Method and apparatus for providing proxy authentication on a mobile terminal

By building a proxy authentication connector on a mobile terminal, using biometric technology and FIDO protocol, the problem of frequent mobile terminal authentication interactions is solved, and the user experience is improved.

CN115842629BActive Publication Date: 2025-08-01CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210885826.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-26
Publication Date
2025-08-01
Estimated Expiration
2042-07-26

AI Technical Summary

Technical Problem

When authenticating on mobile terminals, the number of interactions is large, which affects the user experience.

Method used

Build a proxy verification connector on a mobile terminal, use biometric technologies such as fingerprint, face, voiceprint and iris verification, use the FIDO protocol to perform identity authentication, and store and manage security verification records in a trusted execution environment to reduce the number of verification interactions.

Benefits of technology

Through the proxy verification connector, the number of verification interactions of users on the mobile terminal is reduced and the user experience is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115842629B_ABST
    Figure CN115842629B_ABST
Patent Text Reader

Abstract

This application relates to information security technology, and particularly to a method, apparatus for providing proxy authentication on a mobile terminal, and a computer-readable storage medium storing a computer program for implementing the above method. The method for providing proxy authentication on a mobile terminal according to an embodiment of the present application includes the following steps executed on the mobile terminal: receiving a query request from a first application, the query request indicating the type of authentication information involved in the authentication, wherein the authentication is based on a specified security protocol; searching for a security authentication record matching the indicated type of authentication information; and determining that the authentication is passed if there is a matching security authentication record.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to information security technology, and particularly to a method and apparatus for providing proxy authentication on a mobile terminal, and a computer-readable storage medium storing a computer program for implementing the above method thereon. Background Art

[0002] Online Fast Identity Authentication (FIDO) aims to provide an open and extensible standard protocol for supporting non-password security authentication of web applications, eliminating or reducing users' dependence on passwords. FIDO implements user identity authentication by using public-private key signature / verification and obtains private key authorization through biometric recognition. Due to the introduction of biometric technology, compared with the security of obtaining private key authorization through traditional passwords, there is a comprehensive improvement, and the usability is significantly improved.

[0003] Currently, identity authentication solutions based on the FIDO technology standard have been widely applied, and many mobile terminals support the FIDO protocol. The FIDO technology standard is gradually becoming an identity authentication specification followed by the entire industrial chain (from the device side to the service side). Summary of the Invention

[0004] An object of this application is to provide a method and apparatus for providing proxy authentication on a mobile terminal, which have advantages such as reducing the number of verification interactions.

[0005] According to one aspect of this application, a method for providing proxy authentication on a mobile terminal is provided, including the following steps executed on the mobile terminal:

[0006] Receiving a query request from a first application, the query request indicating the type of verification information involved in the verification, wherein the verification is based on a specified security protocol;

[0007] Searching for a security verification record that matches the indicated type of verification information;

[0008] If there is a matching security verification record, it is determined that the verification passes.

[0009] Optionally, the method is executed in a trusted execution environment of the mobile terminal.

[0010] Optionally, in the above method, the type of verification information includes at least one of fingerprint, face, voiceprint, and iris.

[0011] Optionally, in the above method, the specified security protocol is the FIDO protocol.

[0012] Optionally, in the above method, if a security verification record of the indicated verification information type is searched and the security verification record is within the validity period, it is determined that there is a matching security verification record.

[0013] Optionally, in the above method, the security verification record includes a user unified identifier, an account identifier, a verification information type flag, and a validity period.

[0014] Optionally, the method further includes the following steps:

[0015] Perform an initialization operation on the storage area storing the security verification record, where the initialization operation includes establishing a binding relationship between the user unified identifier and one or more account identifiers, and each account identifier is associated with its respective application.

[0016] Optionally, in the above method, the initialization operation is performed by a remote server before starting to store the security verification record, or the initialization operation is performed by the remote server regularly or irregularly after starting to store the security verification record.

[0017] Optionally, in the above method, the application service associated with the first application has the verification ability based on the specified security protocol, and the method further includes the following steps:

[0018] If there is no matching security verification record, cause the first application to continue to perform verification based on the specified security protocol.

[0019] Optionally, in the above method, the application service associated with the first application does not have the verification ability based on the specified security protocol, and the method further includes the following steps:

[0020] If there is no matching security verification record, call a second application to perform verification based on the specified security protocol, where the application service associated with the second application has the verification ability based on the specified security protocol.

[0021] In addition to the above one or more features, the above method further includes the following steps:

[0022] If the verification performed by the first application or the second application passes, store the corresponding security verification record.

[0023] According to another aspect of the present application, there is provided a device for providing proxy verification on a mobile terminal, including:

[0024] A data storage module configured to store security verification records associated with a user;

[0025] A processing module, configured to perform the following operations:

[0026] Receive a query request from a first application, the query request indicating the type of verification information involved in the verification, wherein the verification is based on a specified security protocol;

[0027] Search within the data storage module for security verification records that match the indicated type of verification information;

[0028] If there are matching security verification records, determine that the current user authentication is passed.

[0029] According to another aspect of the present application, there is provided a computer system, including:

[0030] A memory;

[0031] A processor coupled to the memory; and

[0032] A computer program stored on the memory and executable on the processor, and the above-described method is implemented by running the computer program.

[0033] According to another aspect of the present application, there is provided a computer-readable storage medium, in which instructions are stored, characterized in that the above-described method is implemented by a processor executing the instructions.

[0034] In some embodiments of the present application, by constructing a verification connector on a mobile device to provide proxy verification services for different applications, the number of user interaction verifications can be reduced and the user experience can be improved. Description of the Drawings

[0035] The above and / or other aspects and advantages of the present application will become clearer and easier to understand through the following descriptions of various aspects in conjunction with the drawings, where the same or similar units in the drawings are denoted by the same reference numerals. The drawings include:

[0036] Figure 1 A schematic diagram of a proxy verification architecture according to some embodiments of the present application.

[0037] Figure 2 A flowchart of a method for providing proxy verification on a mobile terminal according to some embodiments of the present application.

[0038] Figure 3 A schematic block diagram of a typical computer system. Detailed Embodiments

[0039] The present application will be described more fully hereinafter with reference to the accompanying drawings, in which exemplary embodiments of the present application are illustrated. However, the present application may be implemented in different forms and should not be construed as limited to the embodiments set forth herein. The above-described embodiments are provided to make the disclosure of the present application thorough and complete, and to more fully convey the scope of protection of the present application to those skilled in the art.

[0040] In this specification, terms such as "including" and "comprising" indicate that, in addition to the elements and steps directly and explicitly recited in the specification and claims, the technical solutions of the present application do not exclude the presence of other elements and steps that are not directly or explicitly recited.

[0041] Unless otherwise specified, terms such as "first" and "second" do not denote an order of the elements in terms of time, space, size, etc., but are merely used to distinguish the elements from each other.

[0042] Figure 1 It is a schematic diagram of an agent verification architecture according to some embodiments of the present application.

[0043] In Figure 1 In the illustrated architecture 10, the parties involved in agent verification include a mobile terminal or mobile side 110, servers 121, 122, and 123, and a remote server 130.

[0044] The mobile terminal 110 provides two co-existing operating environments, namely a non-secure environment (which is implemented by a full-featured operating system such as Linux, Android, iOS, etc.) and a trusted execution environment (TEE), where the TEE provides security services to the non-secure environment.

[0045] In Figure 1 In the illustrated example, the application programs APP1 - APP3 installed on the mobile terminal 110 all run in the non-secure environment and can call the security service functions of the TEE. The application programs APP1 - APP3 can interact with their respective associated servers 121 - 123 to implement corresponding application services S1 - S3. For example, the application services S1 - S3 can be online banking services provided by institutions A, B, and C. To complete a transaction, user identity verification is required. Merely by way of example, it is assumed that the application services S1 and S2 associated with the application programs APP1 and APP2 support verification methods based on one or more specified security protocols (such as the FIDO protocol), but the application service S3 associated with the application program APP3 does not have such support.

[0046] Exemplarily, authentication or transaction verification in application services S1 and S2 can be implemented based on the FIDO protocol. During the verification process based on the FIFO protocol, the authenticator running in the TEE environment uses biometric technologies (such as fingerprint, face, voiceprint, and iris, etc.) to verify the user's identity, and unlocks the user's private key stored in the authenticator after successful verification; subsequently, the authenticator signs the response message from the FIDO server ([ Figure 1 such as server 121 or 122 in it), and the FIDO server uses the public key corresponding to the user to verify the signature, thus completing the entire identity authentication process.

[0047] See Figure 1 , the mobile terminal 110 includes a verification connector 111 that runs in the TTE environment and is used to provide proxy verification. The verification connector includes a data storage module 111A and a processing module 111B. The data storage module 111A is configured to store security verification records associated with the user. The security verification records can be used to indicate the history of verification operations (such as the type of verification information involved in the verification, the user associated with the verification, the server or application service associated with the verification, the time when the verification passed or failed, etc.).

[0048] In some embodiments, the security verification records can be stored in the form shown in Table 1 below.

[0049] Table 1

[0050]

[0051] In Table 1, the user unified identifier can be the user ID, which has uniqueness and globality. The account identifier is the user account or username associated with application services S1, S2, and S3 (for example, in the above example, it can be the accounts opened by user WWB in institutions A, B, and C). The verification information type flag is used to indicate that the corresponding account has passed the verification involving a certain type of verification information. For example, "01", "02", "03", and "04" can respectively indicate that the corresponding account has passed the verification involving fingerprint information, face information, voiceprint information, and iris information. The validity period is used to indicate when the verification result of the corresponding type becomes invalid (that is, after the verification passes, how long the verification result is recognized or continued to be used. Usually, this duration is several minutes or dozens of minutes). In the example of Table 1, the validity period is represented in the format of year-month-day hour-minute-second. Optionally, a flag regarding protocol supportiveness can also be added in Table 1 to indicate whether the relevant application service supports a specific security protocol (such as the FIDO protocol).

[0052] In some embodiments, the remote server 130 may perform an initialization operation on the data storage module 111A that stores security verification records. The initialization operation includes establishing a binding relationship between the user unified identifier and one or more account identifiers. The remote server 130 includes a database 131, on which the binding relationships between the user unified identifiers and account identifiers of multiple users are stored. The initialization operation can be performed at various times according to application requirements, for example, before starting to store security verification records, or periodically or irregularly after starting to store the security verification records.

[0053] Figure 1 The processing module 111B therein is configured to perform various operations related to the proxy verification process. In some embodiments, the processing module 111B can be implemented using a dedicated security processor, which is physically isolated from the non-secure environment. In some other embodiments, the processing module 111B can be implemented using a security processor that includes a Trust Zone, which can share some hardware with the non-secure environment.

[0054] Exemplarily, assume that the application services associated with application programs APP1 and APP2 support verification based on the FIDO protocol, while the application service associated with application program APP3 does not have such support. To utilize the proxy verification function, when application program APP1 initiates a fingerprint-based FIDO verification, it will first determine whether there is an available verification result. If there is no available verification result, it will perform the subsequent verification process; otherwise, it will abort the verification process.

[0055] In some embodiments, the processing module 111B may perform the following operations to provide the proxy verification function to application program APP1 or APP2:

[0056] In operation A, receive a query request from application program APP1, where the query request includes an indicator of the type of verification information involved in the current FIDO verification.

[0057] In operation B, search for a security verification record that matches the type of verification information indicated in the query request within the data storage module 111A (such as Table 1). Optionally, the matching criteria may include:

[0058] 1) A security verification record consistent with the indicated type of verification information is stored in the data storage module 111A; and

[0059] 2) The searched security verification record is within the valid period.

[0060] As an example, assume that the application service S1 associated with the application APP1 needs to perform fingerprint-based FIDO authentication. If a flag corresponding to fingerprint authentication under the user unified identifier WWB is found in Table 1 and the flag is within the valid period, it is determined that a matching security authentication record is found. Accordingly, in operation C, it is determined that the current fingerprint-based authentication passes, and a message indicating successful authentication is returned to the application APP1.

[0061] On the other hand, if a flag corresponding to fingerprint authentication under the user unified identifier WWB is not found in Table 1 or the found corresponding flag is not within the valid period, it is determined that no matching security authentication record is found. Accordingly, in operation D, it is determined that the proxy authentication fails, and a message indicating failed proxy authentication is returned to the application APP1. Subsequently, the application APP1 continues to execute the fingerprint-based FIDO authentication process. If the authentication passes, in operation E, the processing module 111B stores the corresponding security authentication record in the data storage module 111A (such as Table 1).

[0062] The operations described above can also be applied to the application APP2, which will not be elaborated here.

[0063] In some other embodiments, the processing module 111B can perform the following operations to provide the proxy authentication function for APP3:

[0064] Operation A': Receive a query request from the application APP3, where the query request includes an indicator of the type of authentication information involved in the current authentication.

[0065] Operation B': Search for a security authentication record in the data storage module 111A (such as Table 1) that matches the type of authentication information indicated in the query request. The method is similar to operation B and will not be elaborated here.

[0066] Exemplarily, assume that the application service S3 associated with the application APP3 needs to perform fingerprint-based authentication. If a flag corresponding to fingerprint authentication under the user unified identifier WWB is found in Table 1 and the flag is within the valid period, it is determined that a matching security authentication record is found. Accordingly, in operation C', it is determined that the current fingerprint-based FIDO authentication passes, and a message indicating successful authentication is returned to the application APP3.

[0067] On the other hand, if the flag corresponding to fingerprint verification under the user unified identifier WWB is not found in Table 1 or the found corresponding flag is not within the valid period, it is determined that no matching security verification record is found. Correspondingly, in operation D’, a request is sent to application APP1 or APP2 to call application APP1 or APP2 to perform fingerprint-based FIDO verification. Subsequently, application APP1 or APP2 performs the fingerprint-based FIDO verification process. If the verification is passed, in operation E’, processing module 111B stores the corresponding security verification record in data storage module 111A (such as Table 1).

[0068] Figure 2 A flowchart of a method for providing proxy verification on a mobile terminal according to some embodiments of the present application. Exemplarily, the method described below is implemented within the architecture shown in Figure 1 shown below.

[0069] Figure 2 The process shown starts at step 201. In this step, remote server 130 performs an initialization operation on data storage module 111A that stores security verification records. Specifically, the initialization operation includes establishing a binding relationship between the user unified identifier and one or more account identifiers, such as establishing the binding relationship shown in Table 1.

[0070] It should be noted that, in the embodiment shown in Figure 2 the initialization operation is performed in step 201 before starting to store security verification records, but it can also be performed periodically or irregularly after starting to store security verification records, such as between subsequent steps of the process shown in Figure 2 shown below.

[0071] Subsequently, Figure 2 the process shown enters step 202. In this step, processing module 111B receives a query request from an application (such as any one of applications APP1 to APP3), and the query request indicates the type of verification information involved in the current verification. The above types of verification information include, for example, but are not limited to fingerprint, face, voiceprint, and iris, etc.

[0072] Then it enters step 203. In this step 203, processing module 111B searches for a security verification record that matches the indicated type of verification information. If a matching security verification record is found, it enters step 204, otherwise it enters step 205.

[0073] In some embodiments, processing module 111B can search for a security verification record that matches the type of verification information indicated in the query request in data storage module 111A (such as Table 1), for example, in a manner similar to operation B, which will not be elaborated here.

[0074] In step 204, the processing module 111B determines that the current verification is passed and returns a message indicating verification passed to the application that sent the query request.

[0075] In step 205, the processing module 111B determines whether the application that sent the query request supports verification based on a specified security protocol (such as the FIDO protocol). If it supports, it proceeds to step 206 (for example, when the query request comes from application APP1 or APP2), otherwise it proceeds to step 207 (for example, when the query request comes from application APP3).

[0076] As described above, a flag regarding protocol supportiveness can be added to Table 1 stored in the data storage module 111A to indicate whether the relevant application service supports a specific security protocol (such as the FIDO protocol). The processing module 111B can thus make a supportiveness judgment. However, other implementation manners can also be adopted. For example, a flag regarding protocol supportiveness can be included in the query request.

[0077] In step 206, the processing module 111B returns a message indicating proxy verification failed to the application that sent the query request (taking application APP1 as an example). In response to the message indicating proxy verification failed, application APP1 will continue to execute the verification process based on the specified security protocol.

[0078] Figure 2 The method shown will proceed to step 208 after step 206. In this step, if the processing module 111B receives a message indicating verification passed based on the specified security protocol from application APP1, corresponding security verification records are stored in the data storage module 111A (such as in Table 1).

[0079] Returning to another branch step 207 of step 205, in this step, the processing module 111B sends a call request to the application that supports verification based on the specified security protocol (such as APP1 or APP2). In response to the call request, application APP1 or APP2 executes the verification process based on the specified security protocol.

[0080] Figure 2 The method shown will also proceed to step 208 after step 207.

[0081] Figure 3 It is a schematic block diagram of a typical computer system. As Figure 3 shown, the computer system 300 includes a memory 310 (such as non-volatile memory such as flash memory, ROM, hard disk drive, magnetic disk, optical disk), a processor 320, and a computer program 330.

[0082] The memory 310 stores a computer program 330 that can be executed by the processor 320. The processor 320 is configured to run the computer program 330 stored on the memory 310. By running the computer program 330, one or more steps included in the method described above with reference to Figure 2 can be implemented.

[0083] According to another aspect of the present application, there is also provided a computer-readable storage medium storing a computer program, which when executed by a processor can implement one or more steps included in the method described above with reference to Figure 2 can be implemented.

[0084] The computer-readable storage medium referred to in the present application includes various types of computer storage media, which can be any available medium accessible by a general-purpose or special-purpose computer. For example, the computer-readable storage medium can include RAM, ROM, EPROM, E2PROM, registers, hard disks, removable disks, CD-ROMs or other optical disc memories, magnetic disk memories or other magnetic storage devices, or any other transient or non-transient medium capable of carrying or storing desired program code units in the form of instructions or data structures and accessible by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor. The above combinations should also be included within the scope of protection of the computer-readable storage medium. An exemplary storage medium is coupled to the processor so that the processor can read from / write to the storage medium. In an alternative, the storage medium can be integrated into the processor. The processor and the storage medium can reside in an ASIC. The ASIC can reside in a user terminal. In an alternative, the processor and the storage medium can reside in the user terminal as discrete components.

[0085] Those skilled in the art will understand that the various illustrative logical blocks, modules, circuits, and algorithm steps described herein can be implemented as electronic hardware, computer software, or a combination of both.

[0086] To demonstrate the interchangeability between hardware and software, the various illustrative components, blocks, modules, circuits, and steps have been generally described above according to their functionality. Whether such functionality is implemented in hardware form or software form depends on the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in a manner that varies according to the specific particular application, but such implementation decisions should not be construed as causing a departure from the scope of the present application.

[0087] Although only some specific embodiments of the present application have been described, those of ordinary skill in the art should understand that the present application can be implemented in many other forms without departing from its spirit and scope. Therefore, the examples and embodiments shown are considered illustrative rather than restrictive, and the present application may cover various modifications and substitutions without departing from the spirit and scope of the present application as defined by the appended claims.

[0088] The embodiments and examples provided herein are for the purpose of best illustrating the embodiments in accordance with the present technology and its specific applications, and thereby enabling those skilled in the art to implement and use the present application. However, those skilled in the art will know that the above description and examples are provided only for the sake of illustration and example. The description presented is not intended to cover all aspects of the present application or to limit the present application to the precise forms disclosed.

Claims

1. A method for providing proxy authentication on a mobile terminal, including the following steps executed on the mobile terminal: Receive a query request from a first application, the query request indicating the type of verification information involved in the verification, where The authentication is based on a specified security protocol; Search for a security authentication record that matches the indicated type of authentication information; If there is a matching security authentication record, determine that the authentication passes, Wherein, the application service associated with the first application does not have the authentication ability based on the specified security protocol, and further includes the following steps: If there is no matching security authentication record, call a second application to perform authentication based on the specified security protocol, wherein the application service associated with the second application has the authentication ability based on the specified security protocol, Wherein, the security authentication record includes a user unified identifier, an account identifier, an authentication information type flag, and a validity period, Further includes the following steps: Perform an initialization operation on the storage area storing the security authentication record, and the initialization operation includes establishing a binding relationship between the user unified identifier and one or more account identifiers, wherein each account identifier is associated with its respective application, Wherein, the initialization operation is performed periodically or irregularly by a remote server after starting to store the security authentication record.

2. The method according to claim 1, wherein The method is executed in the trusted execution environment of the mobile terminal.

3. The method according to claim 1, wherein The type of authentication information includes at least one of fingerprint, face, voiceprint, and iris.

4. The method according to claim 1, wherein The specified security protocol is the FIDO protocol.

5. The method according to claim 1, wherein, If a security authentication record of the indicated type of authentication information is searched and the security authentication record is within the validity period, determine that there is a matching security authentication record.

6. The method according to claim 1, wherein The initialization operation is performed by a remote server before starting to store the security authentication record.

7. The method according to claim 1, wherein, Further includes the following steps: If the authentication performed by the first application or the second application passes, store the corresponding security authentication record.

8. A device for providing proxy authentication on a mobile terminal, including: A data storage module configured to store security authentication records associated with a user; A processing module configured to perform the following operations: Receive a query request from a first application, the query request indicating the type of authentication information involved in the authentication, wherein the authentication is based on a specified security protocol; Search for a security authentication record that matches the indicated type of authentication information in the data storage module; If there is a matching security authentication record, determine that the current user authentication passes, Wherein, the application service associated with the first application does not have the authentication ability based on the specified security protocol, and the processing module further performs the following operations: If there is no matching security authentication record, call a second application to perform authentication based on the specified security protocol, wherein the application service associated with the second application has the authentication ability based on the specified security protocol, Wherein, the security authentication record includes a user unified identifier, an account identifier, an authentication information type flag, and a validity period, The processing module further performs the following operations: Perform an initialization operation on the data storage module, where the initialization operation includes establishing a binding relationship between the user unified identifier and one or more account identifiers, and each account identifier is associated with its respective application program. Wherein, the initialization operation is performed periodically or irregularly by the remote server after starting to store the security verification record.

9. The device according to claim 8, wherein The device runs in the trusted execution environment of the mobile terminal.

10. The device according to claim 8, wherein, The verification information types include fingerprint, face, voiceprint, and iris.

11. The device according to claim 8, wherein, The specified security protocol is the FIDO protocol.

12. The apparatus according to claim 8, wherein, If a security verification record of the indicated verification information type is searched and the security verification record is within the validity period, it is determined that there is a matching security verification record.

13. The apparatus according to claim 8, wherein, The initialization operation is performed by the remote server before starting to store the security verification record.

14. The device according to claim 8, wherein, The processing module is further configured to perform the following operations: If the verification performed by the first application program or the second application program passes, store the corresponding security verification record.

15. A computer system, comprising: A memory; A processor coupled to the memory; And A computer program stored on the memory and executable on the processor, and the method according to any one of claims 1-7 is implemented by running the computer program.

16. A computer-readable storage medium storing computer programs / instructions, characterized in that, The steps of the method according to any one of claims 1-7 are implemented by the processor executing the computer program / instructions.

17. A computer program product comprising a computer program / instructions, characterized in that, The steps of the method according to any one of claims 1-7 are implemented by the processor executing the computer program / instructions.

Citation Information

Patent Citations

  • Message exchange method, social networking server and communication system

    CN106161183A

  • Information processing apparatus, control method, and storage medium

    CN109428725A