An identity authentication system and method for solving inter-platform communication problems.
By designing an identity authentication system for certificate generation, management and verification in the privacy computing network, the problem of complex certificate application process, inability to effectively limit participants and poor management is solved, and effective management of participants' identities and data security is achieved.
Patent Information
- Application Number
- CN202210906822.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-29
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-07-29
AI Technical Summary
The existing technology has the risk of data breaches and platform paralysis in the privacy computing network.
An identity authentication system is designed, including certificate generation, download, renewal, revocation and verification services. By managing participants' certificates through self-signed root certificates, effective management of participants' identities and data encrypted communication are achieved.
Through unified certificate management, the certificate application process is simplified, data security and management efficiency in the privacy computing network are improved, and malicious third parties are added and data leakage is prevented.
Smart Images

Figure CN115361135B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to an identity authentication system and method for solving mutual communication between multiple platforms. Background Art
[0002] With the frequent occurrence of data security incidents in recent years, data security threats are becoming increasingly severe. We need to apply data while protecting data security. How to balance development and security, balance efficiency and risk, and maximize the value of data while ensuring security is an important issue currently faced. Privacy computing technologies represented by secure multi-party computing (MPC), trusted execution environment (TEE), and federated learning (FL) provide solutions for the "available but invisible" data in the circulation process, which helps to resolve the contradiction between data protection and utilization.
[0003] The prior art has the following defects:
[0004] 1. The application process is complicated. The existing third-party trusted certificate platform has very strict requirements for the application data of the certificate. Inaccurate data will lead to application failure, and it is uncertain when the application will be approved. This will limit the relevant rights and interests of participants in the privacy computing network.
[0005] 2. It is impossible to restrict participants. If the privacy computing platform uses certificates issued by a third-party trusted platform, since they all use the same ROOT CA certificate, malicious third parties will join the privacy computing network through available certificates, leading to serious problems such as platform data leakage.
[0006] 3. Inability to form effective management. First of all, for the privacy computing network, it is equivalent to the alliance chain in the blockchain. Although the members in the network have a high degree of autonomy, effective management and control are required for members to join or leave the network, and the interaction between members and public services also requires data encryption and identity authentication. Therefore, if a trusted third party is used for management or a user management platform is developed separately, only the participants in the privacy computing network can apply for, renew, and revoke certificates, which cannot form effective management.
[0007] 4. Completely restricted third parties. Since certificates are used for interaction within the privacy computing network, it is necessary to verify whether the certificate is available during the interaction. If a third-party trusted platform is used entirely, a third party will be requested to verify the certificate status each time. As long as the certificate is unavailable in the privacy computing network, the current request will fail and the next step of interaction cannot be performed. If an error occurs in the third-party verification service, the privacy computing network will be paralyzed. Summary of the invention
[0008] The embodiments of the present invention mainly provide services such as certificate generation, certificate download, certificate renewal, certificate revocation, and certificate verification, and also provide an encryption and decryption service to perform data encryption and decryption; the present invention is mainly used to manage participants in a privacy computing network and to protect the data privacy and security of the participants.
[0009] The embodiment of the present invention is implemented as follows: an identity authentication system for solving the communication between multiple platforms, comprising:
[0010] Certificate generation module: used to provide certificate generation services;
[0011] Certificate download module: used to provide certificate download service;
[0012] Certificate renewal module: used to provide certificate renewal services;
[0013] Certificate revocation module: used to provide certificate revocation services;
[0014] Certificate verification module: used to provide certificate revocation services;
[0015] The encryption and decryption service module is used to provide encryption and decryption services.
[0016] As a preferred embodiment of the present invention, the present invention also includes a user module, and the user door module includes a participant module and an administrator module. The participant module is used by participants to apply for certificate-related services, and the administrator module is used to manage participants including adding, deleting, modifying and checking participant users, and approving participant applications.
[0017] As a preferred embodiment of the present invention, the present invention also includes a user management login module and a storage database module. The user management login module is used to provide basic user management login services, and the storage database module is used to store data.
[0018] As a preferred implementation scheme of the present invention, all certificates in this system are issued by the same root certificate. A root certificate is generated in this system, namely, a root ca certificate. The root ca certificate is equivalent to a self-signed certificate, so its issuer is the same as the user. When generating a root ca certificate, only the current network name and the organization to which it belongs need to be provided.
[0019] As a preferred implementation scheme of the present invention, when the certificate generation function module executes the certificate generation service, the participant needs to log in to the system through the participant module, and then submit the participant's business license, organization name, organization abbreviation and other required information to apply for the certificate, and then the system's admin user verifies the records submitted by the participant offline or online through the administrator module for approval. If the approval is passed, a node certificate will be generated for the corresponding participant. The node certificate organization information is consistent with the root CA certificate, and the validity period should be less than or equal to the root CA certificate. The child node certificate is consistent with the root CA certificate signature algorithm. If the root CA signature algorithm is a national secret algorithm, the child node needs to generate two sets of certificates, one for encryption and one for decryption.
[0020] As a preferred implementation of the present invention, when the certificate download module executes the certificate download task, the participant needs to log in to the system through the participant module to download the certificate. The downloaded certificate is in the zip package format, which contains the private key and public key of the child node and the public key of the root CA; the public key certificate format is .crt, and the private key certificate format is .pem. And the certificate of each participant is only visible to the participant.
[0021] As a preferred implementation scheme of the present invention, when the certificate renewal module executes the certificate renewal task, the participant needs to submit a certificate renewal application through the participant module. The application premise is that the system determines that the current participant module has a digital certificate. The application method can choose the default extension for a specified year, or a custom extension time period. The maximum time of both request methods cannot be greater than the valid time period of the root CA certificate. After successful submission, the admin user needs to use the administrator module for approval. After approval, a new certificate is generated and downloaded and used by the participant.
[0022] As a preferred implementation scheme of the present invention, the detailed steps of the certificate revocation module in executing the certificate revocation task are as follows: when the admin user determines through the administrator module that a participant has exited the network, the admin user applies through the administrator module to clear the user information of the participant in the certificate system and mark the user's certificate as expired.
[0023] As a preferred implementation scheme of the present invention, the certificate verification service module is provided with an external interface, which does not perform login verification but requires setting a request token, and the token is provided by the certificate platform.
[0024] An identity authentication method for solving communication between multiple platforms includes the following steps:
[0025] a) The net service sends a communication message "hello" to the data center. The net service selects the parameters for the handshake. The choice of the cipher suite determines what type of handshake is performed. The cipher suite is specified by the data center. The "hello" communication message contains the net service random number, the cipher suite selected by the net service, and the net service's certificate. The certificate contains the net service's public key and information about the parties involved.
[0026] b) The data center will first verify whether the certificate is credible and available through the external service of the certificate platform. After verification, the data center will create a random pre-main secret; this secret is encrypted with the public key in the certificate and sent to the net service;
[0027] c) Upon receiving this message, the net service decrypts this pre-master secret using its private key; now that both parties have the pre-main secret, and both the data center and the net service are random, they can both derive the same session key; they then exchange a short message indicating that the next message they send will be encrypted;
[0028] d) The handshake is officially complete when the datacenter and net service exchange "Done" messages; the actual text literally means: "Datacenter Done" or "Net Service Done" encrypted using the session key; any subsequent communications between the two parties are encrypted using the session key.
[0029] Beneficial effects of the present invention:
[0030] 1. Use certificates as the participation credentials for participants in the privacy computing network. Certificates are used to control entry and exit from the privacy computing network. Communication between participants is encrypted through certificate processing to prevent data leakage.
[0031] 2. Unify certificate management to indirectly manage participants. By deploying a certificate management platform to manage certificates and certificate-related operations, all participants in the privacy computing network can only perform certificate-related operations through this platform. The management of certificates by the platform indirectly realizes the management of participants.
[0032] 3. Simplify the certificate application process. According to the situation of the participants in the privacy computing network, simplify the data required for applying for certificates. The certificate management platform does not require multiple hierarchical relationships. One or more admin users are provided to be managed by the participants nominated by the privacy computing network, and the admin directly performs certificate-related approval work.
[0033] 4. Customize the useful life of certificates. The useful life of certificates on commonly used third-party trusted certificate platforms is generally one year. This platform will adjust and increase the useful life based on the actual situation of the participants.
[0034] 5. Certificate authentication: The certificate platform performs certificate authentication services, including whether the certificate is credible, the certificate’s validity period, the certificate’s status, etc. This is used to limit participants in the privacy computing network and prevent malicious third parties from joining. Only certificates issued by the privacy computing platform’s certificate platform can be used for communication between services.
[0035] 6. Secure communication among participants: A secure communication channel is established between the participant service and the data center through the digital certificate provided by the certificate platform to ensure secure data transmission and prevent data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is the overall architecture diagram of the certificate system of the present invention;
[0037] Figure 2 It is an interaction diagram of the participants of the present invention. DETAILED DESCRIPTION
[0038] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0039] The present invention uses certificates as participation credentials for participants in a privacy computing network, controls entry into and exit from the privacy computing network through certificates, and prevents data leakage through certificate encryption processing in communications between participants; unifies certificate management to indirectly manage participants, and manages certificates and certificate-related operations by deploying a certificate management platform. All participants in the privacy computing network can only perform certificate-related operations through this platform, and indirectly manages participants through the platform's management of certificates.
[0040] The embodiment of the present invention is implemented as follows: an identity authentication system for solving the communication between multiple platforms, comprising:
[0041] Certificate generation module: used to provide certificate generation services;
[0042] Certificate download module: used to provide certificate download service;
[0043] Certificate renewal module: used to provide certificate renewal services;
[0044] Certificate revocation module: used to provide certificate revocation services;
[0045] Certificate verification module: used to provide certificate revocation services;
[0046] The encryption and decryption service module is used to provide encryption and decryption services.
[0047] Furthermore, the present invention also includes a user module, and the user door module includes a participant module and an administrator module. The participant module is used by participants to apply for certificate-related services, and the administrator module is used to manage participants including adding, deleting, modifying and checking participant users, and approving participant applications.
[0048] Furthermore, the present invention also includes a user management login module and a storage database module, wherein the user management login module is used to provide basic user management login services, and the storage database module is used to store data.
[0049] Furthermore, all certificates in this system are issued by the same root certificate. A root certificate is generated in this system, namely the root ca certificate. The root ca certificate is equivalent to a self-signed certificate, so its issuer is the same as the user. When generating the root ca certificate, you only need to provide the current network name and the organization to which it belongs.
[0050] Furthermore, when the certificate generation function module executes the certificate generation service, the participant is required to log in to the system through the participant module, and then submit the participant's business license, organization name, organization abbreviation and other required information to apply for the certificate. Then the system's admin user verifies the records submitted by the participant offline or online through the administrator module for approval. If the approval is passed, a node certificate will be generated for the corresponding participant. The node certificate organization information is consistent with the root CA certificate, and the validity period should be less than or equal to the root CA certificate. The child node certificate is consistent with the root CA certificate signature algorithm. If the root CA signature algorithm is the national secret algorithm, the child node needs to generate two sets of certificates, one for encryption and one for decryption.
[0051] Furthermore, when the certificate download module executes the certificate download task, the participant needs to log in to the system through the participant module to download the certificate. The downloaded certificate is in the zip package format, which contains the private key and public key of the child node and the public key of the root CA; the public key certificate format is .crt, and the private key certificate format is .pem. And the certificate of each participant is only visible to the participant.
[0052] Furthermore, when the certificate renewal module performs the certificate renewal task, the participant is required to submit a certificate renewal application through the participant module. The application prerequisite is that the system determines that the current participant module has a digital certificate. The application method can choose the default extension for a specified year, or a custom extension time period. The maximum time of both request methods cannot be greater than the valid time period of the root CA certificate. After successful submission, the admin user needs to use the administrator module for approval. After approval, a new certificate will be generated and downloaded and used by the participant.
[0053] Furthermore, the detailed steps of the certificate revocation module in executing the certificate revocation task are as follows: when the admin user determines through the administrator module that a participant has exited the network, the admin user applies through the administrator module to clear the user information of the participant in the certificate system and mark the user's certificate as expired.
[0054] Furthermore, the certificate verification service module is provided with an external interface, which does not perform login verification but requires setting a request token, and the token is provided by the certificate platform.
[0055] An identity authentication method for solving communication between multiple platforms includes the following steps:
[0056] a) The net service sends a communication message "hello" to the data center. The net service selects the parameters for the handshake. The choice of the cipher suite determines what type of handshake is performed. The cipher suite is specified by the data center. The "hello" communication message contains the net service random number, the cipher suite selected by the net service, and the net service's certificate. The certificate contains the net service's public key and information about the parties involved.
[0057] b) The data center will first verify whether the certificate is credible and available through the external service of the certificate platform. After verification, the data center will create a random pre-main secret; this secret is encrypted with the public key in the certificate and sent to the net service;
[0058] c) Upon receiving this message, the net service decrypts this pre-master secret using its private key; now that both parties have the pre-main secret, and both the data center and the net service are random, they can both derive the same session key; they then exchange a short message indicating that the next message they send will be encrypted;
[0059] d) The handshake is officially complete when the datacenter and net service exchange "Done" messages; the actual text literally means: "Datacenter Done" or "Net Service Done" encrypted using the session key; any subsequent communications between the two parties are encrypted using the session key.
[0060] Embodiment 1
[0061] See also Figure 1-Figure 2 , an identity authentication system for solving the communication between multiple platforms, including:
[0062] Certificate generation module: used to provide certificate generation services;
[0063] Certificate download module: used to provide certificate download service;
[0064] Certificate renewal module: used to provide certificate renewal services;
[0065] Certificate revocation module: used to provide certificate revocation services;
[0066] Certificate verification module: used to provide certificate revocation services;
[0067] The encryption and decryption service module is used to provide encryption and decryption services.
[0068] In this embodiment, the present invention also includes a user module, and the user door module includes a participant module and an administrator module. The participant module is used by participants to apply for certificate-related services, and the administrator module is used to manage participants, including adding, deleting, modifying and checking participant users, and approving participant applications.
[0069] In this embodiment, the present invention also includes a user management login module and a storage database module. The user management login module is used to provide basic user management login services, and the storage database module is used to store data. The user module has simple functions and can simplify the process, thereby increasing the speed.
[0070] In this embodiment, all certificates in this system are issued by the same root certificate. A root certificate is generated in this system, which is a root ca certificate. The root ca certificate is equivalent to a self-signed certificate, so its issuer is consistent with the user; when generating the root ca certificate, only the current network name and the organization to which it belongs need to be provided. 5. Secondly, since the root ca certificate is mainly used for verification and issuance, the validity period of the certificate can be appropriately extended. Finally, since there are many certificate signature algorithms, and the present invention needs to support mainstream algorithms such as 1. SM3WITHSM2 (national secret algorithm), 2. SHA256WITHECDSA (ECDSA encryption algorithm), 3. SHA256WITHRSA (RSA encryption algorithm); and the signature algorithm of the subsequent node certificate should be consistent with the root node algorithm.
[0071] In this embodiment, when the certificate generation function module executes the certificate generation service, the participant is required to log in to the system through the participant module, and then submit the participant's business license, organization name, organization abbreviation and other required information to apply for a certificate. Then the system's admin user verifies the records submitted by the participant offline or online through the administrator module for approval. If the approval is passed, a node certificate will be generated for the corresponding participant. The node certificate organization information is consistent with the root CA certificate, and the validity period should be less than or equal to the root CA certificate. The child node certificate is consistent with the root CA certificate signature algorithm. If the root CA signature algorithm is a national secret algorithm, the child node needs to generate two sets of certificates, one for encryption and one for decryption.
[0072] In this embodiment, when the certificate download module executes the certificate download task, the participant needs to log in to the system through the participant module to download the certificate. The downloaded certificate is in the zip package format, which contains the private key and public key of the child node and the public key of the root CA; the public key certificate format is .crt, and the private key certificate format is .pem. And the certificate of each participant is only visible to the participant.
[0073] In this embodiment, when the certificate renewal module executes the certificate renewal task, the participant is required to submit a certificate renewal application through the participant module. The application premise is that the system determines that the current participant module has a digital certificate. The application method can choose the default extension for a specified year, or a custom extension time period. The maximum time of both request methods cannot be greater than the valid time period of the root CA certificate. After successful submission, the admin user needs to use the administrator module for approval. After approval, a new certificate is generated and downloaded and used by the participant.
[0074] In this embodiment, the detailed steps of the certificate revocation module in executing the certificate revocation task are as follows: when the admin user determines through the administrator module that a participant has exited the network, the admin user sends an application through the administrator module to clear the user information of the participant in the certificate system and mark the user's certificate as expired.
[0075] In this embodiment, the certificate verification service module is provided with an external interface. The external interface does not perform login verification but requires the setting of a request token. The token is provided by the certificate platform. In this embodiment, only services holding valid tokens can access the external interface. The token is synchronized to the external service at regular intervals and expires at regular intervals. The external service obtains the current certificate status by requesting the external interface and providing the unique information of the certificate to be verified. The certificate status is determined by the certificate platform. The status includes but is not limited to: in effect, expired, expired, and non-existent; the external service can use this function to determine whether the current requested certificate is legal.
[0076] Embodiment 2
[0077] See also Figure 2 ,pass Figure 2 It can be seen how the participants in the privacy computing network interact with each other. Each participant requests the data center by operating the console in its own internal service, and realizes communication between the participants through the operation of the data center. The internal services of the participants are deployed in the intranet, and the internal console service and the network service are both in the same server, so there is no security problem in the interaction between the two. Therefore, the encryption and decryption of the certificate needs to be used in the process of interaction between the participants and the data center, and the internal service net service of the participant is mainly used to receive requests from the console, and then request the data center according to the request content. Therefore, the communication between the net service and the data center requires data encryption and decryption and identity authentication.
[0078] An identity authentication method for solving communication between multiple platforms includes the following steps:
[0079] a) The net service sends a communication message "hello" to the data center. The net service selects the parameters for the handshake. The choice of the cipher suite determines what type of handshake is performed. The cipher suite is specified by the data center. The "hello" communication message contains the net service random number, the cipher suite selected by the net service, and the net service's certificate. The certificate contains the net service's public key and information about the parties involved.
[0080] b) The data center will first verify whether the certificate is credible and available through the external service of the certificate platform. After verification, the data center will create a random pre-main secret; this secret is encrypted with the public key in the certificate and sent to the net service;
[0081] c) Upon receiving this message, the net service decrypts this pre-master secret using its private key; now that both parties have the pre-main secret, and both the data center and the net service are random, they can both derive the same session key; they then exchange a short message indicating that the next message they send will be encrypted;
[0082] d) The handshake is officially complete when the datacenter and net service exchange "Done" messages; the actual text literally means: "Datacenter Done" or "Net Service Done" encrypted using the session key; any subsequent communications between the two parties are encrypted using the session key.
[0083] It should be understood that, although each step in the flow chart of each embodiment of the present invention is shown in sequence according to the indication of the arrow, these steps are not necessarily performed in sequence according to the order indicated by the arrow. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0084] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0085] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
[0086] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. An identity authentication system for solving the communication between multiple platforms, characterized in that: include: Certificate generation module: used to provide certificate generation services; Certificate download module: used to provide certificate download service; Certificate renewal module: used to provide certificate renewal services; Certificate revocation module: used to provide certificate revocation services; Certificate verification module: used to provide certificate revocation services; Encryption and decryption service module, used to provide encryption and decryption services; Also includes user modules; The user gate module includes a participant module and an administrator module, wherein the participant module is used by participants to apply for certificate-related services; The administrator module is used to manage participants, including adding, deleting, modifying and checking participant users, and approving participant applications; It also includes a user management login module and a storage database module; The user management login module is used to provide basic user management login services, and the storage database module is used to store data; All certificates in this system are issued by the same root certificate. A root certificate is generated in this system, which is the root ca certificate. The root ca certificate is equivalent to a self-signed certificate, and the issuer is the same as the user. When generating a root CA certificate, you only need to provide the current network name and the organization to which it belongs; When the certificate generation module performs the certificate generation service, the participant needs to log in to the system through the participant module and then submit the required information such as the participant's business license, organization name, and organization abbreviation to apply for the certificate; Then the admin user of the system will verify the records submitted by the participants offline or online through the administrator module for approval. If approved, a node certificate will be generated for the corresponding participant; The node certificate organization information is consistent with the root CA certificate, and the validity period should be less than or equal to the root CA certificate. The sub-node certificate is consistent with the root CA certificate signature algorithm. If the root CA signature algorithm is a national secret algorithm, the sub-node needs to generate two sets of certificates, one for encryption and one for decryption.
2. An identity authentication system for solving communication between multiple platforms as claimed in claim 1, characterized in that: When the certificate download module executes the certificate download task, the participant needs to log in to the system through the participant module to download the certificate. The downloaded certificate is in the zip package format, which contains the private key and public key of the child node and the public key of the root ca; the public key certificate format is .crt, and the private key certificate format is .pem, and each participant's certificate is only visible to the participant.
3. An identity authentication system for solving communication between multiple platforms as claimed in claim 2, characterized in that: When the certificate renewal module performs the certificate renewal task, the participant needs to submit a certificate renewal application through the participant module. The application premise is that the system determines that the current participant module has a digital certificate. The application method can choose the default extension of a specified year, or a custom extension period. The maximum time of both request methods cannot be greater than the valid period of the root CA certificate; After successful submission, the admin user needs to use the administrator module for approval. After approval, a new certificate will be generated and downloaded and used by the participating parties.
4. An identity authentication system for solving communication between multiple platforms as claimed in claim 3, characterized in that: The detailed steps of the certificate revocation module in executing the certificate revocation task are as follows: when the admin user determines through the administrator module that a participant has exited the network, the admin user applies through the administrator module to clear the user information of the participant in the certificate system and mark the user's certificate as expired.
5. An identity authentication system for solving communication between multiple platforms as claimed in claim 4, characterized in that: The certificate verification module is provided with an external interface, which does not perform login verification but requires setting a request token, and the token is provided by the certificate platform.
Citation Information
Patent Citations
Content security supervision system and methods
CN102299927A
Equipment and method for protecting session key of secure socket layer
CN104702611A
Data decryption method and device, equipment and storage medium
CN114679314A