A quantum key distribution network, a wearable device, and a target server
Through the combination of the quantum key distribution network and wearable devices, the problem of easy cracking of encryption methods based on mathematical algorithms in the prior art is solved, and high-security identity authentication is realized, which enhances the reliability of authentication.
Patent Information
- Application Number
- CN202110825804.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-03-09
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2038-03-09
AI Technical Summary
The existing wearable device-based identity authentication method uses mathematical algorithm-based encryption method during information transmission, which is easy to be cracked by rapidly developing computing technology, poses serious security risks, and is difficult to adapt to identity authentication occasions with high security requirements.
The quantum key distribution network is used to combine with the wearable device, and by receiving the device information of the user terminal, finding the wearable device bound to the user terminal, receiving and matching the biometric information collected by the wearable device, and establishing a reliable authentication chain from the user to the user terminal and then to the target server.
It improves the security in the identity authentication process, enhances the anti-impersonation identity and anti-deciphering functions, and greatly improves the reliability of identity authentication between devices and between people and devices.
Smart Images

Figure CN113726734B_ABST
Abstract
Description
[0001] This application is a divisional application of the application with the application number 201810195543.1, the application date of March 9, 2018, and the invention title "Identity Authentication Method and System Based on Wearable Devices". Technical Field
[0002] The present invention relates to the field of information security authentication, and particularly relates to a quantum key distribution network, a wearable device, and a target server. Background Art
[0003] With the rapid development of the mobile Internet, internal business websites of enterprises and institutions have gradually developed towards mobile terminals. In order to facilitate staff to understand work content at any time, users hope to be able to access the internal website server of the unit through a portable mobile terminal. If there are vulnerabilities in identity authentication, it will lead to data leakage, which will bring irreparable consequences to the enterprise. Therefore, a secure and reliable login authentication method is very necessary. The existing authentication methods for mobile terminals mainly include: logging in and authenticating through accounts and passwords, authenticating through dynamic passwords, authenticating by comparing device identification information with pre-stored user device information in the authentication server, etc. However, account passwords, dynamic passwords, and device IDs all have the possibility of being intercepted or leaked. With the popularization of wearable devices, there have been many related technologies that introduce wearable devices into identity authentication technology, including authentication technologies that combine ordinary password technology with wearable devices and authentication technologies that combine biometric recognition technology with wearable devices. For example, "An Authentication Method for Wearable Devices" (application number: 201510598684.4), which introduces lightweight operators such as pseudo-random functions, exclusive OR operations, and one-way authentication functions to achieve mutual authentication between a smart phone and a wearable device. During the interaction between the smart phone and the wearable device, sensitive data such as the pseudo-identity identifier and pre-shared secret value of the wearable device are transmitted anonymously to ensure the security of the interaction data. At the same time, a dynamic update mechanism is introduced to improve the freshness and randomness of the session period and avoid attacks such as replay and impersonation by malicious attackers; "A Method for Authenticating through a Wearable Device and the Wearable Device" (application number: 201310190418.9) obtains the user's identity authentication information based on biometric characteristics and sends the identity authentication information to the terminal through the wearable device for authentication; and "An Authentication Payment Method and Payment Authentication System Based on Wearable Devices" (application number: 201410295802.X) also further improves the security of payment by adding authentication of wearable devices.
[0004] However, the existing authentication methods based on wearable devices are usually applied to identity authentication during the interaction with user terminals; and the existing wearable device authentication methods often use encryption methods based on the complexity of mathematical algorithms during information transmission. However, the confidentiality mechanism based on mathematical algorithms is easily cracked by the increasingly rapidly developing computing technology, new algorithm vulnerabilities are constantly discovered, and it is extremely vulnerable in the face of future quantum computers, making the existing authentication methods based on wearable devices have serious security risks and difficult to adapt to identity authentication scenarios with high security requirements.
[0005] Therefore, how to improve the identity authentication security of mobile terminals logging in to target servers with the help of wearable devices is a technical problem that urgently needs to be solved by those skilled in the art at present. Summary of the Invention
[0006] To solve the above problems, the present invention provides a quantum key distribution network, a wearable device, and a target server for account management and access identity authentication, constructs a reliable authentication chain from the user to the user terminal and then to the target server, and proposes a highly secure authentication mechanism.
[0007] The technical solution of the present invention is a quantum key distribution network for identity authentication:
[0008] Receive the device information of the user terminal;
[0009] Locate the wearable device bound to the user terminal;
[0010] Receive the biometric information collected and sent by the wearable device, and match it with the pre-stored biometric information. If the match is successful, the authentication passes.
[0011] Further, the device information is provided by the user terminal when initiating an authentication request to the target server.
[0012] Further, the quantum key distribution network also receives the temporary session ID generated by the target server upon receiving the authentication request, and then sends it to the wearable device.
[0013] Further, the device information is the device ID or quantum identity number of the user terminal. The quantum identity number is a globally unique identity identifier assigned by the quantum key distribution network to the wearable device registered in the network. After the wearable device establishes a binding relationship with the user terminal, the quantum identity number is shared by the wearable device and the user terminal bound to it.
[0014] Further, when the device information is the device ID of the user terminal, the process of finding the wearable device bound to the user terminal includes: first, finding the corresponding quantum identity number in the quantum key distribution network according to the device ID of the user terminal, and then finding the wearable device with this quantum identity number, which is the wearable device bound to the user terminal; if it cannot be found, the identity authentication fails; wherein, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices pre-registered to the quantum key distribution network, and the device IDs of the user terminals bound to these wearable devices.
[0015] Further, when the device information is a quantum identity number, the process of finding the wearable device bound to the user terminal includes: finding the wearable device with this quantum identity number in the device information pre-stored in the quantum key distribution network according to the quantum identity number of the user terminal, which is the wearable device bound to the user terminal; if it cannot be found, the current identity authentication fails; wherein, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices registered to the quantum key distribution network.
[0016] Further, after successfully matching with the pre-stored biometric information, it further includes: further finding the device information bound to this biometric information stored in the quantum key distribution network, and judging whether the device information is consistent with the device information received from the target server; and / or
[0017] Judging whether the temporary session ID received from the wearable device is consistent with the temporary session ID received from the target server, wherein the temporary session ID received from the wearable device is sent by the wearable device to the quantum key distribution network at the same time as the biometric information.
[0018] If the judgment result is consistent, the authentication passes; wherein, the information pre-stored in the quantum key distribution network should at least include the device information pre-registered to this network and the biometric information bound to the device information.
[0019] Further, both the quantum key distribution network and the target server pre-store a first shared key for encrypting and decrypting communication data between them.
[0020] Further, both the wearable device and the quantum key distribution network pre-store a second shared key for encrypting and decrypting communication data between them.
[0021] The second aspect of the present invention provides a wearable device for identity authentication, which is bound to a user terminal:
[0022] Collect the biometric information of the user;
[0023] Send the biometric information to the quantum key distribution network for authentication.
[0024] Furthermore, the wearable device collects the user's biometric information after receiving the temporary session ID / device information; the temporary session ID is generated by the target server upon receiving the authentication request initiated by the user terminal and is sent by the target server to the quantum key distribution network; the device information is provided by the user terminal when initiating the authentication request to the target server and is sent to the quantum key distribution network after the target server receives the authentication request.
[0025] Furthermore, the wearable device is registered in the quantum key distribution network and stores a globally unique quantum identity number, and has the functions of key storage, data encryption and decryption, and data sending and receiving.
[0026] Furthermore, a second shared key is pre-stored in both the wearable device and the quantum key distribution network for encrypting and decrypting the communication data therebetween.
[0027] The third aspect of the present invention provides a target server:
[0028] Receive the authentication request sent by the user terminal and the device information of the user terminal, and send the device information to the quantum key distribution network;
[0029] Send the authentication result sent by the quantum key distribution network to the user terminal.
[0030] Furthermore, after receiving the authentication request sent by the user terminal, the target server also sends the generated temporary session ID to the quantum key distribution network.
[0031] Furthermore, the target server has both an identity authentication function and a function of providing service access for the user terminal; or only has an identity authentication function. If the identity authentication of the target server is passed, other servers provide the service access function for the user terminal.
[0032] Furthermore, a first shared key is pre-stored in both the quantum key distribution network and the target server for encrypting and decrypting the communication data therebetween.
[0033] The beneficial effects of the present invention:
[0034] The present invention provides an identity authentication method for a user terminal to access a third-party target server. This method is based on a quantum key distribution network, which provides an authentication service interface to the third-party target server to replace the traditional authentication method based on mathematical algorithms. By using quantum key encryption, the security of the identity authentication process is improved.
[0035] In the identity authentication process of the present invention, a wearable device is added. Compared with the user terminal, the wearable device is more closely bound to the identity of the specific user and has higher security. In addition, the wearable device is convenient to use and can effectively improve the user experience.
[0036] In the present invention, the key authentication link is protected by quantum cryptography, so it has extremely strong functions of anti-impersonation and anti-cracking.
[0037] The present invention organically combines biometric identity authentication with quantum keys, greatly enhancing the reliability of identity authentication between devices and between people and devices, solving the security risks brought by the devices themselves, and paving the "last mile" from the remote service server to the user. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation of this application.
[0039] Figure 1 It is a flowchart of the identity authentication method based on a wearable device according to the present invention.
[0040] Figure 2 It is a schematic diagram of the identity authentication process according to the present invention.
[0041] Figure 3 It is a schematic diagram of the method for the quantum key distribution network of the present invention to perform biometric information recognition and matching. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of this application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs.
[0043] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to this application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0044] The mobile terminals referred to in the present invention include but are not limited to mobile phones and tablets. All electronic devices that can connect to the Internet are suitable for the mobile terminals of the present invention; the wearable devices described in the present invention include but are not limited to smart rings, smart bracelets, smart watches, smart necklaces and other small devices that come into contact with the human body and are carried with the body.
[0045] Example 1
[0046] This embodiment provides an identity authentication method based on a wearable device, which uses biometric information recognition technology, such as Figure 1 As shown, the following steps are included:
[0047] S1: The user terminal initiates an authentication request to the target server and provides the device information of the user terminal. The target server receives the authentication request and generates a temporary session, and sends the temporary session ID and device information to the quantum key distribution network;
[0048] S2: The quantum key distribution network receives the temporary session ID and device information, searches for the wearable device bound to the user terminal, and sends the temporary session ID to the wearable device;
[0049] S3: The wearable device receives the temporary session ID, collects the user's biometric information, and sends the biometric information to the quantum key distribution network;
[0050] S4: The quantum key distribution network receives the biometric information and matches the biometric information with the pre-stored biometric information. If the match is successful, it means that the identity authentication corresponding to the temporary session ID is passed, and the authentication result is sent to the target server and then to the user terminal.
[0051] The target server may have both the identity authentication function and the function of providing service access to the user terminal; or it may only have the identity authentication function. If the identity authentication of the target server passes, other servers provide the service access function to the user terminal.
[0052] The quantum key distribution network provides an interface for the target server, establishes communication with it, and distributes a unified first shared key to itself and the target server. The first shared key is used for encryption and decryption of communication data between the quantum key distribution network and the target server. Optionally, key sharing can be achieved between the two in other forms, for example, the quantum key distribution network first generates a quantum key, and then transmits it to the target server using other relatively reliable media (such as VPN private network, mobile storage media) to achieve sharing.
[0053] The wearable device is registered to the quantum key distribution network, and the quantum key distribution network distributes a second shared key to itself and the wearable device, and the second shared key is used for encryption and decryption of communication data between the quantum key distribution network and the wearable device.
[0054] Among them, the registration method is: the wearable device holder (which can be an individual, or a manufacturer or seller of wearable devices) first goes to the operator of the quantum key distribution network to handle the relevant procedures for registration and network access. The operator of the quantum key distribution network is responsible for reviewing the user's network access application. If the review is passed, a unique quantum identity number in the entire network assigned by the quantum key distribution network will be issued to each wearable device applying for network access. The quantum identity number is stored in the permanent storage medium of the wearable device applying for network access. Since very little information is transmitted during each identity authentication process, even if a one-time one-key method is used, the shared key pre-stored on the wearable device during registration with the quantum key distribution network can be used for a long time. If for the purpose of improving security, the shared key stored on the wearable device can be replaced regularly. One method is that the quantum key distribution network generates a new key, encrypts the new shared key with the old shared key, and sends it to the wearable device.
[0055] The wearable device is connected to the user terminal wirelessly or wired.
[0056] Since the distance between the user terminal and the wearable device is very close when executing this process, the two can be bound and information transmitted via Bluetooth. Under more stringent security environment requirements, information can also be transmitted via wired means.
[0057] In order to prevent replay attacks, when two devices that use quantum keys for confidential communication transmit information (for example, between a quantum key distribution network and a wearable device, or between a quantum key distribution network and a target server), they must carry a random code, which is taken from the quantum key shared with the other device and is only used once. Only when the random codes on both sides are consistent is the communication legal and valid.
[0058] Optionally, the wearable device can be registered in the quantum key distribution network to obtain the quantum identity number of the wearable device. When the wearable device is bound to a user terminal, the quantum identity number is also shared by the user terminal, and the binding relationship is stored in the quantum key distribution network. The wearable device can apply to the quantum key distribution network to release the binding relationship with the user terminal, or apply to establish a new binding relationship with another user terminal.
[0059] Preferably, the device information may be a device ID of the user terminal or a quantum identity number.
[0060] Before sending the temporary session ID and device information to the quantum key distribution network in step S1, the following steps are further included: the target server encrypts the temporary session ID and device information using a first shared key; the first shared key is the shared key between the target server and the quantum key distribution network.
[0061] When the quantum key distribution network receives the temporary session ID and device information in step S2, the following steps are further included: decrypting them using the first shared key.
[0062] When the device information provided during authentication initiation is the device ID, in step S2, searching for the wearable device bound to the user terminal, as Figure 3 shown, specifically includes: first, finding the corresponding quantum identity number in the quantum key distribution network according to the device ID of the user terminal, and then searching for the wearable device with this quantum identity number, which is the wearable device bound to the user terminal; if it cannot be found, the identity authentication fails. Among them, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices pre-registered on the quantum key distribution network, and the device IDs of the user terminals bound to these wearable devices.
[0063] When the device information provided during authentication initiation is the device quantum identity number, in step S2, searching for the wearable device bound to the user terminal is to search for the wearable device with this quantum identity number in the device information pre-stored in the quantum key distribution network, which is the wearable device bound to the user terminal; if it cannot be found, the identity authentication fails. Among them, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices registered on the quantum key distribution network.
[0064] Before sending the temporary session ID to the wearable device in step S2, the following steps are further included: encrypting the temporary session ID using a second shared key; the second shared key is the shared key between the wearable device and the quantum key distribution network.
[0065] When the wearable device receives the temporary session ID in step S3, the following steps are further included: decrypting it using the second shared key.
[0066] The biometric information of the user in step S3 includes one or more of the following: fingerprint information, heartbeat information, blood pressure information, retina information, iris information, voiceprint information, vein information, facial information, handwriting signature information.
[0067] Before sending the biometric information to the quantum key distribution network in step S3, the following steps are further included: the wearable device encrypts the biometric information using the second shared key.
[0068] The quantum key distribution network receiving the biometric information in step S4 further includes: the quantum key distribution network decrypts the encrypted biometric information using a second shared key.
[0069] The pre-stored biometric information in step S4 includes one or more of the following: fingerprint information, heartbeat information, blood pressure information, retina information, iris information, voiceprint information, vein information, facial information, handwriting signature information.
[0070] The method of matching with the pre-stored biometric information in step S4 can be: comparing the biometric information received from the wearable device with the pre-stored biometric information in the quantum key distribution network one by one. If a consistent biometric information is found, the matching is successful; otherwise, the matching fails and the current identity authentication fails. It can also be that the quantum key distribution network retrieves the biometric information received from the wearable device from the biometric information stored in this network. If a result is retrieved, it indicates that the initiator of the authentication request is indeed a legitimate user registered in the quantum key distribution network, and the matching is successful. If the retrieval fails, the matching fails and the current identity authentication fails.
[0071] Optionally, as Figure 3 shown, in order to further improve the security during the authentication process, after matching the biometric information during the matching process, the device information is further verified. That is, the process of matching with the pre-stored biometric information in step S4 specifically includes:
[0072] S41: The quantum key distribution network retrieves the biometric information sent by the wearable device from the biometric information stored in this network. If the retrieval fails, the current identity authentication fails.
[0073] S42: If the retrieval is successful, then further find the device information (quantum identity number or device ID, Figure 3 taking the quantum identity number as an example here) bound to this biometric information stored in the quantum key distribution network. As Figure 3 shown, according to the biometric information, the quantum identity number of the wearable device bound to it can be uniquely determined, as well as the device information (device ID or the quantum identity number shared with the wearable device) of the user terminal bound to the wearable device.
[0074] S43: Check whether the device information is consistent with the device information from the target server in step S2.
[0075] S44: The wearable device sends the temporary session ID while sending the biometric information to the quantum key distribution network. The quantum key distribution network checks whether the temporary session ID from the wearable device is consistent with the temporary session ID from the target server in step S2.
[0076] S45: If all match, it indicates that the claimed identity of the authentication request initiator indeed matches the actual identity collected on-site and belongs to the same authentication process, and the match is successful.
[0077] Optionally, it is possible to only verify whether the device information matches the device information from the target server in step S2, or only verify whether the temporary session ID from the wearable device matches the temporary session ID from the target server in step S2.
[0078] Among them, at least the device information pre-registered on this network in advance and the biometric information bound to the device information are stored in the quantum key distribution network.
[0079] In step S4, sending the authentication result to the target server and then to the user terminal includes: the quantum key distribution network encrypts the authentication result using the first shared key and sends it to the target server. The target server receives the encrypted authentication result, decrypts it using the first shared key, and then sends it to the user terminal.
[0080] To more clearly elaborate on the present invention, the following describes this embodiment through an example, as Figure 2 shown:
[0081] ① The user terminal accesses the target server and informs the server of its own identity. The target server generates a temporary session for this login.
[0082] ② The target server applies to the quantum key distribution network for authorization authentication, and after encrypting the relevant information of this temporary session and the user terminal identity with the shared quantum key between the target server and the quantum key distribution network, it sends them to the quantum key distribution network. The quantum key distribution network decrypts and restores the information after receiving it.
[0083] ③ The quantum key distribution network searches for the identity of the login person internally and sends the relevant information of this temporary session to the wearable device with that identity. This information is sent after being encrypted with the pre-set shared quantum key between the quantum key distribution network and the wearable device. The wearable device decrypts and restores the information after receiving it.
[0084] ④ The wearable device collects the user's biometric information characteristics and uploads them to the quantum key distribution network in an encrypted manner using quantum keys. The quantum key distribution network decrypts to obtain the biometric information characteristics uploaded by the user.
[0085] ⑤ The quantum key distribution network compares the biometric information characteristics uploaded by the user with the originally stored biometric information characteristics, determines whether the login authentication passes, and sends it back to the target server in an encrypted manner using quantum keys. The target server decrypts to obtain the authentication result.
[0086] ⑥The target server informs the user terminal of the authentication result of this time.
[0087] The identity authentication of the present invention is particularly suitable for complex application scenarios. For example, the same user terminal sends two or more authentication requests within a relatively short period of time (such as first applying for authorization of target server A and then immediately applying for authorization of target server B). For a quantum key distribution network, in this case, it may occur that the previous authentication has not been completed and the next authentication arrives immediately. Using a temporary session ID to distinguish two different authentication processes ensures the accuracy of identity authentication.
[0088] As a simplified solution of this embodiment, before the authentication request initiated by the user terminal is responded to (that is, before the authentication is passed or not passed), another authentication request cannot be initiated. That is, within a period of time, a user device will only have one authentication request, and there is no need to use a temporary session ID for identification. At this time, only the device information of the user terminal needs to be used to identify the identity in this temporary session. Specifically, it includes the following steps:
[0089] S1: The user terminal sends an authentication request to the target server and provides the device information of the user terminal. The target server receives the authentication request and generates a temporary session, and sends the device information to the quantum key distribution network;
[0090] S2: The quantum key distribution network receives the device information, searches for the wearable device bound to the user terminal, and sends the device information to the wearable device;
[0091] S3: The wearable device receives the device information, collects the biometric information of the user, and sends the biometric information to the quantum key distribution network;
[0092] S4: The quantum key distribution network receives the biometric information, and matches the biometric information with the pre-stored biometric information. If the match is successful, the identity authentication of this time is passed, and the authentication result is sent to the target server and then sent to the user terminal.
[0093] Embodiment 2
[0094] Based on the identity authentication method of Embodiment 1, the present invention also provides an identity authentication system based on a wearable device, including:
[0095] A user terminal, configured to send an authentication request to a target server and provide the device information of the user terminal, and receive the authentication result sent by the target server;
[0096] The target server is used to receive the authentication request and generate a temporary session, send the temporary session ID and device information to the quantum key distribution network, and receive the authentication result sent by the quantum key distribution network, and then send it to the user terminal;
[0097] A quantum key distribution network is used to receive the temporary session ID and device information, search for a wearable device bound to the user terminal, send the temporary session ID to the wearable device, and receive the biometric information sent by the wearable device, and match it with the pre-stored biometric information. If the match is successful, the identity authentication corresponding to the temporary session ID passes, and the authentication result is sent to the target server;
[0098] The wearable device is used to receive the temporary session ID, collect the user's biometric information, and send the biometric information to the quantum key distribution network.
[0099] The target server may have both the identity authentication function and the function of providing service access to the user terminal; or it may only have the identity authentication function. If the identity authentication of the target server passes, other servers provide the service access function to the user terminal.
[0100] Optionally, the device information is the device ID or quantum identity number of the user terminal. The quantum identity number is a network-wide unique identity assigned by the quantum key distribution network to the wearable device registered with the network. After the wearable device establishes a binding relationship with the user terminal, the quantum identity number is shared by the wearable device and the user terminal bound to it.
[0101] Optionally, one way to search for the wearable device bound to the user terminal is: first, find the corresponding quantum identity number in the quantum key distribution network according to the device ID of the user terminal, and then find the wearable device with the quantum identity number, that is, the wearable device bound to the user terminal; if it cannot be found, the identity authentication fails. Among them, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices pre-registered on the quantum key distribution network, and the device IDs of the user terminals bound to these wearable devices.
[0102] Optionally, another way of searching for a wearable device bound to a user terminal is: according to the quantum identity number of the user terminal, searching for a wearable device with the quantum identity number in the device information pre-stored in the quantum key distribution network, that is, the target wearable device; if the device cannot be found, the identity authentication fails. The device information pre-stored in the quantum key distribution network should at least include the quantum identity number of the wearable device registered to the quantum key distribution network.
[0103] Optionally, the biometric information of the user includes one or more of the following: fingerprint information, heartbeat information, blood pressure information, retina information, iris information, voiceprint information, vein information, face information, and handwriting signature information.
[0104] The method of matching with the pre-stored biometric information can be: comparing the biometric information received from the wearable device with the pre-stored biometric information in the quantum key distribution network one by one. If a matching biometric information is found, the matching is successful; otherwise, the matching fails and the current identity authentication fails. It can also be that the quantum key distribution network retrieves the biometric information received from the wearable device from the biometric information stored in this network. If the result is retrieved, it indicates that the initiator of the authentication request is indeed a legitimate user registered in the quantum key distribution network, and the matching is successful. If the retrieval fails, the matching fails and the current identity authentication fails.
[0105] Optionally, as Figure 3 shown, in order to further improve the security during the authentication process, after matching the biometric information during the matching process, the device information is further verified. That is, the process of matching with the pre-stored biometric information specifically includes:
[0106] S41: The quantum key distribution network retrieves the biometric information sent by the wearable device from the biometric information stored in this network. If the retrieval fails, the current identity authentication fails.
[0107] S42: If the retrieval is successful, further search for the device information (quantum identity number or device ID, Figure 3 taking the quantum identity number as an example in Figure 3 this) bound to the retrieved biometric information in the quantum key distribution network. As
[0108] shown, according to the biometric information, the quantum identity number of the wearable device bound to it can be uniquely determined, as well as the device information (device ID or the quantum identity number shared with the wearable device) of the user terminal bound to the wearable device.
[0109] S43: Check whether the device information matches the device information from the target server.
[0110] S44: The wearable device sends the temporary session ID while sending the biometric information to the quantum key distribution network. The quantum key distribution network checks whether the temporary session ID from the wearable device matches the temporary session ID from the target server.
[0111] Optionally, it is possible to verify only whether the device information matches the device information from the target server, or only whether the temporary session ID from the wearable device matches the temporary session ID from the target server.
[0112] Among them, at least the device information pre-registered on this network in advance and the biometric information bound to the device information are pre-stored in the quantum key distribution network.
[0113] Optionally, the communication connection method between devices is as follows:
[0114] The user terminal accesses the target server.
[0115] The first shared key is pre-stored in both the quantum key distribution network and the target server for encrypting and decrypting communication data between the two.
[0116] The second shared key is pre-stored in both the wearable device and the quantum key distribution network for encrypting and decrypting communication data between the two.
[0117] As a simplified solution of this embodiment, before the authentication request initiated by the user terminal is responded to (that is, before the authentication is passed or not passed), another authentication request cannot be initiated. That is, within a period of time, a user device will only have one authentication request, and there is no need to use a temporary session ID for identification. At this time, only the device information of the user terminal needs to be used to identify the identity in this temporary session. Specifically, the identity authentication system based on the wearable device includes:
[0118] A user terminal, configured to initiate an authentication request to the target server and provide the device information of the user terminal, and receive the authentication result sent by the target server;
[0119] A target server, configured to receive the authentication request and generate a temporary session, send the device information to the quantum key distribution network, and receive the authentication result sent by the quantum key distribution network and then send it to the user terminal;
[0120] A quantum key distribution network, configured to receive the device information, find the wearable device bound to the user terminal, send the device information to the wearable device, and receive the biometric information sent by the wearable device and match it with the pre-stored biometric information. If the match is successful, the identity authentication is passed, and the authentication result is sent to the target server;
[0121] A wearable device, configured to receive the device information, collect the biometric information of the user, and send the biometric information to the quantum key distribution network.
[0122] Embodiment 3
[0123] Based on the identity authentication method of Embodiment 1, this embodiment further provides a quantum key distribution network for identity authentication, including:
[0124] Receiving the device information provided by the user terminal when initiating an authentication request to the target server, and the temporary session ID generated by the target server upon receiving the authentication request;
[0125] Searching for the wearable device bound to the user terminal, and sending the temporary session ID to the wearable device;
[0126] Receiving the biometric information collected and sent by the wearable device, and matching it with the pre-stored biometric information. If the match is successful, the authentication passes, and the authentication result is sent to the target server.
[0127] Optionally, the device information is the device ID of the user terminal or the quantum identity number. The quantum identity number is a globally unique identity identifier assigned by the quantum key distribution network to the wearable devices registered in the network. After the wearable device and the user terminal establish a binding relationship, the quantum identity number is shared by the wearable device and the user terminal bound to it.
[0128] Among them, one way to search for the wearable device bound to the user terminal includes: first, finding the corresponding quantum identity number in the quantum key distribution network according to the device ID of the user terminal, and then searching for the wearable device with this quantum identity number, which is the wearable device bound to the user terminal; if it cannot be found, the identity authentication fails. Among them, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices pre-registered on the quantum key distribution network, and the device IDs of the user terminals bound to these wearable devices.
[0129] Another way to search for the wearable device bound to the user terminal includes: searching for the wearable device with this quantum identity number in the device information pre-stored in the quantum key distribution network according to the quantum identity number of the user terminal, which is the wearable device bound to the user terminal; if it cannot be found, this identity authentication fails. Among them, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices registered in the quantum key distribution network.
[0130] After the matching with the pre-stored biometric information, it further includes: further searching for the device information bound to this biometric information stored in the quantum key distribution network, and determining whether the device information is consistent with the device information received from the target server; and / or
[0131] Determining whether a temporary session ID received from the wearable device is consistent with a temporary session ID received from the target server, wherein the temporary session ID received from the wearable device is sent by the wearable device at the same time as the biometric information is sent to the quantum key distribution network;
[0132] If the judgment result is consistent, the authentication is passed; wherein, the quantum key distribution network at least pre-stores the device information pre-registered on the network and the biometric information bound to the device information.
[0133] Optionally, the quantum key distribution network and the target server both pre-store a first shared key for encryption and decryption of communication data between the two.
[0134] Optionally, a second shared key is pre-stored in both the wearable device and the quantum key distribution network for encryption and decryption of communication data between the two.
[0135] As a simplified solution of this embodiment, the user terminal initiates an authentication request. Before the authentication request is responded to (i.e., before the authentication is passed or not), another authentication request cannot be initiated. That is, within a time period, a user device will only have one authentication request, and there is no need to use a temporary session ID for identification. At this time, only the device information of the user terminal is needed to identify the identity in this temporary session. Specifically, the quantum key distribution network for identity authentication includes:
[0136] Receive device information provided by the user terminal when initiating an authentication request to the target server;
[0137] Searching for a wearable device bound to the user terminal, and sending the device information to the wearable device;
[0138] The biometric information collected and sent by the wearable device is received, and the biometric information is matched with the pre-stored biometric information. If the match is successful, the authentication is passed, and the authentication result is sent to the target server.
[0139] Example 4
[0140] Based on the identity authentication method of embodiment 1, this embodiment further provides a wearable device for identity authentication, which is bound to a user terminal and includes:
[0141] Receive a temporary session ID sent by the quantum key distribution network, collect the user's biometric information, and send the biometric information to the quantum key distribution network for authentication; the temporary session ID is generated by the target server when it receives the authentication request initiated by the user terminal, and is sent by the target server to the quantum key distribution network.
[0142] The wearable device is registered in the quantum key distribution network and stores a unique quantum identity number throughout the network, and has the functions of key storage, data encryption and decryption, and data sending and receiving.
[0143] Optionally, a second shared key is pre-stored in both the wearable device and the quantum key distribution network for encrypting and decrypting communication data between the two.
[0144] As a simplified solution of this embodiment, before the authentication request initiated by the user terminal is responded to (that is, before the authentication is passed or not passed), another authentication request cannot be initiated. That is, within a period of time, a user device will only have one authentication request, and there is no need to use a temporary session ID for identification. At this time, only the device information of the user terminal needs to be used to identify the identity in this temporary session. Specifically, the wearable device for identity authentication is bound to the user terminal and includes:
[0145] Receiving the user terminal device information sent by the quantum key distribution network, collecting the biometric information of the user, and sending the biometric information to the quantum key distribution network for authentication; the device information is provided by the user terminal when initiating an authentication request to the target server and is sent to the quantum key distribution network after the target server receives the authentication request.
[0146] Embodiment 5
[0147] Based on the identity authentication method of Embodiment 1, this embodiment further provides a target server, including:
[0148] Receiving the authentication request sent by the user terminal and the device information provided by the user terminal, generating a temporary session, and sending the temporary session ID and the device information to the quantum key distribution network;
[0149] Sending the authentication result sent by the quantum key distribution network to the user terminal.
[0150] Wherein, the target server has both the identity authentication function and the function of providing service access for the user terminal; or only has the identity authentication function. If the identity authentication of the target server is passed, other servers provide the service access function for the user terminal.
[0151] Optionally, a first shared key is pre-stored in both the quantum key distribution network and the target server for encrypting and decrypting communication data between the two.
[0152] As a simplified solution of this embodiment, the user terminal initiates an authentication request. Before the authentication request is responded to (i.e., before the authentication is passed or not), another authentication request cannot be initiated. That is, within a time period, a user device will only have one authentication request, and there is no need to use a temporary session ID for identification. At this time, only the device information of the user terminal is needed to identify the identity in this temporary session. Specifically, the target server includes:
[0153] Receiving an authentication request sent by a user terminal and device information provided by the user terminal, and sending the device information to a quantum key distribution network;
[0154] The authentication result sent by the quantum key distribution network is sent to the user terminal.
[0155] The present invention replaces the encryption method based on the complexity of mathematical algorithms with a one-time symmetric quantum key for user identity authentication, thus improving security; the wearable device is involved in the login authentication of the target server, thus enhancing the user experience; the quantum cryptography technology, biometrics technology and wearable devices are organically combined, thus greatly improving the reliability of identity authentication between devices and between people and devices. Thus, a complete and reliable authentication link from people (users) to remote business servers is established, paving the way for the security of the "last mile".
[0156] The use of quantum keys is one-time one-pad. However, if the security requirements are lowered so that the key usage is no longer strictly one-time one-pad, or other keys are used to replace quantum keys on the basis of this embodiment, such changes should also be considered as the scope of protection of this application proposal.
[0157] Those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computer device, or alternatively, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.
[0158] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A quantum key distribution network for identity authentication, characterized in that, The quantum key distribution network provides an interface for the target server to establish communication with it, and a communication connection is established between the quantum key distribution network and the wearable device; the quantum key distribution network is used to perform the following identity authentication method: Receive device information of a user terminal; the device information of the user terminal is a device ID or a quantum identity number of the user terminal, and the device information of the user terminal is provided when the user terminal initiates an authentication request to a target server; The quantum key distribution network also receives a temporary session ID generated by the target server receiving the authentication request; Searching for a wearable device bound to the user terminal in pre-stored device information, and sending the temporary session ID to the wearable device; Receiving the biometric information of the user collected and sent by the wearable device, and matching it with the pre-stored biometric information. If the match is successful, it means that the identity authentication corresponding to the temporary session ID is passed, and sending the authentication result to the target server, and then to the user terminal; The quantum key distribution network pre-stores a binding relationship between device information and biometric information, and the quantum identity number is a network-wide unique identity assigned by the quantum key distribution network to the wearable device registered in the network.
2. The quantum key distribution network for identity authentication according to claim 1, characterized in that, After the wearable device establishes a binding relationship with the user terminal, the quantum identity number is shared by the wearable device and the user terminal bound thereto.
3. The quantum key distribution network for identity authentication according to claim 2, characterized in that, When the device information of the user terminal is the device ID of the user terminal, the searching for the wearable device bound to the user terminal includes: first searching for the corresponding quantum identity number in the quantum key distribution network according to the device ID of the user terminal, and then searching for the wearable device with the quantum identity number, that is, the wearable device bound to the user terminal; if the number cannot be found, the identity authentication fails; wherein, the device information pre-stored in the quantum key distribution network should at least include the quantum identity numbers of the wearable devices pre-registered on the quantum key distribution network, and the device IDs of the user terminals bound to these wearable devices.
4. The quantum key distribution network for identity authentication according to claim 2, characterized in that, When the device information of the user terminal is a quantum identity number, the searching for the wearable device bound to the user terminal includes: searching for a wearable device having the quantum identity number in the device information pre-stored in the quantum key distribution network according to the quantum identity number of the user terminal, that is, the wearable device bound to the user terminal; if the wearable device cannot be found, the identity authentication fails; wherein the device information pre-stored in the quantum key distribution network should at least include the quantum identity number of the wearable device registered to the quantum key distribution network.
5. The quantum key distribution network for identity authentication according to claim 1, characterized in that, After the matching with the pre-stored biometric information is successful, the method further includes: further searching for device information bound to the biometric information stored in the quantum key distribution network, and determining whether the device information is consistent with the device information received from the target server; and / or Determine whether the temporary session ID received from the wearable device is consistent with the temporary session ID received from the target server, where the temporary session ID received from the wearable device is sent by the wearable device while sending the biometric information to the quantum key distribution network; If the judgment result is consistent, the authentication passes; among them, the information pre-stored in the quantum key distribution network should at least include the device information pre-registered on this network and the biometric information bound to the device information.
6. The quantum key distribution network for identity authentication according to claim 1, characterized in that, Both the quantum key distribution network and the target server pre-store a first shared key for encrypting and decrypting communication data between them.
7. The quantum key distribution network for identity authentication according to any one of claims 1-6, characterized in that, Both the wearable device and the quantum key distribution network pre-store a second shared key for encrypting and decrypting communication data between them.
8. A wearable device for identity authentication, bound to a user terminal, characterized in that, A communication connection is established between the wearable device and the quantum key distribution network, and the wearable device is used to execute the following method: Receive the temporary session ID sent by the quantum key distribution network; Collect the user's biometric information; Send the biometric information to the quantum key distribution network for authentication, so that the quantum key distribution network matches the biometric information with the pre-stored biometric information. If the match is successful, it means that the identity authentication corresponding to the temporary session ID passes, and the authentication result is sent to the target server and then sent to the user terminal; The temporary session ID is generated by the target server receiving the authentication request initiated by the user terminal, and is sent by the target server to the quantum key distribution network together with the device information of the user terminal; The device information of the user terminal is the device ID or quantum identity number of the user terminal; the device information of the user terminal is provided by the user terminal when initiating the authentication request to the target server; The quantum key distribution network pre-stores the binding relationship between the device information and the biometric information, and the quantum identity number is the globally unique identity identifier assigned by the quantum key distribution network to the wearable device registered in the network.
9. The wearable device for identity authentication according to claim 8, characterized in that, The wearable device collects the user's biometric information after receiving the device information of the user terminal.
10. The wearable device for identity authentication according to claim 8, characterized in that, The wearable device is registered in the quantum key distribution network and stores a globally unique quantum identity number, and has the functions of key storage, data encryption and decryption, and data sending and receiving.
11. The wearable device for identity authentication according to any one of claims 8-10, characterized in that, Both the wearable device and the quantum key distribution network pre-store a second shared key for encrypting and decrypting communication data between them.
12. A target server, characterized in that, The target server establishes communication connections with the user terminal and the quantum key distribution network respectively, and the target server is used to execute the following method: Receive the authentication request sent by the user terminal and the device information of the user terminal, and send the device information of the user terminal to the quantum key distribution network; the device information of the user terminal is the device ID or quantum identity number of the user terminal; after receiving the authentication request sent by the user terminal, the target server also sends the generated temporary session ID to the quantum key distribution network, so that the quantum key distribution network searches for the wearable device bound to the user terminal in the pre-stored device information, sends the temporary session ID to the wearable device, receives the biometric information of the user collected and sent by the wearable device, and matches the biometric information with the pre-stored biometric information. If the match is successful, it indicates that the identity authentication corresponding to the temporary session ID passes, and the authentication result is sent to the target server; Send the authentication result sent by the quantum key distribution network to the user terminal; The quantum key distribution network pre-stores the binding relationship between device information and biometric information, and the quantum identity number is the globally unique identity identifier assigned by the quantum key distribution network to the wearable device registered and connected to the network.
13. The target server according to claim 12, characterized in that, The target server has both an identity authentication function and a function of providing service access for the user terminal; or only has an identity authentication function. If the identity authentication of the target server passes, other servers provide the service access function for the user terminal.
14. The target server according to any one of claims 12-13, characterized in that, A first shared key is pre-stored in both the quantum key distribution network and the target server for encrypting and decrypting communication data between the two.
Citation Information
Patent Citations
Method for authenticating by virtue of wearable equipment and wearable equipment
CN104182670A
A kind of authentication method of wearable device
CN105307164B
Authentication payment method and payment authentication system based on wearable devices
CN105321072B
Identity authentication method based on quantum key encryption
CN105471584A
Identity verification method and device
CN106161392A