A secure login verification method, system and storage medium
The Trusted Network Domain (TND) system addresses the inefficiencies and security issues of multiple logins by implementing dual authentication with digital certificates, enhancing user experience and security through single sign-on across systems.
Patent Information
- Application Number
- CN202211474642.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-11-23
AI Technical Summary
The frequent login between multiple information management systems caused by users' cumbersome work, low security and poor user experience.
Build a trusted network domain, and use the two-factor authentication mechanism to form a signature information chain using the digital certificate signature of multiple trusted users, and combine the trustworthy authority and permission characteristics to achieve unified login in multiple systems.
Reduce the repeated login process for users, improve work efficiency and security, and improve the level of digital management and user experience of enterprises.
Smart Images

Figure CN115776403B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security access, and in particular, to a secure login verification method, system, and storage medium. Background Art
[0002] With the continuous deepening of the digital transformation of each company, the company's information assets are increasing continuously. There is no unified entry for the personal to-do information generated by major information management systems. When users handle daily to-dos, there are many entrances and the work is cumbersome, resulting in the need for users to repeatedly perform login operations when accessing business systems, which does not meet the requirements of high efficiency.
[0003] Moreover, multiple information management systems each manage the users under their own systems, which will lead to the same user needing to manage personal information under two systems at the same time and record passwords for multiple systems; when the user switches between different applications under the same system, personal identity verification is required each time; in order to ensure personal identity security, the user needs to set multiple accounts for different systems and so on. Such problems will also greatly reduce the security of the system and the user experience. Summary of the Invention
[0004] In order to solve at least one of the above technical problems, the present invention proposes a secure login verification method, system, and storage medium, which can reduce the repeated login process of users, improve work efficiency; enhance the enterprise digital management level, realize a unified entry and unified to-do for multiple information systems, and enhance the security of login and the user experience.
[0005] The first aspect of the present invention proposes a secure login verification method, and the method includes:
[0006] Construct a trusted network domain, and the trusted network domain provides a secure operating environment for multiple users with trusted identities and multiple business systems;
[0007] Receive a login verification request from User A, where the login verification request includes at least user identity information and a login password;
[0008] Perform a first identity verification based on the login password, and after the verification is passed, enter the second identity verification stage;
[0009] Transmit the user identity information of User A to the trusted network domain, and multiple trusted users in the trusted network domain respectively perform a second identity verification based on the user identity information. After the second identity verification is passed, User A is granted a trusted identity;
[0010] User A requests authorization to enter the trusted network domain based on the trusted identity, and is granted access to multiple business systems in the trusted network domain.
[0011] In this solution, multiple trusted users in the trusted domain perform a second identity authentication based on user identity information, specifically including:
[0012] User B in the trusted network domain verifies the user identity information of user A and generates an identity verification result M1;
[0013] User B uses his own digital certificate private key to sign the identity verification result M1, and obtains the identity verification signature information Q1;
[0014] When user C in the trusted network domain receives the identity verification signature information Q1, it further verifies the user identity information of user A and generates an identity verification result M2;
[0015] User C uses his own digital certificate private key to sign the identity verification result M2, obtains the identity verification signature information Q2, and links the identity verification signature information Q2 to the identity verification signature information Q1 to form a signature information chain;
[0016] After the user identity information of user A is transmitted to the trusted network domain for a preset period of time, all signature information chains related to the identity verification of user A in the trusted network domain are obtained;
[0017] The longest signature information chain is taken as the target signature information chain, and the ratio of identity verification passing and failure passing in the target signature information chain is counted;
[0018] It is determined whether the ratio is greater than a first preset threshold, and if so, the second identity authentication is passed.
[0019] In this solution, the percentage of identity verification pass and fail in the target signature information chain is counted, including:
[0020] The positions or levels of the users with trusted identities in the preset trusted domain are different;
[0021] Obtain all signing users from the target signature information chain, and convert them based on the position or level of each signing user through the trusted authority conversion table to obtain the trusted authority of each signing user;
[0022] The trusted authority of all signature users whose identities have been verified in the target signature information chain is accumulated to obtain a positive verification score;
[0023] The trusted authority of all signing users whose identities have not been verified in the target signature information chain is accumulated to obtain a reverse verification score;
[0024] Divide the positive verification score by the reverse verification score to calculate the ratio of identity verification passes and fails.
[0025] In this solution, before transmitting the user identity information of user A into the trusted network domain, the method further includes:
[0026] Construct multiple trusted network domains, where each trusted network domain corresponds to multiple business systems respectively;
[0027] Obtain the user identity information of user A;
[0028] Respectively take each trusted network domain as the reference trusted network domain, and judge the matching difference degrees between the user identity information and the reference trusted network domain, and between the user identity information and other trusted network domains one by one;
[0029] If the user identity information is more matched with the reference trusted network domain, add one point to the reference trusted network domain;
[0030] After all the trusted network domains have completed pairwise comparisons, count the total scores of each trusted network domain, and sort the multiple trusted network domains according to the total scores from high to low;
[0031] Take the trusted network domain with the highest total score as the target trusted network domain, and transmit the user identity information into the target trusted network domain.
[0032] In this solution, constructing multiple trusted network domains specifically includes:
[0033] Obtain the attribute information of all business systems;
[0034] Calculate the permission features for the attribute information of each business system to obtain the permission features of each business system;
[0035] Based on the permission features of multiple business systems and through density clustering algorithm for calculation, obtain multiple clustering groups;
[0036] Based on the multiple business systems in each clustering group, construct the corresponding trusted network domains respectively.
[0037] In this solution, judging the matching difference degrees between the user identity information and the reference trusted network domain, and between the user identity information and other trusted network domains one by one specifically includes:
[0038] Respectively obtain the multiple business systems of the reference trusted network domain and other trusted network domains, as well as the permission requirements and business matters of each business system;
[0039] Obtain the highest permission requirement R1 in the reference trusted network domain and the highest permission requirement R2 of other trusted network domains;
[0040] Determine whether the user identity information meets the highest privilege requirement R1 or the highest privilege requirement R2. If it only meets the highest privilege requirement R1, directly determine that the user identity information is more matched with the benchmark trusted network domain. If it only meets the highest privilege requirement R2, directly determine that the user identity information is more matched with other trusted network domains. If both are met, proceed to the next step;
[0041] Determine the degree of fit between the business matters of each business system in the benchmark trusted network domain and the user identity information, and select the business matter with the highest degree of fit, denoted as S1;
[0042] Determine the degree of fit between the business matters of each business system in other trusted network domains and the user identity information, and select the business matter with the highest degree of fit, denoted as S2;
[0043] Determine whether the degree of fit between the business matter S1 and the user identity information is higher than the degree of fit between the business matter S2 and the user identity information. If it is higher, determine that the user identity information is more matched with the benchmark trusted network domain. Otherwise, determine that the user identity information is more matched with other trusted network domains.
[0044] In the second aspect of the present invention, a secure login verification system is further proposed, including a memory and a processor. The memory includes a secure login verification method program. When the secure login verification method program is executed by the processor, the following steps are implemented:
[0045] Construct a trusted network domain, which provides a secure operating environment for multiple users with trusted identities and multiple business systems;
[0046] Receive the login verification request of user A, where the login verification request includes at least user identity information and a login password;
[0047] Perform the first identity verification based on the login password. After the verification is passed, enter the second identity verification stage;
[0048] Transmit the user identity information of user A to the trusted network domain, and multiple trusted users in the trusted network domain respectively perform the second identity verification based on the user identity information. After the second identity verification is passed, grant user A a trusted identity;
[0049] User A requests authorization to enter the trusted network domain based on the trusted identity, and is granted access to multiple business systems in the trusted network domain.
[0050] In this solution, multiple trusted users in the trusted network domain respectively perform the second identity verification based on the user identity information, specifically including:
[0051] User B in the trusted network domain verifies the user identity information of user A to generate an identity verification result M1;
[0052] User B uses their private key of the digital certificate to sign the identity verification result M1, obtaining the identity verification signature information Q1;
[0053] When user C in the trusted network domain receives the identity verification signature information Q1, it further verifies the user identity information of user A, generating an identity verification result M2;
[0054] User C uses their private key of the digital certificate to sign the identity verification result M2, obtaining the identity verification signature information Q2, and links the identity verification signature information Q2 to the identity verification signature information Q1 to form a signature information chain;
[0055] After a preset time period since the user identity information of user A is transmitted into the trusted network domain, all signature information chains regarding the identity verification of user A in the trusted network domain are obtained;
[0056] Select the longest one from the signature information chains as the target signature information chain, and count the ratio of passed and failed identity verifications in the target signature information chain;
[0057] Judge whether the ratio is greater than the first preset threshold. If so, the second identity verification passes.
[0058] In this solution, counting the ratio of passed and failed identity verifications in the target signature information chain specifically includes:
[0059] The positions or levels of each user with a trusted identity in the preset trusted network domain are different;
[0060] Obtain all signature users from the target signature information chain, and based on the positions or levels of each signature user, perform conversion through the trusted authority conversion table to obtain the trusted authority of each signature user;
[0061] Accumulate the trusted authorities of all signature users who pass the identity verification in the target signature information chain to obtain a positive verification score;
[0062] Accumulate the trusted authorities of all signature users who fail the identity verification in the target signature information chain to obtain a negative verification score;
[0063] Divide the positive verification score by the negative verification score to calculate the ratio of passed and failed identity verifications.
[0064] The third aspect of the present invention also proposes a computer-readable storage medium, which includes a program for a secure login verification method. When the program for the secure login verification method is executed by a processor, the steps of a secure login verification method as described above are implemented.
[0065] A secure login verification method, system, and storage medium proposed by the present invention can reduce the user's repeated login process, improve work efficiency, enhance the enterprise's digital management level, achieve a unified entry and unified to-do for multiple information systems, and enhance the security and user experience of logging in.
[0066] Additional aspects and advantages of the present invention will be given in the following description section, some will become apparent from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 The flowchart of a secure login verification method of the present invention is shown;
[0068] Figure 2 The block diagram of a secure login verification system of the present invention is shown. DETAILED DESCRIPTION
[0069] In order to more clearly understand the above objects, features, and advantages of the present invention, the present invention will be further described in detail below in conjunction with the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0070] Many specific details are set forth in the following description in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0071] Figure 1 The flowchart of a secure login verification method of the present invention is shown.
[0072] As Figure 1 shown, in the first aspect of the present invention, a secure login verification method is proposed, and the method includes:
[0073] S102, constructing a trusted network domain, where the trusted network domain provides a secure operating environment for multiple users with trusted identities and multiple business systems;
[0074] S104, receiving a login verification request from user A, where the login verification request includes at least user identity information and a login password;
[0075] S106, performing a first identity verification based on the login password, and after the verification passes, entering the second identity verification stage;
[0076] S108, transmitting the user identity information of user A to the trusted network domain, and multiple trusted users in the trusted network domain respectively perform a second identity verification based on the user identity information. After the second identity verification passes, user A is granted a trusted identity;
[0077] S110. User A requests authorization to enter the trusted network domain based on a trusted identity and is granted access to multiple business systems in the trusted network domain.
[0078] In the present invention, multiple business systems are integrated in the same trusted network domain. As long as the login verification process of the trusted network domain is passed, one can enter multiple business systems in the trusted network domain without logging in again, which can reduce the repeated login process of users and improve work efficiency; enhance the enterprise digital management level, realize the unified entry and unified to-do of multiple information systems, and enhance the security and user experience of logging in.
[0079] At the same time, the present invention can effectively enhance the security of the login verification through a dual login verification method. In the second identity verification process, a decentralized verification method is introduced, that is, multiple users with trusted identities in the trusted network domain verify User A. There is no need for a special authorization verification system, and the trusted users in the trusted network domain independently verify other users who log in, effectively solving the problem of illegal login caused by the attack on a single authorization verification system and further enhancing the security of the login verification.
[0080] According to an embodiment of the present invention, multiple trusted users in the trusted network domain respectively perform a second identity verification based on user identity information, which specifically includes:
[0081] User B in the trusted network domain verifies the user identity information of User A and generates an identity verification result M1;
[0082] User B signs the identity verification result M1 with his own digital certificate private key to obtain an identity verification signature information Q1;
[0083] When User C in the trusted network domain receives the identity verification signature information Q1, it further verifies the user identity information of User A and generates an identity verification result M2;
[0084] User C signs the identity verification result M2 with his own digital certificate private key to obtain an identity verification signature information Q2, and links the identity verification signature information Q2 to the identity verification signature information Q1 to form a signature information chain;
[0085] After a preset time period since the user identity information of User A is transmitted into the trusted network domain, all signature information chains regarding the identity verification of User A in the trusted network domain are obtained;
[0086] Take the longest one in the signature information chain as the target signature information chain, and count the ratio of passing and failing the identity verification in the target signature information chain;
[0087] Determine whether the ratio is greater than the first preset threshold. If so, the second identity verification passes.
[0088] It should be noted that when user A transmits his own user identity information (such as name, employee number, face collection information, etc.) into the trusted network domain, other users in the trusted network domain can verify whether the user identity information is true. If the verification is true and it is confirmed that user A indeed belongs to colleagues in the company or department, the verification result is passed; otherwise, the verification result is not passed.
[0089] According to an embodiment of the present invention, counting the ratio of successful and failed identity verifications in the target signature information chain specifically includes:
[0090] The positions or levels of each user with a trusted identity in the preset trusted network domain are different;
[0091] Obtain all signature users from the target signature information chain, and based on the position or level of each signature user, perform conversion through the trusted authority conversion table to obtain the trusted authority of each signature user;
[0092] Accumulate the trusted authorities of all signature users in the target signature information chain whose identity verifications are successful to obtain a positive verification score;
[0093] Accumulate the trusted authorities of all signature users in the target signature information chain whose identity verifications fail to obtain a negative verification score;
[0094] Divide the positive verification score by the negative verification score to calculate the ratio of successful and failed identity verifications.
[0095] It should be noted that within an enterprise, the trusted authorities of grass-roots employees and leaders are different. Usually, the trusted authority of grass-roots employees can be set to the order of magnitude 1, and the leaders of each position increase sequentially based on the order of magnitude 1 according to their positions. Based on this, a trusted authority conversion table can be constructed.
[0096] It can be understood that the trusted authority of a signature user with a higher position is higher than that of a signature user with a lower position. The present invention optimizes the calculation of the ratio based on the trusted authorities of different users, thereby achieving accurate verification of user identities.
[0097] According to a specific embodiment of the present invention, after obtaining the trusted authorities of each signature user, the method further includes:
[0098] Statistically record the verification results of each signature user within the trusted network domain in each previous round and compare them with the final verification result of the second identity verification;
[0099] If the comparison is consistent, add one point to the baseline score of each signed-in user; if the comparison is inconsistent, subtract one point from the baseline score of each signed-in user.
[0100] After multiple rounds of verification of multiple logged-in users, the total score of each signed-in user within the trusted domain is calculated.
[0101] Divide the total score of each signed-in user by the baseline score to obtain the floating coefficient of the trusted authority of the signed-in user, and multiply the trusted authority of each signed-in user by the floating coefficient of the trusted authority to obtain the dynamic trusted authority.
[0102] Use the dynamic trusted authority as the current trusted authority of the corresponding signed-in user.
[0103] It can be understood that the baseline score of each user in the same trusted domain is the same, preferably 100 points, but this is not conclusive.
[0104] The present invention optimizes the trusted authority of each user by integrating the evaluation accuracy of each user, so as to obtain a dynamic trusted authority.
[0105] According to an embodiment of the present invention, before transmitting the user identity information of user A into the trusted domain, the method further includes:
[0106] Construct multiple trusted domains, each of which corresponds to multiple business systems respectively;
[0107] Obtain the user identity information of user A;
[0108] Respectively use each trusted domain as the baseline trusted domain, and judge the matching difference degree between the user identity information and the baseline trusted domain, and between the user identity information and other trusted domains one by one;
[0109] If the user identity information is more matched with the baseline trusted domain, add one point to the baseline trusted domain;
[0110] After all trusted domains have completed pairwise comparison, calculate the total score of each trusted domain, and sort the multiple trusted domains according to the total score from high to low;
[0111] Use the trusted domain with the highest total score as the target trusted domain, and transmit the user identity information into the target trusted domain.
[0112] It should be noted that in order to distinguish the login permissions between different business systems, multiple trusted domains need to be built respectively based on multiple business systems, and each trusted domain supports the corresponding business system. After obtaining the user identity information, it is necessary to judge which trusted domain the user is most suitable to fall into based on the permissions of the business system.
[0113] According to an embodiment of the present invention, multiple trusted network domains are constructed, specifically including:
[0114] Obtain the attribute information of all business systems;
[0115] Calculate the permission characteristics for the attribute information of each business system to obtain the permission characteristics of each business system;
[0116] Based on the permission characteristics of multiple business systems and through density clustering algorithm calculation, obtain multiple clustering groups;
[0117] Based on multiple business systems in each clustering group, construct corresponding trusted network domains respectively.
[0118] According to an embodiment of the present invention, the matching difference degrees between the user identity information and the reference trusted network domain, and between the user identity information and other trusted network domains are judged one by one, specifically including:
[0119] Obtain multiple business systems of the reference trusted network domain and other trusted network domains respectively, as well as the permission requirements and business matters of each business system;
[0120] Obtain the highest permission requirement R1 in the reference trusted network domain and the highest permission requirement R2 of other trusted network domains;
[0121] Judge whether the user identity information meets the highest permission requirement R1 or the highest permission requirement R2. If only the highest permission requirement R1 is met, it is directly determined that the user identity information is more matched with the reference trusted network domain. If only the highest permission requirement R2 is met, it is directly determined that the user identity information is more matched with other trusted network domains. If both are met, proceed to the next step;
[0122] Judge the degree of fit between the business matters of each business system in the reference trusted network domain and the user identity information, and select the business matter with the highest degree of fit, denoted as S1;
[0123] Judge the degree of fit between the business matters of each business system in other trusted network domains and the user identity information, and select the business matter with the highest degree of fit, denoted as S2;
[0124] Judge whether the degree of fit between the business matter S1 and the user identity information is higher than the degree of fit between the business matter S2 and the user identity information. If it is higher, it is determined that the user identity information is more matched with the reference trusted network domain. Otherwise, it is determined that the user identity information is more matched with other trusted network domains.
[0125] It should be noted that the present invention makes a differential comparison based on the permission requirements and business matters of business systems in different trusted network domains, so as to determine which trusted network domain the user identity information is more matched with.
[0126] According to a specific embodiment of the present invention, the method further includes:
[0127] User K preset in trusted network domain H1 requests to access a business system in trusted network domain H2 across the network;
[0128] User K requests services from the business system of trusted network domain H2;
[0129] After receiving the request, trusted network domain H2 requires User K to perform identity authentication, tells User K the public key of trusted network domain H1, and sends a challenge T1 of the user identity to User K;
[0130] User K generates a challenge T2 for verifying trusted network domain H2 and a reply TD1 to the challenge T1 sent by trusted network domain H2, encrypts the challenge T2 and the reply TD1 using the same key to obtain a ciphertext, then encrypts the ciphertext and the key using the public key of trusted network domain H1 to generate identity authentication information, and sends it to trusted network domain H2;
[0131] Trusted network domain H2 proves its own identity to trusted network domain H1 and sends the identity authentication information of User K;
[0132] Trusted network domain H1 decrypts the identity authentication information using its own private key. If the decryption is successful, it verifies the legitimacy of the user's source, generates the public key of trusted network domain H2 and service association information, and transfers the key for encrypting the user's challenge to trusted network domain H2;
[0133] Trusted network domain H2 uses the key to decrypt the ciphertext to obtain the challenge T2 and the reply TD1 of User K to the received challenge T1; verifies the legitimacy of the user's identity according to the reply TD1; generates a challenge reply TD2 according to the user's challenge T2;
[0134] Trusted network domain H2 generates information for verifying its own identity, and sends it together with the challenge reply TD2, the public key of trusted network domain H2 and service association information to User K;
[0135] User K verifies the legitimacy of the source of trusted network domain H2 according to the challenge reply TD2, and verifies the legitimacy of the identity of trusted network domain H2 according to the identity information of trusted network domain H2, as well as the public key of trusted network domain H2 and service association information.
[0136] The present invention supports users to perform cross - network access, and it is necessary for the trusted network domain where the user is located to provide identity proof for the trusted network domain to be pre - entered, thereby enhancing the security of cross - network access.
[0137] Figure 2 The block diagram of a security login verification system according to the present invention is shown.
[0138] As Figure 2As shown in the figure, the second aspect of the present invention further proposes a secure login verification system 2, including a memory 21 and a processor 22. The memory includes a secure login verification method program. When the secure login verification method program is executed by the processor, the following steps are implemented:
[0139] Construct a trusted network domain, which provides a secure operating environment for multiple users with trusted identities and multiple business systems;
[0140] Receive a login verification request from user A, where the login verification request includes at least user identity information and a login password;
[0141] Perform a first identity verification based on the login password. After the verification passes, enter the second identity verification stage;
[0142] Transmit the user identity information of user A to the trusted network domain. Multiple trusted users in the trusted network domain respectively perform a second identity verification based on the user identity information. After the second identity verification passes, grant user A a trusted identity;
[0143] User A requests authorization to enter the trusted network domain based on the trusted identity, and is granted access to multiple business systems in the trusted network domain.
[0144] According to an embodiment of the present invention, multiple trusted users in the trusted network domain respectively perform a second identity verification based on the user identity information, which specifically includes:
[0145] User B in the trusted network domain verifies the user identity information of user A to generate an identity verification result M1;
[0146] User B signs the identity verification result M1 with its own digital certificate private key to obtain an identity verification signature information Q1;
[0147] When user C in the trusted network domain receives the identity verification signature information Q1, it further verifies the user identity information of user A to generate an identity verification result M2;
[0148] User C signs the identity verification result M2 with its own digital certificate private key to obtain an identity verification signature information Q2, and links the identity verification signature information Q2 to the identity verification signature information Q1 to form a signature information chain;
[0149] After a preset time period since the user identity information of user A is transmitted to the trusted network domain, obtain all the signature information chains regarding the identity verification of user A in the trusted network domain;
[0150] Select the longest one in the signature information chain as the target signature information chain, and count the ratio of the number of passed and failed identity verifications in the target signature information chain;
[0151] Determine whether the ratio is greater than the first preset threshold. If so, the second authentication passes.
[0152] According to an embodiment of the present invention, counting the ratio of successful and failed identity verifications in the target signature information chain specifically includes:
[0153] The positions or levels of users with trusted identities in the preset trusted network domain are different;
[0154] Obtain all signature users from the target signature information chain, and based on the positions or levels of each signature user, perform conversion through a trusted authority conversion table to obtain the trusted authority of each signature user;
[0155] Accumulate the trusted authorities of all signature users whose identity verifications are successful in the target signature information chain to obtain a positive verification score;
[0156] Accumulate the trusted authorities of all signature users whose identity verifications fail in the target signature information chain to obtain a negative verification score;
[0157] Divide the positive verification score by the negative verification score to calculate the ratio of successful and failed identity verifications.
[0158] The third aspect of the present invention also proposes a computer-readable storage medium, which includes a program for a secure login verification method. When the program for the secure login verification method is executed by a processor, the steps of a secure login verification method as described above are implemented.
[0159] A secure login verification method, system, and storage medium proposed by the present invention can reduce the repeated login process of users, improve work efficiency; enhance the enterprise's digital management level, realize a unified entry and unified to-do for multiple information systems, and enhance the security and user experience of login.
[0160] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed with each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical, or other forms.
[0161] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they may be located in one place or distributed over multiple network units; and some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0162] In addition, each functional unit in the embodiments of the present invention may be all integrated in a processing unit, or each unit may be separately taken as a unit, or two or more units may be integrated in one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of a combination of hardware and software functional units.
[0163] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: removable storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks and other various media that can store program codes.
[0164] Alternatively, if the above-mentioned integrated units of the present invention are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present invention. And the foregoing storage medium includes: removable storage devices, ROM, RAM, magnetic disks, or optical disks and other various media that can store program codes.
[0165] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, and all of them should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A secure login verification method, characterized in that, The method includes: Constructing a trusted domain, which provides a secure operating environment for multiple users with trusted identities and multiple business systems; Receiving a login verification request from User A, where the login verification request includes at least user identity information and a login password; Performing a first identity verification based on the login password. After the verification passes, enter the second identity verification stage; Transmitting the user identity information of User A into the trusted domain. Multiple trusted users in the trusted domain respectively perform a second identity verification based on the user identity information. After the second identity verification passes, User A is granted a trusted identity; User A requests authorization to enter the trusted domain based on the trusted identity and is granted access to multiple business systems in the trusted domain; Before transmitting the user identity information of User A into the trusted domain, the method further includes: Constructing multiple trusted domains, with each trusted domain corresponding to multiple business systems; Obtaining the user identity information of User A; Taking each trusted domain as the reference trusted domain respectively, and successively judging the matching difference degrees between the user identity information and the reference trusted domain, and between the user identity information and other trusted domains; If the user identity information is more matched with the reference trusted domain, add one point to the reference trusted domain; After all trusted domains have completed pairwise comparisons, count the total scores of each trusted domain, and sort the multiple trusted domains according to the total scores from high to low; Taking the trusted domain with the highest total score as the target trusted domain, and transmitting the user identity information into the target trusted domain; Successively judging the matching difference degrees between the user identity information and the reference trusted domain, and between the user identity information and other trusted domains, specifically including: Respectively obtaining multiple business systems of the reference trusted domain and other trusted domains, as well as the permission requirements and business matters of each business system; Obtaining the highest permission requirement R1 in the reference trusted domain and the highest permission requirement R2 of other trusted domains; Judging whether the user identity information meets the highest permission requirement R1 or the highest permission requirement R2. If it only meets the highest permission requirement R1, directly determine that the user identity information is more matched with the reference trusted domain. If it only meets the highest permission requirement R2, directly determine that the user identity information is more matched with other trusted domains. If both are met, proceed to the next step; Judging the degree of fit between the business matters of each business system in the reference trusted domain and the user identity information, and selecting the business matter with the highest degree of fit, denoted as S1; Judging the degree of fit between the business matters of each business system in other trusted domains and the user identity information, and selecting the business matter with the highest degree of fit, denoted as S2; Judging whether the degree of fit between the business matter S1 and the user identity information is higher than the degree of fit between the business matter S2 and the user identity information. If it is higher, determine that the user identity information is more matched with the reference trusted domain. Otherwise, determine that the user identity information is more matched with other trusted domains.
2. The secure login authentication method according to claim 1, wherein Multiple trusted users in the trusted domain respectively perform a second identity verification based on the user identity information, specifically including: User B in the trusted domain verifies the user identity information of User A and generates an identity verification result M1; User B uses his own digital certificate private key to sign the identity verification result M1, and obtains the identity verification signature information Q1; When user C in the trusted network domain receives the identity verification signature information Q1, it further verifies the user identity information of user A and generates an identity verification result M2; User C uses his own digital certificate private key to sign the identity verification result M2, obtains the identity verification signature information Q2, and links the identity verification signature information Q2 to the identity verification signature information Q1 to form a signature information chain; After the user identity information of user A is transmitted to the trusted network domain for a preset period of time, all signature information chains related to the identity verification of user A in the trusted network domain are obtained; The longest signature information chain is taken as the target signature information chain, and the ratio of identity verification passing and failure passing in the target signature information chain is counted; It is determined whether the ratio is greater than a first preset threshold, and if so, the second identity authentication is passed.
3. The secure login authentication method according to claim 2, wherein Count the percentage of identity verification that passes and fails in the target signature information chain, including: The positions or levels of the users with trusted identities in the preset trusted domain are different; Obtain all signing users from the target signature information chain, and convert them based on the position or level of each signing user through the trusted authority conversion table to obtain the trusted authority of each signing user; The trusted authority of all signature users whose identities have been verified in the target signature information chain is accumulated to obtain a positive verification score; The trusted authority of all signing users whose identities have not been verified in the target signature information chain is accumulated to obtain a reverse verification score; Divide the positive verification score by the reverse verification score to calculate the ratio of identity verification passes and fails.
4. A secure login authentication method according to claim 1, characterized in that Build multiple trusted domains, including: Get the attribute information of all business systems; Calculate the authority characteristics of each business system based on its attribute information to obtain the authority characteristics of each business system; Based on the permission characteristics of multiple business systems, multiple cluster groups are obtained by calculation using a density clustering algorithm; Based on multiple business systems of each cluster group, corresponding trusted network domains are constructed respectively.
5. A secure login verification system, characterized in that, The invention comprises a memory and a processor, wherein the memory comprises a secure login verification method program, and when the secure login verification method program is executed by the processor, the following steps are implemented: Building a trusted network domain that provides a secure operating environment for multiple users with trusted identities and multiple business systems; Receive a login verification request from user A, wherein the login verification request includes at least user identity information and a login password; Perform the first identity authentication based on the login password, and after the authentication is passed, enter the second identity authentication stage; The user identity information of user A is transmitted to the trusted network domain, and multiple trusted users in the trusted network domain respectively perform a second identity authentication based on the user identity information. After the second identity authentication is passed, user A is granted a trusted identity; User A requests authorization to enter the trusted network domain based on the trusted identity, and is granted access to multiple business systems in the trusted network domain; Before the user identity information of user A is transmitted to the trusted network domain, the secure login verification method program further implements the following steps when executed by the processor: Build multiple trusted domains, each of which corresponds to multiple business systems respectively; Obtain the user identity information of User A; Take each trusted domain as the reference trusted domain respectively, and judge the matching difference degrees between the user identity information and the reference trusted domain, and between the user identity information and other trusted domains one by one; If the user identity information is more matched with the reference trusted domain, add one point to the reference trusted domain; After all trusted domains have completed pairwise comparison, count the total scores of each trusted domain, and sort the multiple trusted domains according to the total scores from high to low; Take the trusted domain with the highest total score as the target trusted domain, and pass the user identity information into the target trusted domain; Judge the matching difference degrees between the user identity information and the reference trusted domain, and between the user identity information and other trusted domains one by one, specifically including: Obtain the multiple business systems of the reference trusted domain and other trusted domains respectively, as well as the permission requirements and business matters of each business system; Obtain the highest permission requirement R1 in the reference trusted domain and the highest permission requirement R2 in other trusted domains; Judge whether the user identity information meets the highest permission requirement R1 or the highest permission requirement R2. If it only meets the highest permission requirement R1, directly determine that the user identity information is more matched with the reference trusted domain. If it only meets the highest permission requirement R2, directly determine that the user identity information is more matched with other trusted domains. If both are met, proceed to the next step; Judge the degree of fit between the business matters of each business system in the reference trusted domain and the user identity information, and select the business matter with the highest degree of fit, denoted as S1; Judge the degree of fit between the business matters of each business system in other trusted domains and the user identity information, and select the business matter with the highest degree of fit, denoted as S2; Judge whether the degree of fit between the business matter S1 and the user identity information is higher than the degree of fit between the business matter S2 and the user identity information. If it is higher, determine that the user identity information is more matched with the reference trusted domain. Otherwise, determine that the user identity information is more matched with other trusted domains.
6. A secure login authentication system according to claim 5, wherein, The multiple trusted users in the trusted domain respectively perform a second identity verification based on the user identity information, specifically including: User B in the trusted domain verifies the user identity information of User A, generating an identity verification result M1; User B signs the identity verification result M1 with his own digital certificate private key to obtain an identity verification signature information Q1; When User C in the trusted domain receives the identity verification signature information Q1, further verify the user identity information of User A, generating an identity verification result M2; User C signs the identity verification result M2 with his own digital certificate private key to obtain an identity verification signature information Q2, and links the identity verification signature information Q2 to the identity verification signature information Q1 to form a signature information chain; After a preset time period since the user identity information of User A is passed into the trusted domain, obtain all the signature information chains regarding the identity verification of User A in the trusted domain; Take the longest one in the signature information chains as the target signature information chain, and count the ratio of passed and failed identity verifications in the target signature information chain; Determine whether the ratio is greater than the first preset threshold. If so, the second identity verification passes.
7. The secure login authentication system according to claim 6, wherein, Count the ratio of successful and unsuccessful identity verifications in the target signature information chain, specifically including: The positions or levels of users with trusted identities in the preset trusted network domain are different; Obtain all signature users from the target signature information chain, and based on the positions or levels of each signature user, perform conversion through the trusted authority conversion table to obtain the trusted authority of each signature user; Accumulate the trusted authorities of all signature users whose identity verifications in the target signature information chain are successful to obtain a positive verification score; Accumulate the trusted authorities of all signature users whose identity verifications in the target signature information chain are unsuccessful to obtain a negative verification score; Divide the positive verification score by the negative verification score to calculate the ratio of successful and unsuccessful identity verifications.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a program for a secure login verification method. When the program for the secure login verification method is executed by a processor, the steps of a secure login verification method as described in any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Web system identity authentication system and method
CN113660192A
Identity authentication method and device based on block chain and electronic equipment
CN114710362A