Equipment security authentication method, equipment and storage medium

By managing dynamic certificates and two-way security authentication between the platform and the client, the security and cross-device compatibility issues of existing offline identity authentication schemes are resolved. This achieves high security and cross-device collaboration capabilities in offline environments, enhancing the anti-counterfeiting capabilities and reliability of the authentication system.

CN120856475AActive Publication Date: 2025-10-28SHENZHEN TENDZONE INTELLIGENT TECH

Patent Information

Application Number
CN202511351240.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-22
Publication Date
2025-10-28
Estimated Expiration
2045-09-22

AI Technical Summary

Technical Problem

Existing offline identity authentication schemes have shortcomings in terms of security and cross-device compatibility. They are difficult to ensure both the feasibility of system implementation and cross-device collaboration capabilities. In particular, the authentication system is prone to collapse when the private key is leaked, and it is difficult to support cross-device identity synchronization and mutual recognition.

Method used

By managing dynamic certificates between the control platform and the client, a two-way security authentication mechanism is adopted. The pre-stored platform private key is used to decrypt the client's attendance information, and identity authentication information is generated based on the device's public key. Combined with dynamic certificates and multi-layer encryption mechanisms, the security of information transmission and cross-device compatibility are ensured.

Benefits of technology

It enhances anti-counterfeiting capabilities and cross-device compatibility in offline environments, strengthens the security and reliability of the authentication system, prevents system crashes caused by replay attacks and private key leaks, and supports cross-device identity synchronization and mutual recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856475A_ABST
    Figure CN120856475A_ABST
Patent Text Reader

Abstract

The invention discloses an equipment security authentication method, equipment and a storage medium. The method comprises the following steps: decrypting received client card punching information through a pre-stored platform private key; the decrypted clock-in information is verified, and identity authentication information is generated based on a device public key corresponding to the client when it is determined that the clock-in information is correct; issuing the identity authentication information to the client, so that the client decrypts the identity authentication information based on a pre-stored device private key and then initiates the next time of clock-in information; wherein a platform private key and a platform public key are pre-stored in the management and control platform, a project certificate corresponding to the project is generated based on a current new project, a client side is determined according to the project certificate, and identity authentication information is issued to the client side. According to the method, the technical effect of improving the anti-counterfeiting capability and cross-device compatibility in an offline environment is achieved through the two-way security authentication based on dynamic certificate management between the management and control platform and the client.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security authentication technology, and in particular to a device security authentication method, device and storage medium. Background Technology

[0002] In the field of identity authentication for offline application systems, user information security has always faced severe challenges. Current system solutions generally suffer from vulnerabilities that allow hackers to easily eavesdrop, forge, and obtain sensitive user information without authorization, leading to significant risks such as user data breaches and economic losses. Some systems still transmit user passwords directly in plaintext, allowing attackers to easily intercept valid credentials; others use hash algorithms such as MD5 to process passwords but are unable to defend against replay attacks—attackers do not need to decipher the ciphertext; they can simply resend the encrypted data to pass verification. Furthermore, when authentication platforms access user databases, the database itself often becomes a target for intrusion; once compromised, it can cause large-scale information leaks.

[0003] To enhance security, some solutions employ asymmetric cryptography for offline authentication. The authentication platform generates and stores asymmetric key pairs; the public key is distributed to user devices and the database, while the private key is kept by the platform. User devices encrypt authentication information using the public key and send it; the platform decrypts and verifies it using the private key. While this avoids some risks associated with plaintext transmission, system security heavily relies on the secrecy of the private key. If the private key is leaked, the entire authentication system will collapse. Furthermore, this solution only addresses communication security between a single device and the platform, failing to support cross-device identity synchronization and mutual recognition scenarios, and lacking adaptability to complex trust relationships in distributed environments. Therefore, current technology still struggles to simultaneously ensure offline authentication security while also considering system feasibility and cross-device collaboration capabilities, necessitating a more comprehensive identity authentication solution.

[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of this application is to provide a device security authentication method, device, and storage medium, which aims to solve the technical problems of security and cross-device compatibility of existing offline identity authentication.

[0006] To achieve the above objectives, this application proposes a device security authentication method applied to a management and control platform, the method comprising: The received client attendance information is decrypted using a pre-stored platform private key, wherein the client sends the attendance information to the management platform using a pre-integrated platform public key; Verify the decrypted attendance information, and generate identity authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct. The authentication information is sent to the client so that the client can decrypt the authentication information based on the pre-stored device private key and then initiate the next check-in. The management platform pre-stores a platform private key and a platform public key, generates a project certificate corresponding to the currently created project, identifies the client based on the project certificate, and sends the authentication information to the client. The client then decrypts the authentication information using the device private key to obtain the user's identity credential, and encrypts the user's identity credential using the pre-integrated platform public key to initiate the check-in.

[0007] In one embodiment, the step of verifying the decrypted attendance information and generating authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct includes: Verify the user identity credentials and timeliness information in the check-in information; When the user identity credential is confirmed to be valid, it is determined whether the check-in information has expired based on the current time and the timeliness information. If the check-in information has not expired, then the check-in information is deemed to be correct.

[0008] In one embodiment, the step of verifying the decrypted attendance information and generating authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct includes: Extract user identity credentials from the check-in information and generate time-sensitive information based on the user identity credentials; The user identity credential and the timeliness information are combined to generate a security token; The security token is encrypted using the device public key corresponding to the client, and the encrypted security token is used to generate the identity authentication information.

[0009] In one embodiment, the step of extracting user identity credentials from the check-in information and generating timeliness information based on the user identity credentials includes: Obtain the user permissions corresponding to the user identity credential, and determine the number of times the token can be used based on the user permissions; Obtain the corresponding verification parameters based on the client's current geographical location information; The validity information is generated based on the current time, the number of times the token has been used, and the verification parameters.

[0010] In one embodiment, the step of generating a security token from the user identity credential and the expiration information includes: Collect the hardware fingerprint of the device where the client is located and the hash value of the currently running software environment, and generate additional parameters based on the hardware fingerprint and the software environment hash value; The token generation algorithm is updated based on the additional parameters, and the security token is generated by the user identity credentials and the expiration information through the token generation algorithm.

[0011] In one embodiment, the management platform pre-stores a platform private key and a platform public key, generates a project certificate corresponding to the newly created project, determines the client based on the project certificate, and sends identity authentication information to the client, including: Generate a unique asymmetric key pair for the project, and embed the device private key of the asymmetric key pair into the project certificate; The project certificate is encrypted using an encryption key generated by a symmetric encryption algorithm, and the encrypted project certificate is then sent to the client corresponding to the project.

[0012] To achieve the above objectives, this application also proposes a device security authentication method applied to a client, the device security authentication method comprising the following steps: Receive identity authentication information issued by the management and control platform, and decrypt the identity authentication information using the pre-stored device private key to obtain the user identity credential; The user identity credentials are encrypted using a pre-integrated platform public key to generate attendance information, which is then sent to the management platform for verification. After successful verification on the management platform, you will be taken to the project control page. After successful verification, the management platform reissues the identity authentication information. After decrypting the identity authentication information, the platform sends the next check-in information to the management platform.

[0013] In addition, to achieve the above objectives, this application also proposes a device security authentication device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the device security authentication method as described above.

[0014] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the device security authentication method described above.

[0015] One or more technical solutions proposed in this application have at least the following technical effects: The received client attendance information is decrypted using a pre-stored platform private key. The client sends the attendance information to the management platform using a pre-integrated platform public key. The platform verifies the decrypted attendance information and, if it is correct, generates authentication information based on the client's corresponding device public key. This authentication information is then sent to the client, allowing it to decrypt the authentication information using the pre-stored device private key and initiate the next attendance session. The management platform pre-stores a platform private key and a platform public key, generates a project certificate based on the currently created project, identifies the client using the project certificate, and sends authentication information to the client. The client then decrypts the authentication information using its device private key to obtain user credentials and encrypts these credentials using the pre-integrated platform public key to initiate the attendance session. Therefore, this application achieves improved anti-counterfeiting capabilities and cross-device compatibility in offline environments through two-way secure authentication between the management platform and the client based on dynamic certificate management. Attached Figure Description

[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a flowchart illustrating the first embodiment of the device safety certification method of this application; Figure 2 This is a schematic flowchart of another embodiment of the device safety certification method of this application; Figure 3 A diagram illustrating how user equipment sends attendance information to the management platform; Figure 4 This is a schematic diagram illustrating the management of equipment based on a control platform. Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the device security authentication method in this application embodiment.

[0019] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0020] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.

[0021] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0022] The main solution of this application embodiment is as follows: The received client attendance information is decrypted using a pre-stored platform private key. The client sends the attendance information to the management platform using a pre-integrated platform public key. The decrypted attendance information is verified, and if the attendance information is correct, authentication information is generated based on the device public key corresponding to the client. The authentication information is then sent to the client so that the client can decrypt the authentication information using the pre-stored device private key and initiate the next attendance session. The management platform pre-stores a platform private key and a platform public key, generates a project certificate corresponding to the currently created project, determines the client based on the project certificate, and sends the authentication information to the client. The client then decrypts the authentication information using the device private key to obtain user identity credentials and encrypts the user identity credentials using the pre-integrated platform public key to initiate the attendance session.

[0023] Current solutions employ asymmetric cryptography for offline authentication. The authentication platform generates and stores the asymmetric key pair; the public key is distributed to user devices and the database, while the private key is kept by the platform. User devices encrypt authentication information using the public key and send it, while the platform decrypts and verifies it using the private key. While this avoids some risks associated with plaintext transmission, system security heavily relies on the secrecy of the private key. A leak of the private key could cause the entire authentication system to collapse. Furthermore, this solution only addresses communication security between a single device and the platform, failing to support cross-device identity synchronization and mutual recognition scenarios, and lacking adaptability to complex trust relationships in distributed environments. Therefore, current technology struggles to simultaneously ensure offline authentication security while also considering system feasibility and cross-device collaboration capabilities, necessitating a more comprehensive identity authentication solution.

[0024] This application provides a solution that improves anti-counterfeiting capabilities and cross-device compatibility in offline environments through two-way security authentication based on dynamic certificate management between the management platform and the client.

[0025] Based on this, this application provides a device security authentication method applied to a management and control platform, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the device security authentication method of this application. In this embodiment, the device security authentication method includes steps S10 to S30: Step S10: Decrypt the received client attendance information using the pre-stored platform private key, wherein the client sends the attendance information to the management platform using the pre-integrated platform public key; In this embodiment, the management platform decrypts the received client attendance information using a pre-stored platform private key. The platform private key is generated using an asymmetric encryption algorithm, pre-stored in the hardware security module of the management platform, and access is controlled through a multi-factor authentication mechanism. Specifically, the management of the platform private key adopts a hierarchical deterministic key derivation system, supporting key rotation and updates without affecting the existing authentication process, thereby significantly improving the long-term security of the system.

[0026] When decrypting the client's attendance information using the platform's private key, the decryption process first performs format verification on the received client attendance information data packet, comprehensively checking the data packet length, identifier, and integrity check value. After the format verification passes, the hardware security module's decryption service is invoked, using the pre-stored platform private key to perform asymmetric decryption on the client's attendance information. To ensure key security, all decryption operations are performed in a secure, isolated environment, fundamentally preventing the private key from being exposed in the system's main memory and effectively resisting memory sniffing attacks.

[0027] The decrypted client attendance information employs a multi-layered encryption structure. The outer layer uses an asymmetric encryption algorithm for protection, while the inner layer uses a symmetric encryption algorithm to ensure data confidentiality. The management platform first uses its private key to decrypt the outer layer of the client attendance information, and then uses a dynamically generated session key to decrypt the inner layer data, ultimately restoring the plaintext attendance information. This dual encryption mechanism ensures transmission security while improving encryption and decryption efficiency, making it particularly suitable for high-concurrency scenarios.

[0028] Specifically, the client's attendance information includes key fields such as user identity credentials, high-precision timestamps, encrypted random numbers, and digital signatures. Deep syntax parsing and semantic analysis are performed on the decrypted client attendance information to accurately extract the values ​​of each key field and conduct multi-dimensional verification. Specifically, the timestamp verification mechanism effectively prevents replay attacks, the encrypted random number ensures the uniqueness of each transmission, and the digital signature provides complete data source authentication and integrity protection.

[0029] The platform maintains detailed key usage records and access logs, fully recording information such as the timestamp, client identifier, operation result, and system status of each decryption operation. The access logs are stored using tamper-proof technologies, including blockchain notarization and digital signature mechanisms, providing reliable evidence for security audits and troubleshooting. The system also implements real-time key usage monitoring, using intelligent algorithms to detect abnormal decryption behavior and promptly issue security alerts, forming a complete security protection loop.

[0030] Furthermore, the management platform incorporates Transparent Data Encryption (TDE) technology to provide real-time encryption protection for log files at the storage level, ensuring that even if data files are illegally accessed, attackers cannot read the plaintext content. Simultaneously, the management platform employs a full key lifecycle management scheme, including security controls for each stage of key generation, storage, use, rotation, and destruction, complying with relevant regulatory requirements.

[0031] To enhance the system's resistance to attacks, the management platform also deploys multiple defense mechanisms, including deep packet inspection to prevent injection attacks, frequency limiting to prevent brute-force attempts, and a two-way authentication mechanism to ensure the legitimacy of both communicating parties. For details, please refer to [link / reference needed]. Figure 3 , Figure 3 This is a diagram illustrating how user equipment sends attendance information to the management platform.

[0032] Step S20: Verify the decrypted attendance information, and generate identity authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct; As shown, after decrypting the received client attendance information using a pre-stored platform private key, the decryption result is verified using a pre-created verification strategy. Specifically, this verification strategy is implemented based on relevant fields in the decryption result, including but not limited to identity credential verification and timeliness verification.

[0033] The identity credential verification process includes checking the user's permission scope, certificate validity period, and usage restrictions. During this verification, the identity management system is searched using the decrypted user identity information. Based on the search results, the user identifier in the credential is compared with records in the authorization database to ensure the user is active and has the corresponding operational permissions. Simultaneously, the issuer of the credential and the digital certificate chain are verified to prevent credential forgery. The timeliness verification compares the current time with the timestamp in the credential to ensure the request is within the allowed time window, i.e., within the valid check-in time range. This process incorporates a reasonable time tolerance, balancing network transmission latency and clock synchronization errors. Therefore, if the timestamp of the client's check-in information is within the time window, the client's check-in is considered valid; if the timestamp is not within the time window, it is determined to be an expired check-in, the abnormal event of the expired card is recorded, the security management platform is notified, and the corresponding security response mechanism is triggered.

[0034] After the client's attendance information is verified, new identity authentication information is generated based on the device public key corresponding to the client. This authentication information uses a structured data format and includes fields such as user identifier, session identifier, permission list, effective time, expiration time, and scope of use. All fields are standardized to ensure data consistency and interoperability between systems.

[0035] Specifically, a dynamic strategy mechanism is used to generate the identity authentication information, dynamically adjusting its content composition and validity period based on client type, network environment characteristics, and security level requirements. For high-risk environments, the system employs a short validity period and multi-factor authentication strategy; for low-risk environments, the validity period is appropriately extended to improve user experience. Furthermore, custom field extensions can be added based on the identity authentication information to meet the specific needs of particular projects.

[0036] Based on the generated identity authentication information, the authentication information is signed using the device private key recorded on the management platform, thereby ensuring the integrity and non-repudiation of the information. When signing the identity authentication information based on the device private key, a standardized asymmetric encryption scheme is used to provide sufficient security strength for the signature. Furthermore, the signature value is appended to the end of the authentication information in a standardized format, forming a complete authentication token structure.

[0037] Furthermore, the step of verifying the decrypted attendance information and generating authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct includes: Verify the user identity credentials and timeliness information in the check-in information; When the user identity credential is confirmed to be valid, it is determined whether the check-in information has expired based on the current time and the timeliness information. If the check-in information has not expired, then the check-in information is deemed to be correct.

[0038] In this embodiment, the decrypted attendance information is verified, specifically to verify the user identity credentials and validity information within the attendance information. The verification of the user identity credentials includes permission level matching and digital signature verification to ensure the legitimacy and validity of the credentials. The verification of the validity information specifically involves determining that the validity information includes at least a timestamp and a validity period parameter. Specifically, the settings based on the user identity credentials and validity information can be dynamically configured according to the client type and security requirements.

[0039] After confirming the validity of the user's identity credentials, the system determines whether the check-in information has expired based on the current time and validity period information. The comparison between the current time and validity period information uses a time synchronization service to obtain an accurate time reference, ensuring the accuracy of the time determination. The timeout determination employs a time window mechanism, calculating the difference between the timestamp and the current time and comparing it with a preset valid period threshold.

[0040] If the check-in information has not expired, the check-in information is deemed correct. The validity period threshold is dynamically adjusted based on the network environment and security level. Furthermore, the user identity credential and validity information are combined using a joint signature mechanism to generate a composite verification object, ensuring data integrity and tamper-proofness. Through this dual verification mechanism, the system not only guarantees the legitimacy of the user's identity but also effectively prevents replay attacks and credential reuse risks.

[0041] Furthermore, the step of verifying the decrypted attendance information and generating authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct includes: Extract user identity credentials from the check-in information and generate time-sensitive information based on the user identity credentials; The user identity credential and the timeliness information are combined to generate a security token; The security token is encrypted using the device public key corresponding to the client, and the encrypted security token is used to generate the identity authentication information.

[0042] In this embodiment, a security token is generated by using user identity credentials and timeliness information, and identity authentication information is generated by encryption. If the hardware characteristics and operating environment information of the client's device are not combined during the generation of the security token, the token generation parameters may be too simple, making it easy for attackers to forge security tokens by simulating the device environment, thereby triggering the risk of identity theft.

[0043] This process involves obtaining the token usage count corresponding to user permissions to generate validity information, combining it with verification parameters corresponding to the client's geographical location information, and the current time to generate validity information. Furthermore, after collecting the client's hardware fingerprint and software environment hash value to generate additional parameters, the token generation algorithm is updated. The updated token generation algorithm then combines the user identity credentials and validity information to generate a security token. The hardware fingerprint may include a device serial number or processor identifier, and the software environment hash value is generated by scanning the binary file of the currently running process. Additionally, the combination of these additional parameters with the token generation algorithm introduces dynamic device characteristics into the security token generation process, ensuring the uniqueness of each generated token.

[0044] Specifically, after the client initiates a check-in request, the management platform extracts the user's identity credentials and determines the maximum number of token uses allowed based on the user's permissions. Simultaneously, it obtains the geographical location information reported by the client and matches the corresponding verification parameters according to a preset regional security level mapping table. Combining the current timestamp, the maximum number of token uses, and the verification parameters, it generates validity information including the expiration date. Subsequently, the management platform collects the client's hardware fingerprint and calculates the environmental characteristics of the currently running software process using a hash algorithm. The hardware fingerprint and the software environment hash value are concatenated and used as additional parameters to input into the token generation algorithm, updating the algorithm's initialization vector. The updated algorithm then fuses the user's identity credentials and validity information to generate a security token containing dynamic device characteristics. This token is encrypted with the device's public key and sent to the client. After decryption, the client verifies whether the hardware fingerprint matches the current software environment, ensuring that the token cannot be copied and used by other devices.

[0045] The security token is encrypted using the device's public key, and authentication information is generated from the encrypted security token. Furthermore, the security token is encrypted using the RSA asymmetric encryption algorithm with a 2048-bit device public key to generate encrypted authentication information. Therefore, the authentication information can only be decrypted by the client holding the corresponding private key, ensuring the security of the authentication process.

[0046] This embodiment implements an authentication mechanism that generates a security token based on user identity credentials and expiration information, and transmits it using device public key encryption. This mechanism avoids the plaintext transmission of sensitive information, enhancing the security of the authentication process. Simultaneously, the introduction of expiration information limits the token's validity period, effectively preventing replay attacks. Furthermore, using device public key encryption ensures that legitimate clients can decrypt authentication information, improving the reliability and security of the entire authentication system.

[0047] In addition, the step of extracting user identity credentials from the check-in information and generating timeliness information based on the user identity credentials includes: Obtain the user permissions corresponding to the user identity credential, and determine the number of times the token can be used based on the user permissions; Obtain the corresponding verification parameters based on the client's current geographical location information; The validity information is generated based on the current time, the number of times the token has been used, and the verification parameters.

[0048] In this embodiment, considering that relying solely on user identity credentials when generating timeliness information may lead to the token being maliciously reused or abused in different geographical locations, it is impossible to effectively limit the scope of application and usage of the token, which poses a security risk.

[0049] Therefore, by limiting the number of token uses corresponding to user permissions, and setting verification parameters based on this token usage count and geographical location information, time-sensitive information is generated based on the current time, token usage count, and verification parameters. The user permissions are mapped to an upper limit on the number of token uses; for example, administrator permissions allow the generation of a single valid token, while ordinary user permissions allow the generation of three valid tokens. The client's geographical location information is obtained in real time via a GPS module. The verification parameters include a region code and a network access point identifier. The current time is recorded in Coordinated Universal Time (UTC) format. The time-sensitive information is generated by combining the usage count and verification parameters; for example, the hash value calculated after concatenating these three elements is used as the time-sensitive information.

[0050] Specifically, the number of token usages corresponding to the user permissions is written into the validity period information. When a client initiates a request, the management platform verifies the validity of the remaining usages by decrementing a counter. The geolocation verification parameter is embedded in the validity period information. After receiving the request, the management platform compares the real-time location reported by the client with the area code in the validity period information. If cross-regional use is detected, the token is deemed invalid. The difference between the current time and the timestamp in the validity period information is calculated, and the token is automatically invalidated if the difference exceeds a preset threshold. Through the dynamic combination of multi-dimensional parameters, the validity period information generated each time is unique and scenario-specific, preventing the token from being intercepted and used for unauthorized devices or replay attacks in different locations.

[0051] In the specific implementation process, after extracting the user's identity credential from the attendance information, the user's permission level corresponding to that identity credential is first obtained. The number of times the token can be used is then determined based on the permission level.

[0052] The system retrieves the corresponding verification parameters based on the client's current geographic location. Specifically, the system can pre-divide multiple geographic regions, each corresponding to a unique verification parameter. When the client is located in a certain region, the system retrieves the verification parameters corresponding to that region.

[0053] The system generates time-sensitive information based on the current time, the number of times the token has been used, and verification parameters. The generation process can use the following algorithm: multiply the current timestamp by the number of times the token has been used, and then perform an XOR operation with the verification parameters. The result is the time-sensitive information.

[0054] This embodiment implements a multi-layered dynamic verification mechanism based on user permissions, geographical location, and time. This improves the security and accuracy of identity authentication, effectively preventing identity theft and unauthorized access. Simultaneously, by incorporating geographical location information, the system's ability to identify abnormal login behavior is enhanced. Furthermore, dynamically adjusting the number of token uses ensures convenience for high-privilege users while limiting potential risks for low-privilege users.

[0055] Specifically, the step of generating a security token from the user identity credential and the expiration information includes: Collect the hardware fingerprint of the device where the client is located and the hash value of the currently running software environment, and generate additional parameters based on the hardware fingerprint and the software environment hash value; The token generation algorithm is updated based on the additional parameters, and the security token is generated by the user identity credentials and the expiration information through the token generation algorithm.

[0056] In this embodiment, user identity credentials are extracted from the attendance information and timeliness information is generated based on the user identity credentials. The hardware fingerprint of the client's device and the hash value of the currently running software environment are collected. Additional parameters are generated based on the hardware fingerprint and the software environment hash value. The token generation algorithm is updated based on the additional parameters. The user identity credentials and timeliness information are then used to generate a security token through the token generation algorithm.

[0057] The hardware fingerprint includes unique identifiers such as device serial number, network card MAC address, or motherboard chipset code. The software environment hash value is generated by calculating the currently running process list, system service configuration, and dynamic link library version information. The additional parameters are generated by performing a bitwise XOR operation between the hash digest of the hardware fingerprint and the software environment hash value to produce a binary sequence, which serves as the initialization vector for the token generation algorithm. Furthermore, the token generation algorithm employs an HMAC-SHA256 function that is dynamically adjusted based on the additional parameters. This function allows the salt value of the hash operation to be modified each time a security token is generated.

[0058] Specifically, when the client device initiates the attendance process, it first calls the system interface to obtain the device fingerprint information, including reading the hardware identification code in the baseboard management controller, and simultaneously scanning the currently running process to generate a hash tree. After receiving the client information, the management platform inputs the hardware fingerprint and the software environment hash value into a preset obfuscation function to generate 128-bit additional parameters. The token generation algorithm adjusts the number of hash iterations and the filling rules through the additional parameters, performing multiple rounds of hash operations on the user identity credentials, validity information, and additional parameters, and finally outputting a secure token containing the characteristics of all three. Since the additional parameters are derived from the device's physical characteristics and real-time environmental status, even if an attacker obtains the user identity credentials and validity information, they cannot generate the same token on an unauthorized device, thus achieving a strong binding between the secure token and the device's operating environment.

[0059] In the specific implementation process, the hardware fingerprint of the client's device and the hash value of the currently running software environment are collected. The hardware fingerprint can be generated by obtaining hardware information such as the device's CPU serial number, MAC address, and hard drive serial number. The software environment hash value can be obtained by hashing information such as the currently running operating system version and the list of installed applications.

[0060] Additional parameters are generated based on the hardware fingerprint and the software environment hash value. Specifically, the hardware fingerprint and the software environment hash value are concatenated, and then the concatenated result is subjected to a SHA-256 hash operation to obtain 32 bytes of additional parameters. The token generation algorithm is updated based on these additional parameters.

[0061] The updated token generation algorithm generates a security token from user identity credentials and expiration information. Specifically, the user identity credentials and expiration information are first concatenated, then the concatenated result is encrypted using the updated AES encryption steps, and finally the encrypted result is Base64 encoded to obtain the final security token.

[0062] This embodiment effectively improves the uniqueness and unpredictability of security tokens. Because the latest hardware fingerprint and software environment information are collected each time a security token is generated, even with the same user credentials and validity period, security tokens generated by different devices or at different times will differ. This increases the difficulty for attackers to deduce or forge valid tokens using known information, thereby enhancing the security of the entire authentication system. Simultaneously, by dynamically updating the token generation algorithm, the system's resistance to attacks is further enhanced; even if an attacker obtains information about a particular token generation process, it will not affect the security of subsequent tokens. Furthermore, this scheme can also, to some extent, prevent attacks such as device impersonation and software environment tampering, because any change in the hardware or software environment will cause changes in the generated security token, thus allowing the system to detect potential security risks.

[0063] Step S30: The identity authentication information is sent to the client so that the client can decrypt the identity authentication information based on the pre-stored device private key and then initiate the next check-in. The management platform pre-stores a platform private key and a platform public key, generates a project certificate corresponding to the currently created project, determines the client based on the project certificate, and sends the identity authentication information to the client so that the client can decrypt the identity authentication information using the device private key to obtain the user identity credential, and then encrypt the user identity credential using the pre-integrated platform public key to initiate the check-in.

[0064] In this embodiment, the management platform sends the generated authentication information to the target client through a secure channel. This sending process employs a reliable transmission protocol to ensure that the authentication information is delivered to the target client completely and accurately. Specifically, an end-to-end encryption mechanism prevents intermediate nodes from eavesdropping on or tampering with the data content. Furthermore, it supports multiple transmission methods to adapt to different network environments and device capabilities, including persistent connections, message queues, and asynchronous callbacks, ensuring reliable data transmission under various network conditions.

[0065] The client receiving module performs a preliminary check on the sent authentication information, primarily to verify the data packet format and transmission integrity. Upon successful verification, the authentication information is forwarded to the decryption processing unit for decryption. This decryption operation is performed within the client's hardware security environment, using a pre-stored device private key to decrypt the outer encryption layer, obtain the symmetric encryption key, and then decrypt the inner data.

[0066] The decrypted authentication information is parsed to extract the values ​​of each field. Furthermore, the validity of the digital signature is verified to confirm that the authentication information originates from a trusted management platform. The timestamp and expiration date are also checked to ensure the timeliness and applicability of the authentication information. If the authentication verification fails, the error message is recorded and a retry or alarm mechanism is triggered to prevent the use of invalid or expired authentication information.

[0067] Based on the decrypted authentication information, user identity credentials are extracted and stored in a secure storage area for subsequent attendance tracking. A smart credential caching mechanism is executed based on the stored credentials, enabling offline operations and rapid authentication. Furthermore, the usage records of the user identity credentials are logged and stored, providing comprehensive data support for security auditing and fault recovery.

[0068] Furthermore, all of the above is based on the fact that the management platform pre-stores the platform's private key and public key, and generates a corresponding project certificate based on the newly created project. The project certificate serves as a carrier of security trust, securely associating the corresponding client with it. Based on the project certificate, the management platform identifies the target client and accurately distributes the generated identity authentication information to the appropriate device.

[0069] Furthermore, the client decrypts the authentication information using the device's private key to obtain the user's identity credential, and then encrypts this credential using a pre-integrated platform public key to initiate the attendance tracking. This two-way encryption and decryption mechanism forms a closed-loop authentication process, achieving a secure authentication cycle between the client and the management platform.

[0070] Furthermore, by setting up a dynamic policy adjustment mechanism, the validity period and encryption strength of the authentication information can be adjusted in real time based on network conditions, security threat levels, and device capabilities. For example, security measures can be automatically enhanced in high-risk environments, while user experience can be optimized in low-risk environments, achieving the best balance between security and efficiency.

[0071] Furthermore, the control platform has a comprehensive key management mechanism, including functions such as key rotation, update, and revocation. All key materials are stored in a hardware security module, and access control is implemented through a multi-factor authentication mechanism to ensure that even if some key materials are leaked, the security of the entire system will not be compromised.

[0072] In addition, the management platform pre-stores a platform private key and a platform public key. The steps of generating a project certificate corresponding to the newly created project, determining the client based on the project certificate, and sending authentication information to the client include: Generate a unique asymmetric key pair for the project, and embed the device private key of the asymmetric key pair into the project certificate; The project certificate is encrypted using an encryption key generated by a symmetric encryption algorithm, and the encrypted project certificate is then sent to the client corresponding to the project.

[0073] In this embodiment, a unique asymmetric key pair is generated based on the project, and the device private key of the asymmetric key pair is embedded in the project certificate. The project certificate is encrypted with an encryption key generated by a symmetric encryption algorithm, and the encrypted project certificate is sent to the client corresponding to the project.

[0074] When generating a unique asymmetric key pair, RSA or ECC algorithms can be used to generate the public-private key pair. The device private key is bound to the project certificate to ensure its uniqueness. The symmetric encryption algorithm can use AES-256 or SM4 to generate the encryption key, which is transmitted to the client through a secure channel. After the project certificate is encrypted, the client needs to decrypt it using the pre-stored symmetric key to obtain the device private key. The asymmetric key pair is used to ensure the security of the generation and binding of the device private key, while the symmetric encryption algorithm improves the transmission efficiency of the project certificate. The combination of the two forms a dual protection mechanism during the key distribution stage.

[0075] Specifically, the management platform first generates an asymmetric key pair, combining the device's private key with the project certificate's metadata to generate a digital signature, ensuring the integrity and trustworthiness of the project certificate's origin. Then, a one-time encryption key is generated using a symmetric encryption algorithm to encrypt the project certificate containing the device's private key. The encrypted data is transmitted to the client via a communication link. Upon receiving the encrypted project certificate, the client decrypts it using a pre-set symmetric key, extracts the device's private key, and stores it in a secure area. In this process, asymmetric encryption ensures the immutability of the binding relationship between the device's private key and the project certificate, while symmetric encryption reduces encryption computation overhead and avoids the risk of man-in-the-middle attacks that may be present with asymmetric encryption. Thus, the confidentiality and integrity of the project certificate are effectively protected during transmission, providing a trusted key foundation for subsequent identity authentication processes.

[0076] Based on the technical content described above, in practical applications, the management platform generates a unique asymmetric key pair for each new project, including a device private key and a device public key. The management platform embeds the device private key into the project certificate. Next, the management platform generates an encryption key using a symmetric encryption algorithm and uses this encryption key to encrypt the project certificate. The encrypted project certificate is then distributed to the client corresponding to the project. Upon receiving the encrypted project certificate, the client decrypts it using a pre-obtained decryption key to obtain the project certificate containing the device private key. The client can then use this device private key for subsequent authentication operations. Furthermore, all the platform public and private keys of the management platform, the device public and private keys based on the client, and the project certificate distributed based on the project are backed up and stored in the user database during generation. Based on the above-described embodiment, it can be viewed... Figure 4 , Figure 4 This is a schematic diagram of equipment management based on a control platform.

[0077] This embodiment implements secure distribution of project certificates. By generating a unique asymmetric key pair for each project, isolation between projects is enhanced. Embedding the device's private key into the project certificate and encrypting its transmission avoids the risk of private key leakage during network transmission. Using a symmetric encryption algorithm to encrypt the project certificate improves transmission efficiency. This approach ensures both key security and improved certificate distribution efficiency, laying a secure foundation for subsequent identity authentication processes.

[0078] Based on this, this application provides a device security authentication method, applied to a client, as shown below. Figure 2 , Figure 2 This is a schematic flowchart of another embodiment of the device security authentication method of this application. In this embodiment, steps S40-S60 are included: Step S40: Receive the identity authentication information issued by the management and control platform, and decrypt the identity authentication information using the pre-stored device private key to obtain the user identity credential; Step S50: The user identity credential is encrypted using a pre-integrated platform public key to generate attendance information, which is then sent to the management platform for verification. Step S60: After successful verification on the management platform, the user enters the project control page; wherein, after successful verification, the management platform reissues the identity authentication information, and after decrypting the identity authentication information, the user initiates the next check-in information to the management platform.

[0079] In this embodiment, due to the security risks in the transmission of authentication information between the client and the management platform, attackers may intercept encrypted data packets to carry out replay attacks. Furthermore, a single encryption mechanism cannot adapt to the dynamically changing authentication environment, making identity synchronization difficult in cross-device scenarios.

[0080] Based on this, a device security authentication method applied to the client includes receiving identity authentication information issued by the management platform and obtaining user identity credentials by decrypting them with a pre-stored device private key. The user identity credentials are then encrypted with the platform's public key to generate check-in information, which is sent to the management platform for verification. After successful verification, the user enters the project control page, and the management platform reissues the identity authentication information to initiate the next check-in.

[0081] The device's private key and the platform's public key form a dual-encryption link. When the client decrypts the authentication information, it needs to verify the integrity of the security token. The encrypted check-in information includes dynamic expiration parameters. Before each check-in, the client needs to obtain the latest authentication information. The management platform implements a dynamic verification mechanism by periodically updating the expiration information in the security token.

[0082] Specifically, after receiving the encrypted identity authentication information, the client decrypts it using the device's private key to extract the security token. It then verifies whether the user's identity credentials and validity information in the token match the current system time and device environment parameters. Upon successful verification, the client uses the platform's public key to perform a second encryption of the user's identity credentials to generate attendance information. This encryption process adds a random salt to prevent replay attacks. After successful verification by the management platform, a security token containing the new validity information is issued. The client must update the decryption key synchronously upon the next attendance. The decryption process of updating the decryption key establishes a closed-loop authentication chain through a two-way asymmetric encryption mechanism. Each attendance message carries unique encryption parameters, ensuring that the identity credentials cannot be copied or tampered with across devices.

[0083] Specifically, the client receives authentication information from the management platform. This authentication information is an encrypted security token. The client uses a pre-stored device private key to perform asymmetric decryption of the authentication information to obtain the security token. Further, the client parses the security token to extract the user identity credentials it contains.

[0084] Furthermore, the client uses a pre-integrated platform public key to perform asymmetric encryption on the user's identity credentials to generate attendance information. The client then sends the encrypted attendance information to the management platform for verification. After successful verification by the management platform, the client is authorized to access the project control page. Specifically, the client receives the verification confirmation from the management platform, loads and displays the project control interface, allowing the user to perform relevant operations.

[0085] Furthermore, after successful verification, the management platform will reissue new identity authentication information. The client receives this new identity authentication information and decrypts it using the device's private key to obtain a new user identity credential. For example, the client can set a scheduled task to initiate the next check-in information to the management platform using the new user identity credential after a certain time interval.

[0086] The step of receiving authentication information from the management platform and decrypting the authentication information using a pre-stored device private key to obtain user identity credentials includes: The security token is obtained by decrypting the authentication information using the device's private key. Upon verifying that the security token is correct, the security token is parsed to obtain the user identity credential.

[0087] In this embodiment, after receiving the identity authentication information issued by the management platform, the client directly decrypts it using the device's private key to obtain the user's identity credential. However, the decrypted data may contain an unverified security token, posing a risk of tampering or forgery. This could result in the subsequent encrypted attendance information containing invalid or malicious credentials, reducing the security of the authentication process. Therefore, the identity authentication information is decrypted using the device's private key to obtain a security token; if the security token is verified to be correct, it is parsed to obtain the user's identity credential.

[0088] The device's private key is used to decrypt authentication information to generate a security token. This security token contains encrypted data combining user identity credentials and validity information. Verifying the security token involves checking its integrity, validity, and additional parameters. For example, additional parameters may include the client device's hardware fingerprint and software environment hash value. By comparing the current device fingerprint with the fingerprint parameters embedded in the token, it can be determined whether the device environment has been tampered with. During verification, the token's validity information can be timed out based on the time difference between the current time and the token's generation time, with a time difference threshold set between 5 minutes and 1 hour. When parsing the security token, a predefined token parsing algorithm separates the user identity credentials and validity information to ensure the validity of the credentials.

[0089] Specifically, after receiving the encrypted authentication information, the client first decrypts it using the device's private key to generate a security token. This security token, generated by the management platform, embeds user identity credentials, validity information, and device environment parameters. When the client verifies the integrity of the security token, it performs the following steps: extracting the hardware fingerprint from the token and comparing it with fingerprint data stored on the local device; calculating the hash value of the current software environment and matching it with the hash value recorded in the token; checking the timestamp in the validity information to determine if it exceeds the preset validity period. If all the above verifications pass, the user identity credentials are extracted using a token parsing algorithm. By adding a security token verification step, tampered or forged tokens are effectively prevented from entering subsequent processes, and invalid credentials are avoided from being encrypted with the platform's public key and sent to the management platform, thereby improving the security of the identity authentication process.

[0090] In the specific implementation process, after receiving the identity authentication information issued by the management and control platform, the client calls the locally stored device private key to perform an asymmetric decryption operation on the identity authentication information, generating a security token containing a digital signature and a timestamp. The verification process of the security token is achieved by verifying the integrity of the digital signature and the validity of the timestamp. When it is detected that the digital signature has not been tampered with and the timestamp is within a preset validity period, a token parsing operation is performed to extract the encrypted data of the user's identity credentials. Furthermore, the encrypted data of the user's identity credentials is stored in Base64 encoding format and converted into a recognizable user identifier and permission level information through a decoding operation, completing the complete parsing process of the identity authentication information.

[0091] This embodiment implements secure authentication between the client and the management platform. By employing asymmetric encryption technology, it effectively prevents the theft of user identity information during transmission. Regularly updating authentication information enhances system security and reduces the risk of unauthorized access and replay attacks. Furthermore, this solution supports offline client authentication, improving system availability and user experience.

[0092] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the device security authentication method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0093] This application provides a device security authentication device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the device security authentication method in Embodiment 1 above.

[0094] The following is for reference. Figure 5 The diagram illustrates a structural schematic suitable for implementing the device security authentication device in the embodiments of this application. The device security authentication device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The device security authentication device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0095] like Figure 5As shown, the device security authentication device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the device security authentication device. The processing unit 1001, the read-only memory 1002, and the RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the device security authentication device to communicate wirelessly or wiredly with other devices to exchange data. Although device security authentication devices with various systems are shown in the figure, it should be understood that it is not required to implement or possess all the systems shown. More or fewer systems may be implemented alternatively.

[0096] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0097] The device security authentication device provided in this application, employing the device security authentication method described in the above embodiments, can solve the technical problems of security and cross-device compatibility in existing offline identity authentication. Compared with the prior art, the beneficial effects of the device security authentication device provided in this application are the same as those of the device security authentication method provided in the above embodiments, and other technical features in this device security authentication device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0098] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0099] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0100] This application provides a storage medium, which is a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the device security authentication method in the above embodiments.

[0101] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), or any suitable combination thereof.

[0102] The aforementioned computer-readable storage medium may be included in the device security authentication device; or it may exist independently and not assembled into the device security authentication device.

[0103] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the device security authentication device, enable the device security authentication device to implement the technical content of the device security authentication method embodiment shown above.

[0104] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0105] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0106] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.

[0107] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described device security authentication method, which can solve the technical problems of security and cross-device compatibility of existing offline identity authentication. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the device security authentication method provided in the above embodiments, and will not be repeated here.

Claims

1. A method for authenticating equipment safety, characterized in that, When applied to a management and control platform, the device security authentication method includes the following steps: The received client attendance information is decrypted using a pre-stored platform private key, wherein the client sends the attendance information to the management platform using a pre-integrated platform public key; Verify the decrypted attendance information, and generate identity authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct. The authentication information is sent to the client so that the client can decrypt the authentication information based on the pre-stored device private key and then initiate the next check-in. The management platform pre-stores a platform private key and a platform public key, generates a project certificate corresponding to the currently created project, identifies the client based on the project certificate, and sends the authentication information to the client. The client then decrypts the authentication information using the device private key to obtain the user's identity credential, and encrypts the user's identity credential using the pre-integrated platform public key to initiate the check-in.

2. The device security authentication method as described in claim 1, characterized in that, The step of verifying the decrypted attendance information and generating authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct includes: Verify the user identity credentials and timeliness information in the check-in information; When the user identity credential is confirmed to be valid, it is determined whether the check-in information has expired based on the current time and the timeliness information. If the check-in information has not expired, then the check-in information is deemed to be correct.

3. The device security authentication method as described in claim 1, characterized in that, The step of verifying the decrypted attendance information and generating authentication information based on the device public key corresponding to the client when the attendance information is confirmed to be correct includes: Extract user identity credentials from the check-in information and generate time-sensitive information based on the user identity credentials; The user identity credential and the timeliness information are combined to generate a security token; The security token is encrypted using the device public key corresponding to the client, and the encrypted security token is used to generate the identity authentication information.

4. The equipment security authentication method as described in claim 3, characterized in that, The step of extracting user identity credentials from the check-in information and generating timeliness information based on the user identity credentials includes: Obtain the user permissions corresponding to the user identity credential, and determine the number of times the token can be used based on the user permissions; Obtain the corresponding verification parameters based on the client's current geographical location information; The validity information is generated based on the current time, the number of times the token has been used, and the verification parameters.

5. The equipment security authentication method as described in claim 3, characterized in that, The step of generating a security token from the user identity credential and the validity period information includes: Collect the hardware fingerprint of the device where the client is located and the hash value of the currently running software environment, and generate additional parameters based on the hardware fingerprint and the software environment hash value; The token generation algorithm is updated based on the additional parameters, and the security token is generated by the user identity credentials and the expiration information through the token generation algorithm.

6. The device security authentication method as described in claim 1, characterized in that, The management platform pre-stores a platform private key and a platform public key. The steps of generating a project certificate corresponding to the newly created project, determining the client based on the project certificate, and sending authentication information to the client include: Generate a unique asymmetric key pair for the project, and embed the device private key of the asymmetric key pair into the project certificate; The project certificate is encrypted using an encryption key generated by a symmetric encryption algorithm, and the encrypted project certificate is then sent to the client corresponding to the project.

7. A method for certifying equipment safety, characterized in that, When applied to a client, the device security authentication method includes the following steps: Receive identity authentication information issued by the management and control platform, and decrypt the identity authentication information using the pre-stored device private key to obtain the user identity credential; The user identity credentials are encrypted using a pre-integrated platform public key to generate attendance information, which is then sent to the management platform for verification. After successful verification on the management platform, you will be taken to the project control page. After successful verification, the management platform reissues the identity authentication information. After decrypting the identity authentication information, the platform sends the next check-in information to the management platform.

8. The device security authentication method as described in claim 7, characterized in that, The step of receiving authentication information from the management platform and decrypting the authentication information using a pre-stored device private key to obtain user identity credentials includes: The security token is obtained by decrypting the authentication information using the device's private key. Upon verifying that the security token is correct, the security token is parsed to obtain the user identity credential.

9. A device safety authentication device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the device security authentication method as described in any one of claims 1 to 8.

10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the device security authentication method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Card punch method, device, equipment and system for mobile terminal

    CN107563712A

  • Offline physical isolation authentication method and authentication system thereof

    CN110659470A

  • Attendance check-in method, device and equipment

    CN120318925A

  • System for digital identity authentication and methods of use

    US20190149334A1

Cited By

  • Data processing method and device, electronic equipment and storage medium

    CN121211486A

  • Distributed gateway identity mutual trust method and system and related equipment

    CN121262018A