Digital identity verification method and device based on zero-trust architecture, terminal equipment and storage medium

By generating session tokens and collecting data in real time, dynamically adjusting permissions, the security and persistence of authentication under the zero-trust architecture are solved, effective integration of multi-factor authentication is achieved, and the security and adaptability of the system are improved.

CN120238315APending Publication Date: 2025-07-01GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510460145.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing digital authentication system has the problem of low security and difficulty in achieving continuous verification under the zero-trust architecture. Traditional authentication methods are prone to attacks and lack effective integration of multi-factor authentication technology.

Method used

By generating session tokens, users' behavior data, device fingerprint data and geolocation data are collected in real time, access permissions are dynamically adjusted, and combined with multi-factor authentication, continuous security monitoring and verification are achieved.

Benefits of technology

It enhances the anti-attack capability of identity verification, realizes continuous authentication under the zero-trust architecture, and improves the security and adaptability of digital identity management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238315A_ABST
    Figure CN120238315A_ABST
Patent Text Reader

Abstract

The invention discloses a digital identity verification method and device based on a zero-trust architecture, terminal equipment and a storage medium, and belongs to the field of network security, and the method comprises the steps: obtaining an identity verification result according to user information and multi-factor identity verification information; according to the identity verification result, generating a session token and creating a session; collecting behavior data, equipment fingerprint data and geographic position data of the user during the session in real time, and dynamically adjusting the access authority stored by the session token according to the behavior data, the equipment fingerprint data and the geographic position data; each time a request sent by a client is received, the zero-trust architecture gateway determines the current session state of the server by verifying the current session token. Therefore, through the implementation of the invention, various identity authentication technologies can be organically integrated, continuous identity authentication under a zero-trust architecture is realized, and the security of digital identity authentication is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a digital identity authentication method, apparatus, terminal device and storage medium based on a zero-trust architecture. Background Art

[0002] With the rapid development of information technology, network security is facing increasingly complex challenges. Traditional network security architectures often rely on a boundary-based security model, that is, assuming that the internal network is trustworthy while the external network requires strict protection. In the modern network environment, especially in the case of the widespread application of cloud computing and mobile devices, this model has gradually exposed many drawbacks. The boundary is no longer clear, the diversity of users and devices has increased, and enterprises' networks and data are constantly crossing enterprise boundaries, resulting in traditional network security policies being difficult to cope with complex security threats. To address this challenge, the Zero Trust Architecture (ZTA) has emerged. The zero-trust architecture proposes the principle of "never trust, always verify", requiring that regardless of the location of the user or device in the network, identity authentication and access control must be performed, and no longer relying on the traditional trust boundary. This architecture has been widely regarded as an effective strategy for dealing with modern network security threats, especially showing great potential in scenarios such as multi-cloud environments, remote work, and the widespread use of mobile devices.

[0003] However, the effective implementation of the zero-trust architecture relies on a powerful and flexible digital identity management system. The current digital identity management system has the following deficiencies: First, traditional authentication methods (such as passwords, OTPs, and single biometric recognition) are at risk of being attacked or cracked and cannot effectively cope with increasingly complex network attack methods. Passwords are the most common authentication method, but their inherent flaw is that users usually use passwords that are easy to remember, which makes them vulnerable to being guessed or cracked by attackers; at the same time, users may use the same password on multiple platforms, increasing the risk of password leakage; although password protection measures (such as password strength requirements and regular password changes) can enhance security, they are still difficult to completely eliminate the threat of password leakage. One-time passwords (OTPs) are widely used as a second-factor authentication in most authentication systems. However, OTPs have a time limit. In the case of timeout, users must request a verification code again, which not only increases the inconvenience for users but also may be hijacked or intercepted by attackers through malicious means in some scenarios, thus bypassing the authentication. Biometrics (such as fingerprint, facial recognition, iris scanning, etc.) are considered relatively secure authentication methods, but they also have many problems. For example, fingerprints and facial recognition can be mimicked by high-fidelity technologies, and some biometrics may be inaccurately recognized due to environmental factors (such as light, device quality, etc.); in addition, once biometric data is leaked, it may be misused, seriously threatening user privacy. Second, the zero-trust architecture requires that no user or device be trusted at all times. Even users within the internal network need to undergo dynamic and continuous authentication. However, most existing technologies rely on one-time authentication and ignore authentication during the session. This results in the situation where, when identity information is stolen or out of control, attackers can use the session permissions obtained from the initial successful authentication to continuously access the system. Third, the authentication requirements under the zero-trust architecture require the organic integration of multi-factor authentication and other authentication technologies (such as behavior analysis, device fingerprint recognition, geographical location analysis, etc.). Existing technologies lack an effective integration mechanism in this regard. How to efficiently integrate these technologies and ensure their collaborative work is a difficult point in technical implementation. Summary of the Invention

[0004] The present invention provides a digital identity authentication method, device, terminal device, and storage medium based on the zero-trust architecture. Compared with the prior art, the present application can organically integrate multiple authentication technologies, achieve continuous authentication under the zero-trust architecture, and improve the security of digital identity authentication.

[0005] In a first aspect, an embodiment of the present invention provides a digital identity authentication method based on a zero-trust architecture, which is characterized in that it is applicable to a digital identity authentication system based on a zero-trust architecture. Among them, the digital identity authentication system includes a client and a server, and the client accesses the server through a zero-trust architecture gateway;

[0006] The digital identity authentication method includes:

[0007] Obtain an authentication result based on user information and multi-factor authentication information;

[0008] Generate a session token and create a session according to the authentication result; wherein, the session token encrypts and stores the user information, multi-factor authentication information, initial access rights, and session status;

[0009] Collect the user's behavior data, device fingerprint data, and geographical location data during the session in real time, and dynamically adjust the access rights stored in the session token according to the behavior data, device fingerprint data, and geographical location data;

[0010] When receiving a request sent by the client each time, the zero-trust architecture gateway determines the current session status of the server by verifying the current session token.

[0011] An embodiment of the present invention obtains an authentication result through user information and multi-factor authentication information, enhancing the anti-attack ability of authentication; by generating a session token, managing the user's identity information and session status, avoiding session hijacking and information leakage; by collecting the user's behavior data, device fingerprint data, and geographical location data during the session in real time, and dynamically adjusting the access rights stored in the session token according to the behavior data, device fingerprint data, and geographical location data, realizing continuous security monitoring under the zero-trust architecture; by verifying the session token, ensuring that each access request is verified. Compared with the prior art, the present application can organically integrate various authentication technologies, realize continuous authentication under the zero-trust architecture, and improve the security of digital identity management.

[0012] Further, the obtaining of the authentication result based on user information and multi-factor authentication information is executed by the client, and includes:

[0013] Obtain an initial authentication result based on user information;

[0014] Based on the initial authentication result, obtain an authentication result according to multi-factor authentication information; wherein, the multi-factor authentication information includes dynamic authentication information and biometric information.

[0015] The embodiments of the present invention verify the user's identity information through multiple factors, enhancing the anti-attack ability of identity verification.

[0016] Further, the real-time collection of the user's behavior data, device fingerprint data, and geographical location data during the session, and the dynamic adjustment of the access permissions for storing the session token are executed by the server, including:

[0017] Analyze the behavior data, device fingerprint data, and geographical location data through a preset model to obtain a real-time updated risk score; wherein, the behavior data, device fingerprint data, and geographical location data are encrypted and stored in the session token;

[0018] Dynamically adjust the access permissions for storing the session token according to the risk score.

[0019] The embodiments of the present invention generate a real-time updated risk score through a preset model, providing data support for subsequent verification steps and permission adjustment; through the risk score, dynamically adjust the user's access permissions to determine whether the user's identity has changed during the session.

[0020] Further, the analysis of the behavior data, device fingerprint data, and geographical location data through a preset model to obtain a real-time updated risk score is executed by the server, including:

[0021] Analyze the behavior data through a preset behavior model to obtain a first risk score;

[0022] Analyze the device fingerprint data through a preset device model to obtain a second risk score;

[0023] Analyze the geographical location data through a preset location model to obtain a third risk score;

[0024] Obtain the final risk score according to the first risk score, the second risk score, the third risk score, and a preset scoring rule.

[0025] The embodiments of the present invention compare and analyze the user's current behavior, device, and geographical location through a preset model to generate a real-time updated risk score, and evaluate the user's access risk from multiple aspects.

[0026] Further, the dynamic adjustment of the access permissions for storing the session token according to the risk score is executed by the server, including:

[0027] If the risk score is greater than or equal to the high-risk score threshold, the access permission is to prohibit access to sensitive data and highly sensitive data, and high-risk additional identity verification is required;

[0028] If the risk score is greater than or equal to the medium risk score threshold and less than the high risk score threshold, the access right is to prohibit access to sensitive data and require medium risk additional authentication;

[0029] If the risk score is less than the medium risk score threshold, the access right is the initial access right.

[0030] In an embodiment of the present invention, the access right of a user is dynamically adjusted through a risk score to determine whether the user identity changes during a session.

[0031] Further, when the risk score is greater than or equal to the high risk score threshold, the access right is to prohibit access to sensitive data and highly sensitive data and require high risk additional authentication, including:

[0032] Obtaining a high risk additional authentication result according to dynamic authentication information and biometric information; wherein the dynamic authentication information and biometric information are provided again by a client;

[0033] Adjusting the access right to the initial access right according to the high risk additional authentication result.

[0034] In an embodiment of the present invention, high risk additional authentication is performed through dynamic authentication information and biometric information to enhance the security of authentication.

[0035] Further, when the risk score is greater than or equal to the medium risk score threshold and less than the high risk score threshold, the access right is to prohibit access to sensitive data and require medium risk additional authentication, including:

[0036] Obtaining a medium risk additional authentication result according to dynamic authentication information; wherein the dynamic authentication information is provided again by a client;

[0037] Adjusting the access right to the initial access right according to the medium risk additional authentication result.

[0038] In an embodiment of the present invention, medium risk additional authentication is performed through dynamic authentication information to enhance the security of authentication.

[0039] In a second aspect, an embodiment of the present invention provides a digital identity authentication device based on a zero trust architecture, including: an authentication module, a session creation module, a permission adjustment module, and a token verification module;

[0040] The authentication module is configured to obtain an authentication result according to user information and multi-factor authentication information;

[0041] The session creation module is used to generate a session token and create a session according to the authentication result; wherein, the session token encrypts and stores the user information, multi-factor authentication information, initial access permissions, and session status;

[0042] The permission adjustment module is used to collect the user's behavior data, device fingerprint data, and geographical location data during the session in real time, and dynamically adjust the access permissions stored in the session token according to the behavior data, device fingerprint data, and geographical location data;

[0043] The token verification module is used to determine the current session status of the server by verifying the current session token through the zero-trust architecture gateway each time a request sent by the client is received.

[0044] In the embodiment of the present invention, the authentication result is obtained through the authentication module, enhancing the anti-attack ability of authentication; the session token is generated through the session creation module to manage the user's identity information and session status, avoiding session hijacking and information leakage; the permission adjustment module collects the user's behavior data, device fingerprint data, and geographical location data during the session in real time, and dynamically adjusts the access permissions stored in the session token according to the behavior data, device fingerprint data, and geographical location data, realizing continuous security monitoring under the zero-trust architecture; the session token is verified through the token verification module to ensure that each access request is verified.

[0045] Another embodiment of the present invention also provides a terminal device, including: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the steps of a digital authentication method based on the zero-trust architecture of the present invention are implemented.

[0046] Another embodiment of the present invention also provides a computer-readable storage medium item, including: a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the steps of a digital authentication method based on the zero-trust architecture of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions of the present application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0048] Figure 1 It is a flowchart of a digital authentication method based on the zero-trust architecture provided by the embodiment of the present invention;

[0049] Figure 2 is the main implementation flowchart of the digital identity authentication method based on the zero-trust architecture provided by the embodiments of the present invention;

[0050] Figure 3 is the structural schematic diagram of the core components of the digital identity authentication system based on the zero-trust architecture provided by the embodiments of the present invention;

[0051] Figure 4 is the schematic flowchart of the operation of the digital identity authentication system based on the zero-trust architecture provided by the embodiments of the present invention;

[0052] Figure 5 is the schematic diagram of the audit log of the digital identity authentication method based on the zero-trust architecture provided by the embodiments of the present invention;

[0053] Figure 6 is the structural schematic diagram of the digital identity authentication device based on the zero-trust architecture provided by the embodiments of the present invention. Detailed implementation manners

[0054] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion.

[0056] In the description of the embodiments of the present application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity, specific order, or primary-secondary relationship of the indicated technical features. In the description of the embodiments of the present application, "a plurality of" means two or more unless otherwise specifically defined.

[0057] References herein to "embodiments" mean that the particular features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0058] In the description of the embodiments of the present application, the term "and / or" is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the front and rear associated objects.

[0059] In the description of the embodiments of the present application, the term "plurality" refers to two or more (including two). Similarly, "multiple groups" refers to two or more groups (including two groups), and "multiple pieces" refers to two or more pieces (including two pieces).

[0060] See Figure 1 , to solve the problems of low security of single verification and difficulty in achieving continuous verification in the zero-trust architecture in the prior art, a digital identity verification method based on the zero-trust architecture provided by an embodiment of the present invention includes steps S101 to S104, which are described in detail as follows:

[0061] Step S101, obtaining an identity verification result according to user information and multi-factor identity verification information.

[0062] Further, step S101 is specifically:

[0063] Obtaining an initial identity verification result according to user information;

[0064] Based on the initial identity verification result, obtaining an identity verification result according to multi-factor identity verification information; wherein, the multi-factor identity verification information includes dynamic authentication information and biometric information.

[0065] Optionally, comparing the input user information with the user information stored in the digital identity verification system; if the comparison result is consistent, the initial identity verification result is successful; if the comparison result is inconsistent, the initial identity verification result is failed.

[0066] Optionally, when the initial identity verification result is successful, comparing the input multi-factor identity verification information with the multi-factor identity verification information stored in the digital identity verification system; if the comparison result is consistent, the identity verification result is successful; if the comparison result is inconsistent, the identity verification result is failed.

[0067] Optionally, when the initial authentication result is a failure, the digital authentication system rejects the user's access request.

[0068] Optionally, when the authentication result is a failure, the digital authentication system rejects the user's access request.

[0069] Optionally, the user information includes but is not limited to a username, password, and PIN code; the dynamic authentication information includes but is not limited to a one-time password (OTP, One-Time Password), which is generated via SMS, email, or an authentication application (such as Google Authenticator); the biometric information includes but is not limited to fingerprint information, facial information, and iris information.

[0070] Embodiments of the present invention authenticate the user's identity information through multiple factors, enhancing the anti-attack ability of authentication and achieving multi-layer protection for authentication; by freely combining authentication methods according to different application scenarios and security requirements, the adaptability and scalability are improved. With the emergence of new authentication technologies, it can be easily extended and updated to always remain compatible with the latest security standards.

[0071] Step S102: Generate a session token and create a session according to the authentication result; wherein, the session token encrypts and stores the user information, multi-factor authentication information, initial access rights, and session status.

[0072] Optionally, when the authentication result is a success, the digital authentication system generates a session token and creates a session; wherein, the session token contains a unique session identifier (Session ID), and the session identifier is used in combination with the encrypted information to ensure that each request is authenticated.

[0073] Optionally, the session token contains a validity period; if the session status is active within the validity period, the session token is automatically renewed; if the session status is inactive within the validity period, the session token expires and re-authentication is required.

[0074] Optionally, the user information and multi-factor authentication information are encrypted and transmitted through the TLS / SSL protocol and asymmetric encryption technology, and encrypted and stored through a hashing algorithm; the session status is encrypted and stored through symmetric encryption technology.

[0075] Embodiments of the present invention use encryption technology to ensure that data is not eavesdropped on and tampered with during transmission, avoiding risks such as session hijacking and data leakage.

[0076] Step S103: Collect the user's behavior data, device fingerprint data, and geographical location data in real time during the session, and dynamically adjust the access permissions stored in the session token according to the behavior data, device fingerprint data, and geographical location data.

[0077] Further, step S103 is specifically as follows:

[0078] Analyze the behavior data, device fingerprint data, and geographical location data through a preset model to obtain a real-time updated risk score; wherein, the behavior data, device fingerprint data, and geographical location data are encrypted and stored in the session token;

[0079] Dynamically adjust the access permissions stored in the session token according to the risk score.

[0080] Optionally, the behavior data includes but is not limited to login time data, accessed resource data, and operation frequency data; the device fingerprint data includes but is not limited to hardware information data, operating system data, and browser feature data. Each group of device fingerprint data generates a device identifier (device fingerprint), and one device identifier corresponds to one user name; the geographical location data includes but is not limited to IP address data and GPS coordinate data.

[0081] Optionally, when collecting data in real time, follow the principle of minimizing data collection, and only collect necessary authentication and risk assessment data (for example, when collecting geographical location data, only collect necessary IP addresses or longitude and latitude, and will not over-collect the user's personal location data to ensure that the system complies with data protection regulations).

[0082] In the embodiment of the present invention, a real-time updated risk score is generated through a preset model, providing data support for subsequent verification steps and permission adjustment; through the risk score, the user's access permissions are dynamically adjusted to determine whether the user's identity has changed during the session, reducing the risk of identity forgery and permission abuse; by combining information such as behavior data, device fingerprint data, and geographical location data, it can effectively adapt to complex network environments with multiple terminals and multiple locations, ensuring the implementation effect of the zero-trust architecture.

[0083] Further, the analysis of the behavior data, device fingerprint data, and geographical location data through a preset model to obtain a real-time updated risk score is executed by the server, and includes:

[0084] Analyze the behavior data through a preset behavior model to obtain a first risk score;

[0085] Analyze the device fingerprint data through a preset device model to obtain a second risk score;

[0086] Analyze the geographical location data through a preset location model to obtain a third risk score;

[0087] According to the first risk score, the second risk score, the third risk score, and a preset scoring rule, obtain the final risk score.

[0088] Optionally, use machine learning algorithms (such as K-means clustering and decision trees) to construct a behavior model, a device model, and a location model; input the behavior data into the behavior model, compare and analyze it with the preset normal behavior data, and output the first risk score; input the device fingerprint data into the device model, compare and analyze it with the preset device identifier, and output the second risk score; input the geographical location data into the location model, compare and analyze it with the preset normal geographical location, and output the third risk score; according to the preset weight allocation, perform weighted summation on the first risk score, the second risk score, and the third risk score to obtain the final risk score; the risk score is transmitted through the API.

[0089] Optionally, when performing data analysis and risk assessment, use differential privacy technology and anonymization processing methods to ensure that user information, behavior data, etc. are not leaked or associated with specific identities.

[0090] In the embodiment of the present invention, the preset model is used to compare and analyze the current behavior, device fingerprint, and geographical location of the user, generate a real-time updated risk score, evaluate the access risk of the user from multiple aspects, and effectively prevent attack methods such as phishing attacks and credential theft; in the case of low risk, the system can automatically identify trusted behavior, device fingerprint, and geographical location, eliminating the trouble of repeated authentication for the user, thereby ensuring the smoothness of user operations.

[0091] Further, the dynamic adjustment of the access permission stored in the session token according to the risk score is executed by the server, including:

[0092] If the risk score is greater than or equal to the high-risk score threshold, the access permission is to prohibit access to sensitive data and highly sensitive data, and high-risk additional identity verification is required;

[0093] If the risk score is greater than or equal to the medium-risk score threshold and less than the high-risk score threshold, the access permission is to prohibit access to sensitive data, and medium-risk additional identity verification is required;

[0094] If the risk score is less than the medium-risk score threshold, the access permission is the initial access permission.

[0095] Optionally, the digital authentication system classifies system data into highly sensitive data, sensitive data, and ordinary data according to a preset data sensitivity threshold; the digital authentication system divides the initial access rights of users into high rights, medium rights, and low rights according to a preset scope of authority division; when the initial access right of a user is high rights, the user is allowed to access highly sensitive data, sensitive data, and ordinary data; when the initial access right of a user is medium rights, the user is allowed to access sensitive data and ordinary data and prohibited from accessing highly sensitive data; when the initial access right of a user is low rights, the user is allowed to access ordinary data and prohibited from accessing highly sensitive data and sensitive data.

[0096] In an embodiment of the present invention, the access rights of a user are dynamically adjusted through risk scoring to determine whether the user's identity has changed during a session; potential security vulnerabilities are reduced by granting the permissions required for trusted operations.

[0097] Further, if the risk score is greater than or equal to the high-risk score threshold, the access rights are to prohibit access to sensitive data and highly sensitive data and require high-risk additional identity authentication, including:

[0098] Obtain a high-risk additional identity authentication result based on the dynamic authentication information and biometric information; wherein, the dynamic authentication information and biometric information are provided again by the client;

[0099] Adjust the access rights to the initial access rights according to the high-risk additional identity authentication result.

[0100] Optionally, when the risk score is greater than or equal to the high-risk score threshold, the access rights stored in the session token are dynamically adjusted to low rights; the user inputs dynamic authentication information and compares it with the dynamic authentication information stored in the digital authentication system; if the comparison result is consistent, the initial high-risk additional identity authentication result is successful; if the comparison result is inconsistent, the initial high-risk additional identity authentication result is failed; when the initial high-risk additional identity authentication result is successful, the user inputs biometric information and compares it with the biometric information stored in the digital authentication system; if the comparison result is consistent, the high-risk additional identity authentication result is successful; if the comparison result is inconsistent, the high-risk additional identity authentication result is failed.

[0101] Optionally, when the high-risk additional identity authentication result is successful, the access rights stored in the session token are dynamically adjusted to the user's initial access rights.

[0102] Optionally, when the initial high-risk additional identity authentication result is failed, the access rights stored in the session token remain low rights.

[0103] Optionally, when the high-risk additional authentication result is a failure, the access permission stored in the session token continues to be a low permission.

[0104] In the embodiments of the present invention, high-risk additional authentication is performed through dynamic authentication information and biometric information, enhancing the security of authentication.

[0105] Further, if the risk score is greater than or equal to the medium-risk score threshold and less than the high-risk score threshold, the access permission is to prohibit access to sensitive data, and medium-risk additional authentication is required, including:

[0106] Obtain the medium-risk additional authentication result according to the dynamic authentication information; wherein, the dynamic authentication information is provided again by the client;

[0107] Adjust the access permission to the initial access permission according to the medium-risk additional authentication result.

[0108] Optionally, when the risk score is greater than or equal to the medium-risk score threshold and less than the high-risk score threshold, the access permission stored in the session token is dynamically adjusted to a medium permission; the user inputs dynamic authentication information and compares it with the dynamic authentication information stored in the digital authentication system; if the comparison result is consistent, the medium-risk additional authentication result is a success; if the comparison result is inconsistent, the medium-risk additional authentication result is a failure.

[0109] Optionally, when the medium-risk additional authentication result is a success, the access permission stored in the session token is dynamically adjusted to the user's initial access permission.

[0110] Optionally, when the medium-high-risk additional authentication result is a failure, the access permission stored in the session token continues to be a medium permission.

[0111] In the embodiments of the present invention, medium-risk additional authentication is performed through dynamic authentication information, enhancing the security of authentication.

[0112] Step S104, when receiving a request sent by the client each time, the zero-trust architecture gateway determines the current session state of the server by verifying the current session token.

[0113] Optionally, the user needs to carry the session token each time an access request is made. The zero-trust architecture gateway dynamically adjusts the current session state by verifying the access permission stored in the current session token; if the access permission remains unchanged, the session state remains unchanged; if the access permission changes, the session state changes accordingly according to the access permission.

[0114] Optionally, the embodiments of the present invention can be adapted to various devices, operating systems, and network environments, support cross-platform and cross-device authentication, meet the security requirements in different scenarios, and ensure that authentication is not restricted by device type, operating system, or network environment.

[0115] Optionally, the embodiments of the present invention can be integrated into existing enterprise information systems, such as CRM systems, enterprise intranets, and financial systems. Through standard API interfaces and authentication protocols (such as OAuth 2.0, SAML, etc.), it can be integrated with existing identity management systems to ensure rapid deployment and scalability.

[0116] Optionally, the embodiments of the present invention support asynchronous processing and distributed computing, can efficiently process authentication requests from a large number of concurrent users, are suitable for identity authentication requirements in large-scale enterprise environments, and are particularly suitable for scenarios of distributed, cloud computing, and edge computing.

[0117] As Figure 2 shown, based on the above method item embodiments, embodiments of the corresponding main implementation process are provided, including steps S201 to S207;

[0118] Step S201, the user sends an access request;

[0119] Step S202, complete initial authentication through the username and password;

[0120] Step S203, complete authentication through multi-factor authentication (such as OTP and biometric authentication information);

[0121] Step S204, collect behavior data, device fingerprint data, and geographical location data in real time, perform data analysis and risk assessment, and generate a risk score; if the risk score is high, perform additional authentication and deny access to sensitive data;

[0122] Step S205, generate a session token according to the authentication result, and the session token encrypts and stores identity information and access permissions;

[0123] Step S206, dynamically adjust the access permissions stored in the session token according to the risk score;

[0124] Step S207, the user accesses resources according to the access permissions stored in the session token.

[0125] As Figure 3 shown, based on the above method item embodiments, embodiments of the core component structure of the corresponding digital authentication system are provided, including: user equipment, zero-trust architecture gateway, authentication service, audit log and analysis platform, and backend service and resource control layer;

[0126] The user device (such as mobile devices and computers, etc.) is used for users to perform various forms of authentication (such as biometric identification and OTP, etc.);

[0127] The zero-trust architecture gateway is used to dynamically check all requests of users and implement authentication and authorization decisions;

[0128] The authentication service is used to provide various authentication services (such as multi-factor authentication, device fingerprint authentication, and behavior analysis, etc.);

[0129] The audit log and analysis platform is used to collect all authentication data and perform data analysis, and record the identity data and data analysis results in the corresponding audit logs for subsequent security audits and detection of abnormal behaviors;

[0130] The backend service and resource control layer is used to control the access rights of users to system resources according to the results of authentication and risk assessment.

[0131] Such as Figure 4 As shown, based on the above-mentioned embodiment of the core component structure of the digital authentication system, an embodiment of the corresponding operation process of the digital authentication system is provided, including steps S401 to S406;

[0132] Step S401, the user sends an access request;

[0133] Step S402, the authentication service receives the access request and executes the authentication task;

[0134] Step S403, perform preliminary authentication through the username and password;

[0135] Step S404, perform multi-factor authentication through OTP or biometric authentication information;

[0136] Step S405, perform data analysis based on the user's behavior data, device fingerprint data, and geographical location data to determine whether the session is normal;

[0137] Step S406, decide whether to allow the user to access the resource according to the results of authentication and data analysis, and record the corresponding audit log.

[0138] Such as Figure 5 As shown, based on the above-mentioned embodiment of the core component structure of the digital authentication system, an embodiment of the corresponding audit log is provided.

[0139] In this embodiment, the audit log records the time of each user login, device information, login location, authentication method, behavior analysis results, and access control decisions; the system can track the behavior of users at any time point, detect potential risks or abnormal activities, and take defensive measures in a timely manner.

[0140] To better demonstrate the beneficial effects of the present invention, an embodiment of the present invention provides a specific example to show the specific implementation process of the digital authentication method based on the zero-trust architecture.

[0141] In this specific embodiment, a company has multiple branches and remote workers, and the digital authentication system needs to ensure that all access requests are strictly verified even in a distributed environment, without relying on traditional perimeter protection measures.

[0142] In this specific embodiment, an employee attempts to access the company's internal CRM system at a coffee shop outside the company's headquarters at 9 pm, triggering the digital authentication process based on the zero-trust architecture.

[0143] In this specific embodiment, the employee enters the registered username and password, and the client compares the stored password hash value with the entered password to obtain the initial authentication result; based on the initial authentication result, the authentication application generates a set of one-time passwords, and the employee enters the one-time passwords, and the client compares the preset one-time passwords with the entered one-time passwords to obtain the authentication result.

[0144] In this specific embodiment, according to the authentication result, the server generates a session token and creates a new session for the employee; the session token is encrypted and stored and transmitted through the HTTPS protocol; the session token contains the employee's initial access permissions.

[0145] In this specific embodiment, during the session, the server collects the employee's behavior data, device fingerprint data, and geographical location data in real time, and analyzes the behavior data, device fingerprint data, and geographical location data through a preset model to obtain a real-time updated risk score. Since this employee usually logs in to the CRM system during working hours and accesses the CRM system from the company's internal network, and in this access request, the employee's login time is 9 pm, the device used has not been registered in the past few months, and the IP address shows the geographical location as a coffee shop, the preset model generates a high-risk score, and the initial access permission stored in the session token is adjusted to prohibit access to sensitive data and highly sensitive data (such as customer financial information in the CRM system), and requires high-risk additional identity verification. The client sends a verification code to the employee via mobile phone text message and requires the employee to perform facial recognition verification; the employee successfully enters the correct verification code and completes the facial recognition verification through the smartphone camera, and the access permission stored in the session token is adjusted to the initial access permission.

[0146] In this specific embodiment, during subsequent sessions, each request of this user requires the zero-trust architecture gateway to verify the current session token. If this employee performs an unconventional high-risk operation (such as downloading a large amount of customer data) in the CRM system or suddenly changes the device and login location, the access permission stored in the session token will be dynamically adjusted, and the session status will be automatically terminated until this employee completes additional identity verification.

[0147] The embodiment of the present invention obtains the identity verification result through user information and multi-factor identity verification information, enhancing the anti-attack ability of identity verification; by generating a session token, managing the user's identity information and session status, avoiding session hijacking and information leakage; by collecting the user's behavior data, device fingerprint data, and geographical location data in real time during the session, and dynamically adjusting the access permission stored in the session token according to the behavior data, device fingerprint data, and geographical location data, realizing continuous security monitoring under the zero-trust architecture; by verifying the session token, ensuring that each access request is verified. Compared with the prior art, this application can organically integrate various identity verification technologies, realize continuous identity verification under the zero-trust architecture, and improve the security of digital identity management.

[0148] As Figure 6 shown, based on the above method item embodiment, a corresponding device item embodiment is provided;

[0149] An embodiment of the present invention provides a digital identity verification device based on a zero-trust architecture, including: an identity verification module 601, a session creation module 602, a permission adjustment module 603, and a token verification module 604;

[0150] The authentication module 601 is configured to obtain an authentication result based on user information and multi-factor authentication information;

[0151] The session creation module 602 is configured to generate a session token and create a session according to the authentication result; wherein, the session token encrypts and stores the user information, multi-factor authentication information, initial access permissions, and session status;

[0152] The permission adjustment module 603 is configured to collect the user's behavior data, device fingerprint data, and geographical location data during the session in real time, and dynamically adjust the access permissions stored in the session token according to the behavior data, device fingerprint data, and geographical location data;

[0153] The token verification module 604 is configured to determine the current session status of the server by verifying the current session token each time a request sent by the client is received by the zero-trust architecture gateway.

[0154] In an embodiment of the present invention, the authentication module 601 includes: an initial verification sub-module and a multi-factor verification sub-module;

[0155] The initial verification sub-module is configured to obtain an initial authentication result based on user information;

[0156] The multi-factor verification sub-module is configured to obtain an authentication result based on the initial authentication result and multi-factor authentication information; wherein, the multi-factor authentication information includes dynamic authentication information and biometric information.

[0157] In an embodiment of the present invention, the authentication module 601 performs multi-factor authentication, enhancing the anti-attack ability of authentication.

[0158] In an embodiment of the present invention, the permission adjustment module 603 includes: a data analysis sub-module and a permission adjustment sub-module;

[0159] The data analysis sub-module is configured to analyze the behavior data, device fingerprint data, and geographical location data through a preset model to obtain a real-time updated risk score; wherein, the behavior data, device fingerprint data, and geographical location data are encrypted and stored in the session token;

[0160] The permission adjustment sub-module is configured to dynamically adjust the access permissions stored in the session token according to the risk score.

[0161] In an embodiment of the present invention, the permission adjustment module 603 generates a real-time updated risk score, dynamically adjusts the user's access permissions, and determines whether the user's identity has changed during the session.

[0162] In an embodiment of the present invention, the data analysis sub-module includes: a behavior data analysis unit, a device fingerprint data analysis unit, a geographical location data analysis unit, and a risk score generation unit;

[0163] The behavior data analysis unit is configured to analyze behavior data through a preset behavior model to obtain a first risk score;

[0164] The device fingerprint data analysis unit is configured to analyze device fingerprint data through a preset device model to obtain a second risk score;

[0165] The geographical location data analysis unit is configured to analyze geographical location data through a preset location model to obtain a third risk score;

[0166] The risk score generation unit is configured to obtain a final risk score according to the first risk score, the second risk score, the third risk score, and a preset scoring rule.

[0167] In an embodiment of the present invention, through the data analysis sub-module, the current behavior, device fingerprint, and geographical location of the user are compared and analyzed to generate a real-time updated risk score, and the access risk of the user is evaluated from multiple aspects.

[0168] In an embodiment of the present invention, the permission adjustment sub-module includes: a high-risk permission adjustment unit, a medium-risk permission adjustment unit, and a low-risk permission adjustment unit;

[0169] The high-risk permission adjustment unit is configured to, if the risk score is greater than or equal to the high-risk score threshold, the access permission is to prohibit access to sensitive data and highly sensitive data, and require high-risk additional identity verification;

[0170] The medium-risk permission adjustment unit is configured to, if the risk score is greater than or equal to the medium-risk score threshold and less than the high-risk score threshold, the access permission is to prohibit access to sensitive data, and require medium-risk additional identity verification;

[0171] The low-risk permission adjustment unit is configured to, if the risk score is less than the medium-risk score threshold, the access permission is the initial access permission.

[0172] In an embodiment of the present invention, through the permission adjustment sub-module, the access permission of the user is dynamically adjusted to determine whether the user identity has changed during the session.

[0173] In an embodiment of the present invention, the high-risk permission adjustment unit includes: a high-risk additional identity verification sub-unit and a high-risk permission adjustment sub-unit;

[0174] The high-risk additional authentication subunit is configured to obtain a high-risk additional authentication result based on dynamic authentication information and biometric information; wherein, the dynamic authentication information and biometric information are re-provided by the client;

[0175] The high-risk permission adjustment subunit is configured to adjust the access permission to the initial access permission according to the high-risk additional authentication result.

[0176] In the embodiment of the present invention, the high-risk permission adjustment unit performs high-risk additional authentication to enhance the security of authentication.

[0177] In the embodiment of the present invention, the medium-risk permission adjustment unit includes: a medium-risk additional authentication subunit and a medium-risk permission adjustment subunit;

[0178] The medium-risk additional authentication subunit is configured to obtain a medium-risk additional authentication result based on dynamic authentication information; wherein, the dynamic authentication information is re-provided by the client;

[0179] The medium-risk permission adjustment subunit is configured to adjust the access permission to the initial access permission according to the medium-risk additional authentication result.

[0180] In the embodiment of the present invention, the medium-risk permission adjustment unit performs medium-risk additional authentication to enhance the security of authentication.

[0181] It can be understood that the above device item embodiments correspond to the method item embodiments of the present invention, and can implement the digital identity authentication method based on the zero-trust architecture provided by any one of the above method item embodiments of the present invention.

[0182] It should be noted that the device embodiments described above are merely illustrative, and some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement without creative efforts.

[0183] In an embodiment of the present invention, the authentication result is obtained through the identity authentication module 601, enhancing the anti-attack ability of identity authentication; the session creation module 602 generates a session token to manage the user's identity information and session status, avoiding session hijacking and information leakage; the permission adjustment module 603 collects the user's behavior data, device fingerprint data, and geographical location data during the session in real time, and dynamically adjusts the access permission stored in the session token according to the behavior data, device fingerprint data, and geographical location data, realizing continuous security monitoring under the zero-trust architecture; the token verification module 604 verifies the session token to ensure that each access request is verified. Compared with the prior art, the present application can organically integrate various identity authentication technologies, realize continuous identity authentication under the zero-trust architecture, and improve the security of digital identity management.

[0184] Based on the above embodiment of a digital identity authentication method based on the zero-trust architecture, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a digital identity authentication method based on the zero-trust architecture according to any embodiment of the present invention.

[0185] Exemplarily, in this embodiment, the computer program can be divided into one or more modules. The one or more modules are stored in the memory and executed by the processor to complete the present invention. The one or more modules can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the terminal device.

[0186] The terminal device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.

[0187] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device, and connects all parts of the entire terminal device through various interfaces and lines.

[0188] Based on the above method item embodiments, another embodiment of the present invention provides a computer-readable storage medium, including a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute a digital identity authentication method based on a zero-trust architecture described in any one of the above method item embodiments of the present invention.

[0189] Among them, if the module / unit integrated in the device / terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, Read-Only Memory (ROM), Random Access Memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0190] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A digital identity authentication method based on zero trust architecture, characterized in that: Applicable to a digital identity authentication system based on a zero-trust architecture, wherein the digital identity authentication system includes a client and a server, and the client accesses the server through a zero-trust architecture gateway; The digital identity verification method comprises: Obtaining an identity authentication result according to the user information and the multi-factor identity authentication information; Generate a session token and create a session based on the identity authentication result; wherein the session token encrypts and stores the user information, multi-factor identity authentication information, initial access rights and session status; Collecting the user's behavior data, device fingerprint data, and geographic location data in real time during the session, and dynamically adjusting the access rights of the session token storage according to the behavior data, device fingerprint data, and geographic location data; Each time a request is received from a client, the Zero Trust Architecture Gateway determines the current session state of the server by verifying the current session token.

2. A digital identity authentication method based on zero trust architecture as claimed in claim 1, characterized in that: The step of obtaining an identity authentication result based on the user information and the multi-factor identity authentication information is performed by the client and includes: According to the user information, the initial identity authentication result is obtained; Based on the initial identity authentication result, an identity authentication result is obtained according to multi-factor identity authentication information; wherein the multi-factor identity authentication information includes dynamic authentication information and biometric information.

3. A digital identity authentication method based on zero trust architecture as claimed in claim 1, characterized in that: The real-time collection of the user's behavior data, device fingerprint data, and geographic location data during the session, and the dynamic adjustment of the access rights stored in the session token according to the behavior data, device fingerprint data, and geographic location data, are performed by the server and include: Analyzing the behavior data, device fingerprint data, and geographic location data through a preset model to obtain a risk score updated in real time; wherein the behavior data, device fingerprint data, and geographic location data are encrypted and stored in the session token; The access rights of the session token storage are dynamically adjusted according to the risk score.

4. A digital identity authentication method based on zero trust architecture as claimed in claim 3, characterized in that: The behavior data, device fingerprint data, and geographic location data are analyzed by a preset model to obtain a real-time updated risk score, which is executed by the server and includes: Analyze the behavior data through a preset behavior model to obtain a first risk score; Analyze the device fingerprint data through a preset device model to obtain a second risk score; Analyze the geographic location data through a preset location model to obtain a third risk score; A final risk score is obtained according to the first risk score, the second risk score, the third risk score and a preset scoring rule.

5. A digital identity authentication method based on zero trust architecture as claimed in claim 3, characterized in that: The dynamically adjusting the access rights stored in the session token according to the risk score is performed by the server and includes: If the risk score is greater than or equal to the high risk score threshold, the access permission is to prohibit access to sensitive data and highly sensitive data, and require high risk additional identity verification; If the risk score is greater than or equal to the medium risk score threshold and less than the high risk score threshold, the access permission is to prohibit access to sensitive data and require medium risk additional identity verification; If the risk score is less than the medium risk score threshold, the access permission is the initial access permission.

6. A digital identity authentication method based on zero trust architecture as claimed in claim 5, characterized in that: If the risk score is greater than or equal to the high risk score threshold, the access permission is to prohibit access to sensitive data and highly sensitive data, and require high-risk additional identity verification, including: Obtaining a high-risk additional identity authentication result according to the dynamic authentication information and the biometric information; wherein the dynamic authentication information and the biometric information are re-provided by the client; The access permission is adjusted to the initial access permission according to the high-risk additional identity authentication result.

7. A digital identity authentication method based on zero trust architecture as claimed in claim 5, characterized in that: If the risk score is greater than or equal to the medium risk score threshold and less than the high risk score threshold, the access permission is to prohibit access to sensitive data and require medium risk additional identity verification, including: Obtaining a medium-risk additional identity authentication result according to the dynamic authentication information; wherein the dynamic authentication information is re-provided by the client; The access rights are adjusted to the initial access rights according to the medium-risk additional identity authentication result.

8. A digital identity authentication device based on zero trust architecture, characterized in that: include: Authentication module, session creation module, permission adjustment module, and token verification module; The identity authentication module is used to obtain an identity authentication result based on user information and multi-factor identity authentication information; The session creation module is used to generate a session token and create a session according to the identity authentication result; wherein the session token encrypts and stores the user information, multi-factor identity authentication information, initial access rights and session status; The permission adjustment module is used to collect the user's behavior data, device fingerprint data and geographic location data in real time during the session, and dynamically adjust the access rights stored in the session token according to the behavior data, device fingerprint data and geographic location data; The token verification module is used to determine the current session status of the server by verifying the current session token each time the zero trust architecture gateway receives a request sent by the client.

9. A terminal device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a digital identity authentication method based on a zero trust architecture as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: include: A stored computer program, wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a digital identity authentication method based on a zero-trust architecture as described in any one of claims 1-7.

Citation Information

Cited By

  • Automatic VPN authentication method and system integrating OAuth and zero-trust architecture

    CN120979770A

  • An automated VPN authentication method and system integrating OAuth and zero-trust architecture

    CN120979770B

  • Zero-trust adaptive API gateway method and device based on multi-dimensional spatio-temporal context awareness

    CN121984687A

  • Zero trust adaptive API gateway method and apparatus based on multi-dimensional spatiotemporal context perception

    CN121984687B

  • Security verification method and device, network equipment and readable storage medium

    CN122475951A