An identity authentication method and device based on a commercial cipher algorithm
By using UKey and PCI-E cryptographic card hardware in collaboration and employing SM2/SM3/SM4 algorithms, the security and performance contradiction in remote operation and maintenance identity authentication of bastion hosts is resolved, achieving high-security, high-performance two-way identity authentication and meeting the compliance requirements of critical information infrastructure.
Patent Information
- Application Number
- CN202611065145.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-17
- Publication Date
- 2026-08-25
AI Technical Summary
Existing bastion hosts suffer from problems in remote operation and maintenance identity authentication, such as insecure private key storage, computational performance bottlenecks, single and non-compliant authentication mechanisms, low hardware resource utilization, and shortcomings in standard protection, which cannot meet the high security and high performance requirements of critical information infrastructure.
By using UKey and PCI-E cryptographic card hardware collaboration, and employing SM2/SM3/SM4 algorithms, hardware collaborative authentication is achieved, and multiple security enhancements and performance optimizations are implemented, including true random number generation, hardware isolated storage, multi-dimensional signature verification, timestamp binding, and DMA non-blocking transmission, which meet national cryptographic algorithm standards and improve authentication security and performance.
It achieves highly secure and high-performance two-way identity authentication, significantly improves anti-attack capabilities, further strengthens compliance, makes identity authentication more rigorous, greatly improves computing performance, reduces operation and maintenance costs, and adapts to existing bastion host architectures without additional modifications.
Smart Images

Figure CN122640127A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security and commercial cryptography application technology, and in particular relates to an identity authentication method and device based on commercial cryptographic algorithms. Background Technology
[0002] With the full implementation of the "Information Security Technology - Basic Requirements for Network Security Level Protection" (GB / T 22239-2019) and the "Information Security Technology - Basic Requirements for Cryptographic Applications in Information Systems" (GB / T 39786-2021), the security, compliance, and high performance of the identity authentication process of the operation and maintenance audit system (bastion host) of critical information infrastructure, as the sole entry point for remote operation and maintenance, have become core prerequisites for ensuring network security. It is necessary to adopt compliant commercial cryptographic technologies for identity authentication and communication protection, and strictly follow relevant national commercial cryptographic standards and industry specifications.
[0003] In existing technologies, bastion hosts have the following deficiencies when performing remote operation and maintenance identity authentication, and these deficiencies have become core bottlenecks in the national cryptographic upgrade, information security level protection assessment, and cryptographic evaluation compliance of critical information infrastructure. Specifically:
[0004] 1) Insecure private key storage: Traditional solutions often use software certificates or private keys stored on the server's hard drive for signing and verification. Private keys are vulnerable to memory dump attacks, side-channel attacks, and Trojan viruses, failing to meet the Level 3 requirements of "key security" in the cryptographic assessment. Furthermore, they do not comply with the core specification of key isolation storage in GM / T 0028 "Security Technical Requirements for Cryptographic Modules". In confidential operation and maintenance scenarios such as finance and government, this can easily lead to major security incidents such as identity forgery, privilege theft, and data leakage.
[0005] 2) Computational performance bottleneck: In high-concurrency operation and maintenance scenarios (such as financial data centers and government cloud platforms, where daily concurrent operation and maintenance sessions can reach 500-2000), the bastion host CPU needs to handle business logic, session forwarding, log auditing and heavy SM2 / SM3 password operations at the same time, resulting in excessive CPU load (actually measured to reach 75%-90%), large session establishment latency (single authentication takes more than 200ms), which seriously affects operation and maintenance efficiency and may even cause problems such as session lag and authentication failure, and cannot meet the needs of critical business 24 / 7 uninterrupted operation and maintenance.
[0006] 3) The authentication mechanism is singular and non-compliant: Most existing solutions are one-way authentication (only the server verifies the user), lacking a two-way entity authentication mechanism based on the national cryptographic standard GB / T 15843.3-2023 "Information Technology Security Technology Entity Authentication Part 3: Authentication Using Asymmetric Signature Mechanism". As a result, maintenance personnel cannot verify the authenticity of bastion host devices, making them vulnerable to phishing gateways or man-in-the-middle attacks. At the same time, some solutions do not fully comply with the national cryptographic algorithm specifications, and have problems such as simplified authentication processes and non-standard key derivation. They cannot pass the security assessment of commercial cryptographic applications and cannot meet the compliance requirements of critical information infrastructure.
[0007] 4) Low hardware resource utilization: In the existing solutions, UKey and PCI-E cryptographic cards are mostly used independently, without forming a hardware collaborative authentication system. The hardware computing advantages of PCI-E cryptographic cards are not fully utilized, and some cryptographic operations are still performed by the CPU, which wastes hardware resources and further exacerbates the performance bottleneck. In addition, the compatibility between UKey and PCI-E cryptographic cards is poor, and there are cross-vendor compatibility issues, which increases the cost and difficulty of bastion host national cryptographic transformation.
[0008] 5) The standard itself has shortcomings in protection: GB / T 15843.3-2023 only specifies the basic process and core requirements of asymmetric two-way three-way authentication. It does not design enhanced protection mechanisms for high-risk attacks in remote operation and maintenance scenarios (such as replay attacks, side-channel attacks, and device forgery attacks), nor does it consider the actual implementation needs such as cryptographic operation performance optimization and key lifecycle management. Simply following the standard cannot meet the high security operation and maintenance requirements of critical information infrastructure.
[0009] Therefore, there is an urgent need for a two-way identity authentication technology solution that can combine the hardware advantages of UKey and PCI-E cryptographic cards, strictly adhere to the GB / T 15843.3 standard, and enhance security and optimize performance based on the standard to achieve high performance, high security, and high compliance. This solution would resolve the security and performance contradictions faced by existing bastion hosts in the national cryptographic standard transformation, make up for the original protection shortcomings of the GB / T15843.3 standard, and meet the compliance requirements and actual usage needs of critical information infrastructure operation and maintenance. Summary of the Invention
[0010] In view of this, the present invention aims to overcome the shortcomings of the above-mentioned problems in the prior art and proposes an identity authentication method and device based on commercial cryptographic algorithms. Through hardware collaboration between UKey and the PCI-E cryptographic card built into the bastion host, relying on the national cryptographic algorithm and the GB / T 15843.3 standard, multiple security enhancement functions and performance optimization mechanisms are added on the basis of the standard to solve the security and performance contradiction faced by the existing bastion host in the national cryptographic transformation. At the same time, it meets the compliance requirements of information security level protection and cryptographic evaluation, improves the security, performance and compliance of remote operation and maintenance identity authentication of the bastion host, and makes up for the shortcomings of the original protection of the standard.
[0011] To achieve the above objectives, the technical solution of the present invention is implemented as follows:
[0012] In a first aspect, the present invention provides an identity authentication method based on commercial cryptographic algorithms, applied to a bastion host system. The system includes an operation and maintenance terminal, a smart cryptographic key (UKey) connected to the operation and maintenance terminal, a bastion host main control unit, and a PCI-E cryptographic card connected to the bastion host main control unit via a PCI-E bus. The UKey contains a user private key, a user digital certificate, and a hardware true random number generation module. The PCI-E cryptographic card contains a bastion host device private key, a user public key, and a national cryptographic algorithm hardware engine. The method includes the following steps:
[0013] Step S1: The maintenance terminal initiates a connection request to the bastion host. The bastion host main control unit calls the built-in physical noise source of the PCI-E password card through the PCI-E bus to generate a 16-byte first true random number R. B The first random number is sent to memory via the PCI-E bus.
[0014] Step S2: The PCI-E cryptographic card calls the private key of the bastion host device stored internally, performs SM2 digital signature operation on the first random number and preset identifier data, and generates the first token. BA And return to the bastion host main control unit via the PCI-E bus;
[0015] Step S3: The bastion host main control unit transfers the first token. BA Send to the maintenance terminal;
[0016] Step S4: After the maintenance terminal detects the insertion of the UKey, it calls the UKey driver through the USB interface to read the user certificate stored in the UKey and prompts the user to enter a PIN code. After the UKey verifies the PIN code, it generates a 16-byte second true random number R through the internal TRNG module. A And use the user's private key stored inside the UKey to access R A R B and the first token BAPerform SM2 signature calculation to generate the second token. AB ;
[0017] Step S5: The operation and maintenance terminal will transfer the second token. AB and the second random number R A Send to the bastion host main control unit;
[0018] Step S6: After receiving the data, the bastion host main control unit transmits the second token via the PCI-E bus. AB The second random number R A and the first random number R B Transmitted to PCI-E cryptographic card;
[0019] Step S7: The PCI-E cryptographic card calls the first random number R from its internal cache. B Using a pre-set user public key to the second token AB Perform signature verification calculation to verify R. A With R B The validity of the signature and the reasonableness of the timestamp; after the signature verification is successful, a third-party token is generated. BB And return to the bastion host main control unit;
[0020] Step S8: The bastion host main control unit will transfer the third-party token. BB The UKey is sent to the operations and maintenance terminal to perform local verification of the third-party authentication token to confirm the authenticity of the bastion host's identity. After successful verification, the entire two-way three-way authentication process is completed.
[0021] Step S9: After successful bidirectional three-way authentication, the PCI-E cryptographic card is based on R... A With R B Session keys are derived using the SM3 hash algorithm to establish a national cryptographic SSL secure channel, and subsequent operation and maintenance instructions and audit logs are encrypted with SM4 and protected with SM3 integrity.
[0022] Furthermore, in step S1, the first truly random number R B After generation, randomness is verified in real time using the internal algorithm of the PCI-E cryptographic card. The core verification formula is as follows:
[0023] ;
[0024] In the formula: F is the randomness test statistic, The number of "1"s in the random number sequence. F is the number of "0"s in the random number sequence, and n is the length of the random number sequence. When F < 1.96, the random number is determined to meet the randomness requirement; otherwise, it is regenerated.
[0025] Furthermore, in step S2, the SM2 digital signature operation is optimized using the NAF scalar multiplication algorithm, with the core formula as follows:
[0026] ;
[0027] ;
[0028] In the formula: k is the temporary key generated by the PCI-E cryptographic card hardware, G is the base point of the SM2 elliptic curve, p is the prime number of the finite field of the elliptic curve, n is the order of the base point G; e is the data to be signed (R B +ID B The SM3 hash value of ) d B The private key of the bastion host device, r and s together constitute the SM2 signature result, and x is an object-oriented value symbol that represents the x-coordinate of the point.
[0029] Furthermore, in steps S3 and S5, the first token... BA The transmission process uses SM4-CBC encryption mode, combined with SM3 hash verification; the SM4-CBC encryption formula is as follows:
[0030] ;
[0031] In the formula: K is the SM4 temporary encryption key, P i To segment the data to be encrypted into plaintext, IV i Let C be the initial vector. i This is the encrypted segmented ciphertext data;
[0032] The SM3 integrity verification formula is as follows:
[0033] ;
[0034] In the formula: Hash is the integrity check value, C is the complete ciphertext after SM4 encryption, and K MAC This is the SM3 message authentication key.
[0035] Furthermore, in step S5, a millisecond-level timestamp is embedded in the transmitted data, and the timestamp is related to R. A Token AB Once bound, the timestamp validity will be verified synchronously during subsequent signature verification, with a time difference not exceeding 30 seconds. The formula for timestamp binding and validity verification is as follows:
[0036] ;
[0037] ;
[0038] In the formula: TS is the millisecond-level timestamp when the operation and maintenance terminal sends data. bind TS is a verification value used to bind timestamps to transmitted data. send For the sender's timestamp, TS recv ΔTS is the timestamp of the bastion host receiver, and ΔTS is the time difference.
[0039] Furthermore, in step S6, the data transmission between the bastion host main control unit and the PCI-E cryptographic card adopts the Scatter-Gather transmission mode of DMA direct memory access, supports non-blocking requests, and realizes hardware offloading of cryptographic operations; the performance improvement rate of the SM3 algorithm after multi-core architecture optimization is verified by the following formula:
[0040] ;
[0041] In the formula: η is the performance improvement rate, V opt To optimize the SM3 hash operation speed for multi-core processors, V std This represents the SM3 hash operation speed before optimization.
[0042] Furthermore, in step S7, the PCI-E cryptographic card has a built-in CA root certificate, which completes the chain verification of user certificates at the hardware level; the core formula for SM2 signature verification is as follows:
[0043] ;
[0044] ;
[0045]
[0046] In the formula: P A t is the user's public key, and t is the intermediate parameter for signature verification. The result of the point operation on the elliptic curve. The random number is calculated for verification; when = At that time, the signature verification was successful;
[0047] The multi-dimensional signature verification conditions are as follows:
[0048] ;
[0049] ;
[0050] ;
[0051] In the formula: For from Token AB The first random number obtained from parsing needs to be compared with the R in the PCI-E cryptographic card cache. BIf all three conditions are met, the verification is deemed successful, and ΔTS is the time difference.
[0052] Furthermore, in step S9, the session key derivation formula is as follows:
[0053] ;
[0054] In the formula: K session The session key is dynamically derived, Salt is the random salt value generated by the PCI-E cryptographic card, and R is... A R B Generated truly random numbers for both parties to ensure that the session key derived from each authentication is unique;
[0055] The SM4 encryption formula for operation and maintenance data is as follows:
[0056] ;
[0057] In the formula: P data For plaintext data such as operation and maintenance instructions and audit logs, C data The data is encrypted, and the IV is the session-level initialization vector.
[0058] Furthermore, in steps S2 and S7, the data transmission between the bastion host main control unit and the PCI-E cryptographic card adopts the DMA direct memory access method, bypassing CPU interrupt processing and realizing cryptographic operation offloading.
[0059] The formula for CPU load reduction rate is as follows:
[0060] ;
[0061] In the formula: δ is the CPU load reduction rate, CPU std The CPU is the workload of traditional CPU operations. opt The load after hardware offloading;
[0062] The formula for verifying the identification time is as follows:
[0063] ;
[0064] In the formula: T auth For the time required for a single complete two-way identity authentication, T S1 ~T S9 These represent the total time taken for steps S1 to S9, respectively.
[0065] Secondly, this invention provides an identity authentication device based on commercial cryptographic algorithms, applied to a bastion host system, comprising:
[0066] The PCI-E cryptographic card module is plugged into the PCI-E slot of the bastion host motherboard. It is used to perform SM2 signature verification, SM3 hash and SM4 encryption and decryption operations, and provides protected key storage space. It supports physical anti-tampering, key isolation, DMA data transfer, and realizes hardware offloading of cryptographic operations.
[0067] The authentication control module, integrated into the bastion host main control unit, is used to coordinate the operation and maintenance terminal UKey and PCI-E cryptographic card module to execute the asymmetric two-way three-stage authentication process specified in GB / T 15843.3. It is responsible for data forwarding, random number generation, and process scheduling, but does not participate in cryptographic operations.
[0068] The channel establishment module, integrated into the bastion host main control unit, is used to call the PCI-E cryptographic card module after successful authentication, derive the session key based on the random number generated during the two-way authentication process, establish a national cryptographic SSL secure channel, and encrypt and protect the integrity of subsequent operation and maintenance instructions and audit logs.
[0069] The certificate verification module, integrated into the PCI-E cryptographic card module, is used to verify the legitimacy of user certificates, parse user public keys, ensure the authenticity of user identities, and support CA root certificate updates.
[0070] The anti-attack module is integrated into the UKey and PCI-E cryptographic card module respectively, and is used to implement timestamp verification, random number validity verification, PIN code protection, physical anti-tampering, and side-channel attack protection functions.
[0071] The key management module, integrated into the PCI-E cryptographic card module, is used to manage the entire lifecycle of keys, including generation, storage, backup, recovery, and destruction.
[0072] Compared with existing technologies, the identity authentication method and apparatus based on commercial cryptographic algorithms described in this invention have the following advantages:
[0073] (1) Significantly enhanced anti-attack capability: The newly added timestamp binding, multi-dimensional signature verification, and transmission encryption functions can completely resist replay attacks, man-in-the-middle attacks, and data tampering attacks; the key hardware isolation and side-channel protection functions can prevent private key leakage and side-channel attacks; the multi-factor verification and certificate chain hardware verification functions can prevent identity forgery and forged certificate attacks. The overall anti-attack capability reaches the fourth level of commercial cryptography security, far exceeding the basic requirements of the GB / T 15843.3 standard.
[0074] (2) Compliance is further enhanced: The newly added key lifecycle management, full data protection and anomaly tracing functions not only meet the requirements of GB / T 15843.3 standard, but also comply with the relevant requirements of Information Security Technology Basic Requirements for Cryptographic Applications in Information Systems (GB / T 39786-2021) and Level 3 and above of the Information Security Protection Level. They can directly pass the security assessment and information security protection evaluation of commercial cryptographic applications without additional modifications.
[0075] (3) More rigorous identity authentication: By binding device identifiers and cross-signature verification, the user and the bastion host can achieve strong two-way identity verification, which completely solves the identity fraud problem that may exist in the standard and ensures the uniqueness and security of operation and maintenance access.
[0076] (4) Significantly improved computing performance: Functions such as hardware offloading of cryptographic operations, non-blocking DMA transmission, and algorithm optimization reduce the CPU load of the bastion host by more than 60%, shorten the time for a single authentication to less than 50ms, and can easily support 1000+ concurrent operation and maintenance sessions, solving the shortcomings of the standard that does not consider high concurrency performance, and meeting the 7×24-hour uninterrupted operation and maintenance needs of critical business.
[0077] (5) Optimized operation and maintenance experience: No additional operation and maintenance personnel are required. All enhanced functions are completed automatically at the hardware level without affecting the original authentication process. At the same time, the anomaly tracing function makes it easy for operation and maintenance personnel to quickly investigate security issues and reduce operation and maintenance costs.
[0078] (6) More practical: The newly added enhanced functions are all designed based on the hardware characteristics of UKey and Tianjin Optoelectronic Anchen PCI-E password card. No additional hardware equipment is required. They can be directly adapted to the existing bastion host architecture. The transformation is simple and cost-effective, and it has the conditions for large-scale industrialization. Attached Figure Description
[0079] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings:
[0080] Figure 1 A flowchart of an identity authentication method provided in an embodiment of the present invention;
[0081] Figure 2 This is a schematic diagram of the internal hardware architecture and data flow of the bastion host provided in an embodiment of the present invention;
[0082] Figure 3 The interaction timing diagram of GB / T 15843.3 asymmetric bidirectional three-dimensional discrimination in a hardware environment is provided for the embodiments of the present invention;
[0083] Figure 4This is a comparison chart of CPU load under high concurrency scenarios in this embodiment of the invention;
[0084] Figure 5 This is a comparison chart of identity authentication time in embodiments of the present invention;
[0085] Figure 6 This is a schematic diagram comparing the standard enhancement function in this embodiment of the invention with the GB / T 15843.3 standard. Detailed Implementation
[0086] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.
[0087] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.
[0088] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art will understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0089] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0090] Example 1
[0091] refer to Figure 1This invention provides an identity authentication method based on commercial cryptographic algorithms, applied to a bastion host system. The system includes an operation and maintenance terminal, a smart cryptographic key (UKey) connected to the operation and maintenance terminal, a bastion host main control unit, and a PCI-E cryptographic card connected to the bastion host main control unit via a PCI-E bus. The UKey adopts a national cryptographic standard, conforming to GM / T 0016 "Smart Cryptographic Key Cryptographic Application Interface Specification," and incorporates a user private key, user digital certificate, and a hardware true random number generation module (TRNG). The private key is permanently stored in a secure chip after generation and is never exported. The cryptographic card adopts a PCI-E national cryptographic standard, conforming to GM / T 0018 "Cryptographic Device Application Interface Specification" and GM / T 0028 "Security Technical Requirements for Cryptographic Modules" Level 2 security requirements. It incorporates the bastion host device private key, user public key, and a national cryptographic algorithm hardware engine (SM2 / SM3 / SM4), and features physical tamper protection and key isolation storage, enabling hardware offloading of cryptographic operations.
[0092] Figure 2 This is a schematic diagram of the internal hardware architecture and data flow of the bastion host provided in the embodiments of the present invention. It clearly marks the connection relationship of hardware modules such as PCI-E cryptographic card, main control unit, authentication control module, and channel establishment module, and also shows the data transmission path between the operation and maintenance terminal and the bastion host, and between the main control unit and the cryptographic card.
[0093] The method includes the following steps:
[0094] Step S1: The maintenance terminal initiates a connection request to the bastion host. The bastion host main control unit calls the built-in physical noise source of the PCI-E password card through the PCI-E bus to generate a 16-byte first true random number R. B (The random number conforms to the requirements of GM / T 0008 "Specification for Randomness Detection of Cryptographic Algorithms"), and the first random number is sent to memory again through the PCI-E bus; in this step, the bastion host main control unit is only responsible for data forwarding and does not participate in any cryptographic operations, thus reducing CPU load.
[0095] This step, based on the GB / T 15843.3 standard, adds the function of "true random number hardware generation + randomness verification": the PCI-E cryptographic card has a built-in physical noise source to generate R... B It generates true random numbers in hardware, rather than pseudo-random numbers in software. At the same time, it performs real-time randomness verification through the internal algorithm of the password card to prevent random numbers from being predicted or forged. This solves the risk of identity forgery caused by the unclear random number generation method in the standard and further enhances the basic security of authentication.
[0096] The randomness verification of true random numbers adopts the frequency verification algorithm specified in GM / T 0062-2018 Requirements for Random Number Detection of Cryptographic Products. The core verification formula is as follows:
[0097]
[0098] In the formula: F is the randomness test statistic, The number of "1"s in the random number sequence. The number of "0"s in the random number sequence is denoted by F, and n is the length of the random number sequence (in this invention, n = 128 bits, corresponding to 16 bytes). When F < 1.96, the random number is determined to meet the randomness requirement; otherwise, it is regenerated.
[0099] Step S2: The PCI-E cryptographic card calls the private key of the bastion host device stored internally (the private key is stored in the anti-tamper key area built into the cryptographic card; the key is automatically destroyed after physical anti-tampering is triggered), and compares the first random number with the preset identification data (the unique identifier ID of the bastion host device). B (Used to distinguish different bastion host devices and prevent device forgery) Performs SM2 digital signature calculation to generate the first authorization token. BA (Token) BA The format conforms to the requirements of GB / T 15843.3-2023 standard, including signature data, device identification, timestamp, etc., and is returned to the bastion host main control unit via PCI-E bus; the entire signature operation is completed inside the PCI-E cryptographic card hardware, and the key is not exposed in the bastion host system memory, eliminating the risk of key leakage.
[0100] This step adds two core functions to the GB / T 15843.3 standard: ① Hardware-isolated private key storage: The key storage area of the PCI-E cryptographic card has physical anti-tampering and side-channel attack protection functions. The private key is never exported after it is generated, and the SM2 operation is optimized using the NAF scalar multiplication algorithm to resist side-channel attacks such as power consumption analysis, thus solving the risk of key leakage caused by the lack of explicit private key storage security requirements in the standard; ② Unique device identifier ID. B Binding involves signing the bastion host device identifier along with a random number to ensure the primary token is valid. BA By binding the device to the bastion host hardware, attackers can prevent spoofing attacks by impersonating the bastion host, thus addressing the shortcoming of the standard's lack of strong device identity binding. Simultaneously, the cryptographic card uses DMA (Direct Memory Access) to transfer data, reducing host CPU usage and improving computational efficiency.
[0101] The core formula for SM2 digital signature computation (optimized with NAF scalar multiplication) is as follows, which conforms to the requirements of GM / T 0003 "SM2 Elliptic Curve Public Key Cryptography Algorithm":
[0102]
[0103]
[0104] In the formula: k is the temporary key (random number) generated by the PCI-E cryptographic card hardware, G is the base point of the SM2 elliptic curve, p is the prime number of the finite field of the elliptic curve, n is the order of the base point G; e is the data to be signed (R B +ID B The SM3 hash value of (e=SM3(R)) B ||ID B )), The bastion host device's private key, r, and s together constitute the SM2 signature result, i.e., the Token. BA The core signature data, x, is an object-oriented value symbol that represents the x-coordinate of the point.
[0105] Step S3: The bastion host main control unit transfers the first token. BA The data is sent to the maintenance terminal. During transmission, the data is temporarily encrypted using the national cryptographic SM4 algorithm to prevent the data from being stolen or tampered with during transmission.
[0106] This step, based on the GB / T 15843.3 standard, adds a "Token authentication for encrypted data transmission" function. BA The transmission process uses SM4-CBC encryption mode combined with SM3 hash verification to ensure that the data is not stolen or tampered with during transmission. This solves the risk of man-in-the-middle attacks caused by plaintext transmission of authentication data in the standard, forming a dual protection of "transmission encryption + identity authentication" and further improving the security of the entire link.
[0107] The core formulas for SM4-CBC encryption and SM3 integrity verification are as follows, conforming to the requirements of GM / T 0002 "SM4 Block Cipher Algorithm" and GM / T 0004 "SM3 Cipher Hash Algorithm":
[0108] SM4-CBC encryption formula:
[0109]
[0110] In the formula: K is the SM4 temporary encryption key (dynamically generated by the PCI-E cryptographic card), P i For Token BA Segmented plaintext data, IV i The initial vector (IV1 is the preset initial value when i=1, IV>1 is the preset initial value when i>1) i =C i-1 ), C i This is encrypted segmented ciphertext data.
[0111] SM3 integrity verification formula:
[0112]
[0113] In the formula: Hash is the integrity check value, C is the complete ciphertext after SM4 encryption, and K MAC This is the SM3 message authentication key, used to verify that the transmitted data has not been tampered with.
[0114] Step S4: After the maintenance terminal detects the insertion of the UKey, it calls the UKey driver through the USB interface to read the user certificate stored in the UKey (the user certificate is issued by a compliant national cryptographic CA and contains the user's public key and user identity information, which can be verified via a PCI-E cryptographic card). The user is then prompted to enter a PIN code (the PIN code is used to unlock the UKey and prevent unauthorized use if the UKey is lost; the UKey is automatically locked after three failed PIN code verifications). After the UKey successfully verifies the PIN code, it generates a 16-byte second true random number R through the internal TRNG module. A And use the user's private key stored inside the UKey to access R A R B and the first token BA Perform SM2 signature calculation to generate the second token. AB (Token) AB It includes information such as user signature, user identifier, and random number, used to prove the legitimacy of the user's identity to the bastion host. In this step, all calculations are completed inside the UKey security chip, and the user's private key never leaves the UKey, completely eliminating the possibility of private key leakage caused by attacks such as Trojans and memory scraping.
[0115] This step adds two enhanced functions to the GB / T 15843.3 standard: ① Enhanced UKey PIN code protection, supporting PIN code complexity verification (at least 8 characters, including letters, numbers, and special characters), with brute-force attack protection, and automatic locking after 3 failed PIN code verifications to prevent unauthorized unlocking after UKey loss; ② Multi-factor authentication, binding "UKey hardware + PIN code + user private key" to form triple authentication, solving the risk of identity forgery after UKey theft caused by relying solely on private key signature in the standard. At the same time, the UKey has a built-in hardware anti-tampering module, and the internal data cannot be illegally read or tampered with, further improving the security of user authentication.
[0116] Step S5: The operation and maintenance terminal will transfer the second token. AB and the second random number R A It is sent to the bastion host main control unit; during transmission, the SM4 algorithm is also used for encryption to ensure data transmission security, and timestamp information is also carried for subsequent anti-replay attack verification.
[0117] This step, based on the GB / T 15843.3 standard, adds a "dynamic timestamp binding" function: embedding a high-precision timestamp (millisecond level) into the transmitted data, and the timestamp is linked to the R... A Token AB Binding ensures that the validity of the timestamp is verified synchronously during subsequent signature verification (with a time difference not exceeding 30 seconds), effectively resisting replay attacks. Even if an attacker steals the transmitted data, they cannot reuse it outside the time window. This addresses the shortcoming of the GB / T 15843.3 standard, which lacks a protection mechanism against replay attacks, and enhances the anti-attack capability of the authentication process.
[0118] The formulas for timestamp binding and validity verification are as follows:
[0119]
[0120]
[0121] In the formula: TS is the millisecond-level timestamp when the operation and maintenance terminal sends data. bind This is a verification value used to bind the timestamp to the transmitted data, verifying that the timestamp has not been tampered with; TS send For the sender's timestamp, TS recv ΔTS is the timestamp of the bastion host receiver. When the time difference does not exceed 30 seconds, it is determined that the data has not been replayed; otherwise, the signature verification is rejected.
[0122] Step S6: After receiving the data, the bastion host main control unit does not perform any cryptographic calculations, but transmits the second token via the PCI-E bus. AB The second random number R A and the first random number R B Transmitted to the PCI-E cryptographic card; this process uses DMA direct memory access to bypass CPU interrupt handling, enabling fast data transfer and offloading of cryptographic operations, further improving computational efficiency.
[0123] This step, based on the GB / T 15843.3 standard, adds the "hardware offloading + non-blocking transmission" optimization function: the bastion host main control unit is only responsible for data pass-through, and all cryptographic operations are completed by the PCI-E cryptographic card. It adopts the Scatter-Gather transmission mode of the DMA engine, supports non-blocking requests, avoids performance loss caused by frequent interruptions, and the cryptographic card adopts a multi-core architecture to optimize the SM3 algorithm, improving the computing performance by more than 19%. This solves the problem of computing performance not being considered in high-concurrency scenarios in the standard, significantly reduces the CPU load of the bastion host, and improves authentication efficiency.
[0124] The following formula verifies the improved computational efficiency of the SM3 algorithm after multi-core optimization:
[0125]
[0126] In the formula: η is the performance improvement rate, V opt To optimize the SM3 hash operation speed for multi-core processing (≥8Gbps in this invention), V std This represents the SM3 hash operation speed before optimization.
[0127] Step S7: The PCI-E cryptographic card calls the first random number R from its internal cache. B The second token is determined using a pre-set user public key (obtained by parsing the user certificate and verified for validity by the CA root certificate embedded in the cryptographic card). AB Perform signature verification calculation to verify R. A With R B The validity of the signature and the reasonableness of the timestamp are ensured to prevent replay attacks and data tampering attacks; after successful signature verification, a third-party token is generated. BB (Token) BB Used to verify the legitimacy of the bastion host's identity to users (complying with the two-way authentication requirements of GB / T 15843.3-2023 standard) and returned to the bastion host's main control unit; the entire signature verification process is completed by the PCI-E cryptographic card hardware, which is fast, highly secure, and does not consume bastion host CPU resources.
[0128] This step, based on the GB / T 15843.3 standard, adds two enhanced functions: ① Hardware verification of the certificate chain: The PCI-E cryptographic card has a built-in CA root certificate, which can complete the chain verification of user certificates at the hardware level to confirm the legality and validity of user certificates, prevent attacks launched by forged user certificates, and solve the risk of identity forgery caused by the lack of a clear certificate verification process in the standard; ② Multi-dimensional signature verification: In addition to verifying the validity of the signature, it also verifies the R... A With R B The consistency and reasonableness of the timestamps form a multi-dimensional verification system of "signature verification + random number verification + timestamp verification," further enhancing the rigor of signature verification and eliminating potential security vulnerabilities associated with single signature verification. Meanwhile, the SM2 cryptographic card boasts a signature verification speed of over 50,000 times per second, effectively supporting high-concurrency operation and maintenance scenarios.
[0129] The core formula for SM2 verification (compliant with GM / T 0003 requirements) and the multi-dimensional verification formula are as follows:
[0130] 1.SM2 signature verification formula:
[0131]
[0132]
[0133]
[0134] In the formula: P A For user public key (P A =d A ·G), where t is the intermediate parameter for signature verification. The result of the point operation on the elliptic curve. The random number is calculated for verification; when At that time, the signature verification was successful.
[0135] 2. Multi-dimensional signature verification conditions:
[0136]
[0137] In the formula: For from Token AB The first random number obtained from parsing needs to be compared with the R in the PCI-E cryptographic card cache. B If all three conditions are met, the verification is deemed successful.
[0138] Step S8: The bastion host main control unit will transfer the third-party token. BB The UKey is sent to the operation and maintenance terminal. The UKey performs local signature verification on the third token (the signature verification uses the bastion host public key corresponding to the user's public key to ensure the accuracy of the signature verification). It confirms that the bastion host's identity is genuine and has not been subjected to replay attacks or forgery. After the signature verification is successful, the entire process of two-way three-way authentication is completed, and both parties confirm that the other party's identity is legitimate.
[0139] This step adds two enhanced functions to the GB / T 15843.3 standard: ① Two-way cross-verification, UKey verification of tokens. BB At the same time, it not only verifies the validity of the signature, but also verifies the bastion host device identifier ID. B With R B ① Ensure consistency and achieve cross-identity verification between users and the bastion host, completely eliminating man-in-the-middle attacks; ② Abnormal signature verification and tracing: If the signature verification fails, both the UKey and the PCI-E cryptographic card will record an abnormal log (including abnormal time, abnormal data, and initiating terminal information), which facilitates subsequent security audits and attack tracing, solves the problem that the standard does not specify an abnormal handling and tracing mechanism, and improves the completeness of operation and maintenance audits.
[0140] Step S9: After successful bidirectional three-way authentication, the PCI-E cryptographic card is based on R... A With R BSession keys are derived using the SM3 hash algorithm (the session keys are dynamically derived, with different session keys generated for each authentication to reduce the risk of key leakage), and a national cryptographic SSL secure channel (compliant with GM / T 0024 "SSL VPN Technical Specification") is established. Subsequent operation and maintenance instructions (such as RDP, SSH, Telnet and other protocol instructions) and audit logs are encrypted with SM4 and protected with SM3 integrity to ensure that the operation and maintenance process is secure and auditable throughout.
[0141] This step adds two core enhancements to the GB / T 15843.3 standard: ① Dynamic session key derivation, based on the R key generated during each authentication. A With R B ① Dynamically derived session keys: Different session keys are generated for each authentication. Even if a session key is leaked once, it will not affect the security of other authentication sessions, solving the problem of session key management not specified in the standard; ② End-to-end operation and maintenance data protection: A national cryptographic SSL secure channel is established, and all subsequent operation and maintenance instructions and audit logs are encrypted with SM4 and verified for integrity with SM3. This achieves a full-process security closed loop of "identity authentication + data encryption + integrity protection", making up for the shortcomings of GB / T 15843.3 standard, which only focuses on identity authentication and does not cover the security of subsequent operation and maintenance data. At the same time, it meets the requirements of information security level protection and information security assessment for data transmission and storage security.
[0142] The core formulas for SM3 dynamic session key derivation and SM4 end-to-end encryption are as follows:
[0143] 1. Session key derivation formula:
[0144]
[0145] In the formula: Ksession is the dynamically derived session key (used for national cryptographic SSL secure channel encryption), Salt is the random salt value generated by the PCI-E cryptographic card (to further enhance key randomness), and R A R B Generated true random numbers for both parties ensure that the session key derived from each authentication is unique.
[0146] 2. SM4 encryption formula for operation and maintenance data (same as step S3, the key is the session key):
[0147]
[0148] In the formula: P data For plaintext data such as operation and maintenance instructions and audit logs, C data The data is encrypted, and the IV is a session-level initialization vector (generated once per session).
[0149] Figure 3The interaction timing diagram of GB / T 15843.3 asymmetric bidirectional three-way authentication in a hardware environment provided for the embodiments of the present invention fully demonstrates the message sending and receiving timing and the order of token transmission of the four terminals: operation and maintenance terminal, UKey, bastion host, and PCI-E cryptographic card, and intuitively presents the complete interaction logic of standard bidirectional three-way authentication under hardware collaborative architecture.
[0150] As a further solution, the PCI-E cryptographic card meets the Level 2 security requirements of GM / T 0028 "Security Technical Requirements for Cryptographic Modules". Its internal key storage area has a physical anti-tampering mechanism, and the private key is never exported after it is generated. It also supports key backup and recovery functions, meeting the key lifecycle management requirements in cryptographic evaluation. At the same time, the cryptographic card has a built-in hardware national cryptographic algorithm engine, which adopts an optimized design of ARM64 multi-core processor. The SM2 signature operation speed can reach more than 50,000 times / second, and the SM3 hash operation speed can reach more than 8Gbps, which can effectively support high-concurrency operation and maintenance scenarios. This is also a performance optimization and enhancement based on the GB / T 15843.3 standard.
[0151] The formula for verifying the SM2 signature processing speed is as follows:
[0152]
[0153] In the formula: For SM2 signature processing speed, This represents the number of signatures completed within a unit of time T, where T = 1 second.
[0154] As a further solution, in steps S2 and S7, the data transmission between the bastion host main control unit and the PCI-E cryptographic card adopts the DMA direct memory access method, which bypasses the CPU interrupt processing and realizes the offloading of cryptographic operations. Compared with the traditional CPU operation method, it can reduce the CPU load of the bastion host by more than 60% and shorten the time for a single identity authentication to less than 50ms, significantly improving the operation and maintenance experience in high-concurrency scenarios and solving the shortcoming of GB / T 15843.3 standard that does not consider the computing performance.
[0155] The formulas for CPU load reduction rate and identification time verification are as follows:
[0156] 1. CPU load reduction rate:
[0157]
[0158] In the formula: δ is the CPU load reduction rate. The load is equivalent to that of traditional CPU operations (78%). The load after the hardware of this invention is unloaded (12%).
[0159] 2. Time consumed per identification:
[0160]
[0161] In the formula: The time required for a single complete two-way identity verification ~ These represent the total time taken for steps S1 to S9, respectively.
[0162] Figure 4 This is a comparison chart of CPU load in high-concurrency scenarios in this embodiment of the invention. By comparing the CPU usage curves of the traditional pure CPU cryptographic operation scheme and the PCI-E hardware offloading scheme of this invention under 500~2000 concurrent sessions, the optimization effect of hardware offloading on host load can be intuitively demonstrated.
[0163] As a further solution, both the UKey and PCI-E cryptographic cards support the national cryptographic algorithms SM2, SM3, and SM4, strictly adhering to the GB / T 15843.3-2023 asymmetric bidirectional three-stage authentication process. There are no process deletions or parameter tampering, ensuring the compliance of the authentication process and allowing it to directly pass the security assessment and information security level protection evaluation for commercial cryptographic applications. At the same time, all the enhanced functions added on the basis of the standard are compatible with the standard process and do not change the core interaction logic of the standard, ensuring both compliance and improving security and practicality.
[0164] As a further solution, in step S4, the UKey supports PIN code complexity verification (at least 8 characters, including letters, numbers, and special characters) and has brute-force attack protection to effectively prevent the UKey from being illegally unlocked; at the same time, the UKey supports hardware-level anti-tampering, and the internal data cannot be illegally read or tampered with, further improving the security of user identity authentication. This is also a user-side security enhancement based on the GB / T 15843.3 standard.
[0165] Figure 5 This is a comparison chart of identity authentication time in an embodiment of the present invention. By comparing the time of a single identity authentication with that of the traditional scheme and the optimized scheme, the advantages of latency reduction brought about by the process optimization and hardware acceleration of the present invention are clearly demonstrated.
[0166] The effectiveness of this scheme will be verified through experiments below.
[0167] This embodiment takes the operation and maintenance scenario of a financial data center bastion host as an example. This scenario requires the bastion host to meet the requirements of Level 4 Information Security Protection and Level 3 Security Assessment. The daily concurrent operation and maintenance sessions can reach 1,000. It needs to achieve high security, high performance, and high compliance two-way identity authentication, while making up for the shortcomings of the native protection of the GB / T 15843.3 standard.
[0168] In this embodiment, the UKey uses a smart cryptographic key, and the PCI-E cryptographic card uses a PCI-E national cryptographic card. Both strictly follow the core processes of the GB / T 15843.3-2023 standard and implement all the aforementioned enhanced functions, as specifically as follows:
[0169] True random number generation and verification: The PCI-E cryptographic card has a built-in physical noise source to generate a 16-byte true random number R. B The system performs verification through an internal randomness detection algorithm to ensure that random numbers are unpredictable. Compared with random number generation methods that are not explicitly defined in the standard, it can effectively resist random number prediction attacks and improve the basic security of identification.
[0170] Hardware isolation of keys and protection against side channels: The key storage area of the PCI-E cryptographic card adopts a physical anti-tamper design. After the private key is generated, it is solidified in the chip and never exported. At the same time, the NAF scalar multiplication algorithm is used to optimize the SM2 operation and resist side channel attacks such as power consumption analysis. The UKey also adopts hardware key isolation. The user's private key never leaves the security chip, which solves the problem of the lack of clear private key storage security in the standard and prevents key leakage.
[0171] Encryption and timestamp binding for transmission: Authentication data (Token) BA Token AB R A The transmission process uses SM4-CBC encryption mode, combined with SM3 hash verification, and embeds millisecond-level timestamps. The time window is set to 30 seconds, which effectively resists replay attacks and man-in-the-middle attacks, filling the gaps in transmission security and anti-replay protection in the standard.
[0172] Multi-factor authentication and PIN code protection: The UKey enables PIN code complexity verification (8 digits, including letters, numbers, and special characters). It automatically locks after 3 brute-force attacks. Combined with the UKey hardware and the user's private key, it forms a triple identity verification to prevent the UKey from being used illegally after it is lost, thus solving the security shortcomings of the standard that only relies on private key signature.
[0173] Hardware offloading and performance optimization: The Scatter-Gather transfer mode of DMA direct memory access is adopted, which supports non-blocking request processing. All cryptographic operations are performed by the PCI-E cryptographic card. The cryptographic card adopts a multi-core architecture to optimize the SM3 algorithm, which improves the computing performance by more than 19%. Under 1000 concurrent sessions, the CPU load of the bastion host is reduced from 78% of the traditional solution to 12%, and the single authentication time is less than 50ms, which is far better than the standard unoptimized solution.
[0174] Multi-dimensional signature verification and certificate chain verification: The PCI-E cryptographic card has a built-in CA root certificate, which completes the chain verification of user certificates at the hardware level. During the signature verification process, the validity of the signature, random number, and timestamp are verified simultaneously, forming a multi-dimensional verification system and eliminating the security vulnerabilities of single signature verification.
[0175] Dynamic Session Keys and End-to-End Data Protection: Based on R A With R B Dynamically derive session keys, generate different keys for each authentication, establish a national cryptographic SSL secure channel, encrypt operation and maintenance instructions and audit logs with SM4 and verify their integrity with SM3, realize a secure closed loop throughout the process, and make up for the shortcomings of subsequent operation and maintenance data security not covered by the standard.
[0176] Anomaly tracing and key lifecycle management: When signature verification fails, the UKey and PCI-E cryptographic card automatically record anomaly logs, including the anomaly time, anomaly data, and initiating terminal information, which facilitates security auditing and attack tracing; the PCI-E cryptographic card supports key backup, recovery, and destruction, meeting the key lifecycle management requirements in security evaluation.
[0177] Actual testing showed that, compared with the solution that simply follows the GB / T 15843.3 standard, the proposed solution in this embodiment exhibits significant improvements in all indicators, as detailed below:
[0178]
[0179] This invention adds multiple security enhancement functions and performance optimization mechanisms to the GB / T 15843.3 standard. It not only strictly follows the national cryptographic standard to ensure compliance, but also makes up for the shortcomings of the standard's original protection. It solves the contradiction between security and performance in existing solutions and achieves "compliant, secure, efficient and practical" identity authentication. It is applicable to the operation and maintenance scenarios of bastion hosts in critical information infrastructure such as finance, government affairs and energy, and has significant substantive features and progress.
[0180] The figure is a comparative diagram of the standard enhancement function in this embodiment of the invention and the GB / T 15843.3 standard. It compares the functional differences between the original standard and the enhanced solution of this invention from six dimensions: random number security, transmission protection, anti-attack measures, computing performance, key management, and compliance. It intuitively demonstrates the comprehensive upgrade and enhancement of the national standard process by this invention.
[0181] Example 2
[0182] An identity authentication device based on commercial cryptographic algorithms, applied to a bastion host system, includes:
[0183] The PCI-E cryptographic card module is plugged into the PCI-E slot of the bastion host motherboard. It is used to perform SM2 signature verification, SM3 hash and SM4 encryption and decryption operations, and provides protected key storage space. It supports physical anti-tampering, key isolation, DMA data transfer, and realizes hardware offloading of cryptographic operations.
[0184] The authentication control module, integrated into the bastion host main control unit, is used to coordinate the operation and maintenance terminal UKey and PCI-E cryptographic card module to execute the asymmetric two-way three-stage authentication process specified in GB / T 15843.3. It is responsible for data forwarding, random number generation, and process scheduling, but does not participate in cryptographic operations.
[0185] The channel establishment module, integrated into the bastion host main control unit, is used to call the PCI-E cryptographic card module after successful authentication, derive the session key based on the random number generated during the two-way authentication process, establish a national cryptographic SSL secure channel, and encrypt and protect the integrity of subsequent operation and maintenance instructions and audit logs.
[0186] The certificate verification module, integrated into the PCI-E cryptographic card module, is used to verify the legitimacy of user certificates, parse user public keys, ensure the authenticity of user identities, and support CA root certificate updates.
[0187] The anti-attack module is integrated into the UKey and PCI-E cryptographic card module respectively, and is used to implement timestamp verification, random number validity verification, PIN code protection, physical anti-tampering, and side-channel attack protection functions.
[0188] The key management module, integrated into the PCI-E cryptographic card module, is used to manage the entire lifecycle of keys, including generation, storage, backup, recovery, and destruction.
[0189] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An authentication method based on commercial cryptographic algorithms, applied to a bastion host system, the system comprising an operation and maintenance terminal, a smart cryptographic key (UKey) connected to the operation and maintenance terminal, a bastion host main control unit, and a PCI-E cryptographic card connected to the bastion host main control unit via a PCI-E bus; the UKey contains a user private key, a user digital certificate, and a hardware true random number generation module; the PCI-E cryptographic card contains a bastion host device private key, a user public key, and a national cryptographic algorithm hardware engine, characterized in that: The method includes the following steps: Step S1: The maintenance terminal initiates a connection request to the bastion host. The bastion host main control unit calls the built-in physical noise source of the PCI-E password card through the PCI-E bus to generate a 16-byte first true random number R. B The first random number is sent to memory via the PCI-E bus. Step S2: The PCI-E cryptographic card calls the private key of the bastion host device stored internally, performs SM2 digital signature operation on the first random number and preset identifier data, and generates the first token. BA And return to the bastion host main control unit via the PCI-E bus; Step S3: The bastion host main control unit transfers the first token. BA Send to the maintenance terminal; Step S4: After the maintenance terminal detects the insertion of the UKey, it calls the UKey driver through the USB interface to read the user certificate stored in the UKey and prompts the user to enter a PIN code. After the UKey verifies the PIN code, it generates a 16-byte second true random number R through the internal TRNG module. A And use the user's private key stored inside the UKey to access R A R B and the first token BA Perform SM2 signature calculation to generate the second token. AB ; Step S5: The operation and maintenance terminal will transfer the second token. AB and the second random number R A Send to the bastion host main control unit; Step S6: After receiving the data, the bastion host main control unit transmits the second token via the PCI-E bus. AB The second random number R A and the first random number R B Transmitted to PCI-E cryptographic card; Step S7: The PCI-E cryptographic card calls the first random number R from its internal cache. B Using a pre-set user public key to the second token AB Perform signature verification calculation to verify R. A With R B The validity of the signature and the reasonableness of the timestamp; after the signature verification is successful, a third-party token is generated. BB And return to the bastion host main control unit; Step S8: The bastion host main control unit will transfer the third-party token. BB The UKey is sent to the operations and maintenance terminal to perform local verification of the third-party authentication token to confirm the authenticity of the bastion host's identity. After successful verification, the entire two-way three-way authentication process is completed. Step S9: After successful bidirectional three-way authentication, the PCI-E cryptographic card is based on R... A With R B Session keys are derived using the SM3 hash algorithm to establish a national cryptographic SSL secure channel, and subsequent operation and maintenance instructions and audit logs are encrypted with SM4 and protected with SM3 integrity.
2. The identity authentication method based on commercial cryptographic algorithms according to claim 1, characterized in that: In step S1, the first true random number R B After generation, randomness is verified in real time using the internal algorithm of the PCI-E cryptographic card. The core verification formula is as follows: ; In the formula: F is the randomness test statistic, The number of "1"s in the random number sequence. F is the number of "0"s in the random number sequence, and n is the length of the random number sequence. When F < 1.96, the random number is determined to meet the randomness requirement; otherwise, it is regenerated.
3. The identity authentication method based on commercial cryptographic algorithms according to claim 1, characterized in that: In step S2, the SM2 digital signature operation is optimized using the NAF scalar multiplication algorithm, and the core formula is as follows: ; ; In the formula: k is the temporary key generated by the PCI-E cryptographic card hardware, G is the base point of the SM2 elliptic curve, p is the prime number of the finite field of the elliptic curve, n is the order of the base point G; e is the data to be signed (R B +ID B The SM3 hash value of ) d B The private key of the bastion host device, r and s together constitute the SM2 signature result, and x is an object-oriented value symbol that represents the x-coordinate of the point.
4. The identity authentication method based on commercial cryptographic algorithms according to claim 1, characterized in that: In steps S3 and S5, the first token... BA The transmission process uses SM4-CBC encryption mode, combined with SM3 hash verification; the SM4-CBC encryption formula is as follows: ; In the formula: K is the SM4 temporary encryption key, P i To segment the data to be encrypted into plaintext, IV i Let C be the initial vector. i This is the encrypted segmented ciphertext data; The SM3 integrity verification formula is as follows: ; In the formula: Hash is the integrity check value, C is the complete ciphertext after SM4 encryption, and K MAC This is the SM3 message authentication key.
5. The authentication method based on commercial cryptographic algorithms according to claim 1, characterized in that: In step S5, a millisecond-level timestamp is embedded in the transmitted data, and the timestamp is related to R. A Token AB Once bound, the timestamp validity will be verified synchronously during subsequent signature verification, with a time difference not exceeding 30 seconds. The formula for timestamp binding and validity verification is as follows: ; ; In the formula: TS is the millisecond-level timestamp when the operation and maintenance terminal sends data. bind TS is a verification value used to bind timestamps to transmitted data. send For the sender's timestamp, TS recv ΔTS is the timestamp of the bastion host receiver, and ΔTS is the time difference.
6. The authentication method based on commercial cryptographic algorithms according to claim 1, characterized in that: In step S6, the data transmission between the bastion host main control unit and the PCI-E cryptographic card adopts the Scatter-Gather transmission mode of DMA direct memory access, which supports non-blocking requests and realizes hardware offloading of cryptographic operations; the performance improvement rate of the SM3 algorithm after multi-core architecture optimization is verified by the following formula: ; In the formula: η is the performance improvement rate, V opt To optimize the SM3 hash operation speed for multi-core processors, V std This represents the SM3 hash operation speed before optimization.
7. The authentication method based on a commercial cryptographic algorithm according to claim 3, characterized in that: In step S7, the PCI-E cryptographic card has a built-in CA root certificate, which completes the chain verification of user certificates at the hardware level; the core formula for SM2 signature verification is as follows: ; ; In the formula: P A t is the user's public key, and t is the intermediate parameter for signature verification. The result of the point operation on the elliptic curve. The random number is calculated for verification; when = At that time, the signature verification was successful; The multi-dimensional signature verification conditions are as follows: ; ; ; In the formula: For from Token AB The first random number obtained from parsing needs to be compared with the R in the PCI-E cryptographic card cache. B If all three conditions are met, the verification is deemed successful, and ΔTS is the time difference.
8. The authentication method based on a commercial cryptographic algorithm according to claim 1, characterized in that: In step S9, the session key derivation formula is as follows: ; Where: K session The session key is dynamically derived, Salt is the random salt value generated by the PCI-E cryptographic card, and R is... A R B Generated truly random numbers for both parties to ensure that the session key derived from each authentication is unique; The SM4 encryption formula for operation and maintenance data is as follows: ; In the formula: P data For plaintext data such as operation and maintenance instructions and audit logs, C data The data is encrypted, and the IV is the session-level initialization vector.
9. The authentication method based on a commercial cryptographic algorithm according to claim 1, characterized in that: In steps S2 and S7, the data transmission between the bastion host main control unit and the PCI-E cryptographic card adopts the DMA direct memory access method, which bypasses the CPU interrupt processing and realizes the offloading of cryptographic operations. The formula for CPU load reduction rate is as follows: ; In the formula: δ is the CPU load reduction rate, CPU std The CPU is the workload of traditional CPU operations. opt The load after hardware offloading; The formula for verifying the identification time is as follows: ; In the formula: T auth For the time required for a single complete two-way identity authentication, T S1 ~T S9 These represent the total time taken for steps S1 to S9, respectively.
10. An identity authentication device based on commercial cryptographic algorithms, applied to a bastion host system, characterized in that: include: The PCI-E cryptographic card module is plugged into the PCI-E slot of the bastion host motherboard. It is used to perform SM2 signature verification, SM3 hash and SM4 encryption and decryption operations, and provides protected key storage space. It supports physical anti-tampering, key isolation, DMA data transfer, and realizes hardware offloading of cryptographic operations. The authentication control module, integrated into the bastion host main control unit, is used to coordinate the operation and maintenance terminal UKey and PCI-E cryptographic card module to execute the asymmetric two-way three-stage authentication process specified in GB / T 15843.
3. It is responsible for data forwarding, random number generation, and process scheduling, but does not participate in cryptographic operations. The channel establishment module, integrated into the bastion host main control unit, is used to call the PCI-E cryptographic card module after successful authentication, derive the session key based on the random number generated during the two-way authentication process, establish a national cryptographic SSL secure channel, and encrypt and protect the integrity of subsequent operation and maintenance instructions and audit logs. The certificate verification module, integrated into the PCI-E cryptographic card module, is used to verify the legitimacy of user certificates, parse user public keys, ensure the authenticity of user identities, and support CA root certificate updates. The anti-attack module is integrated into the UKey and PCI-E cryptographic card module respectively, and is used to implement timestamp verification, random number validity verification, PIN code protection, physical anti-tampering, and side-channel attack protection functions. The key management module, integrated into the PCI-E cryptographic card module, is used to manage the entire lifecycle of keys, including generation, storage, backup, recovery, and destruction.