Autonomous identity authentication method and system based on third-party platform and trusted hardware

By combining cross-authentication with third-party platforms and trusted hardware, cross-platform autonomous identity registration and login are generated, which solves the data leakage risk of centralized storage and the inconvenience of user key management. It realizes cross-platform autonomous identity authentication and simplifies key operations, and is suitable for asymmetric encryption scenarios such as blockchain.

CN115514493BActive Publication Date: 2026-01-23ADVANCED INST OF INFORMATION TECH (AIIT) PEKING UNIV +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211041592.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-29
Publication Date
2026-01-23
Estimated Expiration
2042-08-29

AI Technical Summary

Technical Problem

Existing digital identity authentication technologies suffer from several problems, including data leakage risks due to centralized storage, inconvenient user password management, lack of data control, cumbersome and easily tampered verification processes, inability to manage identities independently, and the inability of third-party platforms to be directly applied to asymmetric encryption systems.

Method used

It adopts a method based on cross-authentication of third-party platforms and trusted hardware, generates cross-platform autonomous identity registration and login through trusted devices, uses multiple authoritative third-party platforms for cross-authentication of identity, generates and recovers key pairs, simplifies user management, and establishes trusted connections.

Benefits of technology

It enables cross-platform autonomous identity authentication, simplifies user key management, and improves the security and credibility of identity authentication, making it suitable for asymmetric encryption scenarios such as blockchain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115514493B_ABST
    Figure CN115514493B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of self-identity authentication method and system based on third party platform and trusted hardware.The method comprises: using third party platform cross authentication, and combining trusted hardware, generate cross-platform self-identity registration for user;Using third party platform cross authentication, and combining trusted hardware, generate cross-platform self-identity login for user.The present application uses trusted hardware to realize the security of user information.In the trusted hardware, an independent hardware environment is isolated to establish a security area, and the identity authentication chain is divided into two parts: user to security area, security area to server, respectively guarantee the trust and security of the two paths, so as to guarantee the trusted identity authentication from user to server.The present application realizes the registration and recovery of user real identity through third party platform cross authentication, so as to simplify the operation of personal user management key pair, and is suitable for blockchain and other asymmetric encryption based scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a method and system for realizing self-identity authentication based on third-party platform cross authentication and trusted hardware. BACKGROUND

[0002] Digital identity authentication is an important part of network security, and is the process of computer network system identifying the identity of the operator. The current digital identity authentication technology has the following defects:

[0003] 1. Digital identity and its related data are stored by a single centralized mechanism, which not only increases the data maintenance cost, but also increases the risk of data leakage and theft. Attackers can steal all user information data by attacking the centralized server, and can also use these information to commit fraud or sell to make profits. The central mechanism that stores this information can use the user's information data for commercial profit without the user's knowledge or consent, and can delete and tamper with the user's data, resulting in the user's information data being randomly stolen.

[0004] 2. Most systems currently use traditional username-password login methods. Due to the independence between different systems and different requirements for passwords, users need to remember a large number of different passwords, which causes great inconvenience to users logging into the system.

[0005] 3. Users cannot have control over their own information data, cannot modify and delete information data saved in different systems at will, and need to upload data in corresponding formats according to the format requirements of different systems, resulting in difficulty in sharing data with other institutions and not conducive to realizing data sharing and unified management.

[0006] 4. The digital information stored in most systems cannot be safely and effectively verified, resulting in the inability of third-party systems to determine the legality and accuracy of the user's uploaded information. If verified, the process is cumbersome and easy to be tampered with.

[0007] 5. In digital life, identity authentication and management cannot be done autonomously, and need to rely on third-party platforms to verify their identity. The management right of identity is owned by the platform rather than the individual.

[0008] 6. Third-party platform data cannot be directly applied to asymmetric encryption systems. SUMMARY

[0009] Therefore, the purpose of the present application is to provide a method and system for realizing self-identity authentication based on third-party platform cross authentication and trusted hardware, which can solve the existing problems.

[0010] Based on the above purpose, according to the first aspect of the present application, the present application provides a method for realizing autonomous identity authentication based on third-party platform cross authentication and trusted hardware, comprising:

[0011] Cross authentication of the third-party platform is used to generate cross-platform autonomous identity registration for the user in combination with the trusted hardware;

[0012] Cross authentication of the third-party platform is used to generate cross-platform autonomous identity login for the user in combination with the trusted hardware.

[0013] Further, the cross authentication of the third-party platform is used to generate cross-platform autonomous identity registration for the user in combination with the trusted hardware, comprising:

[0014] The local authentication information and a certain third-party platform are selected on the user equipment and sent to the trusted hardware as the main ID to initiate the registration process;

[0015] The trusted device sends an invitation to the user equipment, inviting the user to use at least two third-party platforms authenticated by the user as identity cross authentication;

[0016] The user equipment initiates an identity authentication request to all third-party authentication platforms respectively;

[0017] All third-party authentication platforms respectively send confirmation tokens to the trusted device;

[0018] The trusted device confirms the identity again by sending the confirmation token to the third-party authentication platform;

[0019] After confirming the identity, the third-party authentication platform returns the confirmed token to the trusted hardware;

[0020] When the trusted device receives the token returned by all third-party authentication platforms, a key pair is generated for the user in the trusted device.

[0021] Further, the local authentication information is one of the following: PIN code, fingerprint identification information, and pupil identification information.

[0022] Further, the third-party platform includes WeChat, Alipay, and mobile phone verification code.

[0023] Further, the user equipment initiates an identity authentication request to all third-party authentication platforms respectively, comprising:

[0024] A small program development platform or SDK provided by the third-party platform is used to simultaneously initiate a third-party identity authentication request from the user equipment to all third-party authentication platforms.

[0025] Further, all third-party authentication platforms respectively send confirmation tokens to the trusted device, comprising:

[0026] transmitting the confirmation token to the trusted hardware through an encrypted channel.

[0027] Further, the third-party authentication platform returns the confirmed token to the trusted hardware after confirming the identity, including:

[0028] The trusted hardware establishes a trusted connection with the user device after confirming the token.

[0029] Further, the third-party platform cross-authentication is used to generate a cross-platform autonomous identity login for the user in combination with the trusted hardware, including:

[0030] The user device selects local authentication information and a certain third-party platform as the main ID and sends them to the trusted hardware to initiate a login process.

[0031] The trusted device sends an invitation to the user device, inviting the user to use a part of the third-party platform authenticated by the user as identity cross-authentication.

[0032] The user device initiates an identity authentication request to each of the part of the third-party authentication platforms.

[0033] Each of the part of the third-party authentication platforms sends a confirmation token to the trusted device.

[0034] The trusted device confirms the identity again by sending the confirmation token to the part of the third-party authentication platforms.

[0035] Each of the part of the third-party authentication platforms returns a confirmed token to the trusted device after confirming the identity.

[0036] When the trusted device receives all the tokens returned by the part of the third-party authentication platforms, the trusted device restores the key pair for the user.

[0037] To achieve the above purpose, according to a second aspect of the present application, the present application provides a system for implementing autonomous identity authentication based on third-party platform cross-authentication and trusted hardware, including:

[0038] A user device;

[0039] At least one trusted device;

[0040] At least one third-party identity authentication server;

[0041] The user device, the trusted device, and the third-party identity authentication server execute the method of the first aspect to implement autonomous identity authentication.

[0042] In general, the advantages of the present application and the experience brought to the user are:

[0043] 1. Provide trusted encapsulation for independent third-party authentication services.

[0044] 2. The system enables users to register and restore their real identities through cross-verification by multiple authoritative third-party platforms.

[0045] 3. Utilize authoritative third-party platforms to authenticate individual user identities, thereby simplifying the operation of managing key pairs for individual users.

[0046] 4. The personal identity authentication generated by this invention can be used across platforms.

[0047] 5. After using this method, users no longer need to manage their own keys;

[0048] 6. The authentication results of third-party authentication platforms can be used to generate personal electronic signatures, which are suitable for scenarios based on asymmetric encryption, such as blockchain. Attached Figure Description

[0049] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the various drawings denote the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings depict only some embodiments disclosed in the invention and should not be construed as limiting the scope of the invention.

[0050] Figure 1 The flowchart of the method for implementing autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware according to the present invention is shown.

[0051] Figure 2 The diagram shows a flowchart of the method for generating cross-platform self-registration for users using third-party platform cross-authentication combined with trusted hardware.

[0052] Figure 3 The diagram shows a flowchart of the method for generating cross-platform self-identity login for users by utilizing cross-authentication from a third-party platform and combining trusted hardware.

[0053] Figure 4 The diagram illustrates the system architecture of this invention, which implements autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware.

[0054] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present invention is shown;

[0055] Figure 6 A schematic diagram of a storage medium provided in an embodiment of the present invention is shown. Detailed Implementation

[0056] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the invention. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0057] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0058] Figure 1 The flowchart of the method for implementing autonomous identity authentication based on third-party platform cross-authentication and trusted hardware according to the present invention is shown, including:

[0059] S1. Utilize cross-authentication through third-party platforms and combine trusted hardware to generate cross-platform self-registered identities for users.

[0060] S2. Utilize cross-authentication through third-party platforms and combine trusted hardware to generate cross-platform self-identity login for users.

[0061] like Figure 2 As shown, this invention discloses a flowchart of a method for generating cross-platform self-registered identities for users by utilizing cross-authentication from a third-party platform and combining trusted hardware.

[0062] A1. The user selects a PIN code and a third-party platform as the primary ID on their device and sends them to the trusted hardware to initiate the registration process. The third-party platform can be WeChat, Alipay, mobile verification code, etc.

[0063] In the technical solution of this invention, in addition to using PIN codes, biometric identification methods such as fingerprint recognition and iris recognition can also be used.

[0064] A2. Based on the security levels of different platforms, the trusted device sends invitations to the user device, inviting the user to use at least M platforms for cross-authentication. Here, M is the total number of application platforms the user has authenticated on, greater than or equal to 2. Thus, the personal identity authentication generated by this invention can be used across multiple platforms, including multiple different third-party platforms and the registration and login platform designed in this application.

[0065] A3. The user equipment initiates identity authentication requests to M third-party authentication platforms respectively.

[0066] In this step, the user's device (usually a mobile phone) simultaneously initiates third-party identity authentication requests to M platforms using the mini-program development platform or SDK provided by a third-party platform.

[0067] A4. M third-party authentication platforms each send M confirmation tokens to the trusted device.

[0068] In this step, the identity authentication result Token is transmitted to the trusted device through an encrypted channel.

[0069] A5. The trusted device confirms the identity again by sending the confirmation token to the third-party authentication platform.

[0070] In this step, the trusted hardware uses the token to send a secondary confirmation to the server again.

[0071] A6. After the third-party authentication platform confirms the identity, it returns the confirmed token to the trusted device.

[0072] In this step, after the confirmation token, the trusted hardware establishes a trusted connection with the user device. Thus, through two token confirmations of the independent third-party authentication service by the trusted device, trusted encapsulation is achieved.

[0073] A7. When the number of tokens returned by the third-party authentication platform received by the trusted device reaches M, a key pair is generated for the user within the trusted device. In the prior art, the user needs to remember the key himself to log in or register, and the user often forgets his key artificially. This application uses an authoritative third-party platform to authenticate the identity of individual users. Only the key pair automatically generated by the trusted device is required, without the user designing and remembering the key by himself. Thus, the operation of managing the key pair by individual users is simplified. The user no longer needs to manage his own key, but only needs to hand over the management task to the trusted device.

[0074] As Figure 3 shown, the present invention discloses a method flowchart for generating a cross-platform autonomous identity login for users by using cross-certification of a third-party platform and combining trusted hardware.

[0075] B1. The user selects a PIN code and a certain third-party platform as the main ID through the user device and sends them to the trusted hardware to initiate the login process. The third-party platform can be WeChat, Alipay, mobile phone verification code, etc.

[0076] B2. According to the security levels of different platforms, invite the user to use at least N platforms for identity cross-certification.

[0077] In this step, according to the security level, require the user to perform N of M (N < M) authentication, where N is the number of third-party platforms to be confirmed in this authentication, and M is the total number of application platforms authenticated by the user.

[0078] B3. The user device sends identity authentication requests to N third-party authentication platforms respectively.

[0079] In this step, the user's device (usually a mobile phone) simultaneously initiates third-party identity authentication requests to N platforms using the mini-program development platform or SDK provided by a third-party platform.

[0080] B4. N third-party authentication platforms each send N confirmation tokens to the trusted device.

[0081] In this step, the authentication result token is transmitted to a trusted device via an encrypted channel.

[0082] B5. The trusted device confirms its identity again by sending the confirmation token to a third-party authentication platform.

[0083] In this step, the trusted hardware uses the token to send a second confirmation to the server.

[0084] B6. After verifying the identity, the third-party authentication platform returns a confirmed token to the trusted hardware.

[0085] In this step, after the token is confirmed, the trusted hardware establishes a trusted connection with the user equipment.

[0086] B7. When the number of tokens returned by the third-party authentication platform received by the trusted device reaches N, the key pair is restored for the user within the trusted device.

[0087] Through the above technical solution, this invention achieves user information security using trusted hardware. An independent hardware environment is isolated within the trusted hardware to establish a secure zone. This secure zone divides the identity authentication chain into two parts: user to the secure zone, and secure zone to the server. By ensuring the trustworthiness and security of these two separate paths, trusted identity authentication from the user to the server can be guaranteed. Authentication from the user to the secure zone is also called local authentication, and generally includes biometric identification methods such as PIN codes, fingerprint recognition, and iris recognition. On the one hand, due to hardware isolation, this authentication information is directly input into the secure zone without passing through open software systems, so viruses cannot affect it; on the other hand, this authentication is performed locally, and since the zone itself is trusted and secure, this path can be guaranteed to be secure.

[0088] Furthermore, this invention simplifies the process of managing keys for individual users through cross-certification by multiple authoritative third parties, while also achieving cross-platform identity authentication. The authentication results from third-party platforms can be used to generate personal electronic signatures, suitable for scenarios based on asymmetric encryption, such as blockchain.

[0089] In summary, the advantages of this invention and the user experience it brings are as follows:

[0090] 1. Provide trusted encapsulation for independent third-party authentication services.

[0091] 2. The system enables users to register and restore their real identities through cross-verification by multiple authoritative third-party platforms.

[0092] 3. Utilize authoritative third-party platforms to authenticate individual user identities, thereby simplifying the operation of managing key pairs for individual users.

[0093] 4. The personal identity authentication generated by this invention can be used across platforms.

[0094] 5. After using this method, users no longer need to manage their own keys;

[0095] 6. The authentication results of third-party authentication platforms can be used to generate personal electronic signatures, which are suitable for scenarios based on asymmetric encryption, such as blockchain.

[0096] The application provides a system for implementing autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware. This system is used to execute the method for implementing autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware described in the above embodiments, such as... Figure 4 As shown, the system includes:

[0097] Registration module 501 utilizes cross-authentication from a third-party platform, combined with trusted hardware, to generate cross-platform self-registered identities for users; the registration process is as follows: Figure 2 As shown, the method is consistent with the one described above, and will not be repeated here.

[0098] Login module 502 utilizes cross-authentication from a third-party platform, combined with trusted hardware, to generate a cross-platform, self-identified login for users. The login process is as follows: Figure 3 As shown, the method is consistent with the one described above, and will not be repeated here.

[0099] The system for autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware provided in the above embodiments of the present invention and the method for autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware provided in the embodiments of the present invention are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0100] This invention also provides an electronic device corresponding to the method for autonomous identity authentication based on third-party platform cross-certification and trusted hardware provided in the foregoing embodiments, to execute the method for autonomous identity authentication based on third-party platform cross-certification and trusted hardware. This invention is not limited in its embodiments.

[0101] Please refer to Figure 5 This illustrates a schematic diagram of an electronic device provided by some embodiments of the present invention. For example... Figure 5As shown, the electronic device 20 includes: a processor 200, a memory 201, a bus 202, and a communication interface 203. The processor 200, the communication interface 203, and the memory 201 are connected via the bus 202. The memory 201 stores a computer program that can run on the processor 200. When the processor 200 runs the computer program, it executes the method for autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware provided in any of the foregoing embodiments of the present invention.

[0102] The memory 201 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 203 (which can be wired or wireless), such as the Internet, wide area network, local area network, or metropolitan area network.

[0103] Bus 202 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 201 is used to store programs. After receiving an execution instruction, the processor 200 executes the program. The method for implementing autonomous identity authentication based on third-party platform cross-certification and trusted hardware disclosed in any of the foregoing embodiments of the present invention can be applied to the processor 200, or implemented by the processor 200.

[0104] The processor 200 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 200 or by instructions in software form. The processor 200 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 201. The processor 200 reads the information in memory 201 and, in conjunction with its hardware, completes the steps of the above method.

[0105] The electronic device provided in this embodiment of the invention and the method for autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware provided in this embodiment of the invention are based on the same inventive concept and have the same beneficial effects as the methods they adopt, operate or implement.

[0106] This invention also provides a computer-readable storage medium corresponding to the method for autonomous identity authentication based on third-party platform cross-certification and trusted hardware provided in the foregoing embodiments. Please refer to [link / reference]. Figure 6 The computer-readable storage medium shown is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it executes the method for autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware provided in any of the foregoing embodiments.

[0107] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.

[0108] The computer-readable storage medium provided in the above embodiments of the present invention and the method for implementing autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware provided in the embodiments of the present invention are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0109] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope disclosed in the present invention, and these should all be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for implementing self-sovereign identity authentication based on third-party platform cross-certification and trusted hardware, characterized in that, The method comprises the following steps: Cross-authentication with a third-party platform is used to generate a cross-platform autonomous identity registration for a user in combination with trusted hardware; Cross-authentication with a third-party platform is used to generate a cross-platform autonomous identity login for a user in combination with trusted hardware; The step of generating a cross-platform autonomous identity registration for a user in combination with trusted hardware by cross-authentication with a third-party platform comprises the following steps: Local authentication information and a certain third-party platform are selected as a main ID on a user device and are sent to trusted hardware to initiate a registration process; Trusted hardware sends an invitation to the user device, inviting the user to use at least two third-party platforms authenticated by the user as cross-authentication of identity; The user device initiates an identity authentication request to all third-party platforms respectively; All third-party platforms send a confirmation token to trusted hardware respectively; Trusted hardware confirms the identity again by sending the confirmation token to the third-party platforms; After the third-party platforms confirm the identity, the third-party platforms return the confirmed token to trusted hardware; After trusted hardware receives the token returned by all third-party platforms, a key pair is generated for the user in trusted hardware; The step of generating a cross-platform autonomous identity login for a user in combination with trusted hardware by cross-authentication with a third-party platform comprises the following steps: Local authentication information and a certain third-party platform are selected as a main ID on a user device and are sent to trusted hardware to initiate a login process; Trusted hardware sends an invitation to the user device, inviting the user to use part of the third-party platforms authenticated by the user as cross-authentication of identity; The user device initiates an identity authentication request to the part of third-party platforms respectively; Each of the part of third-party platforms sends a confirmation token to trusted hardware respectively; Trusted hardware confirms the identity again by sending the confirmation token to the part of third-party platforms; After each of the part of third-party platforms confirms the identity, the part of third-party platforms returns the confirmed token to trusted hardware; After trusted hardware receives the token returned by all of the part of third-party platforms, a key pair is recovered for the user in trusted hardware.

2. The method of claim 1, wherein: The local authentication information is one of the following: a PIN code, fingerprint identification information, and pupil identification information.

3. The method of claim 1, wherein: The third-party platforms include WeChat, Alipay, and a mobile phone verification code.

4. The method of claim 1, wherein: The step of initiating an identity authentication request to all third-party platforms respectively by the user device comprises the following step: A third-party identity authentication request is simultaneously initiated from the user device to all third-party platforms by using a mini-program development platform or an SDK provided by the third-party platforms.

5. The method of claim 1, wherein: The step of sending a confirmation token to trusted hardware by all third-party platforms respectively comprises the following step: The confirmation token is transmitted to trusted hardware through an encrypted channel.

6. The method of claim 1, wherein: The step of returning the confirmed token to trusted hardware by the third-party platforms after confirming the identity comprises the following step: A trusted connection is established between trusted hardware and the user device after the confirmation token.

7. A system for autonomous identity authentication based on cross-certification of a third-party platform and trusted hardware, characterized in that, The method comprises the following steps: A user device; At least one trusted hardware; At least one third-party identity authentication server; The user device, trusted hardware, third-party identity authentication server perform the method of any one of claims 1-6 to implement autonomous identity authentication.

8. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Identity authentication method, device and equipment and computer readable storage medium

    CN114553432A