Authentication method and system
Through the authentication process between the tax system application platform and the unified identity management platform, Ukey and SM2 signature public and private key pairs are used to encrypt and generate encrypted certificates and signature certificates, the problems of missing identity management and duplicate authentication channels in the tax system are solved, and the user's secure login and security guarantees of the tax information system are realized.
Patent Information
- Application Number
- CN202111675484.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The existing tax management system lacks a nationwide unified network identity management system, and the identity authentication system is not unified, so it is impossible to ensure that each tax account corresponds one by one to the real individual. There are problems such as lack of identity management and repeated construction of authentication channels, which leads to the inability to ensure that users can log in and access the tax system application platform safely.
Through the authentication process between the tax system application platform and the unified identity management platform, Ukey and SM2 signature public and private key pairs are encrypted, encrypted certificates and signature certificates are generated, and identity verification is generated in combination with digital envelope algorithms to generate authentication credentials to ensure the authenticity and security of user identity.
It has achieved a nationwide unified and trustworthy identity authentication, ensuring that users can log in to the tax system application platform safely, and ensuring the security and consistency of the tax information system.
Smart Images

Figure CN114329410B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the fields of identity authentication and cryptography technology, and in particular to an identity authentication method and system. Background Art
[0002] At present, as the users of the tax system include more than hundreds of millions of taxpayers, natural persons, tax officials, etc., strengthening tax network identity management and ensuring the security of tax network space has become an urgent need for the development of tax informatization.
[0003] The existing tax management system has the following problems: First, a nationwide unified network identity management system that is independently managed based on information systems and crosses systems, provinces and cities has not yet been established; second, identity management and mission authentication do not fully cover all tax-related entities, and it is impossible to ensure that each tax account corresponds to a real individual, resulting in serious identity management deficiencies; third, the identity authentication system has not yet been unified, and there are problems with duplicate authentication channels and a single authentication method.
[0004] Therefore, the technical problem of how to provide nationwide unified and trusted identity authentication technology support to ensure users' safe login and access to the tax system application platform and ensure the security of the tax information system needs to be solved. Summary of the Invention
[0005] In view of this, embodiments of the present application provide a method and system to solve some or all of the above problems.
[0006] According to a first aspect of an embodiment of the present application, there is provided an identity authentication method, comprising:
[0007] Obtaining login information of the user at the first end, and sending a first authentication request to the second end based on the login information, wherein the first end is the tax system application platform and the second end is the unified identity management platform;
[0008] Receive the identity verification QR code returned by the second end based on the first authentication request, and send a second authentication request to the second end according to the identity verification QR code;
[0009] Receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet;
[0010] Sending a tax digital identity authentication request to the second end based on the authentication credentials;
[0011] Determine whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request.
[0012] Optionally, obtaining login information of the user on the first end and sending a first authentication request to the second end based on the login information, wherein the first end of the electronic invoice issuance application platform refers to the tax system application platform, and the second end refers to the unified identity management platform, including:
[0013] Prompt the user to insert the Ukey and receive the user's identity ID and Ukey login password;
[0014] Verify the authenticity of the user-related identity information corresponding to the identity ID based on the Ukey login password and obtain the encryption certificate related information stored on the second end;
[0015] Send a first authentication request to the second end based on the user-related identity information and encryption certificate-related information.
[0016] Optionally, verifying the authenticity of the user-related identity information corresponding to the identity ID according to the Ukey login password and obtaining the encryption certificate-related information stored on the second end includes:
[0017] Prompt to insert the relevant operator's Ukey and log in to the second end;
[0018] The second end obtains the Ukey device number through the unified certificate service component and initializes the user's Ukey to generate the SM2 signature public and private key pair;
[0019] Encrypt the user identity information using the SM2 signature public key in the unified password service component and send the encrypted user identity information to the tax certificate system;
[0020] The tax certificate system generates an SM2 encryption public-private key pair based on the encrypted user identity information, encrypts the user identity information through the digital envelope algorithm, and generates an encryption certificate, a signature certificate, and a root CA certificate;
[0021] The encryption certificate, signature certificate, and root CA certificate are stored on the second end.
[0022] Optionally, receiving an identity verification QR code returned by the second end based on the first authentication request, and sending a second authentication request to the second end according to the identity verification QR code, includes:
[0023] The first end receives the first request from the second end, and signs the user-related identity information and encryption certificate-related information into an identity authentication QR code through the SM2 encryption algorithm through the collaborative signature service component;
[0024] The first end displays the identity authentication QR code. After the mobile end scans the identity authentication QR code, the first end sends a second authentication request to the second end.
[0025] Optionally, receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet, includes:
[0026] Based on the second authentication request sent by the first end, the second end calls the collaborative signature SDK to sign the user's relevant identity information and encryption certificate information, and then returns a response data packet to the first end;
[0027] The first end generates authentication credentials based on the response data packet.
[0028] Optionally, sending a tax digital identity authentication request to the second end according to the authentication credential includes:
[0029] The local authentication credentials include the signed user identity information and encryption certificate related information;
[0030] The first end sends a tax digital identity authentication request to the second end based on the authentication credentials.
[0031] Optionally, based on the verification result returned by the customer's tax digital identity authentication request, determine whether the user identity is successfully verified, including:
[0032] The second end receives the customer's tax digital identity authentication request, calls the collaborative signature SDK to verify the user's identity information and encryption certificate information, verifies the user's encryption certificate, signature certificate, root CA certificate, certificate trust chain, certificate validity period, and other information, and returns the verification results to the first end;
[0033] The first end determines whether the user identity is successfully authenticated based on the authentication result.
[0034] Optionally, the method further comprises: obtaining invoice information input by the user;
[0035] The invoice information is sent to the user Ukey, and the user Ukey generates a formatted invoice and stores the formatted invoice on the first end.
[0036] According to a first aspect of an embodiment of the present application, a tax system application platform login system is provided, characterized by comprising: a first terminal, a second terminal, and a mobile terminal, wherein:
[0037] Obtaining login information of the user on the first end, and sending a first authentication request to the second end according to the login information, wherein the first end of the electronic invoice issuance application platform refers to the tax system application platform, and the second end refers to the unified identity management platform;
[0038] Receive the identity verification QR code returned by the second end based on the first authentication request, and send a second authentication request to the second end according to the identity verification QR code;
[0039] Receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet;
[0040] Sending a tax digital identity authentication request to the second end based on the authentication credentials;
[0041] Determine whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request.
[0042] Optionally, the first end is also used to: authenticate the identity of the issuer and generate an identity authentication result of the issuer; based on the identity authentication result of the issuer, remind the user to fill in the electronic invoice; and sign the electronic invoice through Ukey to generate a formatted electronic invoice.
[0043] According to an identity authentication method provided by an embodiment of the present application, by obtaining the user's login information at the first end and sending a first authentication request to the second end based on the login information, wherein the first end refers to the tax system application platform and the second end refers to the unified identity management platform; receiving the authentication QR code returned by the second end based on the first authentication request, and sending a second authentication request to the second end based on the authentication QR code; receiving the response data packet returned by the server at the second end based on the second authentication request, and generating authentication credentials based on the response data packet; sending a tax digital identity authentication request to the second end based on the authentication credentials; and determining whether the user identity is successfully authenticated based on the verification result returned by the tax digital identity authentication request. This method solves the technical problem of how to ensure the user's secure login and access to the tax system application platform and protect the security of the tax information system, and achieves the technical effect of providing a nationwide unified and trusted identity authentication technology and protecting the security of the tax information system. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0045] Figure 1 This is a flowchart of the steps of an identity authentication method according to Example 1 of the present application;
[0046] Figure 2 This is a diagram of an identity authentication system according to Example 2 of the present application. DETAILED DESCRIPTION
[0047] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the embodiments of the present application, all other embodiments obtained by ordinary technicians in this field should fall within the scope of protection of the embodiments of the present application.
[0048] The specific implementation of the embodiment of the present application is further explained below in conjunction with the accompanying drawings of the embodiment of the present application.
[0049] Example 1
[0050] Reference Figure 1 , shows a step flow chart of an identity authentication method according to embodiment 1 of the present application.
[0051] It should be noted that any of the following identity authentication methods, when applied to the first end, can be applied to a tax system application platform, such as an electronic invoice issuance application platform, a tax bureau system application platform, a bank application platform, or a financial application platform, among other application platforms involving identity authentication. The following embodiments all use the electronic invoice issuance application platform as an example.
[0052] Step 101: Obtaining the user's login information at a first end and sending a first authentication request to a second end based on the login information, wherein the first end of the electronic invoice issuance application platform refers to a tax system application platform and the second end refers to a unified identity management platform; optionally, obtaining the user's login information at a first end and sending the first authentication request to a second end based on the login information, wherein the first end of the electronic invoice issuance application platform refers to a tax system application platform and the second end refers to a unified identity management platform, includes:
[0053] Prompt the user to insert the Ukey and receive the user's identity ID and Ukey login password;
[0054] Verify the authenticity of the user-related identity information corresponding to the identity ID based on the Ukey login password and obtain the encryption certificate related information stored on the second end;
[0055] Send a first authentication request to the second end based on the user-related identity information and encryption certificate-related information.
[0056] Optionally, verifying the authenticity of the user-related identity information corresponding to the identity ID according to the Ukey login password and obtaining the encryption certificate-related information stored on the second end includes:
[0057] Prompt to insert the relevant operator's Ukey and log in to the second end;
[0058] The second end obtains the Ukey device number through the unified certificate service component and initializes the Ukey to generate the SM2 signature public and private key pair;
[0059] Encrypt the user identity information using the SM2 signature public key in the unified password service component and send the encrypted user identity information to the tax certificate system;
[0060] The tax certificate system generates an SM2 encryption public-private key pair based on the encrypted user identity information, encrypts the user identity information through the digital envelope algorithm, and generates an encryption certificate, a signature certificate, and a root CA certificate;
[0061] Store the signature certificate, encryption certificate, and root CA certificate on the second end.
[0062] It should be noted that the users here refer to taxpayers, which can be natural persons, legal persons and other users.
[0063] In one embodiment, using the electronic invoice issuance application platform as an example, a taxpayer can log in to the first end (i.e., the electronic invoice issuance application platform) using various login methods. These methods can include logging in through an account, scanning a QR code, or logging in through a device, among other methods, without limitation. During the login process, the user enters login information, such as their ID. The electronic invoice issuance application platform then sends an identity authentication request to the unified identity management platform based on the received ID. Specifically, the first end sends a first authentication request to the second end based on the user's login information.
[0064] Taking the device login method as an example, a prompt message will first be generated on the interface of the electronic invoice billing application platform to prompt the user to insert the Ukey. When the Ukey interface scans the Ukey inserted by the user, it obtains the identity ID and Ukey login password entered by the user, and confirms that the user clicks the login button to log in with the Ukey. At this time, it is necessary to first perform local authentication of the user's identity in the Ukey, confirm the authenticity of the user's relevant identity information based on the user's identity ID, and find the encryption certificate encrypted by the SM2 encryption algorithm corresponding to the user's identity ID in the Ukey, that is, pass the local user identity authentication. The Ukey generates a first authentication request based on the user's relevant identity information and the encryption certificate related information and returns it to the electronic invoice billing application platform. The electronic invoice billing application platform sends the first authentication request to the second end (the unified identity management platform).
[0065] It should be noted that before searching for the encryption certificate in the user's Ukey and obtaining related information of the encryption certificate, a pre-made digital certificate is required. The relevant operator inserts the Ukey in the electronic invoice issuance application platform and logs in to the unified identity management platform. The unified identity management platform obtains the operator's PEM certificate and Ukey device number stored in the operator's Ukey, and parses the operator's related identity information in the PEM certificate through the SM2 decryption algorithm to realize the operator's identity authentication. At this time, the unified identity management platform, that is, the second end, calls the unified certificate service component or takes the device number of the Ukey inserted by the current user to be certified, initializes the user's Ukey, generates the corresponding SM2 signature public-private key pair, and encrypts the user's relevant identity information through the SM2 signature algorithm in the unified password service component, and sends the encrypted user identity information to the tax certificate system. The tax certificate system encrypts the user identity information through the SM2 signature private key, and finally generates an encryption certificate, a signature certificate, and a root CA certificate. The tax certificate system returns the generated encryption certificate, signature certificate, and root CA certificate to the unified identity management platform, that is, the encryption certificate, root CA certificate, and root CA certificate are stored with the second end. The user's Ukey will obtain the encryption certificate from the second end for storage. According to the unified certificate service component set up according to the unified identity platform, the relevant identity information and digital certificate information of natural persons and legal persons across the country can be called by the authorized institutions and tax bureaus in various systems; through the unified password service component, all user identity authentication information is encrypted and decrypted with a unified standardized encryption algorithm to ensure the secure transmission of user identity-related information in the network.
[0066] Step 102: Receive the identity verification QR code returned by the second end based on the first authentication request, and send a second authentication request to the second end based on the identity verification QR code;
[0067] Optionally, receiving an identity verification QR code returned by the second end based on the first authentication request, and sending a second authentication request to the second end according to the identity verification QR code, includes:
[0068] The first end receives the first request from the second end, and signs the user-related identity information and encryption certificate-related information into an identity authentication QR code through the SM2 encryption algorithm through the collaborative signature service component;
[0069] The first end displays the identity authentication QR code. After the mobile end scans the identity authentication QR code, the first end sends a second authentication request to the second end.
[0070] In one embodiment, the second end, based on the first authentication request, calls the collaborative signature service component to sign the user's identity information and encryption certificate-related information using the SM2 encryption algorithm, ultimately generating an identity authentication QR code containing the user's identity information and encryption certificate-related information, and returning this QR code to the electronic invoice issuance application platform. That is, the first end receives the identity authentication QR code generated by the second end, and the electronic invoice issuance application platform will display the QR code on the display interface for the electronic tax bureau APP to scan and access the electronic tax server. At this time, the first end sends a second authentication request to the second end based on the identity authentication QR code. The second end calls the electronic tax bureau system service component to send a second authentication request, requesting identity authentication from the electronic tax system.
[0071] Step 103: receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet;
[0072] Optionally, receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet, includes:
[0073] Based on the second authentication request sent by the first end, the second end calls the collaborative signature SDK to sign the user's relevant identity information and encryption certificate information, and then returns a response data packet to the first end;
[0074] The first end generates authentication credentials based on the response data packet.
[0075] In one embodiment, after scanning the identity authentication QR code, the mobile electronic tax APP obtains the user-related identity information and encryption certificate related information contained in the QR code. The second-end unified identity management platform calls the collaborative signature SDK based on the second authentication request, queries the user identity information in the electronic tax system that is authorized by the authorized agency to be queried online, and verifies the user-related identity information. The verification result is encrypted using the SM2 signature algorithm for the user identity related information and encryption certificate related information, and a response data packet based on the second authentication request is generated and returned to the second end, that is, returned to the unified identity authentication platform. The unified identity authentication platform returns the data packet to the electronic invoice issuance application platform, and the electronic invoice issuance application platform generates authentication credentials locally based on the received data packet.
[0076] Step 104: Send a tax digital identity authentication request to the second end based on the authentication credentials;
[0077] Optionally, sending a tax digital identity authentication request to the second end according to the authentication credential includes:
[0078] The local authentication credentials include the signed user identity information and encryption certificate related information;
[0079] The first end sends a tax digital identity authentication request to the second end based on the authentication credentials.
[0080] In one embodiment, the electronic invoice issuance application platform sends a tax identity authentication request for the user to the second end based on the generated authentication credentials, specifically requesting verification of the authenticity of other relevant certificates of the user, such as encryption certificates, signature certificates, root CA certificates, certificate trust chains, certificate validity periods, and other information.
[0081] Step 105: Determine whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request.
[0082] Optionally, based on the verification result returned by the customer's tax digital identity authentication request, determine whether the user identity is successfully verified, including:
[0083] The second end receives the customer's tax digital identity authentication request, calls the collaborative signature SDK to verify the user's identity information and encryption certificate information, verifies the user's encryption certificate, signature certificate, root CA certificate, certificate trust chain, certificate validity period, and other information, and returns the verification results to the first end;
[0084] The first end determines whether the user identity is successfully authenticated based on the authentication result.
[0085] In one embodiment, the unified identity management platform at the second end receives a user tax digital identity authentication request sent by the electronic invoice issuance application platform. The unified identity management platform calls the tax certificate system service component to query the user's relevant identity information and encryption certificate related information. When the user's relevant identity information and encryption certificate related information are queried, the collaborative signature SDK is called to verify the user's relevant identity information and encryption certificate related information, and verify the user's encryption certificate, signature certificate, root CA certificate, certificate trust chain, certificate validity period and other information. The verification result is returned to the first end, that is, to the electronic invoice issuance application platform. This process uses digital mailbox technology to ensure the security of information transmission. After completing the user identity information verification, if the user identity authentication is successful, the electronic invoice issuance application platform prompts the user that the identity authentication is successful; if the user identity authentication fails, the electronic invoice issuance application platform prompts the user that the identity authentication failed.
[0086] Optionally, the method further comprises: obtaining invoice information input by the user;
[0087] The invoice information is sent to the user Ukey, and the user Ukey generates a formatted invoice and stores the formatted invoice on the first end.
[0088] In one embodiment, after successfully logging into the electronic invoice issuance application platform, a user enters invoice information on the invoice information filling interface of the electronic invoice issuance application platform. For example, 1. a copy of the business license (with a fresh stamp), photos of the front and back of the ID card, and the contact person's name and phone number are required; 2. a list of invoice items, tax rate, and other information are provided. The completed invoice information is then sent to the user's UKey, which directly generates a formatted electronic invoice and sends it to the electronic invoice issuance application platform, allowing the user to subsequently print or download the electronic version of the electronic invoice.
[0089] Example 2
[0090] Reference Figure 2 , shows a diagram of an identity authentication system according to Example 2 of the present application.
[0091] It should be noted that the identity authentication platform login method executable by the system is exactly the same as the method steps in the above method embodiment, and will not be repeated here.
[0092] According to a first aspect of an embodiment of the present application, an identity authentication system is provided, characterized in that it includes: a first end, a second end, and a mobile end, wherein:
[0093] Obtaining login information of the user at the first end, and sending a first authentication request to the second end based on the login information, wherein the first end is the tax system application platform and the second end is the unified identity management platform;
[0094] Receive the identity verification QR code returned by the second end based on the first authentication request, and send a second authentication request to the second end according to the identity verification QR code;
[0095] Receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet;
[0096] Sending a tax digital identity authentication request to the second end based on the authentication credentials;
[0097] Determine whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request.
[0098] Optionally, the first end is also used to: authenticate the identity of the issuer and generate an identity authentication result of the issuer; based on the identity authentication result of the issuer, remind the user to fill in the electronic invoice; and sign the electronic invoice through Ukey to generate a formatted electronic invoice.
[0099] Those skilled in the art will appreciate that the units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of this application.
[0100] The above implementation methods are only used to illustrate the embodiments of the present application, and are not intended to limit the embodiments of the present application. Ordinary technicians in the relevant technical field can make various changes and modifications without departing from the spirit and scope of the embodiments of the present application. Therefore, all equivalent technical solutions also fall within the scope of the embodiments of the present application, and the scope of patent protection of the embodiments of the present application should be defined by the claims.
Claims
1. An identity authentication method, characterized in that: include: Obtaining login information of a user on a first end, and sending a first authentication request to a second end based on the login information, wherein the first end is a tax system application platform and the second end is a unified identity management platform; receiving an identity verification QR code returned by the second end based on the first authentication request, and sending a second authentication request to the second end according to the identity verification QR code; receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet; Sending a tax digital identity authentication request to the second end according to the authentication credential; Determining whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request; Among them, the method of obtaining the user's login information at the first end and sending a first authentication request to the second end according to the login information, wherein the first end refers to the tax system application platform and the second end refers to the unified identity management platform, includes: prompting the user to insert the Ukey, receiving the user-entered identity ID and Ukey login password; verifying the authenticity of the user-related identity information corresponding to the identity ID according to the Ukey login password and obtaining the encryption certificate related information stored in the second end; sending a first authentication request to the second end according to the user-related identity information and the encryption certificate related information; the second end obtains the device number of the Ukey inserted by the user through the unified certificate service component, and initializes the Ukey to generate an SM2 signature public-private key pair; encrypts the user identity information through the SM2 signature public key, and sends the encrypted user identity information to the tax certificate system; the tax certificate system generates an SM2 encryption public-private key pair based on the encrypted user identity information, encrypts the user identity information through the digital envelope algorithm, and generates the encryption certificate, signature certificate, and root CA certificate; stores the encryption certificate, the signature certificate, and the root CA certificate on the second end.
2. The method according to claim 1, characterized in that Receiving an identity verification QR code returned by the second end based on the first authentication request, and sending a second authentication request to the second end according to the identity verification QR code, including: The first end receives the first authentication request from the second end, and signs the user-related identity information and the encryption certificate-related information into the identity verification QR code through the collaborative signature service component using the SM2 encryption algorithm; The first end displays the identity verification QR code, and after the mobile end scans the identity verification QR code, the first end sends a second authentication request to the second end.
3. The method according to claim 1, characterized in that Receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet, including: The second end, based on the second authentication request sent by the first end, calls the collaborative signature SDK to sign the user-related identity information and the encryption certificate-related information, and then returns a response data packet to the first end; The first end generates the authentication credential according to the response data packet.
4. The method according to claim 3, characterized in that Sending a tax digital identity authentication request to the second end according to the authentication credential includes: The authentication credentials include the signed user-related identity information and the encryption certificate-related information; The first end sends a tax digital identity authentication request to the second end according to the authentication credential.
5. The method according to claim 3, characterized in that Determining whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request includes: The second end receives the tax digital identity authentication request, calls the collaborative signature SDK to verify the user's identity information and the encryption certificate information, verifies the user's encryption certificate, the signing certificate, the root CA certificate, the certificate trust chain, the certificate validity period and other information, and returns the verification result to the first end; The first end determines whether the user identity is successfully authenticated according to the authentication result.
6. The method according to claim 1, characterized in that Also includes: Get the invoice information entered by the user; The invoice information is sent to the user Ukey, and the user Ukey generates a formatted invoice and stores the formatted invoice on the first end.
7. An identity authentication system, characterized in that: include: First end, second end, wherein: Obtaining login information of a user on a first end, and sending a first authentication request to a second end based on the login information, wherein the first end is a tax system application platform and the second end is a unified identity management platform; receiving an identity verification QR code returned by the second end based on the first authentication request, and sending a second authentication request to the second end according to the identity verification QR code; receiving a response data packet returned by the server at the second end based on the second authentication request, and generating an authentication credential according to the response data packet; Sending a tax digital identity authentication request to the second end according to the authentication credential; Determining whether the user identity is successfully verified based on the verification result returned by the tax digital identity authentication request; Among them, the method of obtaining the user's login information at the first end and sending a first authentication request to the second end according to the login information, wherein the first end refers to the tax system application platform and the second end refers to the unified identity management platform, includes: prompting the user to insert the Ukey, receiving the user-entered identity ID and Ukey login password; verifying the authenticity of the user-related identity information corresponding to the identity ID according to the Ukey login password and obtaining the encryption certificate related information stored in the second end; sending a first authentication request to the second end according to the user-related identity information and the encryption certificate related information; the second end obtains the device number of the Ukey inserted by the user through the unified certificate service component, and initializes the Ukey to generate an SM2 signature public-private key pair; encrypts the user identity information through the SM2 signature public key, and sends the encrypted user identity information to the tax certificate system; the tax certificate system generates an SM2 encryption public-private key pair based on the encrypted user identity information, encrypts the user identity information through the digital envelope algorithm, and generates the encryption certificate, signature certificate, and root CA certificate; stores the encryption certificate, the signature certificate, and the root CA certificate on the second end.
8. The identity authentication system according to claim 7, characterized in that: include: The first end is further configured to: authenticate the identity of the issuer and generate the issuer identity authentication result; Based on the identity verification result of the issuer, remind the user to fill in the electronic invoice; The electronic invoice is signed through Ukey to generate a formatted electronic invoice.