Identity authentication method, device and electronic device
By adding the entity's current environmental attributes to the identity credentials and using trusted hardware modules to verify, the problem of the legality of the entity's environment in the existing technology is solved, and the reliability and communication security of identity authentication are improved.
Patent Information
- Application Number
- CN202111314068.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-08
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-11-08
AI Technical Summary
The existing identity authentication methods cannot effectively guarantee the environmental legitimacy of the entity, resulting in insufficient security during the communication process.
Add the entity's current environmental attributes to the identity credentials, and generate and verify the entity's real-time environmental attributes through the trusted hardware module to ensure that the communication party can verify the entity's environmental legitimacy.
Improve the reliability of identity authentication, ensure the legitimacy of the operating environment of the entity after startup, and enhance the security of the communication process.
Smart Images

Figure CN113987461B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of identity authentication, and particularly to an identity authentication method, apparatus, and electronic device. Background Art
[0002] If an entity (such as an application) on a device wishes to communicate with another device (such as obtaining resources from another device), the other device usually needs to authenticate the identity of the entity.
[0003] Related technologies only focus on the authentication of device identity and / or entity identity, and this identity authentication method is not reliable enough. Summary of the Invention
[0004] In view of this, the present disclosure provides an identity authentication method, apparatus, and electronic device to improve the reliability of identity authentication.
[0005] In a first aspect, an identity authentication method is provided. The method is applied to a first device on which a first entity is running. The method includes: sending an identity credential of the first entity to a second device, where the identity credential includes the current environment attribute of the first entity, and the current environment attribute is used by the second device to verify the environmental legality of the first entity; after the second device passes the verification of the identity credential, communicating with the second device through the first entity.
[0006] Optionally, in some embodiments, the identity credential of the first entity includes a private key signature of the identity private key of the first entity, and the current environment attribute is included in the private key signature. The method further includes: sending an identity certificate of the first entity to the second device, where the identity certificate of the first entity includes the identity public key of the first entity and the environment attribute of the first entity, so that the second device can obtain the current environment attribute from the private key signature based on the identity public key of the first entity, and verify the environmental legality of the first entity by comparing the current environment attribute with the environment attribute in the identity certificate of the first entity.
[0007] Optionally, in some embodiments, the identity certificate of the first entity further includes the identity identifier of the first entity and the identity identifier of the first device. The identity identifier of the first entity is used by the second device to verify the identity legality of the first entity, and the identity identifier of the first device is used by the second device to verify the identity legality of the first device.
[0008] Optionally, in some embodiments, before sending the identity credential of the first entity to the second device, the method further includes: sending an identity registration message of the first entity to a first certificate authority, where the identity registration message of the first entity includes the identity identifier of the first device, the identity identifier of the first entity, and the environmental attributes of the first entity; receiving an identity certificate of the first entity from the first certificate authority.
[0009] Optionally, in some embodiments, the identity certificate of the first entity further includes at least one of the following information: the serial number of the identity certificate of the first entity, the identity identifier of the first entity, the identity identifier of the first device, the identity public key of the first entity, the private key signature of the first certificate authority, and the timestamp.
[0010] Optionally, in some embodiments, the identity registration message of the first entity further includes the identity certificate of the first device. Before sending the identity registration message of the first entity to the first certificate authority, the method further includes: sending an identity registration message of the first device to a second certificate authority, where the identity registration message of the first device includes the identity identifier of the first device and the identity identifier of the first entity; receiving an identity certificate of the first device from the second certificate authority, where the identity certificate of the first device includes the identity identifier of the first device and the identity identifier of the first entity.
[0011] Optionally, in some embodiments, the identity certificate of the first device further includes at least one of the following information: the serial number of the identity certificate of the first device, the device attributes of the first device, the private key signature of the second certificate authority, the identity public key of the first device, and the timestamp.
[0012] Optionally, in some embodiments, an identity proxy module is installed on the first device, and the first entity is communicatively connected to the identity proxy module to trigger the identity proxy module to perform at least one of the following operations: sending an identity registration message of the first entity to a first certificate authority to obtain an identity certificate of the first entity; sending an identity registration message of the first device to a second certificate authority to obtain an identity certificate of the first device; generating an identity credential of the first entity.
[0013] Optionally, in some embodiments, the first device includes a trusted hardware module, and the identity private key of the first device and / or the identity private key of the first entity is stored in the trusted hardware module.
[0014] Optionally, in some embodiments, the current environmental attributes of the first entity include: the current device attributes of the first device and / or the current operating environment attributes of the first entity.
[0015] In a second aspect, an identity authentication method is provided. The method is applied to a second device and includes: receiving, from a first device, an identity credential of a first entity running on the first device, where the identity credential includes the current environmental attributes of the first entity; verifying the identity credential, where the verification of the identity credential includes verifying the environmental legality of the first entity based on the current environmental attributes; and if the verification of the identity credential passes, communicating with the first entity.
[0016] Optionally, in some embodiments, the identity credential of the first entity includes a private key signature of the identity private key of the first entity, and the current environmental attributes are included in the private key signature. Verifying the identity credential includes: receiving, from the first device, an identity certificate of the first entity, where the identity certificate of the first entity includes the identity public key of the first entity and the environmental attributes of the first entity; decrypting the private key signature using the identity public key of the first entity to obtain the current environmental attributes; and if the current environmental attributes match the environmental attributes in the identity certificate of the first entity, determining that the environment of the first entity is legal.
[0017] Optionally, in some embodiments, the identity certificate of the first entity further includes the identity identifier of the first entity and the identity identifier of the first device. Verifying the identity credential includes: verifying the identity legality of the first entity according to the identity identifier of the first entity; and verifying the identity legality of the first device according to the identity identifier of the first device.
[0018] Optionally, in some embodiments, the identity certificate of the first entity is issued by a first certificate authority, and the identity certificate of the first entity further includes at least one of the following information: the serial number of the identity certificate of the first entity, the private key signature of the first certificate authority, and the identity public key of the first entity.
[0019] Optionally, in some embodiments, the current environmental attributes of the first entity include: the current device attributes of the first device and / or the current operating environment attributes of the first entity.
[0020] In a third aspect, an identity authentication method is provided. The method is applied to a first certificate authority and includes: receiving, from the first device, an identity registration message of a first entity running on the first device, where the identity registration message of the first entity includes environmental attributes of the first entity; and sending, to the first device, an identity certificate of the first entity, where the identity certificate of the first entity includes the environmental attributes of the first entity.
[0021] Optionally, in some embodiments, the identity certificate of the first entity further includes at least one of the following information: a serial number of the identity certificate of the first entity, an identity identifier of the first entity, an identity identifier of the first device, a public key of the identity of the first entity, a private key signature of the first certificate authority, and a timestamp.
[0022] Optionally, in some embodiments, the identity registration message of the first entity further includes the identity certificate of the first device.
[0023] Optionally, in some embodiments, the identity certificate of the first device includes an identity identifier of the first device and an identity identifier of the first entity.
[0024] Optionally, in some embodiments, the identity certificate of the first device further includes at least one of the following information: a serial number of the identity certificate of the first device, device attributes of the first device, a private key signature of the second certificate authority, a public key of the identity of the device, and a timestamp.
[0025] Optionally, in some embodiments, an identity proxy module is installed on the first device. The first entity is communicatively connected to the identity proxy module, and the identity registration message of the first entity is sent by the identity proxy module to the first certificate authority.
[0026] In a fourth aspect, an identity authentication device is provided. The identity authentication device is applied to a first device on which a first entity runs. The device includes: a sending module, configured to send an identity credential of the first entity to a second device, where the identity credential includes current environmental attributes of the first entity, and the current environmental attributes are used by the second device to verify the environmental legality of the first entity; and a communication module, configured to communicate with the second device through the first entity after the second device successfully verifies the identity credential.
[0027] Fifth aspect, there is provided an identity authentication device, which is applied to a second device. The device includes: a receiving module, configured to receive, from a first device, an identity credential of a first entity running on the first device, where the identity credential includes current environment attributes of the first entity; a verification module, configured to verify the identity credential, and the verification of the identity credential includes verifying the environmental legality of the first entity based on the current environment attributes; and a communication module, configured to communicate with the first entity if the verification of the identity credential passes.
[0028] Sixth aspect, there is provided an identity authentication device, which is applied to a first certificate authority. The device includes: a receiving module, configured to receive, from a first device, an identity registration message of a first entity running on the first device, where the identity registration message of the first entity includes environmental attributes of the first entity; and a sending module, configured to send an identity certificate of the first entity to the first device, where the identity certificate of the first entity includes environmental attributes of the first entity.
[0029] Seventh aspect, there is provided an electronic device, including a memory and a processor. An executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method as described in the first aspect.
[0030] Eighth aspect, there is provided an electronic device, including a memory and a processor. An executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method as described in the second aspect.
[0031] Ninth aspect, there is provided an electronic device, including a memory and a processor. An executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method as described in the third aspect.
[0032] Seventh aspect, there is provided a computer-readable storage medium, on which an executable code is stored. When the executable code is executed, it can implement the method as described in any one of the first aspect to the third aspect.
[0033] Tenth aspect, there is provided a computer program product, including an executable code. When the executable code is executed, it can implement the method as described in any one of the first aspect to the third aspect.
[0034] In the embodiments of the present disclosure, the current environment attributes (or real-time environment attributes) of the entity are added to the identity credential, so that the communication partner can verify the current environment attributes of the entity, improving the reliability of identity authentication. Description of the Drawings
[0035] Figure 1Schematic diagram of the identity credential of the first entity provided by an embodiment of the present disclosure.
[0036] Figure 2 Schematic flowchart of the identity authentication method provided by an embodiment of the present disclosure.
[0037] Figure 3 Schematic diagram of the structure of the identity certificate of the first entity provided by an embodiment of the present disclosure.
[0038] Figure 4 Schematic flowchart of the identity authentication method provided by an embodiment of the present disclosure.
[0039] Figure 5 Schematic flowchart of the identity authentication method provided by an embodiment of the present disclosure.
[0040] Figure 6 Schematic diagram of the identity certificate of the first device provided by an embodiment of the present disclosure.
[0041] Figure 7 Schematic diagram of the identity authentication system provided by an embodiment of the present disclosure.
[0042] Figure 8 Schematic diagram of the structure of the identity authentication device provided by an embodiment of the present application.
[0043] Figure 9 Schematic diagram of the structure of the identity authentication device provided by an embodiment of the present application.
[0044] Figure 10 Schematic diagram of the structure of the identity authentication device provided by an embodiment of the present application.
[0045] Figure 11 Schematic diagram of the structure of the electronic device provided by an embodiment of the present application. Detailed implementation manners
[0046] For better understanding, some concepts related to the embodiments of the present application are introduced first.
[0047] Device
[0048] The devices mentioned in the present application refer to the devices that need to perform identity authentication before communication. The device can also be referred to as a node or a platform. The device can refer to a physical device, such as a mobile phone, a tablet computer, a laptop computer, a personal digital assistant, a server, etc. The device can also refer to a virtual device, such as an elastic cloud server (ECS), an online trading platform, etc.
[0049] Entity
[0050] An entity can be software with communication functions running on a device. For example, an entity can refer to an application, a component, a pod, etc. running on the device.
[0051] Device Attribute
[0052] Device attributes can also be referred to as platform attributes. Device attributes can, for example, refer to information or features related to the device that can be used to identify the device's identity. For example, device attributes can include one or more of the following attributes: BIOS attributes, OS attributes, OS kernel attributes, OS loading attributes, other firmware attributes, etc.
[0053] Environmental Attribute of Entity
[0054] The environment of an entity can refer to the device's startup environment and / or running environment. The environment of an entity can also refer to the entity's software and hardware environment, such as the entity's operating system environment or the application environment to which the entity belongs. The environment attributes of an entity can, for example, refer to information or features related to the entity that can be used to identify the entity's running environment. For example, it can refer to the running time of the first entity, the type of the operating system where the first entity is located, etc.
[0055] Based on the above concepts, the technical solutions in the embodiments of the present disclosure are clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments.
[0056] With the continuous advancement of the informatization process and the development of computer network technology, people's daily lives are becoming increasingly networked, assets are being digitalized, and the identity authentication of both communication parties before communication has gradually become a basic means to ensure information security.
[0057] Identity authentication is a technology that is based on the identity management of entities, aims at identity trustworthiness, controllable permissions, and restricted behaviors, and ensures the information security of entities and prevents data theft by identifying and verifying the authenticity and legality of the identities of both communication parties.
[0058] Some related technologies use passwords for identity authentication. Or, to improve the reliability of identity authentication, a method of adding dynamic verification codes on the basis of password verification is used for identity authentication. However, passwords and dynamic verification codes are easily intercepted during the distribution and use process. In addition, this method does not consider the legality of the device identity. A third party (such as a malicious attacker) can use the intercepted passwords and dynamic verification codes through other devices to communicate with the peer device, resulting in data leakage.
[0059] To solve the above problems, some related technologies have added verification of the legality of the device identity during the identity authentication process.
[0060] However, verifying the legitimacy of the device identity can only ensure that the device running the entity is a trusted device, but cannot guarantee that the environment where the entity is located (such as the operating system environment or application environment) is legal.
[0061] To improve the reliability of identity authentication, there are also some related technologies that perform identity verification based on trusted hardware. Such trusted hardware can be, for example, a trusted platform control module (TPCM), a trusted platform module (TPM), a trusted platform module (TPM), or trusted hardware that supports software guard extensions (SGX).
[0062] In addition to providing protected secure storage and cryptographic computing capabilities, trusted hardware such as TPCM, TCM, and TPM can also provide the ability to prove the trustworthiness of the device identity to the communication counterpart by means of the device's identity certificate. The device identity certificate can be, for example, an attestation key certificate (AK certificate). However, the identity verification scheme based on trusted hardware only verifies the environment of the entity at the startup or record stage at most, and does not consider whether the operating environment of the entity after startup is legal.
[0063] In summary, the reliability of the current identity authentication methods still needs to be improved.
[0064] In response to the above problems, the identity authentication method provided in the embodiments of the present disclosure will be described in detail below in conjunction with Figures 1 to 6 the following content.
[0065] Figures 1 to 6 This is described from the perspective of communication between a first device and a second device. The first device and the second device mentioned here can be any two communication nodes. For example, they can be two communication nodes based on Internet communication. The first device or the second device can be, for example, a mobile phone, a tablet computer, a server, etc. The first device and the second device can be the same or different. For example, the first device can be a mobile phone, and the second device can be a server.
[0066] A first entity runs on the first device. The first entity can be any entity that needs to obtain data from the second device through the first device. The first entity can be, for example, software such as a client, an application, or a pod running on the first device. Taking the access to Alipay as an example, the first entity can be the Alipay client, the first device can be a mobile phone installed with this client, and the second entity can be the server that maintains the Alipay application.
[0067] Embodiments of the present disclosure add the current environmental attributes (or real-time environmental attributes) of the first entity to the identity credential of the first entity. The current environmental attributes can be used by the second device to verify the environmental legality of the first entity. Since the real-time environmental attributes of the first entity are added to the identity credential, the identity credential is a dynamic credential. In some embodiments, the identity credential can be referred to as a dynamic credential for entity identity request. After the second device successfully verifies the identity credential, the first entity can communicate with the second device. Embodiments of the present application make the current environmental legality of the first entity a necessary condition for communication between the first device and the second device, thereby improving the reliability of identity authentication and communication.
[0068] Figure 1 is a schematic flowchart of an identity authentication method provided by an embodiment of the present disclosure.
[0069] See Figure 1 , in step S110, the first device sends the identity certificate and identity credential of the first entity to the second device.
[0070] The identity certificate of the first entity can be issued by a certificate authority. The issuance process of the identity certificate of the first entity will be described in detail later in combination with Figure 4 , and will not be elaborated here for the time being.
[0071] Figure 2 gives an example of the entity identity certificate of the first entity. See Figure 2 , the entity identity certificate of the first entity may include one or more of the following information: entity certificate serial number, identity identifier of the first device, identity identifier of the first entity, identity public key of the first entity, environmental attributes of the first entity, private key signature of the first certificate authority, and timestamp.
[0072] The identity public key of the first entity and the environmental attributes of the first entity can be used by the second device to decrypt and verify the current environmental attributes in the identity credential. For a detailed description, see step S120 in the following text.
[0073] The identity identifier of the first entity can be used by the second device to verify the identity legality of the first entity. The identity identifier of the first device can be used by the second device to verify the identity legality of the first device. By binding the identity identifier of the first entity to the identity identifier of the first device, the entity identity and the device identity can be ensured to be trustworthy at the same time.
[0074] The environmental attributes of the first entity can refer to the environmental attributes corresponding to the startup or loading of the first device. The environmental attributes can include the system software and hardware environment of the first device, and can also include the running environment of the first device. The running environment of the first device can refer to the environmental attributes of the first device when the first entity runs on the first device.
[0075] Figure 3 An example of the identity credential of the first entity is given. As Figure 3 shown, the identity credential of the first entity may include the identity credential serial number of the first entity, the identity identifier of the first device, the identity identifier of the first entity, the signature of the identity private key of the first entity on the current environment attributes, and a time stamp.
[0076] In some embodiments, the first device may include a trusted hardware module. The trusted hardware module may refer to, for example, a TPM module or an SGX module. The private key of the first entity may be stored in the trusted hardware module. The trusted hardware module has extremely high security, and the data stored in the trusted hardware module is usually not accessible to the outside world. Storing the identity private key of the first entity in the trusted hardware device can further improve the credibility of the first entity.
[0077] The signature of the identity private key of the first entity on the current environment attributes included in the identity credential of the first entity may be implemented by the trusted hardware on the first device or may rely on the host CPU or an encryption card for implementation.
[0078] In step S120, the second device verifies the identity credential of the first entity.
[0079] The second device may first extract the identity public key from the identity certificate of the first entity. Based on the identity public key of the first entity, the second device may obtain the current environment attributes from the private key signature in the identity credential of the first entity.
[0080] After the second device obtains the current environment attributes, it may compare the current environment attributes with the environment attributes in the identity certificate of the first entity to verify the environmental legality of the first entity.
[0081] In step S130, after the identity credential is verified, the first entity communicates with the second device. For example, the first entity may obtain data resources through the second device.
[0082] In the embodiments of the present disclosure, by using the identity private key of the first entity to encrypt the current environment attributes of the first entity, the immutability of the current environment attributes is further ensured, thereby enhancing the reliability of identity authentication.
[0083] Figure 4 is a schematic flowchart of an identity authentication method provided by an embodiment of the present disclosure. Figure 4 The method is described from the perspective of the interaction between the first device and the first certificate authority. Through Figure 4 the method, the first device may register the first entity and obtain the identity certificate of the first entity.
[0084] As Figure 4As shown, in step S410, the first device sends an identity registration message of the first entity running on the first device to the first certificate authority. The identity registration message of the first entity may include the environmental attributes of the first entity.
[0085] The first certificate authority refers to the institution used to issue certificates. The first certificate authority can be used to be responsible for the control of entity identity keys and certificates. Therefore, the first certificate authority can also be referred to as the key management CA.
[0086] The identity registration message of the first entity can be sent to the first certificate authority before the first entity prepares to send a communication request to the second device. The identity registration message of the first entity can also be sent passively to the first certificate authority according to the program set on the first device when the first entity runs on the first device for the first time.
[0087] For example, the first entity refers to the Bank of Communications client, and the first device refers to the user terminal. When the Bank of Communications client is installed on the user terminal for the first time, the user terminal can send an identity registration message to the first certificate authority at the same time when receiving the installation request to request an identity certificate for the Bank of Communications client.
[0088] The environmental attributes of the first entity may include the attributes of the first device and / or the operating environment attributes of the first entity.
[0089] In some embodiments, the identity registration message of the first entity may further include the identity certificate of the first device. For the acquisition method of the identity certificate of the first device, see Figure 5 , which will not be elaborated here for the time being.
[0090] In step S420, the first certificate authority sends the identity certificate of the first entity to the first device. The identity certificate of the first entity includes the environmental attributes of the first entity. The environmental attributes of the first entity may refer to the environmental attributes of the first device where the first entity is located, or may refer to the environmental attributes when the first entity runs on the first device, or may refer to the combined environmental attributes of the two.
[0091] In some embodiments, the identity certificate of the first entity may include at least one of the following information: the serial number of the identity certificate of the first entity, the identity identifier of the first entity, the identity identifier of the first device, the identity public key of the first entity, the private key signature of the first certificate authority, and the timestamp.
[0092] The private key signature of the first issuing authority may refer to the first issuing authority using its own private key to sign the content included in the identity certificate of the first entity. For example, the private key signature of the first issuing authority may be the first issuing authority using its own private key to sign the identity public key of the first entity, the identity identifier of the first entity, the identity identifier of the first device, and the environmental attributes of the first entity.
[0093] The following combines Figure 5 to introduce the process of obtaining the identity certificate of the first device.
[0094] Figure 5 is a schematic flowchart of an identity authentication method provided by an embodiment of the present disclosure.
[0095] In step S510, the first device sends an identity registration message to the second certificate issuing authority. The first certificate issuing authority and the second certificate issuing authority may be the same certificate issuing authority or different certificate issuing authorities. The second certificate issuing authority may be responsible for the control of the system, the public key corresponding to the identity private key of the first device, and the platform identity certificate. The second certificate issuing authority may refer to, for example, a privacy CA.
[0096] In step S520, the second certificate issuing authority sends the device identity certificate of the first device to the first device.
[0097] Figure 6 gives an example of the format of the identity certificate of the first device. As Figure 6 shown, the device identity certificate of the first device may include at least one of the following information: device certificate serial number, identity identifier of the first device, identity identifier of the first entity, identity public key of the first device, device attributes of the first device, private key signature of the second certificate issuing authority, timestamp.
[0098] By adding the identity identifier of the first entity to the identity certificate of the first device, the first entity and the first device can be bound. The first entity and the first device can prove the trustworthiness of each other, further enhancing the credibility of the entity.
[0099] In some embodiments, when the first entity sends an identity registration message of the first entity to the first certificate issuing authority, it may first send an identity registration message of the first device to the second certificate issuing authority to obtain the identity certificate of the first device.
[0100] The identity certificate of the first device and / or the identity certificate of the first entity may be obtained through an identity proxy. The identity credential of the first entity may be obtained through an identity proxy or generated by the identity proxy.
[0101] The identity proxy may assist the first entity and / or the first device in communicating with the certificate issuing authority (such as the first certificate issuing authority and / or the second certificate issuing authority) to manage the information (such as the identity certificate) of the first entity and / or the first device.
[0102] By adding an identity proxy to manage the identity certificates and credentials of the first entity and / or the first device, it is possible to avoid modifying the software structure or functions of the entity (such as an application). The first entity can complete the identity registration mentioned in the embodiments of the present disclosure through the identity proxy, and can even complete the identity authentication mentioned in the embodiments of the present disclosure with the assistance of the identity proxy, thereby simplifying the functions of the first entity.
[0103] For example, the first entity refers to the Alipay client, and the first device refers to the user terminal. An identity proxy module can be configured in the user terminal. When the user logs in to the Alipay client, the identity proxy module obtains the user's login operation and triggers the identity authentication process provided by the embodiments of the present disclosure according to this operation. The server of Alipay confirms the legitimacy of the Alipay client based on the identity certificate and identity credentials of the Alipay client provided by the identity proxy module.
[0104] In some embodiments, the first entity is communicatively connected to the identity proxy (such as an identity proxy module installed on the first device), and the identity proxy can perform at least one of the following operations: sending an identity registration message of the first entity to the first certificate authority to obtain an identity certificate of the first entity; sending an identity registration message of the first device to the second certificate authority to obtain an identity certificate of the first device; generating an identity credential of the first entity.
[0105] When the first entity applies to communicate with the second device, the identity proxy can directly complete the authentication-related work. For example, when the identity proxy receives a message for applying to communicate sent by the first entity to the second device, it actively applies for an identity credential of the first entity for the first entity. The first entity does not need to perceive the specific operations of identity authentication, meeting the user's requirements for a simple and reliable communication process.
[0106] The following takes Figure 7 as an example to specifically introduce the identity authentication method of the present disclosure. Figure 7 The platform and the device in Figure 7 can be understood to have the same meaning. For example, the entity platform refers to the device on which the entity runs. Refer to
[0107] As Figure 7 shown, in step S7002, the entity registers with the identity proxy. The entity can refer to the first entity or the first device.
[0108] In this embodiment, to obtain the identity certificate of the first entity, it is necessary to first obtain the identity certificate of the first device from the second certificate authority 750, and then carry the identity information of the first entity, the information hash value of the first device (for example, the hash value obtained by hashing the attribute information of the first device), and the identity certificate of the first device. Then, go to the first certificate authority 740 to obtain the identity credential (certificate or token) and key associated with the identity of the first device and the first entity.
[0109] Therefore, in this embodiment, before the first entity is registered, in step S7002, the first device registers with the identity proxy 720.
[0110] In step S7004, the identity proxy 720 registers the first device with the second certificate authority 750.
[0111] In step S7006, the second certificate authority 750 grants the identity certificate of the first device to the identity proxy 720. The second certificate authority 750 also stores the key and identity certificate of the first device in the key pool 760.
[0112] The key of the first device (such as a public-private key pair) can be generated by trusted hardware (such as a trusted chip) on the first device. The private key of the first device can be stored in the trusted hardware to ensure that the private key cannot be obtained by the outside world and improve data security.
[0113] The identity certificate of the first device may include: the serial number of the first device certificate, the identity identifier of the first device, the identity identifier of the first entity, the identity public key of the first device, the attributes of the first device, the private key signature of the second certificate authority 750, and the timestamp.
[0114] In step S7008, the identity proxy 720 forwards the identity certificate of the first device to the first device.
[0115] After completing the registration of the first device, the identity proxy continues to execute the following steps to obtain the identity certificate of the first entity.
[0116] In step S7002, the first entity registers with the identity proxy 720.
[0117] In step S7010, the identity proxy 720 registers the first entity with the first certificate authority 740.
[0118] In step S7012, the first certificate authority 740 grants the identity certificate of the first entity to the identity proxy 720. The first certificate authority 740 also stores the key and identity certificate of the first entity in the entity key and entity identity certificate library 770.
[0119] The key of the first entity (e.g., a public-private key pair) can be generated by trusted hardware (e.g., a trusted chip) on the first device. The private key of the first entity can be stored in the trusted hardware to ensure that the private key cannot be obtained by the outside world and improve data security.
[0120] The identity certificate of the first entity may include: the serial number of the first entity certificate, the identity identifier of the first device, the identity identifier of the first entity, the public key of the first entity's identity, the environmental attributes of the first entity, the private key signature of the first certificate authority 740, and a timestamp.
[0121] In step S7014, the identity proxy 720 forwards the identity certificate of the first entity to the first entity.
[0122] As described above in conjunction with Figures 1 to 7 , the method embodiments of the present application have been described in detail. Below, in conjunction with Figures 8 to 11 , the apparatus embodiments of the present application will be described in detail. It should be understood that the descriptions of the method embodiments and the apparatus embodiments correspond to each other. Therefore, for the parts not described in detail, reference can be made to the previous method embodiments.
[0123] Figure 8 FIG. is a schematic structural diagram of an identity authentication apparatus provided by an embodiment of the present application. Figure 8 The identity authentication apparatus 800 shown can be applied to the first device mentioned above. The first entity runs on the first device. The apparatus 800 may include a sending module 810 and a communication module 820.
[0124] The sending module 810 can be used to send the identity credential of the first entity to the second device, and the identity credential includes the current environmental attributes of the first entity, and the current environmental attributes are used for the second device to verify the environmental legality of the first entity.
[0125] The communication module 820 can be used to communicate with the second device through the first entity after the verification of the identity credential by the second device passes.
[0126] Figure 9 FIG. is a schematic structural diagram of an identity authentication apparatus provided by an embodiment of the present application. Figure 9 The identity authentication apparatus 900 shown can be applied to the second device mentioned above. The apparatus 900 may include a receiving module 910, a verification module 920, and a communication module 930.
[0127] The receiving module 910 can be used to receive the identity credential of the first entity running on the first device from the first device, and the identity credential includes the current environmental attributes of the first entity.
[0128] The verification module 920 can be used to verify the identity credentials, and the verification of the identity credentials includes verifying the environmental legality of the first entity based on the current environmental attributes.
[0129] The communication module 930 can be used to communicate with the first entity if the verification of the identity credentials passes.
[0130] Figure 10 It is a schematic structural diagram of an identity authentication device provided by an embodiment of the present application. Figure 10 The illustrated identity authentication device 1000 can be applied to a first certificate authority. The device 1000 may include a receiving module 1010 and a sending module 1020.
[0131] The receiving module 1010 can be used to receive an identity registration message of a first entity running on the first device from the first device, and the identity registration message of the first entity includes the environmental attributes of the first entity.
[0132] The sending module 1020 can be used to send an identity certificate of the first entity to the first device, and the identity certificate of the first entity includes the environmental attributes of the first entity.
[0133] Figure 11 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The device 1100 can be, for example, any one of the aforementioned first device, second device, or first certificate authority. The device 1100 may include a memory 1110 and a processor 1120. The memory 1110 can be used to store executable code. The processor 1120 can be used to execute the executable code stored in the memory 1110 to implement the steps in the various methods described above. In some embodiments, the device 1100 may further include a network interface 1130, and the data exchange between the processor 1120 and external devices can be implemented through this network interface 1130.
[0134] It should be understood that in various embodiments of the present disclosure, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present disclosure.
[0135] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present disclosure are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a Digital Video Disc (DVD)), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.
[0136] Those of ordinary skill in the art will realize that the units and algorithm steps of each example described in combination with the embodiments of the present disclosure can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.
[0137] In several embodiments provided by the present disclosure, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in an electrical, mechanical, or other form.
[0138] The unit described as a separating component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0139] In addition, in each embodiment of the present disclosure, each functional unit may be integrated into one processing unit, may exist separately as individual physical units, or two or more units may be integrated into one unit.
[0140] As described above, only the specific embodiments of the present disclosure are provided, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present disclosure can easily think of changes or substitutions, which should be covered by the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. An identity authentication method, which is applied to a first device on which a first entity runs, and the method includes: Sending an identity credential of the first entity to a second device, where the identity credential includes the current environmental attributes of the first entity, and the current environmental attributes are used by the second device to verify the environmental legality of the first entity; after the verification of the identity credential by the second device passes, communicating between the first entity and the second device; Wherein, the identity credential of the first entity includes a private key signature of the identity private key of the first entity, and the current environmental attributes are included in the private key signature, and the method further includes: Sending an identity certificate of the first entity to the second device, where the identity certificate of the first entity includes the identity public key of the first entity and the environmental attributes of the first entity, so that the second device can obtain the current environmental attributes from the private key signature based on the identity public key of the first entity, and verify the environmental legality of the first entity by comparing the current environmental attributes with the environmental attributes in the identity certificate of the first entity.
2. The method according to claim 1, where the identity certificate of the first entity further includes the identity identifier of the first entity and the identity identifier of the first device, the identity identifier of the first entity is used by the second device to verify the identity legality of the first entity, and the identity identifier of the first device is used by the second device to verify the identity legality of the first device.
3. The method according to claim 2, before sending the identity credential of the first entity to the second device, the method further includes: Sending an identity registration message of the first entity to a first certificate issuing authority, where the identity registration message of the first entity includes the identity identifier of the first device, the identity identifier of the first entity, and the environmental attributes of the first entity; Receiving the identity certificate of the first entity from the first certificate issuing authority.
4. The method according to claim 3, the identity certificate of the first entity further includes at least one of the following information: the serial number of the identity certificate of the first entity, the identity identifier of the first entity, the identity identifier of the first device, the identity public key of the first entity, the private key signature of the first certificate issuing authority, and the timestamp.
5. The method according to claim 3, the identity registration message of the first entity further includes the identity certificate of the first device, Before sending the identity registration message of the first entity to the first certificate issuing authority, the method further includes: Sending an identity registration message of the first device to a second certificate issuing authority, where the identity registration message of the first device includes the identity identifier of the first device and the identity identifier of the first entity; Receiving the identity certificate of the first device from the second certificate issuing authority, where the identity certificate of the first device includes the identity identifier of the first device and the identity identifier of the first entity.
6. The method according to claim 5, wherein the identity certificate of the first device further includes at least one of the following information: the serial number of the identity certificate of the first device, the device attributes of the first device, the private key signature of the second certificate issuing authority, the identity public key of the first device, and a timestamp.
7. The method according to claim 1, wherein an identity proxy module is installed on the first device, and the first entity is communicatively connected to the identity proxy module to trigger the identity proxy module to perform at least one of the following operations: Sending an identity registration message of the first entity to a first certificate issuing authority to obtain an identity certificate of the first entity; Sending an identity registration message of the first device to a second certificate issuing authority to obtain an identity certificate of the first device; Generating an identity credential of the first entity.
8. The method according to claim 1, wherein the first device includes a trusted hardware module, and the identity private key of the first device and / or the identity private key of the first entity are stored in the trusted hardware module.
9. The method according to claim 1, wherein the current environmental attributes of the first entity include: The current device attributes of the first device and / or the current operating environment attributes of the first entity.
10. An identity authentication method, which is applied to a second device, and the method includes: Receiving, from a first device, an identity credential of a first entity running on the first device, where the identity credential includes the current environment attributes of the first entity; Verifying the identity credential, where the verification of the identity credential includes verifying the environmental legality of the first entity based on the current environment attributes; if the verification of the identity credential passes, communicating with the first entity; wherein the identity credential of the first entity includes a private key signature of the identity private key of the first entity, and the current environment attributes are included in the private key signature, The verifying of the identity credential includes: Receiving, from the first device, an identity certificate of the first entity, where the identity certificate of the first entity includes the identity public key of the first entity and the environmental attributes of the first entity; Decrypting the private key signature by using the identity public key of the first entity to obtain the current environment attributes; If the current environment attributes match the environmental attributes in the identity certificate of the first entity, determining that the environment of the first entity is legal.
11. The method according to claim 10, wherein the identity certificate of the first entity further includes the identity identifier of the first entity and the identity identifier of the first device, The verifying of the identity credential includes: Verifying the identity legality of the first entity according to the identity identifier of the first entity; Verifying the identity legality of the first device according to the identity identifier of the first device.
12. The method according to claim 11, wherein the identity certificate of the first entity is issued by a first certificate issuing authority, and the identity certificate of the first entity further includes at least one of the following information: the serial number of the identity certificate of the first entity, the private key signature of the first certificate issuing authority, and the identity public key of the first entity.
13. According to the method described in claim 10, the current environmental attributes of the first entity include: The current device attributes of the first device and / or the current operating environment attributes of the first entity.
14. An identity authentication method, which is applied to a first certificate authority, and the method includes: Receiving, from a first device, an identity registration message of a first entity running on the first device, where the identity registration message of the first entity includes the environmental attributes of the first entity; Sending an identity certificate of the first entity to the first device, where the identity certificate of the first entity includes the environmental attributes of the first entity and the identity public key of the first entity. The identity public key of the first entity is used for a second device to obtain the current environmental attributes of the first entity from the identity credentials of the first entity. The identity credentials of the first entity include the private key signature of the identity private key of the first entity, and the current environmental attributes are included in the private key signature. The current environmental attributes are used to compare with the environmental attributes in the identity certificate of the first entity to verify the environmental legality of the first entity.
15. The method according to claim 14, where the identity certificate of the first entity further includes at least one of the following information: the serial number of the identity certificate of the first entity, the identity identifier of the first entity, the identity identifier of the first device, the private key signature of the first certificate authority, and the timestamp.
16. The method according to claim 14, where the identity registration message of the first entity further includes the identity certificate of the first device.
17. The method according to claim 16, where the identity certificate of the first device includes the identity identifier of the first device and the identity identifier of the first entity.
18. The method according to claim 17, where the identity certificate of the first device further includes at least one of the following information: the serial number of the identity certificate of the first device, the device attributes of the first device, the private key signature of the second certificate authority, the identity public key of the first device, and the timestamp.
19. The method according to claim 14, where an identity proxy module is installed on the first device, the first entity is communicatively connected to the identity proxy module, and the identity registration message of the first entity is sent by the identity proxy module to the first certificate authority.
20. An identity authentication device, which is applied to a first device, and a first entity runs on the first device. The device includes: A sending module, configured to send the identity credentials of the first entity to a second device, where the identity credentials include the current environmental attributes of the first entity, and the current environmental attributes are used for the second device to verify the environmental legality of the first entity; A communication module, configured to communicate with the second device through the first entity after the verification of the identity credentials by the second device is passed; Wherein, the identity credentials of the first entity include the private key signature of the identity private key of the first entity, the current environmental attributes are included in the private key signature, and the sending module is further configured to: Send the identity certificate of the first entity to the second device. The identity certificate of the first entity includes the identity public key of the first entity and the environmental attributes of the first entity, so that the second device can obtain the current environmental attributes from the private key signature based on the identity public key of the first entity, and verify the environmental legality of the first entity by comparing the current environmental attributes with the environmental attributes in the identity certificate of the first entity.
21. An identity authentication device, which is applied to a second device. The device includes: A receiving module, configured to receive the identity credential of a first entity running on a first device from the first device. The identity credential includes the current environmental attributes of the first entity. A verification module, configured to verify the identity credential. The verification of the identity credential includes verifying the environmental legality of the first entity based on the current environmental attributes. A communication module, configured to communicate with the first entity if the verification of the identity credential passes. Wherein, the identity credential of the first entity includes the private key signature of the identity private key of the first entity, and the current environmental attributes are included in the private key signature. The receiving module is further configured to receive the identity certificate of the first entity from the first device. The identity certificate of the first entity includes the identity public key of the first entity and the environmental attributes of the first entity. The verification module is specifically configured to decrypt the private key signature by using the identity public key of the first entity to obtain the current environmental attributes. If the current environmental attributes match the environmental attributes in the identity certificate of the first entity, determine that the environment of the first entity is legal.
22. An identity authentication device, which is applied to a first certificate authority. The device includes: A receiving module, configured to receive the identity registration message of a first entity running on a first device from the first device. The identity registration message of the first entity includes the environmental attributes of the first entity. A sending module, configured to send the identity certificate of the first entity to the first device. The identity certificate of the first entity includes the environmental attributes of the first entity and the identity public key of the first entity. The identity public key of the first entity is used for the second device to obtain the current environmental attributes of the first entity from the identity credential of the first entity. The identity credential of the first entity includes the private key signature of the identity private key of the first entity and the current environmental attributes are included in the private key signature. The current environmental attributes are used to compare with the environmental attributes in the identity certificate of the first entity to verify the environmental legality of the first entity.
23. An electronic device, including a memory and a processor. An executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method according to any one of claims 1-9.
24. An electronic device, comprising a memory and a processor, wherein executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method according to any one of claims 10-13.
25. An electronic device, comprising a memory and a processor, wherein executable code is stored in the memory, and the processor is configured to execute the executable code to implement the method according to any one of claims 14-19.
Citation Information
Patent Citations
Method and device for downloading identity certificate of mobile phone shield equipment, and electronic equipment
CN112073967A