Secondary authentication method based on out-of-band authentication and enhanced OTP (One-time Password) mechanism

A secondary authentication and mechanism technology, applied in the field of identity authentication and information security, can solve problems such as password theft, hacker deciphering, fund theft, etc., achieve safe and convenient two-factor authentication, and eliminate the threat of phishing and man-in-the-middle attacks

CN105357186AActive Publication Date: 2016-02-24JIANGSU PAYEGIS TECH CO LTD
5 Cites 18 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2016-02-24

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a secondary authentication method based on out-of-band authentication and an enhanced OTP (One-time Password) mechanism. Authentication of a client to a server is added based on a common OTP mechanism, and the client and the server are communicated based on PKI / CA (Public Key Infrastructure / Certificate Authority) by adopting a one-way SSL (Secure Socket Layer) authentication protocol; after secondary authentication is completed, the server adopts an out-of-band secure channel to push a business authentication message to equipment bound to a user based on an equipment fingerprint. After the user affirms the push message on the equipment, a business party can proceed. Meanwhile, mobile equipment of the user is provided with an environment site-cleaning control to prevent Trojan from controlling communication to destroy business security. Through the whole secondary authentication method, threats from phishing and a man-in-the-middle attack of a common OTP token are eliminated, and the method is a good replacement for commonly used short message verification codes in business, such as quick payment, on-line payment and mobile payment.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to the field of information security and to the field of identity authentication, in particular to a secondary authentication method based on out-of-band authentication and enhanced OTP mechanism, which is a strong identity authentication technology. Background technique

[0002] Authentication technology is an important aspect of information security theory and technology. Before accessing the security system, the user first needs to be identified by the identity authentication system, and then the system determines whether the user can access a certain resource according to the user's identity and authorization database. Identity authentication plays an extremely important role in the security system. It is the most basic security service, and other security services depend on it. Once the identity authentication system is breached, all the security measures of the system will be useless. The target of hacker attacks is often ...

Examples

Embodiment Construction

[0040] The present invention aims at the phishing problem and man-in-the-middle attack problem existing in the existing OTP token authentication, proposes an enhanced OTP mechanism, and combines out-of-band security communication, proposes a new type based on out-of-band verification and enhanced OTP mechanism Multi-factor authentication method, and its realization method is given at the same time. In order to more clearly illustrate the new identity authentication scheme and implementation method in the present invention, the present invention will be described in detail below in conjunction with the accompanying drawings and embodiments. Other feasible equivalent variations can be obtained from these figures.

[0041] Such as figure 1As shown, it is a block diagram of the secondary authentication system based on the out-of-band verification and enhanced OTP mechanism of the present invention, and the system mainly involves the client, the server, the data server, and the mo...