login computer system to generate a third trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user responsive to determining the to-be-verified terminal device is a specified device of the to-be-verified user, wherein the access management server is configured to access the service server according to the service access instruction with the generated third trusted identifier.

4. The method according to claim 3 , wherein the method further comprises:

sending a verification failure notification to the login computer system, to perform authentication on the to-be-verified user, responsive to determining the to-be-verified terminal device is a specified device of the to-be-verified user; and

determining, according to the performed authentication on the to-be-verified user, whether to generate the further trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user.

5. A device for accessing a service server, comprising:

a processor; and

a memory configured to store computer executable instructions executable by the processor to cause the processor to perform operations comprising:

receiving a service access instruction to access the service server from a login computer system, the service access instruction comprising fingerprint information of a to-be-verified terminal device, identification information of a to-be-verified user, and a first trusted identifier previously generated by the login computer system according to data of the to-be-verified terminal device and the identification information of the to-be-verified user in combination with a preset calculation rule, wherein the first trusted identifier indicates that the to-be-verified terminal device and the to-be-verified user are trusted, and the service access instruction is initiated by the to-be-verified user using the to-be-verified terminal device;

parsing the service access instruction to obtain the fingerprint information of the to-be-verified terminal device, the identification information of the to-be-verified user, and the trusted identifier;

calculating, according to the preset calculation rule, a second trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user using the fingerprint information of the to-be-verified terminal device and the identification information of the to-be-verified user received in the service access instruction;

determining whether the first trusted identifier matches the second trusted identifier;

determining the login computer system is allowed to access the service server according to the service access instruction responsive to determining the first trusted identifier matches the second trusted identifier; and

in response to determining that the login computer system is allowed to access the service server, sending a notification to the login computer system to enable the login computer system to access the service server.

6. The device according to claim 5 , wherein the operations further comprise:

forwarding the service access instruction by an access management server to the login computer system responsive to determining the first trusted identifier does not match the second trusted identifier.

7. The device according to claim 6 , wherein the operations further comprise:

determining whether the to-be-verified terminal device is a specified device of the to-be-verified user; and

sending a verification success notification to the login computer system, to enable the login computer system to generate a third trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user responsive to determining the to-be-verified terminal device is a specified device of the to-be-verified user, wherein the access management server is configured to access the service server according to the service access instruction with the generated third trusted identifier.

8. A non-transitory computer-readable storage medium configured with instructions executable by one or more processors to cause the one or more processors to perform operations comprising:

receiving a service access instruction to access a service server from a login computer system, the service access instruction comprising fingerprint information of a to-be-verified terminal device, identification information of a to-be-verified user, and a first trusted identifier previously generated by the login computer system according to data of the to-be-verified terminal device and the identification information of the to-be-verified user in combination with a preset calculation rule, wherein the first trusted identifier indicates that the to-be-verified terminal device and the to-be-verified user are trusted, and the service access instruction is initiated by the to-be-verified user using the to-be-verified terminal device;

parsing the service access instruction to obtain the fingerprint information of the to-be-verified terminal device, the identification information of the to-be-verified user, and the trusted identifier;

calculating, according to the preset calculation rule, a second trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user using the fingerprint information of the to-be-verified terminal device and the identification information of the to-be-verified user received in the service access instruction;

determining whether the first trusted identifier matches the second trusted identifier;

determining the login computer system is allowed to access the service server according to the service access instruction responsive to determining the first trusted identifier matches the second trusted identifier; and

in response to determining that the login computer system is allowed to access the service server, sending a notification to the login computer system to enable the login computer system to access the service server.

9. The non-transitory computer-readable storage medium according to claim 8 , wherein the operations further comprise:

forwarding the service access instruction by an access management server to the login computer system responsive to determining the first trusted identifier does not match the second trusted identifier.

10. The non-transitory computer-readable storage medium according to claim 9 , wherein the operations further comprise:

sending a verification success notification to the login computer system, to enable the login computer system to generate a third trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user responsive to determining the to-be-verified terminal device is a specified device of the to-be-verified user, wherein the access management server is configured to access the service server according to the service access instruction with the generated third trusted identifier.

11. The non-transitory computer-readable storage medium according to claim 8 , wherein the operations further comprise:

sending a verification failure notification to the login computer system, to perform authentication on the to-be-verified user, responsive to determining the to-be-verified terminal device is a specified device of the to-be-verified user; and

determining, according to the performed authentication on the to-be-verified user, whether to generate a third trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user.

12. The device according to claim 7 , wherein the operations further comprise:

sending a verification failure notification to the login computer system, to perform authentication on the to-be-verified user, responsive to determining the to-be-verified terminal device is a specified device of the to-be-verified user; and

determining, according to the performed authentication on the to-be-verified user, whether to generate the third trusted identifier corresponding to the to-be-verified terminal device and the to-be-verified user.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053796/0281 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053702/0392 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2020
From: ZHENG, HONGDONG; CHEN, LONG; XIAO, HANXIAO; LIU, ZIXI; ZHANG, BIAO; ZENG, ZIHAO; LIU, YUJIANG; YAO, XING; DING, FENGXIANG; ZHANG, YUANCHAO; JIN, LU
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 053297/0114 →