US 12,294,572 B2
Information verification method and related apparatus, device, and storage medium for logging in to a server of a target application without exposing privacy information of a user to the target application
Ben Wang, Shenzhen (CN); Xu Wang, Shenzhen (CN); Xiangkai Zeng, Shenzhen (CN); and Junhao Li, Shenzhen (CN)
Assigned to TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED, Shenzhen (CN)
Filed by TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED, Guangdong (CN)
Filed on Oct. 31, 2022, as Appl. No. 17/977,407.
Application 17/977,407 is a continuation of application No. PCT/CN2022/080538, filed on Mar. 14, 2022.
Claims priority of application No. 202110360917.2 (CN), filed on Apr. 2, 2021.
Prior Publication US 2023/0071847 A1, Mar. 9, 2023
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/045 (2013.01) 20 Claims
OG exemplary drawing
 
1. An information verification method, performed by a verification server, the information verification method comprising:
obtaining, in response to a key agreement request from a terminal device, key agreement data comprising a public key and a first random number, the key agreement request including an identifier of a target user;
transmitting, to the terminal device, the key agreement data, based on which, after an application login request to an application server is initiated by the terminal device and to-be-verified information is entered through the terminal device, encryption processing is performed at the terminal device on the to-be-verified information for a target application by using a second random number, the public key, and the first random number included in the key agreement data, to obtain to-be-verified ciphertext information, the to-be-verified information comprising user information corresponding to the target user, the application server being a server of the target application;
receiving, either from the terminal device or from the application server, the to-be-verified ciphertext information;
performing decryption processing on the to-be-verified ciphertext information, to obtain a first information digest;
matching the first information digest with a second information digest, to obtain an information verification result, the second information digest being a stored information digest; and
transmitting the information verification result to the terminal device, the information verification result indicating a result of logging in to the application server by the terminal device, without providing the to-be-verified information to the server of the target application.