Authentication Method, Readable Medium, and Electronic Device

By using cloud server certificates that are not associated with terminal device information in smart terminal devices to sign business-level certificates, the problem of identity information leakage of smart terminal devices is solved, and higher security is achieved.

CN115706993BActive Publication Date: 2025-06-27HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110886365.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-03
Publication Date
2025-06-27
Estimated Expiration
2041-08-03

AI Technical Summary

Technical Problem

In the prior art, the identity information of the smart terminal device is easily leaked, resulting in security risks for users when using some functions of the smart terminal device.

Method used

The service-level certificates involved in each terminal device are signed using the certificates of the cloud server that are not associated with the terminal device information, obtain the application certificates of each terminal device, and then send the application certificates to the cloud server for verification.

Benefits of technology

Through this method, the identification information of the terminal device is avoided, and the user's personal privacy information cannot be obtained based on the certificate matching of the cloud server, which improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115706993B_ABST
    Figure CN115706993B_ABST
Patent Text Reader

Abstract

The present application relates to an authentication method, a readable medium, and an electronic device. The method includes: the electronic device uses the device identity information of the electronic device to sign the self-signed certificate generated by the application program of the electronic device to obtain a first application certificate, and sends the first application certificate to the authentication server; when the authentication server determines that the first application certificate is trustworthy, it signs the self-signed certificate in the first application based on the server identity information of the application server to obtain a second application certificate, and sends the second application certificate to the electronic device; when the electronic device determines that the second application certificate is trustworthy, it sends the second application certificate to the application server; and, when the application server determines that the second application certificate is trustworthy, it provides services to the electronic device. The technical solution of the present application can avoid the technical problem of user personal privacy leakage caused by the exposure of device certificates, and has high security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular, to an authentication method, a readable medium, and an electronic device. Background Art

[0002] With the development of Internet information technology, people's daily lives increasingly rely on various intelligent electronic devices. For example, smart home devices provide users with a more intelligent home life experience; wearable intelligent electronic devices can plan exercise routes for users and monitor the users' health status; smart phones can provide users with intelligent experiences such as online shopping, chatting, office work, and learning. During the process of users using intelligent terminal devices, for services involving the interaction between intelligent terminal devices (such as smart phones) and cloud servers, especially services with high requirements for network security, such as payment services, the cloud server needs to verify the identity information of the intelligent terminal devices. However, in existing security authentication technical solutions, the identity information of intelligent terminal devices is prone to leakage. Typically, for example, the security certificates pre-installed on intelligent terminal devices are prone to leakage, so that the personal privacy data of users can be matched according to the leaked certificates of intelligent terminal devices, resulting in security risks when users use some functions of intelligent terminal devices. Summary of the Invention

[0003] Embodiments of this application provide an authentication method, a readable medium, and an electronic device. The technical solution of this application uses the certificate of a cloud server that has no association with the information of the terminal device to sign the service-level certificates involved in each of the foregoing terminal devices, obtaining the application certificates of each terminal device. Then, the application certificates are sent to the cloud server, and the cloud server or the certificate authentication server verifies the application certificates of each terminal device, and then returns the authentication result to each terminal device. Since the certificate of the cloud server has no association with the device information of the terminal device, the identification information of the terminal device will not be leaked, and thus the personal privacy information of the user cannot be matched according to the certificate of the cloud server, with high security.

[0004] In a first aspect, embodiments of this application provide an authentication method, which is applied to an electronic device and includes:

[0005] The electronic device uses the device identity information of the electronic device to sign the self-signed certificate generated by the application program of the electronic device, obtains the first application certificate, and sends the first application certificate to the authentication server; when the authentication server determines that the first application certificate is trustworthy, it signs the self-signed certificate in the first application based on the server identity information of the application server, obtains the second application certificate, and sends the second application certificate to the electronic device; when the electronic device determines that the second application certificate is trustworthy, it sends the second application certificate to the application server; and when the application server determines that the second application certificate is trustworthy, it provides services to the electronic device.

[0006] In a possible implementation of the first aspect above, the self-signed certificate is generated in the following manner:

[0007] Use the business data related to the user's privacy as the digital document of the self-signed certificate;

[0008] Use a preset self-signed digest algorithm to perform a hash calculation on the digital document to obtain the digest of the self-signed certificate;

[0009] Use a preset self-signed private key to sign the digest to obtain the signature of the self-signed certificate;

[0010] Generate a self-signed certificate based on the signature of the self-signed certificate, the self-signed digest algorithm, the digital document of the self-signed certificate, and the public key of the self-signature.

[0011] Among them, the process of using a preset self-signed private key to sign the digest is also the process of using a preset self-signed private key to encrypt the digest.

[0012] In a possible implementation of the first aspect above, the device identity information of the electronic device includes the device certificate of the electronic device.

[0013] The electronic device uses the device identity information of the electronic device to sign the self-signed certificate generated by the application program of the electronic device, obtaining the first application certificate, including:

[0014] The electronic device uses the first digest algorithm preset in the device certificate to perform a hash calculation on the complete content of the self-signed certificate to obtain the first digest;

[0015] The electronic device uses the private key of the device certificate to sign the first digest to obtain the first signature;

[0016] The electronic device obtains the first application certificate based on the first signature, the first digest algorithm, the complete content of the self-signed certificate, and the public key of the device certificate.

[0017] In a possible implementation of the above first aspect, the method further includes: after receiving the first application certificate, the authentication server verifies the first application certificate in the following manner:

[0018] The authentication server decrypts the first signature using the public key of the device certificate to obtain the first digest;

[0019] The authentication server performs a hash calculation on the complete content of the self-signed certificate using the first digest algorithm, and compares the hash calculation result with the first digest, and determines whether the first application certificate is trustworthy based on the comparison result.

[0020] That is, the process of the authentication server verifying the signature of the first application certificate using the public key of the device certificate includes: the authentication server decrypts the first signature using the public key of the device certificate, and compares the first digest obtained by decryption with the result of performing a hash calculation on the complete content of the self-signed certificate using the first digest algorithm.

[0021] In a possible implementation of the above first aspect, the server identity information of the application server includes an application server certificate,

[0022] When the authentication server determines that the first application certificate is trustworthy, based on the server identity information of the application server, it signs the self-signed certificate in the first application to obtain a second application certificate, including:

[0023] When the authentication server determines that the first application certificate is trustworthy, it performs a hash calculation on the complete content of the self-signed certificate in the first application certificate using a preset second digest algorithm to obtain a second digest;

[0024] Sign the second digest using the private key of the application server certificate to obtain a second signature;

[0025] Based on the second signature, the second digest algorithm, the complete content of the self-signed certificate, and the public key of the application server certificate, obtain the second application certificate.

[0026] In a possible implementation of the above first aspect, the method further includes: after receiving the second application certificate, the electronic device verifies the second application certificate in the following manner:

[0027] The electronic device decrypts the second signature using the public key of the application server certificate to obtain a second digest;

[0028] Perform a hash calculation on the complete content of the self-signed certificate using the second digest algorithm, and compare the hash calculation result with the second digest, and determine whether the second application certificate is trustworthy based on the comparison result.

[0029] In a possible implementation of the first aspect above, the method further includes: after receiving the second application certificate, the application server verifies the second application certificate in the following manner:

[0030] The application server decrypts the second signature using the public key of the application server certificate to obtain a second digest;

[0031] Perform a hash calculation on the complete content of the self-signed certificate using the second digest algorithm, and compare the hash calculation result with the second digest. Based on the comparison result, determine whether the second application certificate is trustworthy.

[0032] In a possible implementation of the first aspect above, the method further includes: after receiving the second application certificate, the application server calls the authentication server to verify the second application certificate in the following manner:

[0033] The authentication server decrypts the second signature using the public key of the application server certificate to obtain a second digest;

[0034] Perform a hash calculation on the complete content of the self-signed certificate using the second digest algorithm, and compare the hash calculation result with the second digest. Based on the comparison result, determine whether the second application certificate is trustworthy, and return the authentication result to the application server.

[0035] In a second aspect, an embodiment of the present application provides a computer-readable storage medium, on which instructions are stored. When the instructions are executed on an electronic device, the electronic device is caused to execute any one of the methods in the first aspect and various possible implementations of the first aspect.

[0036] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0037] A memory for storing instructions executed by one or more processors of the electronic device, and

[0038] A processor that, when the instructions are executed by one or more processors, is configured to execute any one of the methods in the first aspect and various possible implementations of the first aspect. Description of the Drawings

[0039] Figure 1 According to some embodiments of the present application, a schematic diagram of a scenario for communication between a terminal device and a cloud server is shown;

[0040] FIG. 2(a) exemplarily shows a technical solution for security authentication;

[0041] FIG. 2(b) exemplarily shows a certificate chain involved in the technical solution shown in FIG. 2(a);

[0042] Figure 2(c) exemplarily shows another technical solution for security authentication;

[0043] Figure 3 According to some embodiments of the present application, a structural diagram of a security authentication system provided by the present application is shown;

[0044] Figure 4 According to some embodiments of the present application, it shows Figure 3 an interaction flowchart between various devices in the shown security authentication system;

[0045] Figures 5(a) to 5(c) Exemplarily shows the display interface of a shopping APP on a mobile phone;

[0046] Figure 5(d) exemplarily shows Figure 3 in the shown security authentication system, a certificate chain of a second application certificate obtained by the certificate authentication server signing with a cloud server certificate;

[0047] Figure 5(e) exemplarily shows the display interface of the shopping APP on the mobile phone after payment is completed;

[0048] Figure 6 According to some embodiments of the present application, it shows Figure 3 another interaction flowchart between various devices in the shown security authentication system;

[0049] Figure 7 According to some embodiments of the present application, a hardware structure diagram of a mobile phone is shown. Detailed implementation manners

[0050] Exemplary embodiments of the present application include but are not limited to an authentication method, a readable medium, and an electronic device.

[0051] To better understand the technical solutions of the present application, some terms related to the embodiments of the present application are first described.

[0052] (1) Digital certificate

[0053] A digital certificate refers to an electronic certificate issued by a Certificate Authority (CA) for identifying the identity information of the digital certificate holder (such as a terminal device). It provides a way to verify the identity of the communication peer. A digital certificate may include public key information assigned by the CA to the digital certificate holder, identity information of the digital certificate holder, and signature information of the CA, etc.

[0054] Among them, the CA is an authoritative institution responsible for issuing and managing digital certificates. As a trusted third party in the network, the CA can verify the identity of the digital certificate application device, manage and update digital certificates, maintain the digital certificate revocation list, etc.

[0055] (2) Root certificate

[0056] The root certificate is the basis for the CA certification center to establish a trust relationship with other electronic devices. It is a digital certificate issued by the CA to itself and is the starting point of the trust chain. To verify the authenticity of a certificate (i.e., to verify whether the signature of the CA center on the certificate information is valid), the public key of the CA center needs to be used for verification. And the public key of the CA center exists in the certificate that signs this certificate, that is, the public key of the CA center exists in the root certificate issued by the CA to itself. Therefore, an electronic device needs to pre-install a root certificate in the device to verify the authenticity of a certificate.

[0057] The technical solution of the present application will be introduced in detail below with reference to the accompanying drawings.

[0058] First, in combination with Figure 1 introduce the scenarios applicable to the technical solution of the present application. Figure 1 According to some embodiments of the present application, a schematic diagram of a scenario for communication between a terminal device and a cloud server is shown. It includes multiple terminal devices 100 (including terminal devices 100-1 to terminal devices 100-N) and a cloud server 200. Multiple application programs (applications, APPs) can be installed on each terminal device 100, such as: instant messaging APP, shopping APP, game APP, video playback APP, office APP, map APP, etc., so as to provide users with various functions such as chatting, shopping, gaming, audio-visual, office, and navigation.

[0059] Generally, when the terminal device 100 sends business data of some applications to the cloud server 200, in order to verify whether the terminal device 100 is a legitimate device and to avoid the business data sent by the terminal device 100 from being hijacked or tampered with, the cloud server 200 needs to verify the identity information of the terminal device 100 and needs to verify the integrity of the business data sent by the terminal device 100. For example, the cloud server 200 verifies the device certificate of the terminal device 100 and the application certificate corresponding to the application that initiates a business request on the terminal device 100. It can be understood that an illegal device does not have a corresponding device certificate, and the business data that has been hijacked or tampered with is incomplete.

[0060] In some security authentication technical solutions, such as the security authentication technology shown in Fig. 2(a), in order to verify the identity information of the terminal device 100 and the integrity of the service data sent by the terminal device 100, on the side of the terminal device 100, an application certificate is issued by the device certificate pre-set in the terminal device 100, and on the side of the cloud server 200, the application certificate issued by the received device certificate is verified. Specifically, the principle of the security authentication technology shown in Fig. 2(a) generally includes the following content:

[0061] When each terminal device 100 runs some of its own APPs, the APPs involved in each terminal device 100 generate corresponding service-level certificates (i.e., certificates self-signed by the APPs), and then each terminal device 100 signs the aforementioned certificates self-signed by the APPs with its own device certificate to obtain an application certificate. Then, the application certificate is sent to the cloud server 200, and the cloud server 200 performs security authentication on the directly received application certificate, or sends the application certificate to a dedicated certificate authentication server 300 for verification, and then returns the authentication result to each terminal device 100. Among them, the device certificate of each terminal device 100 is: before the device leaves the factory, a subordinate certificate (i.e., a sub-certificate of the CA root certificate) re-issued by the terminal device supplier based on the root certificate issued by the CA for the terminal device supplier. The root certificate, device certificate, application certificate, and service-level certificate involved above form a certificate chain as shown in Fig. 2(b). Referring to Fig. 2(b), the certificate on the left side of the arrow is the upper-level certificate (i.e., the parent certificate) of the certificate on the right side of the arrow. Correspondingly, the certificate on the right side of the arrow is the lower-level certificate (i.e., the sub-certificate) of the certificate on the left side of the arrow. It should be noted that Fig. 2(b) above is only an example of the certificate chain composed of the root certificate, device certificate, application certificate, and service-level certificate involved in this application. In actual application scenarios, the levels of each certificate are variable. For example, the application certificate has multiple levels or zero levels; another example is that the service-level certificate has multiple levels or zero levels. This application does not make any limitations in this regard. However, in the security authentication technical solution shown in Fig. 2(a), since the device certificate of each terminal device 100 is unique and the device certificate contains the device information of the terminal device 100, such as the serial number (Serial Number) of the device, etc., the device certificate can be used as the identification information of each terminal device 100. When the device certificate is intercepted, it is possible to match the personal data of the user based on the device certificate of each terminal device 100, and there is a risk of leaking user privacy.

[0062] To address the potential problem of user privacy leakage in the security authentication technical solution shown in Fig. 2(a), in some security authentication technical solutions, such as the security authentication technology shown in Fig. 2(c), by presetting the same device certificate in each terminal device 100, using the same device certificate to sign the self-signed certificates of the aforementioned APPs in each terminal device 100, an application certificate is obtained. Then the application certificate is sent to the cloud server 200, and the cloud server 200 or the certificate authentication server 300 verifies the application certificates of each terminal device 100, and then returns the authentication result to each terminal device 100.

[0063] However, in the security authentication technical solution shown in Fig. 2(c), since each terminal device 100 uses the same device certificate to sign its respective business-level certificates, if the private key of this device certificate is leaked, it will bring security risks to multiple terminal devices involved in this certificate.

[0064] Therefore, to solve the above technical problems, in the security authentication technical solution provided in this application, the certificate of the cloud server 300 that has no association with the terminal device 100 is used to sign the business-level certificates involved in each of the aforementioned terminal devices 100, obtaining the application certificates of each terminal device 100. Then the application certificates are sent to the cloud server 200, and the cloud server 200 or the certificate authentication server 300 verifies the application certificates of each terminal device 100, and then returns the authentication result to each terminal device 100. Since the certificate of the cloud server 300 has no association with the terminal device 100, it will not leak the identification information of the terminal device 100, and thus it is impossible to match and obtain the user's personal privacy information based on the certificate of the cloud server 300, with high security.

[0065] In addition, it should be noted that the above terminal device 100 can be any electronic device that can install an APP and can communicate with the cloud server 200, including but not limited to tablet computers, smart phones, laptop computers, desktop computers, wearable electronic devices, head-mounted displays, mobile email devices, portable game consoles, portable music players, reader devices, televisions in which one or more processors are embedded or coupled, or other electronic devices with relatively high computing power that can access the network. Wearable electronic devices include but are not limited to smart watches, smart bracelets, smart glasses, smart helmets, smart headbands, and so on.

[0066] The following will combine Figure 3 to introduce the structure of a security authentication system applicable to the technical solution of this application. As Figure 3 shown, the system includes multiple terminal devices 100, a cloud server 200, and a certificate authentication server 300.

[0067] The terminal device 100 (denoted as terminal devices 100-1 to 100-N respectively) includes an application program 112, a certificate authentication service module 111, and a storage module 113. For example, Figure 3 the illustrated terminal device 100-1 includes an application program 112', a certificate authentication service module 111', and a storage module 113'; the terminal device 100-2 includes an application program 112", a certificate authentication service module 111", and a storage module 113"; the terminal device 100-N includes an application program 112"', a certificate authentication service module 111"', and a storage module 113"'.

[0068] Among them, the application program 112 can be any APP that needs to request services from the cloud server 200. For example: payment APP, instant messaging APP, shopping APP, game APP, video playback APP, office APP, map APP, etc., so as to provide users with various functions such as online payment, chatting, shopping, gaming, audio and video, office, and navigation.

[0069] In some embodiments, when the application program 112 runs, if it needs to request services from the cloud server 200, in order to ensure the security of data transmission, the application program 112 will generate a call instruction to call functions such as certificate issuance and certificate authentication of the certificate authentication service module 111.

[0070] In some embodiments, the certificate authentication service module 111 is used to respond to the call instruction generated by the application program 112, generate a self-signed certificate (business-level certificate) corresponding to the application program 112 that generates the call instruction, obtain the device certificate pre-set in the terminal device 100, and then use the device certificate to sign the above self-signed certificate to obtain a first application certificate. The certificate authentication service module 111 can also be used to send the first application certificate to the certificate authentication server 300 for security authentication, receive the authentication result returned by the certificate authentication server 300, and the second application certificate reissued by the certificate authentication server 300 based on the pre-set cloud server certificate. In addition, the certificate authentication service module 111 can also be used to return the received second application certificate to the application program 112.

[0071] Among them, the process of the certificate authentication service module 111 using the device certificate to sign the above self-signed certificate to obtain the first application certificate is as follows: the certificate authentication service module 111 uses a preset first digest algorithm to perform a hash calculation on the complete content of the above self-signed certificate (denoted as the first digital document), signs the result of the hash calculation (denoted as the first digest) with the private key of the device certificate to obtain the signature of the first application certificate (denoted as the first signature), and then the first application certificate is composed of the first signature, the first digest algorithm, the first digital document, and the public key of the device certificate (denoted as the first public key).

[0072] In some embodiments, the storage module 113 is configured to store the device certificate of the terminal device 100. For example, the storage module 113 is configured to store the device certificate issued by the CA. In response to the call instruction generated by the application 112, the certificate authentication service module 111 obtains the device certificate from the storage module 113, and then signs the self-signed certificate with the device certificate to obtain the first application certificate. In some embodiments, the storage module 113 is further configured to store the second application certificate returned by the certificate authentication service module 111.

[0073] In some embodiments, the certificate authentication server 300 is configured to perform security authentication on the above-mentioned first application certificate sent by the certificate authentication service module 111 of the terminal device 100, and then re-sign the first application certificate based on the preset cloud server certificate to obtain the second application certificate. In some embodiments, the certificate authentication server 300 is further configured to, when the cloud server 200 needs to verify the second application certificate of the application 112, replace the cloud server 200 to perform the verification on the second application certificate of the application 112.

[0074] Wherein, the process of the certificate authentication server 300 performing security authentication on the above-mentioned first application certificate is as follows: First, the certificate authentication server 300 verifies the public key (i.e., the first public key) of the device certificate through the preset root certificate corresponding to the device certificate. When it is confirmed that the public key of the device certificate is legal, the certificate authentication server 300 decrypts the first signature in the first application certificate with the public key of the device certificate, and then performs a hash calculation on the first digital document using the first digest algorithm in the first application certificate to obtain a new digest. The new digest is compared with the first digest in the first application certificate. If the two are consistent, it indicates that the first application certificate is legal.

[0075] After verifying the legality of the first application certificate, the specific process by which the certificate authentication server 300 re-signs the first application certificate based on the pre-set cloud server certificate to obtain the second application certificate is as follows: The certificate authentication server 300 uses a pre-set second digest algorithm to perform a hash calculation on the first digital document in the first application certificate (i.e., the complete content of the self-signed certificate of the above-mentioned application program 112) to obtain a new digest (denoted as the second digest). The second digest is signed with the private key of the cloud server certificate to obtain a new signature (denoted as the second signature). Then, the second application certificate is composed of the second signature, the second digest algorithm, the first digital (i.e., the complete content of the self-signed certificate of the above-mentioned application program 112) document, and the public key of the cloud server certificate (denoted as the second public key). From the above process, it can be seen that the second application certificate does not involve any information of the terminal device 100 at all. Therefore, in the process of the application program 112 sending the second application certificate to the cloud server 200, even if the second application certificate is intercepted, no information of the terminal device 100 can be matched based on the second application certificate, and the information of the terminal device 100 will not be leaked. Thus, it is even more impossible to match the personal privacy data of the user based on the second application certificate, and the security is high.

[0076] In some embodiments, the cloud server 200 is used to directly verify the second application certificate after receiving the second application certificate sent by the application program 112 of the terminal device 100. In some embodiments, the cloud server 200 is used to, after receiving the second application certificate sent by the application program 112 of the terminal device 100, send the second application certificate to the certificate authentication server 300, and the certificate authentication server 300 verifies the second application certificate and returns the verification result to the application program 112 of the terminal device 100.

[0077] It can be understood that the above Figure 3 merely shows an exemplary structural diagram of a security authentication system applicable to the technical solution of the present application. A security authentication system with other structures and capable of implementing similar functions is also applicable to the technical solution of the present application, and no limitation is made here.

[0078] Next, in combination with Figure 1 the following scenario diagram, and Figure 3 a structural diagram of a security authentication system shown, taking the terminal device 100 as a mobile phone and the application program 112 installed on the mobile phone as a shopping APP to request a payment service from the cloud server 200 as an example, the technical solution of the present application will be introduced in detail. Specifically, as Figure 4 shown, in the process of the shopping APP installed on the mobile phone 100 requesting a service from the cloud server 200, the security authentication process involved includes the following steps:

[0079] Step 401: The application 112 of the mobile phone 100 starts to run.

[0080] For example, in the embodiment shown in FIG. 5(a), the user clicks on the icon 113 of the shopping APP on the desktop of the mobile phone 100. In response to the user's click operation, the mobile phone 100 opens the shopping APP and enters the product display interface shown in FIG. 5(b). After the user selects a product 2 from the product display interface shown in FIG. 5(b), the mobile phone 100 enters the payment interface shown in FIG. 5(c), which includes a "payment account prompt box" 114, a "payment method prompt box" 115, and a "facial recognition prompt box" 116. After the user determines the payment account and payment method, the mobile phone 100 captures a face image and performs face recognition on the user's face image to compare it with the reference face ID of the user pre-stored in the mobile phone 100, so as to verify the user's face. After the verification passes, the payment process is entered.

[0081] It can be understood that the above method of verifying the user's identity through face recognition is only an example of the mobile phone 100 verifying the user's identity. In some embodiments, the mobile phone 100 can also collect other biometric information of the user, and then authenticate the user based on the other biometric information of the user collected. Among them, the other biometric information of the user can include one or more of fingerprint information, voiceprint information, and iris information.

[0082] Step 402: The application 112 of the mobile phone 100 sends an instruction to the certificate authentication service module 111 of the mobile phone 100 to call the certificate authentication service module 111 of the mobile phone 100 to perform related operations such as certificate generation and certificate authentication.

[0083] For example, after the shopping APP shown in FIG. 5(c) verifies the user's identity and obtains the verification result, in order to prevent some sensitive business data including the verification result from being tampered with during the process of being sent to the cloud server 200, a business-level certificate can be generated for these sensitive business data, and other legitimate certificates are used to sign the business-level certificate to make the business-level certificate trusted. In some embodiments, the shopping APP of the mobile phone 100 can send an instruction to the certificate authentication service module 111 of the mobile phone 100 to call the certificate authentication service module 111 of the mobile phone 100 to generate a business-level certificate for these sensitive business data, and use the trusted device certificate to sign the business-level certificate, thereby trusting the business-level certificate. Among them, these sensitive business data can include data such as the verification result of the user's identity and the verification timestamp.

[0084] Step 403: The certificate authentication service module 111 of the mobile phone 100 generates a self-signed certificate.

[0085] After receiving the instruction sent by the application 112 of the mobile phone 100, the certificate authentication service module 111 of the mobile phone 100 generates a self-signed certificate based on the above-mentioned sensitive service data in response to the instruction. For example, in some embodiments, the certificate authentication service module 111 of the mobile phone 100 signs the above-mentioned sensitive service data to obtain a self-signed certificate. In some embodiments, the generation process of the self-signed certificate may be as follows: The certificate authentication service module 111 of the mobile phone 100 uses the sensitive service data including the verification result of the user identity generated by the shopping APP as the digital document of the self-signed certificate, performs a hash calculation on the digital document using a preset digest algorithm to obtain the digest of the self-signed certificate, then signs the generated digest using a custom private key to obtain the signature of the self-signed certificate, and then constructs the self-signed certificate (i.e., the service-level certificate) of the shopping APP with the signature, digest, digital document (sensitive service data including the verification result of the user identity), and the public key corresponding to the custom private key.

[0086] Step 404: The certificate authentication service module 111 of the mobile phone 100 sends an instruction to obtain the device certificate to the storage module 113 of the mobile phone 100.

[0087] Step 405: The storage module 113 of the mobile phone 100 returns the device certificate to the certificate authentication service module 111.

[0088] In some embodiments, the device certificate is a legal certificate (i.e., a trusted certificate) issued by the CA stored in the storage module 113 of the mobile phone 100, and the CA root certificate is the superior certificate (i.e., the parent certificate) of the device certificate.

[0089] It should be noted that for security performance considerations, the storage area storing the device certificate in the storage module 113 is generally the secure storage area of the mobile phone 100, and the application 112 of the mobile phone 100 cannot directly access this secure storage area. Therefore, the application 112 can execute corresponding instructions through the application program interface (Application Program Interface, API) between the application 112 and the operating system of the mobile phone 100 to use the device certificate stored in the secure storage area of the storage module 113.

[0090] Step 406: The certificate authentication service module 111 of the mobile phone 100 signs the self-signed certificate using the device certificate to obtain the first application certificate. Thus, the self-signed certificate becomes a trusted certificate.

[0091] For example, the process by which the certificate authentication service module 111 of the mobile phone 100 signs the above self-signed certificate with the device certificate to obtain the first application certificate is as follows: The certificate authentication service module 111 uses a preset first digest algorithm to perform a hash calculation on the complete content of the above self-signed certificate (denoted as the first digital document), signs the result of the hash calculation (denoted as the first digest) with the private key of the device certificate to obtain the signature of the first application certificate (denoted as the first signature), and then the first signature, the first digest algorithm, the first digital document, and the public key of the device certificate (denoted as the first public key), etc. constitute the first application certificate.

[0092] Step 407: The certificate authentication service module 111 of the mobile phone 100 sends the first application certificate to the certificate authentication server 300.

[0093] In some embodiments, the certificate authentication service module 111 of the mobile phone 100 sends a certificate chain similar to Figure 2(b) including the first application certificate to the certificate authentication server 300. The trust levels of this certificate chain from high to low are: the CA root certificate of the terminal device vendor, the device certificate, the first application certificate, and the service-level certificate.

[0094] Step 408: The certificate authentication server 300 verifies whether the first application certificate is legal. If so, it indicates that the first application certificate is legal and proceeds to step 411; otherwise, it indicates that the first application certificate is illegal and proceeds to step 409.

[0095] For example, the certificate authentication server 300 performs security authentication on the above first application certificate in the following manner: The certificate authentication server 300 decrypts the first signature in the first application certificate with the public key of the device certificate, then uses the first digest algorithm in the first application certificate to perform a hash calculation on the first digital document to obtain a new digest, and compares this new digest with the first digest in the first application certificate. If the two are consistent, it indicates that the first application certificate is legal and proceeds to step 411; otherwise, it indicates that the first application certificate is illegal and proceeds to step 409.

[0096] Step 409: The certificate authentication server 300 returns the verification result to the application 112 of the mobile phone 100. That is, if the certificate authentication server 300 returns the result that the identity authentication of the first application certificate is illegal to the application 112 of the mobile phone 100, it proceeds to step 410 and terminates the process of requesting the service.

[0097] For example, in some embodiments, the certificate authentication server 300 returns the result that the identity authentication of the first application certificate is illegal to the certificate authentication service module 111 of the mobile phone 100, and the certificate authentication server 300 then sends this result to the shopping APP of the mobile phone 100.

[0098] Step 410: The application 112 of the mobile phone 100 terminates the process of requesting service.

[0099] For example, in some embodiments, after the shopping APP of the mobile phone 100 receives the result that the identity authentication of the first application certificate is illegal, it terminates the process of requesting the payment service from the cloud server 200.

[0100] Step 411: The certificate authentication server 300 uses the preset cloud server certificate to re-sign the self-signed certificate included in the first application certificate to obtain a second application certificate.

[0101] That is, after the certificate authentication server 300 verifies the legitimacy of the identity of the first application certificate, in order to prevent the application 112 of the mobile phone 100 from leaking the identity information of the mobile phone 100 in the process of requesting services from the cloud server 200, thereby causing criminals to use the leaked identity information of the mobile phone 100 in combination with big data technology to obtain the user's personal privacy, the relationship between the business data of the application 112 of the mobile phone 100 and the mobile phone 100 is terminated, and the self-signed certificate contained in the first application certificate is re-signed through a preset certificate of another trusted cloud server 200 that has nothing to do with the identity information of the mobile phone 100, and the second application certificate is re-trusted.

[0102] In some embodiments, after the certificate authentication server 300 verifies the legitimacy of the first application certificate, the certificate authentication server 300 re-signs the first application certificate based on the preset cloud server certificate to obtain the second application certificate. The specific process is as follows: the certificate authentication server 300 uses the preset second digest algorithm to perform hash calculation on the first digital document in the first application certificate (i.e., the complete content of the shopping APP self-signed certificate) to obtain a new digest (referred to as the second digest), and the second digest is signed with the private key of the cloud server certificate to obtain a new signature (referred to as the second signature), and then the second signature, the second digest algorithm, the first digital document (i.e., the complete content of the shopping APP self-signed certificate) and the public key of the cloud server certificate (referred to as the second public key) constitute the second application certificate. It can be seen from the above process that the second application certificate does not involve any information of the terminal device 100 at all. Therefore, in the process of the shopping APP sending the second application certificate to the cloud server 200, even if the second application certificate is intercepted, it is impossible to match any information of the mobile phone 100 based on the second application certificate, and will not cause the leakage of the mobile phone 100 information, and thus it is even more impossible to match the user's personal privacy data based on the second application certificate, and the security is high.

[0103] Step 412 : the certificate authentication server 300 returns the second application certificate to the certificate authentication service module 111 of the mobile phone 100 .

[0104] In some embodiments, the certificate authentication server 300 returns to the certificate authentication service module 111 of the mobile phone 100 a certificate chain as shown in FIG. 5(d) including the second application certificate. The trust levels of this certificate chain, from high to low, are as follows: the CA root certificate of the cloud server certificate of the terminal device vendor (such as the mobile phone vendor), the cloud server certificate of the terminal device vendor, the second application certificate, and the service-level certificate (i.e., the aforementioned self-signed certificate).

[0105] Step 413: The certificate authentication service module 111 of the mobile phone 100 verifies whether the second application certificate is legal. If so, it indicates that the second application certificate is legal, and proceeds to step 415; otherwise, the second application certificate is illegal, and proceeds to step 414.

[0106] It can be understood that after the certificate authentication service module 111 of the mobile phone 100 receives the second application certificate returned by the certificate authentication server 300, in order to verify whether the second application certificate has been tampered with during the transmission process, it is also necessary to verify the legality of the second application certificate. In some embodiments, the certificate authentication service module 111 of the mobile phone 100 verifies the second application certificate returned by the certificate authentication server 300 in the following manner: The certificate authentication service module 111 of the mobile phone 100 uses the public key of the cloud server certificate (i.e., the aforementioned second public key) to decrypt the second signature in the second application certificate to obtain a second digest, and then uses the second digest algorithm in the second application certificate to perform a hash calculation on the first digital document in the second application certificate (i.e., the complete content of the aforementioned shopping APP self-signed certificate) to obtain a new digest. Compare the new digest obtained by decryption with the new digest. If the two values are the same, it indicates that the second application certificate is legal, and proceeds to step 415; otherwise, the second application certificate is illegal, and proceeds to step 414.

[0107] Step 414: The certificate authentication service module 111 of the mobile phone 100 returns the verification result to the application 112 of the mobile phone 100. That is, when the certificate authentication service module 111 of the mobile phone 100 determines that the second application certificate is illegal, it returns to the application 112 of the mobile phone 100 the verification result that the second application certificate is illegal. After the application 112 of the mobile phone 100 receives this result, it proceeds to step 410 and terminates the process of requesting services from the cloud server 200. For example, after the shopping APP of the mobile phone 100 receives the verification result that the second application certificate is illegal, it proceeds to step 410 and terminates the process of requesting payment services from the cloud server 200.

[0108] Step 415: The certificate authentication service module 111 of the mobile phone 100 sends the second application certificate to the application 112 of the mobile phone 100. That is, when the certificate authentication service module 111 of the mobile phone 100 determines that the second application certificate is legal, it returns the second application certificate to the application 112 of the mobile phone 100, so that the application 112 can send the second application certificate to the cloud server 200 for identity authentication when requesting services from the cloud server 200. After receiving the second application certificate, the application 112 of the mobile phone 100 enters Step 416. For example, after the shopping APP of the mobile phone 100 receives the second application certificate, it enters Step 416 and continues to send the second application certificate to the cloud server 200.

[0109] Step 416: The application 112 of the mobile phone 100 sends the second application certificate to the cloud server 200.

[0110] In some embodiments, what the application 112 of the mobile phone 100 sends to the cloud server 200 is a certificate chain as shown in FIG. 5(d) including the second application certificate.

[0111] Step 417: The cloud server 200 verifies whether the second application certificate is legal. If so, it indicates that the second application certificate is legal and enters Step 419; otherwise, the second application certificate is illegal and enters Step 418.

[0112] In some embodiments, after the cloud server 200 receives the second application certificate sent by the application 112 of the mobile phone 100, it can verify the second application certificate by a method similar to that in Step 413. For specific details, please refer to the relevant description in Step 413 above and will not be elaborated here.

[0113] Step 418: The cloud server 200 returns a reply message of denying service to the application 112 of the mobile phone 100. That is, when the cloud server 200 verifies that the second application certificate is illegal, it refuses to provide services for the application 112 of the mobile phone 100 and returns a reply message of denying service to the application 112 of the mobile phone 100. For example, in some embodiments, when the cloud server 200 verifies that the second application certificate is illegal, it refuses to provide a deduction service for the shopping APP of the mobile phone 100 and returns a reply message of denying deduction to the shopping APP of the mobile phone 100.

[0114] Step 419: The cloud server 200 executes the corresponding service. That is, when the cloud server 200 verifies that the second application certificate is legal, it provides services for the application 112 of the mobile phone 100. For example, in some embodiments, when the cloud server 200 verifies that the second application certificate is legal, it executes a deduction service for the shopping APP of the mobile phone 100.

[0115] Step 420: The cloud server 200 returns a reply message indicating the completion of the service to the application 112 of the mobile phone 100. For example, in some embodiments, after the cloud server 200 completes the deduction, it returns a reply message indicating the completion of the deduction to the shopping APP of the mobile phone 100. After receiving this reply message, the shopping APP of the mobile phone 100 displays a prompt message indicating successful payment as shown in FIG. 5(e).

[0116] The above content, combined with Figure 4 , takes the shopping APP installed on the mobile phone 100 requesting a payment service from the cloud server 200 as an example to introduce the technical solution of the present application in detail. Among them, after receiving the second application certificate sent by the application 112 of the mobile phone 100, the cloud server 200 directly verifies the second application certificate. In some embodiments, as Figure 6 shown, after receiving the second application certificate sent by the application 112 of the mobile phone 100, the cloud server 200 can also send the second application certificate and a verification instruction to the certificate authentication server 300 through the interface between the cloud server 200 and the certificate authentication server 300, and the certificate authentication server 300 performs the verification of the second application certificate.

[0117] Since Figure 6 the steps 401 to 416 in the interaction diagram shown are similar to the steps 401 to 416 in the interaction diagram Figure 4 shown, for the sake of simplicity of description, only the steps 417' to 423' that are different from the interaction diagram Figure 6 in Figure 4 shown will be introduced below. Specifically, as Figure 6 shown, the specific steps of 417' to 423' are as follows:

[0118] Step 417': The cloud server 200 sends the second application certificate and a verification instruction to the certificate authentication server 300. For example, after receiving the second application certificate sent by the application 112 of the mobile phone 100, the cloud server 200 uses the communication interface with the certificate authentication server 300 to send the second application certificate and a verification instruction to the certificate authentication server 300.

[0119] Step 418': The certificate authentication server 300 verifies the second application certificate. For example, after receiving the second application certificate and the verification instruction sent by the cloud server 200, in response to this instruction, the certificate authentication server 300 uses a method similar to step 413 in Figure 4 to verify the second application certificate.

[0120] Step 419': The certificate authentication server 300 returns the verification result to the cloud server 200.

[0121] Step 420': The cloud server 200 determines whether the second application certificate is legal according to the verification result. If so, it indicates that the second application certificate is legal, and proceeds to Step 422'. Otherwise, it indicates that the second application certificate is illegal, and proceeds to Step 421'.

[0122] Step 421': The cloud server 200 returns a rejection message from the server to the application 112 of the mobile phone 100. That is, when the cloud server 200 determines that the second application certificate is illegal, it refuses to provide services to the application 112 of the mobile phone 100 and returns a rejection message for the service to the application 112 of the mobile phone 100. For example, in some embodiments, when the cloud server 200 determines that the second application certificate is illegal, it refuses to provide a deduction service for the shopping APP of the mobile phone 100 and returns a rejection message for the deduction to the shopping APP of the mobile phone 100.

[0123] Step 422': The cloud server 200 executes the corresponding service. That is, when the cloud server 200 determines that the second application certificate is legal, it provides services to the application 112 of the mobile phone 100. For example, in some embodiments, when the cloud server 200 determines that the second application certificate is legal, it executes a deduction service for the shopping APP of the mobile phone 100.

[0124] Step 423': The cloud server 200 returns a response message indicating the completion of the service to the application 112 of the mobile phone 100. For example, in some embodiments, after the cloud server 200 completes the deduction, it returns a response message indicating the completion of the deduction to the shopping APP of the mobile phone 100. After receiving this response message, the shopping APP of the mobile phone 100 displays a prompt message indicating successful payment as shown in FIG. 5(e).

[0125] Figure 7 According to an embodiment of the present application, a schematic diagram of the hardware structure of a mobile phone 100 is shown.

[0126] The mobile phone 100 can execute the display method provided by the embodiment of the present application. In Figure 7 , similar components have the same reference numerals. As Figure 7As shown in the figure, the mobile phone 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. Among them, the sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0127] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on the mobile phone 100. In other embodiments of the present application, the mobile phone 100 may include more or fewer components than those shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0128] Specifically, such as Figure 7As shown in the figure, the above structure of the mobile phone 100 determines the types of functional components that the mobile phone 100 has and the various types of capabilities that it can implement. For example, the voice processing capability of the mobile phone 100 can be implemented based on the audio module 170 and the processor 110 in the above structure. Due to the different structural functions of the components that make up the audio module 170 and the functional differences of different processing units in the processor 110, the voice processing capability of the mobile phone 100 can be refined and split into the capabilities corresponding to multiple functional components, such as voice collection capability, voice recognition capability, voice conversion capability, and voice synthesis capability, etc. Another example is that the photographing capability, image processing capability, display capability, etc. required for the photographing application can be implemented based on the processor 110, the camera 193, the display screen 194, and the internal memory 121 in the above structure. Among them, the image processing capability can also be split into beautification processing capability, beauty capability, etc., and the capabilities corresponding to multiple functional components, such as the photographing capability of the camera or the camera, the image processing capability (including), etc. Therefore, the various application functions run by the mobile phone 100 can ultimately be realized through a certain functional component or the cooperation of multiple functional components. The level of the capability of each functional component depends on the system configuration, software and hardware configuration, and real-time operation dynamic information of the mobile phone 100, etc.

[0129] The following takes the above structures of the mobile phone 100 and the partial capabilities based on some functional components as examples for introduction.

[0130] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors. Among them, the controller can generate operation control signals according to the instruction operation code and the timing signal to complete the control of fetching instructions and executing instructions. In some embodiments of the present application, the processor 110 can also be used to verify the second application certificate returned by the device authentication server 300 (that is, the service-level certificate re-signed by the device authentication server 300 using the cloud server certificate).

[0131] The internal memory 121 can be used to store data, software programs, and modules. It can be a volatile memory, such as a random-access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or a combination of the above types of memories, or it can also be a removable storage medium, such as a Secure Digital (SD) memory card. In some embodiments of the application, the internal memory 121 is used to store the device certificate issued by the CA for the mobile phone 100.

[0132] The charging management module 140 is used to receive charging input from a charger. The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives inputs from the battery 142 and / or the charging management module 140 to supply power to the processor 110, the internal memory 121, the display screen 194, the camera 193, the wireless communication module 160, etc. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be disposed in the processor 110. In some other embodiments, the power management module 141 and the charging management module 140 can also be disposed in the same device.

[0133] The wireless communication function of the mobile phone 100 can be implemented by the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modulation and demodulation processor, and the baseband processor, etc. In some embodiments, the antenna 1 of the mobile phone 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the mobile phone 100 can communicate with the network and other devices through wireless communication technologies.

[0134] The mobile phone 100 implements the display function through the GPU, the display screen 194, and the application processor, etc. The GPU is a microprocessor for image processing, and is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.

[0135] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oled, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the display screen 194 is used to display the user interfaces of various application programs 112, such as the product display interface, the payment interface, the payment success interface, etc. of the shopping APP. The sensor module 190 can include a proximity light sensor, a pressure sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, etc.

[0136] The audio module 150 can convert digital audio information into an analog audio signal for output, or convert an analog audio input into a digital audio signal. The audio module 150 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 150 can be disposed in the processor 110, or some functional modules of the audio module 150 can be disposed in the processor 110.

[0137] The sensor module 180 can include a proximity light sensor, a pressure sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, etc.

[0138] In some embodiments, the mobile phone 100 further includes a key 190, a motor 191, and an indicator 192, etc. Among them, the key 190 can include a volume key, a power on / off key, etc. The motor 191 is used to make the mobile phone 100 produce a vibration effect. The indicator 192 can include a laser indicator, a radio frequency indicator, an LED indicator, etc.

[0139] Embodiments of the mechanisms disclosed in this application can be implemented in hardware, software, firmware, or combinations of these implementation methods. Embodiments of this application can be implemented as a computer program or program code executed on a programmable system, which includes at least one processor, a storage system (including volatile and non-volatile memories and / or storage elements), at least one input device, and at least one output device.

[0140] The program code can be applied to the input instructions to perform the various functions described in this application and generate output information. The output information can be applied to one or more output devices in a known manner. For the purposes of this application, a processing system includes any system having a processor such as, for example, a Digital Signal Processor (DSP), a microcontroller, an Application Specific Integrated Circuit (ASIC), or a microprocessor.

[0141] The program code can be implemented in a high-level procedural language or an object-oriented programming language to communicate with the processing system. When necessary, the program code can also be implemented in assembly language or machine language. In fact, the mechanisms described in this application are not limited to the scope of any specific programming language. In any case, the language can be a compiled language or an interpreted language. In some cases, the disclosed embodiments can be implemented in hardware, firmware, software, or any combination thereof. The disclosed embodiments can also be implemented as instructions carried or stored on one or more transient or non-transient machine-readable (e.g., computer-readable) storage media, which can be read and executed by one or more processors. For example, the instructions can be distributed via a network or via other computer-readable media. Therefore, the machine-readable media can include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), including but not limited to, floppy disks, optical disks, optical discs, compact discs read-only memory (CD-ROMs), magneto-optical discs, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic or optical cards, flash memory, or tangible machine-readable memories for transmitting information (e.g., carrier waves, infrared signals, digital signals, etc.) in electrical, optical, acoustic, or other forms via the Internet. Therefore, the machine-readable media includes any type of machine-readable media suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).

[0142] In addition, the technical solution of this application also provides a computer-readable storage medium, on which instructions are stored, and when the instructions are executed on the mobile phone 100, the mobile phone 100 executes the authentication method provided by the technical solution of this application.

[0143] In addition, the technical solution of this application also provides a computer program product, which includes instructions for implementing the authentication method provided by the technical solution of this application.

[0144] In addition, the technical solution of this application also provides a chip device, which includes: a communication interface for inputting and / or outputting information; a processor for executing computer-executable programs, so that the device installed with the chip device executes the authentication method provided by the technical solution of this application.

[0145] In the accompanying drawings, some structural or method features may be shown in a particular arrangement and / or order. However, it should be understood that such a particular arrangement and / or ordering may not be required. Instead, in some embodiments, these features may be arranged in a manner and / or order different from that shown in the illustrative drawings. Additionally, the inclusion of a structural or method feature in a particular figure does not imply that such a feature is required in all embodiments, and in some embodiments, these features may not be included or may be combined with other features.

[0146] It should be noted that each unit / module mentioned in the device embodiments of this application is a logical unit / module. Physically, a logical unit / module can be a physical unit / module, a part of a physical unit / module, or can be implemented as a combination of multiple physical units / module. The physical implementation manner of these logical units / modules themselves is not the most important. The combination of the functions implemented by these logical units / modules is the key to solving the technical problems proposed in this application. In addition, to highlight the innovative part of this application, the above device embodiments of this application do not introduce units / modules that are not closely related to solving the technical problems proposed in this application. This does not mean that there are no other units / modules in the above device embodiments.

[0147] It should be noted that in the examples and descriptions of this patent, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one" does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0148] Although this application has been illustrated and described by reference to certain preferred embodiments thereof, those of ordinary skill in the art should understand that various changes in form and detail may be made therein without departing from the spirit and scope of this application.

Claims

1. A authentication method, applied to an electronic device, characterized in that, Including: The electronic device uses the device identity information of the electronic device to sign the self-signed certificate generated by the application program of the electronic device, obtains the first application certificate, and sends the first application certificate to the authentication server; When the authentication server determines that the first application certificate is trustworthy, based on the server identity information of the application server, it signs the self-signed certificate in the first application certificate to obtain the second application certificate, and sends the second application certificate to the electronic device, where the server identity information of the application server includes the application server certificate; When the electronic device determines that the second application certificate is trustworthy, it sends the second application certificate to the application server; And, When the application server determines that the second application certificate is trustworthy, it provides services to the electronic device.

2. The method according to claim 1, wherein The self-signed certificate is generated by the following method: Taking the service data related to the user's privacy as the digital document of the self-signed certificate; Using a preset self-signed digest algorithm to perform a hash calculation on the digital document to obtain the digest of the self-signed certificate; Using a preset self-signed private key to sign the digest to obtain the signature of the self-signed certificate; Generating the self-signed certificate based on the signature of the self-signed certificate, the self-signed digest algorithm, the digital document of the self-signed certificate, and the public key of the self-signature.

3. The method according to claim 1 or 2, characterized in that, The device identity information of the electronic device includes the device certificate of the electronic device, The electronic device uses the device identity information of the electronic device to sign the self-signed certificate generated by the application program of the electronic device, obtaining the first application certificate, including: The electronic device uses the first digest algorithm preset in the device certificate to perform a hash calculation on the complete content of the self-signed certificate to obtain the first digest; The electronic device uses the private key of the device certificate to sign the first digest to obtain the first signature; The electronic device obtains the first application certificate based on the first signature, the first digest algorithm, the complete content of the self-signed certificate, and the public key of the device certificate.

4. The method according to any one of claims 3, characterized in that Also including: After receiving the first application certificate, the authentication server verifies the first application certificate by the following method: The authentication server uses the public key of the device certificate to decrypt the first signature to obtain the first digest; The authentication server uses the first digest algorithm to perform a hash calculation on the complete content of the self-signed certificate, and compares the hash calculation result with the first digest, and determines whether the first application certificate is trustworthy based on the comparison result.

5. The method according to claim 4, characterized in that, When the authentication server determines that the first application certificate is trustworthy, based on the server identity information of the application server, it signs the self-signed certificate in the first application to obtain the second application certificate, including: When the authentication server determines that the first application certificate is trustworthy, it uses a preset second digest algorithm to perform a hash calculation on the complete content of the self-signed certificate in the first application certificate to obtain the second digest; Sign the second abstract using the private key of the application server certificate to obtain a second signature; Obtain a second application certificate based on the second signature, the second digest algorithm, the complete content of the self-signed certificate, and the public key of the application server certificate.

6. The method according to claim 5, wherein Further included are: After receiving the second application certificate, the electronic device verifies the second application certificate in the following manner: The electronic device decrypts the second signature using the public key of the application server certificate to obtain the second digest; Perform a hash calculation on the complete content of the self-signed certificate using the second digest algorithm, and compare the hash calculation result with the second digest. Based on the comparison result, determine whether the second application certificate is trustworthy.

7. The method according to claim 6, characterized in that, Further included are: After receiving the second application certificate, the application server verifies the second application certificate in the following manner: The application server decrypts the second signature using the public key of the application server certificate to obtain the second digest; Perform a hash calculation on the complete content of the self-signed certificate using the second digest algorithm, and compare the hash calculation result with the second digest. Based on the comparison result, determine whether the second application certificate is trustworthy.

8. The method according to claim 6, characterized in that Further included are: After receiving the second application certificate, the application server invokes the authentication server to verify the second application certificate in the following manner: The authentication server decrypts the second signature using the public key of the application server certificate to obtain the second digest; Perform a hash calculation on the complete content of the self-signed certificate using the second digest algorithm, and compare the hash calculation result with the second digest. Based on the comparison result, determine whether the second application certificate is trustworthy, and return the authentication result to the application server.

9. A computer-readable storage medium, characterized in that, Instructions are stored on the computer-readable storage medium, and when executed on the electronic device, the instructions cause the electronic device to execute the method according to any one of claims 1-8.

10. An electronic device, characterized in that, Included are: A memory for storing instructions executed by one or more processors of the electronic device, and A processor that, when the instructions are executed by one or more processors, is configured to execute the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Method and device for verifying terminal equipment identity

    CN110417554A