Quantum key based portable secure authentication system, method and components
By introducing quantum key technology into portable secure authentication systems to generate and encrypt identity authentication information, the security deficiencies of portable secure authentication systems are solved, achieving higher security and reliability.
Patent Information
- Application Number
- CN202111381718.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-22
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2041-11-22
AI Technical Summary
Existing security authentication systems have insufficient security for portable use, especially classic encryption methods which are easily eavesdropped on and cracked.
A portable security authentication system based on quantum keys is adopted. By storing shared quantum keys and user authentication keys on the mobile terminal and the server, quantum key technology is used to generate and encrypt identity authentication information, thereby enhancing the security of the authentication process.
This improves the security of portable security authentication systems, avoids security risks caused by complex application environments, and ensures the reliability and security of identity authentication.
Smart Images

Figure CN114139136B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure communication, and more particularly to a portable secure authentication system and method based on quantum key distribution, as well as a mobile terminal, client, and server for the secure authentication system. Background Technology
[0002] In existing security authentication systems, physical authentication devices such as USB tokens are generally required. Only after using a USB token for authentication can one securely log in to the business system.
[0003] To enhance the portability of identity authentication devices such as USB tokens, existing technologies also propose embedding USB tokens or similar authentication devices into mobile phones for authentication of the phone's own services, or using mobile phones with built-in security authentication modules as USB tokens to provide security authentication services for other devices such as PCs. Figure 1 As shown.
[0004] Figure 2 This paper illustrates a prior art system integrating multiple security authentication methods. It proposes setting up a PKI (Public Key Infrastructure) module in a smart terminal to receive random information sent by a user whose security verification has been successful. The module retrieves the user's matching private key, performs a digital signature on the message, and sends the signed random information to a server. The server then uses the public key to verify the digital signature, thereby achieving secure verification of the user's identity.
[0005] Figure 3 This paper presents a security authentication device and method in the prior art, which proposes to set up a banking security token or USB security token in a mobile terminal such as a mobile phone, and provide security authentication for it by communicating with a computer through data communication, thereby overcoming the disadvantage of needing to carry an additional security authentication tool.
[0006] Figure 4 This invention illustrates a mobile terminal in the prior art that has an embedded USB key, thereby overcoming the disadvantage of needing to carry an additional security authentication tool, while also providing security for payment transactions made on the mobile terminal.
[0007] However, with the rapid development of computer technology, the identity authentication process implemented using classic encryption is at risk of being eavesdropped on and cracked, and the security of existing security authentication systems still needs to be improved. Summary of the Invention
[0008] To address the aforementioned problems in existing technologies, this invention proposes a portable secure authentication system and method based on quantum key distribution, as well as a mobile terminal, client, and server for implementing the secure authentication system. By introducing quantum key distribution technology into the portable secure authentication system, the portability of the system is ensured while the security of the authentication process is enhanced, thereby avoiding the security risks caused by the complexity of the application environment during portable use.
[0009] Specifically, the first aspect of the present invention relates to a portable security authentication system based on quantum keys, which includes a client, a mobile terminal, and a server.
[0010] The client is configured to submit a security authentication request to the server to obtain authentication data, and to return identity authentication information or encrypted identity authentication information to the server to obtain authentication results, wherein the authentication data includes authentication method and authentication information;
[0011] The mobile terminal and the server store a shared quantum key and a user authentication key. The mobile terminal is configured to obtain the authentication data from the client, generate the identity authentication information or encrypted identity authentication information based on the authentication data, the shared quantum key and the user authentication key, and return it to the client.
[0012] The server is configured to issue the authentication data according to the security authentication application, and to authenticate the identity authentication information provided by the client based on the authentication data, the shared quantum key and the user authentication key, and to return the authentication result to the client.
[0013] Furthermore, the mobile terminal is configured to authenticate the operator, and after successful authentication, use the user authentication key and / or shared quantum key to generate the identity authentication information or encrypted identity authentication information. Optionally, the mobile terminal may be configured to implement the operator authentication through one or more of the following methods: password input, fingerprint recognition, facial recognition, voice recognition, and iris recognition.
[0014] Furthermore, the mobile terminal is configured to: generate identity authentication information using the shared quantum key, the user authentication key, and authentication information; or, generate first identity authentication information using the shared quantum key and authentication information, and generate second identity authentication information using the user authentication key and authentication information; or, generate identity authentication information using the user authentication key and authentication information, and encrypt the identity authentication information using the shared quantum key.
[0015] Furthermore, the server-side includes a quantum security service platform and an authentication function module;
[0016] The quantum security service platform is configured to obtain the authentication data from the authentication function module, generate identity authentication information using the shared quantum key, user authentication key and authentication information, or generate identity authentication information using the shared quantum key and user authentication key and authentication information respectively, or generate identity authentication information using the user authentication key and authentication information and decrypt the encrypted identity authentication information returned by the client using the shared quantum key, and return it to the authentication function module.
[0017] The authentication function module is configured to perform identity authentication based on the identity authentication information returned by the quantum security service platform and the identity authentication information provided by the client.
[0018] Preferably, the mobile terminal and the client establish a communication channel via a wired or wireless near-end connection; and / or, the authentication method includes a digital signature algorithm or an identity authentication code algorithm, and the authentication information includes a random number; and / or, the server is configured to send the shared quantum key to the mobile terminal in an encrypted manner according to the mobile terminal's quantum key request; and / or, the shared quantum key is used in a one-to-one manner; and / or, the mobile terminal has a security module for storing the shared quantum key and the user authentication key, as well as generating and / or encrypting / decrypting the identity authentication information.
[0019] The second aspect of the present invention relates to a quantum key-based secure authentication method, which includes a secure authentication service initiation step, a quantum key acquisition step, an identity authentication information generation step, and a secure authentication step.
[0020] In the security authentication service initiation step, the client submits a security authentication request to the server, and the server sends authentication data to the client. The authentication data includes authentication method and authentication information.
[0021] In the quantum key acquisition step, the mobile terminal submits a quantum key request to the server, and the server responds to the quantum key request by sending a shared quantum key to the mobile terminal.
[0022] In the identity authentication information generation step, the mobile terminal obtains the authentication data from the client, generates identity authentication information or encrypted identity authentication information based on the shared quantum key, user authentication key and authentication data, and returns it to the client;
[0023] In the security authentication step, the server performs identity authentication based on the identity authentication information returned by the client or encrypted identity authentication information, and then returns the authentication result.
[0024] Preferably, the identity authentication information generation step further includes a step of authenticating the operator of the mobile terminal.
[0025] Furthermore, in the identity authentication information generation step, identity authentication information is generated using the shared quantum key, the user authentication key, and authentication information; or, first identity authentication information is generated using the shared quantum key and authentication information, and second identity authentication information is generated using the user authentication key and authentication information; or, identity authentication information is generated using the user authentication key and authentication information, and the identity authentication information is encrypted using the shared quantum key.
[0026] Furthermore, in the security authentication step, the server generates authentication information using the shared quantum key, user authentication key, and authentication information, or generates authentication information using the shared quantum key, user authentication key, and authentication information respectively, and compares and authenticates it with the authentication information returned by the client; or, the server generates authentication information using the user authentication key and authentication information, and decrypts the encrypted authentication information returned by the client using the shared quantum key, so as to perform comparison and authentication.
[0027] Optionally, data communication between the mobile terminal and the client can be achieved using a wired or wireless near-end connection; and / or, the authentication method includes a digital signature algorithm or an identity authentication code algorithm, and the authentication information includes a random number; and / or, in the identity authentication information generation step, the shared quantum key is used in a one-to-one manner; and / or, the user authentication can be achieved using one or more of the following: password input, fingerprint recognition, facial recognition, voice recognition, and iris recognition; and / or, the service provider authenticates the mobile terminal and issues the user authentication key.
[0028] A third aspect of the invention relates to a mobile terminal in a portable security authentication system based on quantum keys, which stores a shared quantum key and a user authentication key with a server, and is configured to obtain authentication data from a client, generate identity authentication information or encrypted identity authentication information based on the authentication data, the shared quantum key, and the user authentication key, and return it to the client; wherein,
[0029] The authentication data is sent from the server to the client based on the security authentication request submitted by the client, and includes the authentication method and authentication information.
[0030] Furthermore, the mobile terminal according to the present invention can also be configured to perform user authentication on the operator, and after the user authentication is passed, use the user authentication key and / or shared quantum key to generate the identity authentication information or encrypted identity authentication information.
[0031] Optionally, the user authentication can be achieved by entering a password, fingerprint recognition, facial recognition, voice recognition, iris recognition, or one or more of these methods.
[0032] Furthermore, the mobile terminal according to the present invention can also be configured to: generate identity authentication information using the shared quantum key, the user authentication key, and authentication information; or, generate first identity authentication information using the shared quantum key and authentication information, and generate second identity authentication information using the user authentication key and authentication information; or, generate identity authentication information using the user authentication key and authentication information, and encrypt the identity authentication information using the shared quantum key; and / or,
[0033] The mobile terminal and the client communicate via a wired or wireless near-end connection; and / or,
[0034] The authentication method includes a digital signature algorithm or an identity verification code algorithm, and the authentication information includes a random number; and / or,
[0035] The shared quantum key is used in a one-to-one manner; and / or,
[0036] The mobile terminal has a security module for storing the shared quantum key and user authentication key, as well as generating and / or encrypting / decrypting the identity authentication information.
[0037] A fourth aspect of the invention relates to a client for a portable secure authentication system based on quantum key distribution, which establishes a near-end connection with a mobile terminal via wired or wireless means for data communication; wherein,
[0038] The client is configured to submit a security authentication request to the server to obtain authentication data, send the authentication data to the mobile terminal and receive identity authentication information or encrypted identity authentication information from the mobile terminal, and return the identity authentication information or encrypted identity authentication information to the server to obtain the authentication result.
[0039] The authentication data includes authentication methods and authentication information;
[0040] The identity authentication information or encrypted identity authentication information is generated by the mobile terminal based on the authentication data, the shared quantum key, and the user authentication key.
[0041] Preferably, the authentication method includes a digital signature algorithm or an identity authentication code algorithm, and the authentication information includes a random number; and / or, the shared quantum key is used in a one-to-one manner.
[0042] The fifth aspect of the invention relates to a server for a portable secure authentication system based on quantum keys, which stores a shared quantum key and a user authentication key with a mobile terminal, and is configured to:
[0043] Based on the security authentication request submitted by the client, authentication data is sent to the client.
[0044] Based on the authentication data, the shared quantum key, and the user authentication key, an authentication result is generated according to the identity authentication information returned by the client or encrypted identity authentication information, and the authentication result is fed back to the client; wherein...
[0045] The authentication data includes authentication methods and authentication information;
[0046] The identity authentication information or encrypted identity authentication information is generated by the mobile terminal connected to the client in the near end, based on the authentication data, the shared quantum key and the user authentication key, and then returned to the client.
[0047] Furthermore, the server-side component according to the present invention may include a quantum security service platform and an authentication function module;
[0048] The quantum security service platform is configured to obtain the authentication data from the authentication function module, generate identity authentication information using the shared quantum key, user authentication key and authentication information, or generate identity authentication information using the shared quantum key and user authentication key and authentication information respectively, or generate identity authentication information using the user authentication key and authentication information and decrypt the encrypted identity authentication information returned by the client using the shared quantum key, and return it to the authentication function module.
[0049] The authentication function module is configured to perform identity authentication based on the identity authentication information returned by the quantum security service platform and the identity authentication information provided by the client.
[0050] Preferably, the authentication method includes a digital signature algorithm or an identity authentication code algorithm, and the authentication information includes a random number; and / or, the server is configured to send the shared quantum key to the mobile terminal in an encrypted manner according to the quantum key request of the mobile terminal; and / or, the shared quantum key is used in a one-to-one manner. Attached Figure Description
[0051] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0052] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0053] Figure 1 This illustrates a current technology for mobile phone-based identity security authentication.
[0054] Figure 2 This illustrates a prior art system that integrates multiple security authentications;
[0055] Figure 3 This illustrates a security authentication device and method in the prior art;
[0056] Figure 4 This illustrates a mobile terminal with an embedded USB security token in the prior art;
[0057] Figure 5 A portable secure authentication system and method based on quantum key distribution according to the present invention are shown, as well as a mobile terminal, client, and server for the secure authentication system. Detailed Implementation
[0058] In the following description, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example in order to fully convey the spirit of the invention to those skilled in the art. Therefore, the invention is not limited to the embodiments disclosed herein.
[0059] Figure 5 A portable secure authentication system and method based on quantum key distribution according to the present invention is shown, as well as a mobile terminal, client, and server for the secure authentication system.
[0060] like Figure 5 As shown, a portable security authentication system based on quantum keys can include a client, a mobile terminal, and a server.
[0061] The client can be in the form of a PC, laptop, etc., and is used to submit a security authentication request to the server to initiate the security authentication process, and to submit identity authentication information to the server to obtain the authentication result.
[0062] Authentication data can include authentication methods (authentication algorithms) and authentication information.
[0063] As an example, authentication methods may include digital signature algorithms or identity verification code algorithms, and the authentication information may include random numbers.
[0064] Mobile terminals can establish a communication channel with clients via near-end connections, enabling them to obtain authentication data from clients, generate identity authentication information based on the authentication data, and return the identity authentication information to clients.
[0065] The mobile terminal can be a mobile phone (e.g.) Figure 5 The quantum-safe mobile phone (as shown) or tablet computer, etc.
[0066] Near-end connectivity can be wired or wireless, such as via USB, Bluetooth, WiFi, or infrared.
[0067] The mobile terminal stores the user authentication key, which is used to generate identity authentication information.
[0068] As an example, a mobile terminal may have a security module that requires approval from a service provider (such as a bank), and the service provider writes the user authentication key into it. For example, the security module of a mobile terminal may include at least one of a secure SIM card, a secure TF card, and an eSE security chip.
[0069] In the security authentication system of the present invention, a shared quantum key can also be stored in the mobile terminal and the server for the generation and / or protection (i.e. encryption) of identity authentication information.
[0070] As an example, the shared quantum key can be stored separately in the security module of the mobile terminal and in the quantum security service platform on the server.
[0071] In one specific embodiment, the shared quantum key in the mobile terminal can be obtained by the server based on a quantum key request submitted by the mobile terminal. Preferably, the mobile terminal submits the quantum key request when conducting the security authentication service, and the shared quantum key obtained based on the quantum key request is used only for this security authentication service, achieving the so-called "one key per service" requirement.
[0072] Preferably, the transmission of the shared quantum key between the server and the mobile terminal can be encrypted. For example, the server and the mobile terminal can pre-store a shared encryption key, so that the server can use the shared encryption key to encrypt the shared quantum key to generate encrypted shared quantum key data, which is then sent to the mobile terminal; at the same time, the mobile terminal can use the same shared encryption key to decrypt the encrypted shared quantum key data to obtain the shared quantum key.
[0073] Therefore, in the security module of a mobile terminal, a shared quantum key can be used to generate authentication information and / or encrypted authentication information.
[0074] In one specific embodiment, the security module of the mobile terminal can directly use the shared quantum key to generate identity authentication information. For example, identity authentication information, such as a digital signature or identity authentication code, can be generated based on an authentication method (authentication algorithm) using the shared quantum key, the user authentication key, and authentication information. Alternatively, first identity authentication information can be generated based on an authentication method (authentication algorithm) using the shared quantum key and authentication information, while second identity authentication information can be generated simultaneously using the user authentication key and authentication information.
[0075] In another specific embodiment, the security module of the mobile terminal can use the shared quantum key to generate encrypted identity authentication information, thereby protecting the identity authentication information. For example, based on the authentication method (authentication algorithm), identity authentication information can first be generated using the user authentication key and authentication information, and then the shared quantum key can be used to encrypt the identity authentication information so that it can be uploaded to the server in an encrypted manner.
[0076] Therefore, the high security of quantum keys can effectively improve the security of the authentication process.
[0077] To ensure the secure use of the key, the mobile terminal can also authenticate the operator, and after successful authentication, use the user authentication key and / or shared quantum key corresponding to the operator to generate or encrypt identity authentication information.
[0078] As an example, mobile terminals can authenticate users by entering passwords, fingerprint recognition, facial recognition, voice recognition, iris recognition, etc.
[0079] exist Figure 5 In the specific embodiment shown, the server may include a quantum security service platform, an authentication function module, and a business function module.
[0080] The quantum security service platform is used to issue shared quantum keys according to quantum key requests and to generate identity authentication information based on authentication data.
[0081] The authentication module is used to authenticate the identity authentication information returned by the client based on the identity authentication information generated by the quantum security service platform, and to provide feedback on the authentication result.
[0082] In one specific embodiment, the quantum security service platform can obtain authentication data from the authentication function module. Based on the negotiated authentication method (authentication algorithm), it generates identity authentication information using a shared quantum key, a user authentication key, and authentication information, or generates identity authentication information using the shared quantum key and the user authentication key and authentication information respectively, and returns this identity authentication information to the authentication function module. The authentication function module compares the identity authentication information generated by the quantum security service platform in the same manner with the identity authentication information returned by the client. If the comparison matches, it reports an authentication result indicating successful authentication; otherwise, it reports an authentication result indicating unsuccessful authentication, thereby completing the security authentication process.
[0083] In another specific embodiment, the quantum security service platform can obtain authentication data from the authentication function module, generate identity authentication information based on the negotiated authentication method (authentication algorithm) using the user authentication key and authentication information, and return it to the authentication function module. At the same time, it can use the shared quantum key to decrypt the encrypted identity authentication information returned by the client and return it to the authentication function module so that the authentication function module can perform comparison and authentication.
[0084] Furthermore, the client can also perform security authentication on the server, thereby achieving two-way security authentication.
[0085] The business function module is used to conduct two-way business communication directly with the client after two-way security authentication is passed.
[0086] Therefore, in the security authentication system of the present invention, a quantum security service platform can be set up on the server side to distribute a shared quantum key to the mobile terminal in the security authentication service. This enables the mobile terminal to use the quantum key to generate and protect the identity authentication information when generating identity authentication information based on the authentication data obtained from the client in security modules such as U-shields. Thus, the high security of the quantum key ensures the security of the identity authentication information, thereby ensuring the security and reliability of the security authentication service.
[0087] To further understand the working principle of this invention, please refer to the following sections. Figure 5 The security authentication method according to the present invention is described.
[0088] The security authentication method of the present invention may include a security authentication service initiation step, a quantum key acquisition step, an identity authentication information generation step, and a security authentication step.
[0089] In the security authentication process, the client can submit a security authentication request to the server (e.g., Figure 5 In ), and the server sends authentication data to the client (e.g. Figure 5 In ).
[0090] In the quantum key acquisition step, the mobile terminal can submit a quantum key request to the server (e.g., Figure 5 (1) in the middle), and the server responds to the quantum key request by sending a shared quantum key (e.g., in response to the quantum key request) to the mobile terminal. Figure 5 (2)). Therefore, the shared quantum key will be stored in the quantum security service platform on the server and the security module of the mobile terminal, respectively.
[0091] Preferably, the shared quantum key is distributed to the mobile terminal in an encrypted manner. In one specific embodiment, the server (quantum security service platform) and the mobile terminal (security module) can pre-store a shared encryption key, so that the server can use the shared encryption key to encrypt the shared quantum key to generate encrypted shared quantum key data, and then distribute it to the mobile terminal; the mobile terminal can then use the shared encryption key to decrypt the encrypted shared quantum key data, thereby obtaining the shared quantum key, thus realizing the distribution process of the shared quantum key.
[0092] In the identity authentication information generation step, the mobile terminal can obtain authentication data from the client (e.g., Figure 5 In Based on the shared quantum key, user authentication key, and authentication data, it generates authentication information or encrypted authentication information and returns it to the client (e.g., Figure 5 In ).
[0093] In this invention, the communication channel between the mobile terminal and the client can be implemented by means of wired or wireless near-end connection, such as USB, Bluetooth, WiFi or infrared.
[0094] In one specific embodiment, the mobile terminal can directly use the shared quantum key to generate identity authentication information, wherein: identity authentication information can be generated according to the authentication algorithm using the shared quantum key, the user authentication key, and the authentication information; or, first identity authentication information can be generated according to the authentication algorithm using the shared quantum key and the authentication information, and second identity authentication information can also be generated according to the authentication algorithm using the user authentication key and the authentication information.
[0095] In another specific embodiment, the mobile terminal can use the shared quantum key to protect identity authentication information. For example, the mobile terminal can generate identity authentication information using the user authentication key and authentication information according to the authentication algorithm, and then encrypt the identity authentication information using the shared quantum key.
[0096] Preferably, the shared quantum key is used only for this security authentication process.
[0097] Preferably, the identity authentication information generation step may further include a step of authenticating the operator of the mobile terminal to ensure the secure use of the user authentication key and / or shared quantum key. For example, user authentication can be achieved through methods such as password input, fingerprint recognition, facial recognition, voice recognition, iris recognition, etc., and after successful user authentication, the corresponding user authentication key and / or shared quantum key can be used for the generation and protection of identity authentication information.
[0098] During the security authentication process, the client can upload authentication information to the server (e.g., ...). Figure 5 In The server authenticates the identity information and sends the authentication result back to the client (e.g., Figure 5 In ).
[0099] In one specific embodiment, the server can generate identity authentication information using the shared quantum key, the user authentication key, and authentication information, or generate identity authentication information using the shared quantum key and the user authentication key and authentication information respectively. The server then compares the generated identity authentication information with the identity authentication information provided by the client. If the comparison matches, the server will return an authentication result indicating that the identity authentication has passed; otherwise, the server will return an authentication result indicating that the identity authentication has failed, thereby completing the security authentication process.
[0100] For example, the quantum security service platform can obtain authentication data from the authentication function module (e.g., Figure 5 In (3) of the above, identity authentication information is generated using the shared quantum key, user authentication key, and authentication information, or identity authentication information is generated using the shared quantum key, user authentication key, and authentication information respectively, and the identity authentication information is returned to the authentication function module (e.g., Figure 5 (4)). Subsequently, the authentication module can compare the identity authentication information generated by the quantum security service platform with the identity authentication information provided by the client, and if the comparison is consistent, it will return the authentication result of successful identity authentication; otherwise, it will return the authentication result of unsuccessful identity authentication, thereby completing this security authentication business.
[0101] In another specific embodiment, the server can also use the user authentication key and authentication information to generate identity authentication information, and at the same time decrypt the encrypted identity authentication information returned by the client in order to compare and return the authentication result.
[0102] For example, the quantum security service platform can obtain authentication data from the authentication function module, generate identity authentication information based on the negotiated authentication method (authentication algorithm) using the user authentication key and authentication information, and return it to the authentication function module. At the same time, it can use the shared quantum key to decrypt the encrypted identity authentication information returned by the client and return it to the authentication function module for comparison and authentication.
[0103] Furthermore, the security authentication method of the present invention may also include a step of performing security authentication on the server, so that after completing two-way security authentication, it can directly conduct two-way business communication with the client, for example... Figure 5 In .
[0104] Although the present invention has been described above with reference to the accompanying drawings and specific embodiments, those skilled in the art will readily recognize that the above embodiments are merely exemplary and used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A portable secure authentication system based on quantum key, comprising a client, a mobile terminal and a server; The client is configured to apply for security authentication to the server to obtain authentication data, and return identity authentication information or encrypted identity authentication information to the server to obtain an authentication result, wherein the authentication data comprises an authentication mode and authentication information; the mobile terminal and the server store a shared quantum key and a user authentication key, and the mobile terminal is configured to obtain the authentication data from the client, generate the identity authentication information or encrypted identity authentication information based on the authentication data, the shared quantum key and the user authentication key, and return to the client; the server is configured to issue the authentication data according to the secure authentication application, and authenticate the identity authentication information provided by the client based on the authentication data, the shared quantum key and the user authentication key, and feed back the authentication result to the client.
2. The portable security authentication system of claim 1, wherein, the mobile terminal is further configured to perform operation user authentication on the operator, and use the user authentication key and / or the shared quantum key to generate the identity authentication information or encrypted identity authentication information after the operation user authentication is passed.
3. The portable security authentication system of claim 2, wherein, the mobile terminal is configured to implement the operation user authentication by inputting one or more of a password, fingerprint recognition, face recognition, voice recognition and iris recognition.
4. The portable security authentication system of claim 1, wherein, the mobile terminal is configured to: generate the identity authentication information by using the shared quantum key, the user authentication key and the authentication information; or, generate a first identity authentication information by using the shared quantum key and the authentication information, and generate a second identity authentication information by using the user authentication key and the authentication information; or, generate the identity authentication information by using the user authentication key and the authentication information, and encrypt the identity authentication information by using the shared quantum key.
5. The portable security authentication system of claim 1, wherein, the server comprises a quantum security service platform and an authentication function module; the quantum security service platform is configured to obtain the authentication data from the authentication function module, generate the identity authentication information by using the shared quantum key, the user authentication key and the authentication information, or generate the identity authentication information by using the shared quantum key and the user authentication key respectively and the authentication information, or generate the identity authentication information by using the user authentication key and the authentication information and decrypt the encrypted identity authentication information returned by the client by using the shared quantum key, and return to the authentication function module; the authentication function module is configured to perform identity authentication based on the identity authentication information returned by the quantum security service platform and the identity authentication information provided by the client. 6.The portable secure authentication system according to any one of claims 1-5, wherein: the mobile terminal and the client realize a communication channel by means of a wired or wireless near-end connection; and / or, the authentication mode comprises a digital signature algorithm or an identity authentication code algorithm, and the authentication information comprises a random number; and / or, the server is configured to issue the shared quantum key to the mobile terminal in an encrypted manner according to a quantum key request of the mobile terminal; and / or, the shared quantum key is used in a one-industry-one-key manner; and / or, The mobile terminal has a security module for storing the shared quantum key and user authentication key, and generating and / or encrypting / decrypting the identity authentication information.
7. A quantum key-based security authentication method, comprising a security authentication service initiation step, a quantum key acquisition step, an identity authentication information generation step, and a security authentication step; In the security authentication service initiation step, a client applies for security authentication to a server, and the server issues authentication data to the client, wherein the authentication data comprises an authentication method and authentication information; In the quantum key acquisition step, a mobile terminal applies for a quantum key to the server, and the server issues a shared quantum key to the mobile terminal in response to the quantum key application; In the identity authentication information generation step, the mobile terminal acquires the authentication data from the client, generates identity authentication information or encrypted identity authentication information based on the shared quantum key, user authentication key and authentication data, and returns the information to the client; In the security authentication step, the server performs identity authentication based on the identity authentication information or encrypted identity authentication information returned by the client, and feeds back the authentication result.
8. The security authentication method of claim 7, wherein, The identity authentication information generation step further comprises a step of performing operation user authentication on the operator of the mobile terminal.
9. The security authentication method of claim 7, wherein, In the identity authentication information generation step, the shared quantum key, user authentication key and authentication information are used to generate identity authentication information; Alternatively, the shared quantum key and authentication information are used to generate first identity authentication information, and the user authentication key and authentication information are used to generate second identity authentication information; Alternatively, the user authentication key and authentication information are used to generate identity authentication information, and the shared quantum key is used to encrypt the identity authentication information.
10. The security authentication method of claim 7, wherein, In the security authentication step, the shared quantum key, user authentication key and authentication information are used to generate identity authentication information in the server, or the shared quantum key and user authentication key and authentication information are respectively used to generate identity authentication information, and the identity authentication information returned by the client is compared for authentication; alternatively, the user authentication key and authentication information are used to generate identity authentication information, and the shared quantum key is used to decrypt the encrypted identity authentication information returned by the client for comparison authentication.
11. The security authentication method of claim 8, wherein: The data communication between the mobile terminal and the client is realized by means of a wired or wireless near-end connection; and / or, The authentication method comprises a digital signature algorithm or an identity authentication code algorithm, and the authentication information comprises a random number; and / or, In the identity authentication information generation step, the shared quantum key is used in a one-industry-one-key manner; and / or, The operation user authentication is realized by means of one or more of input password, fingerprint recognition, face recognition, voice recognition and iris recognition; and / or, The user authentication key is issued by a service provider to the mobile terminal.
12. A mobile terminal for use in the quantum key based portable security authentication system as claimed in any one of claims 1-6, which stores a shared quantum key and a user authentication key with a server, and is configured to obtain authentication data from a client, generate identity authentication information or encrypted identity authentication information based on the authentication data, the shared quantum key and the user authentication key, and return to the client; wherein, the authentication data is issued by the server to the client based on a security authentication application raised by the client, and includes an authentication method and authentication information.
13. The mobile terminal as claimed in claim 12, which is further configured to perform an operational user authentication on an operator, and use the user authentication key and / or the shared quantum key to generate the identity authentication information or encrypted identity authentication information after the operational user authentication is passed.
14. The mobile terminal of claim 13, wherein, the operational user authentication is implemented by one or more of inputting a password, fingerprint recognition, face recognition, voice recognition, and iris recognition.
15. The mobile terminal as claimed in claim 12, wherein: the mobile terminal is configured to generate identity authentication information using the shared quantum key, the user authentication key and the authentication information; or, generate first identity authentication information using the shared quantum key and the authentication information, and generate second identity authentication information using the user authentication key and the authentication information; or, generate identity authentication information using the user authentication key and the authentication information, and encrypt the identity authentication information using the shared quantum key; and / or, the mobile terminal and the client communicate via a wired or wireless near-end connection to form a communication channel; and / or, the authentication method includes a digital signature algorithm or an identity authentication code algorithm, and the authentication information includes a random number; and / or, the shared quantum key is used in a one-key-per-industry manner; and / or, the mobile terminal has a security module for storing the shared quantum key and the user authentication key, and generating and / or encrypting / decrypting the identity authentication information.
16. A client for use in the quantum key based portable security authentication system as claimed in any one of claims 1-6, which forms a near-end connection with a mobile terminal in a wired or wireless manner to communicate data; wherein, the client is configured to raise a security authentication application to a server to obtain authentication data, send the authentication data to the mobile terminal and receive identity authentication information or encrypted identity authentication information from the mobile terminal, and return the identity authentication information or encrypted identity authentication information to the server to obtain an authentication result; the authentication data includes an authentication method and authentication information; the identity authentication information or encrypted identity authentication information is generated by the mobile terminal based on the authentication data, a shared quantum key and a user authentication key.
17. The client as claimed in claim 16, wherein: the authentication method includes a digital signature algorithm or an identity authentication code algorithm, and the authentication information includes a random number; and / or, The shared quantum key is used in a one-industry-one-key manner.
18. A server for a portable security authentication system based on quantum key, which stores a shared quantum key and a user authentication key with a mobile terminal, and is configured to: issue authentication data to a client according to a security authentication application of the client; generate an authentication result according to identity authentication information or encrypted identity authentication information returned by the client based on the authentication data, the shared quantum key and the user authentication key, and feed back the authentication result to the client; wherein the authentication data comprises an authentication method and authentication information; the identity authentication information or the encrypted identity authentication information is generated by the mobile terminal connected to the client in proximity, based on the authentication data, the shared quantum key and the user authentication key, and returned to the client.
19. The server of claim 18, comprising a quantum security service platform and an authentication function module; the quantum security service platform is configured to obtain the authentication data from the authentication function module, generate identity authentication information using the shared quantum key, the user authentication key and authentication information, or generate identity authentication information using the shared quantum key and the user authentication key respectively and authentication information, or generate identity authentication information using the user authentication key and authentication information and decrypt encrypted identity authentication information returned by the client using the shared quantum key, and return to the authentication function module; the authentication function module is configured to perform identity authentication based on identity authentication information returned by the quantum security service platform and identity authentication information provided by the client.
20. The server of claim 18 or 19, wherein: the authentication method comprises a digital signature algorithm or an identity authentication code algorithm, and the authentication information comprises a random number; and / or the server is configured to issue the shared quantum key to the mobile terminal in an encrypted manner according to a quantum key request of the mobile terminal; and / or the shared quantum key is used in a one-industry-one-key manner.
Citation Information
Patent Citations
Mobile phone token identity authentication system and method based on quantum cipher network
CN106712931A
Communication method and system based on quantum Ukey
CN107769913A