A user authentication method and apparatus

By collaborating between a unified identity authentication platform and authentication agents, and employing encoded and hybrid processing of user authentication digest data, the security and efficiency issues under centralized control of personal privacy data are addressed, achieving both security of user identity authentication and a sharing of the platform's burden.

CN115865367BActive Publication Date: 2025-12-05NEW H3C SECURITY TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211483841.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-12-05
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

In the context of centralized management of personal privacy data, how can we improve the security of users' personal privacy data and avoid information leakage and loss of system efficiency?

Method used

By collaborating between a unified identity authentication platform and authentication agents, and employing encoded and hybrid processing of user authentication digest data to generate encoded digest data and hybrid authentication digest data for identity authentication, instead of directly using raw personal information, the risk of information leakage is reduced and the platform's authentication burden is shared.

Benefits of technology

This system enables centralized management of users' personal privacy data through a unified identity authentication platform, thereby improving the security of authentication feature data, reducing the platform's authentication burden, and avoiding the risks of information leakage and system downtime.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865367B_ABST
    Figure CN115865367B_ABST
Patent Text Reader

Abstract

The application provides a user authentication method and device, and relates to the technical field of data processing. When the method is implemented by a proxy device, an authentication request of a user is received, the authentication request comprising authentication feature data; authentication summary data is generated according to the authentication feature data; the authentication summary data is encoded according to an encoding mode agreed with a unified identity authentication platform, to obtain encoded summary data; mixed authentication summary data is obtained, the mixed authentication summary data being obtained by encoding and mixing authentication summary data of authentication feature data of a plurality of users in a user database according to the encoding mode by the unified identity authentication platform; and if it is confirmed that the encoded summary data matches the mixed authentication summary data, it is confirmed that the user authentication is passed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a user authentication method and device. BACKGROUND

[0002] With the deepening of digital transformation, the generation and rapid development of a series of new service modes such as socializing, shopping, traveling, payment, and government affairs have made it a common practice for massive amounts of user personal information to interact across applications and platforms. User personal information inevitably remains in different information systems at each link in the whole life cycle of collection, storage, processing, application, exchange, and destruction, resulting in the separation of ownership, management, and use rights of information, and seriously threatening the user's right to know, right to delete / right to be forgotten, and extended authorization. The leakage, misuse, and sale of personal information provide opportunities for various illegal and criminal activities, such as network fraud, spam emails, and harassment calls, which pose a great danger to individuals and society. In recent years, with the implementation of laws and regulations such as security and personal information protection, personal privacy information protection has become increasingly important. In the process of promoting digital transformation, how to make personal privacy data available but invisible without sacrificing the efficiency and user experience of information systems or platforms is one of the important directions of current privacy protection research.

[0003] Currently, in order to achieve personal privacy data protection, ICT systems in various scenarios establish a unified access authentication platform system to realize centralized storage and control of personal privacy data. When a user accesses various business application systems, the user first performs identity authentication and authorization to the unified access authentication platform, and then accesses the business system. The unified access authentication platform system realizes personal privacy data protection through a series of security technical protection measures such as decentralization, auditing, encryption, and hiding. However, this method achieves privacy protection by strengthening the control of personal privacy data, which essentially sacrifices the efficiency and convenience of the system. At the same time, centralized storage and control of privacy data also easily causes single-point failure, and in the face of sudden access traffic, it also easily causes congestion or downtime.

[0004] Therefore, how to improve the security of user personal privacy data while realizing centralized control of personal privacy data is one of the technical problems worth considering. SUMMARY

[0005] Therefore, the present application provides a user authentication method and device to improve the security of user personal privacy data while realizing centralized control of personal privacy data.

[0006] Specifically, the present application is realized by the following technical solutions:

[0007] According to a first aspect of the present application, a user authentication method is provided, applied in an authentication agent, and the method comprises:

[0008] receiving an authentication request of a user, the authentication request comprising authentication feature data;

[0009] generating authentication summary data according to the authentication feature data;

[0010] encoding the authentication summary data according to an encoding manner agreed with a unified identity authentication platform to obtain encoded summary data;

[0011] obtaining mixed authentication summary data, the mixed authentication summary data being obtained by encoding and mixing authentication summary data of a plurality of users in a user database according to the encoding manner by the unified identity authentication platform;

[0012] if it is confirmed that the encoded summary data matches the mixed authentication summary data, confirming that the user is authenticated successfully.

[0013] According to a second aspect of the present application, a user authentication method is provided, applied to a unified identity authentication platform, the method comprising:

[0014] extracting authentication feature data of a plurality of users from a user database;

[0015] generating corresponding authentication summary data according to the extracted authentication feature data respectively;

[0016] encoding each of the generated authentication summary data according to an encoding manner agreed with an authentication agent to obtain encoded authentication summary data;

[0017] mixing each of the encoded authentication summary data to obtain mixed authentication summary data;

[0018] sending the mixed authentication summary data to the authentication agent, so that the authentication agent receives an authentication request of a user, the authentication request comprising authentication feature data; generates authentication summary data according to the authentication feature data; encodes the authentication summary data according to an encoding manner agreed with a unified identity authentication platform to obtain encoded summary data; obtains mixed authentication summary data; and if it is confirmed that the encoded summary data matches the mixed authentication summary data, confirms that the user is authenticated successfully.

[0019] According to a third aspect of the present application, a user authentication device is provided, arranged in an authentication agent, the device comprising:

[0020] a receiving module, configured to receive an authentication request of a user, the authentication request comprising authentication feature data;

[0021] a generating module, configured to generate authentication summary data according to the authentication feature data;

[0022] an encoding module configured to encode the authentication digest data according to an encoding manner agreed with the unified identity authentication platform, to obtain encoded authentication digest data;

[0023] an obtaining module configured to obtain mixed authentication digest data, the mixed authentication digest data being obtained by encoding and mixing authentication digest data of authentication feature data of a plurality of users in a user database according to the encoding manner by the unified identity authentication platform;

[0024] a confirming module configured to confirm that the user is authenticated successfully if it is confirmed that the encoded authentication digest data matches the mixed authentication digest data.

[0025] According to a fourth aspect of the present application, a user authentication apparatus is provided, which is arranged in a unified identity authentication platform, and the apparatus comprises:

[0026] an extracting module configured to extract authentication feature data of a plurality of users from a user database;

[0027] a generating module configured to generate corresponding authentication digest data according to each of the extracted authentication feature data;

[0028] an encoding module configured to encode each of the generated authentication digest data according to an encoding manner agreed with an authentication agent, to obtain encoded authentication digest data;

[0029] a mixing module configured to mix each of the encoded authentication digest data, to obtain mixed authentication digest data;

[0030] a sending module configured to send the mixed authentication digest data to the authentication agent, so that the authentication agent receives an authentication request of a user, the authentication request comprising authentication feature data; generates authentication digest data according to the authentication feature data; encodes the authentication digest data according to an encoding manner agreed with the unified identity authentication platform, to obtain encoded authentication digest data; obtains mixed authentication digest data; and confirms that the user is authenticated successfully if it is confirmed that the encoded authentication digest data matches the mixed authentication digest data.

[0031] According to a fifth aspect of the present application, an electronic device is provided, comprising a processor and a machine readable storage medium, the machine readable storage medium stores a computer program capable of being executed by the processor, and the processor is prompted by the computer program to execute the method provided in the first aspect of the embodiments of the present application.

[0032] According to a sixth aspect of the present application, a machine readable storage medium is provided, which stores a computer program, which, when invoked and executed by a processor, causes the processor to perform the method provided by the first aspect of the present application.

[0033] The present application has the following beneficial effects:

[0034] In the user authentication method and device provided by the present application, a user's authentication request is received, the authentication request including authentication feature data; authentication summary data is generated according to the authentication feature data; the authentication summary data is encoded according to an encoding mode agreed upon by a unified identity authentication platform, to obtain encoded summary data; mixed authentication summary data is obtained, the mixed authentication summary data being obtained by encoding and mixing authentication summary data generated by the unified identity authentication platform according to authentication feature data of a plurality of users in a user database; and if it is confirmed that the encoded summary data matches the mixed authentication summary data, it is confirmed that the user is authenticated. By using the above authentication method, the security of the authentication feature data of the user is ensured in the case that the unified identity authentication platform centrally manages and controls the personal privacy data of the user. BRIEF DESCRIPTION OF DRAWINGS

[0035] Figure 1 is a flowchart of a user authentication method provided by the present application;

[0036] Figure 2 is a flowchart of another user authentication method provided by the present application;

[0037] Figure 3 is a structural diagram of a user authentication device provided by the present application;

[0038] Figure 4 is a structural diagram of another user authentication device provided by the present application;

[0039] Figure 5 is a hardware structural diagram of an electronic device for implementing a user authentication method provided by the present application. DETAILED DESCRIPTION

[0040] The exemplary embodiments will be described in detail herein with reference to the drawings. When the following description refers to arrangements in the drawings, identical numbers on different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of apparatuses and methods consistent with some aspects of the present application.

[0041] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting. As used in this application, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "and / or," as used herein, refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0042] It is to be understood that, although the terms first, second, third, etc. can be used herein to describe various information, these terms are not intended to denote a particular order or hierarchy. These terms are used only to distinguish one type of information from another. For example, a first information can be termed a second information, and similarly, a second information can be termed a first information, without departing from the scope of this application. As used herein, the term "if' can be interpreted to mean "when" or "in response to determining" depending on the context.

[0043] The user authentication method provided by the present application is described in detail below.

[0044] Referring to Figure 1 , Figure 1 is a flowchart of a user authentication method provided by the present application. The method can be applied to an authentication agent, which can include the following steps when implementing the above method:

[0045] S101, receiving an authentication request of a user, the authentication request including authentication feature data.

[0046] In this step, when a user of a user terminal needs to access across platforms or applications, the user will send an authentication request to the connected authentication agent, and the authentication request will include authentication summary data at this time. In this way, the authentication agent can parse the authentication feature data of the user from the authentication request after receiving the authentication request.

[0047] Optionally, the authentication feature data can include, but is not limited to, account information, passwords, and the like.

[0048] S102, generating authentication summary data according to the authentication feature data.

[0049] In this step, in order to facilitate the authentication of the identity of the user, authentication summary data is generated based on the parsed authentication feature data for subsequent authentication. Specifically, the authentication summary data can be generated by using the methods that can be provided at present, and the present embodiment does not limit this.

[0050] S103, encoding the authentication summary data according to an encoding mode agreed with a unified identity authentication platform to obtain encoded summary data.

[0051] In this step, in order to avoid the leakage of personal information, the original personal privacy information of each user for cross-application and cross-platform interaction is no longer used for user identity authentication on the unified identity authentication platform, but the original personal privacy information is processed to obtain encoded summary data.

[0052] In order to facilitate the identity authentication of the user, the encoded summary data needs to be encoded to obtain the encoded summary data. It should be noted that the encoding method used by the authentication agent can be previously informed to the unified identity authentication platform, can be negotiated with the unified identity authentication platform, and can be selected according to actual conditions.

[0053] S104, obtaining mixed authentication summary data.

[0054] The mixed authentication summary data is obtained by encoding and mixing a plurality of authentication summary data in the user database according to the encoding method.

[0055] The unified identity authentication platform provided at present is used for centralized storage and management of the identity information of the user whose authentication is passed, and is used for management of the access right of the user, and is also responsible for authentication of the identity of the user. As a result, not only the leakage of personal information of the user is caused, but also the processing pressure of the unified identity authentication platform for user identity authentication is relatively large. Therefore, the present application proposes that a plurality of authentication agents are connected to the unified identity authentication platform, and each authentication agent is responsible for identity authentication of a part of the user. In this way, the processing pressure of the unified identity authentication platform is relieved. In addition, in order to avoid the leakage of personal information of the user, the personal information of the user is no longer used for authentication of the user in the unified identity authentication platform, but authentication is performed based on the authentication summary data. The mixed authentication summary data is the verification data generated by the unified identity authentication platform for authentication of the identity of the user by the authentication agent.

[0056] Specifically, when the unified identity authentication platform generates the mixed authentication summary data, the authentication summary data is generated based on the authentication feature data of each user recorded in the user database, and then the mixed authentication summary data is obtained by encoding and mixing each authentication summary data. It should be noted that the encoding method used by the unified identity authentication platform when encoding the authentication summary data is the same as the encoding method used by the authentication agent when performing identity authentication.

[0057] S105, if it is confirmed that the encoded summary data matches the mixed authentication summary data, it is confirmed that the authentication of the user is passed.

[0058] In this step, when matching the encoded summary data with the mixed authentication summary data, it can be judged whether the encoded summary data is contained in the mixed authentication summary data. When it is contained, it indicates that the authentication feature data of the user conforms to the content and format characteristics of the authentication data set by the unified identity authentication platform, that is, the identity authentication of the user is passed, and further the cross-platform or cross-application access of the user is allowed. When the mixed authentication summary data does not contain the component of the encoded summary data, it indicates that the authentication feature data of the user does not conform to the authentication requirements set by the unified identity authentication platform, so the identity authentication of the user is not passed, and the cross-platform or cross-application access of the user is not passed. In this way, when performing identity authentication, the authentication agent no longer directly stores the authentication feature data of each user, but uses the encoded summary data and the mixed authentication summary data generated based on the authentication feature data to authenticate the identity of the user. In this way, the identity of the user can be authenticated, and the loss of the authentication feature data (account information) of the user can be ensured. Even if the mixed authentication summary data recorded in the authentication agent is stolen, it is impossible to restore any valuable authentication feature data of the user, so the security of the personal privacy data is improved in the case of centralized management of the personal privacy data of the user in the unified identity authentication platform.

[0059] By implementing the user authentication method provided in the present application, the authentication request of the user is received, the authentication request includes authentication feature data; the authentication summary data is generated according to the authentication feature data; the authentication summary data is encoded according to the encoding mode agreed with the unified identity authentication platform to obtain the encoded summary data; the mixed authentication summary data is obtained, the mixed authentication summary data is the authentication summary data of a plurality of users in the user database generated by the unified identity authentication platform and mixed by encoding processing according to the encoding mode; if it is confirmed that the encoded summary data matches the mixed authentication summary data, it is confirmed that the authentication of the user is passed. By using the above authentication method, the security of the authentication feature data of the user is ensured in the case of centralized management of the personal privacy data of the user in the unified identity authentication platform.

[0060] Optionally, based on the above embodiment, in this embodiment, the authentication summary data can be encoded according to the encoding mode agreed with the unified identity authentication platform to obtain the encoded summary data: the authentication summary data is subjected to orthogonal encoding processing to obtain the encoded summary data.

[0061] Optionally, based on the above embodiment, in this embodiment, the encoded summary data and the mixed authentication summary data can be matched by the following method: filtering operation is performed on the encoded summary data and the mixed authentication summary data to obtain an authentication decision value; if the authentication decision value satisfies an authentication passing condition, it is determined that the encoded summary data and the mixed authentication summary data are matched.

[0062] Specifically, the encoded summary data and the mixed authentication summary data are input into a matched filter for matched filtering operation, so that an authentication decision value can be obtained, which can be represented by the following formula:

[0063]

[0064] wherein P is the authentication decision value, CS i is the encoded summary data of the user, and CH is the mixed authentication summary data.

[0065] Then, it is determined whether the authentication decision value P satisfies an authentication passing condition. When it is satisfied, it is determined that the authentication of the user is passed.

[0066] Optionally, when it is determined whether the authentication decision value P satisfies the authentication passing condition, the following process can be performed: if the authentication decision value P is a first set value, it is determined that the authentication decision value satisfies the authentication passing condition; if the authentication decision value is a second set value, it is determined that the authentication decision value does not satisfy the authentication passing condition.

[0067] Specifically, according to the basic principle of orthogonal encoding, the encoded authentication summary data after orthogonal encoding needs to satisfy the following conditions:

[0068]

[0069] In the above formula, i can represent the encoded authentication summary data obtained after orthogonal encoding of the i th authentication summary data; j can represent the encoded authentication summary data obtained after orthogonal encoding of the j th authentication summary data.

[0070] On this basis, if the CS i component exists in the mixed authentication summary data CH, the authentication decision value P = |CS i | 2 , that is, the first set value is |CS i | 2 , then it can be determined that the authentication decision value satisfies the authentication passing condition, and it is further determined that the user is a legal user, and the authentication of the user is passed. If the CS i component does not exist in the mixed authentication summary data, the authentication P = 0, that is, the second set value is 0, then it can be determined that the authentication decision value does not satisfy the authentication passing condition, and it is further determined that the user is an illegal user, and the authentication of the user is not passed.

[0071] Further, in the actual application process, the encoded data CS i may not be completely orthogonal, as shown in the above formula, which may cause the authentication decision value P to be unable to be strictly equal to 0 or |CS j may not be completely orthogonal, as shown in the above formula, which may cause the authentication decision value P to be unable to be strictly equal to 0 or |CS i | 2 In order to avoid misjudgment of the user's identity authentication, the authentication passing condition can be set as a detection threshold P0. When the authentication decision value P is within the range specified by the detection threshold P0, it is determined that the authentication decision value P satisfies the authentication passing condition. It should be noted that the range of the above-mentioned detection threshold P0 can be a first set range centered on |CS i | 2 Similarly, when the authentication decision value is within a second set range centered on 0, it is determined that the authentication decision value does not satisfy the authentication passing condition.

[0072] Optionally, based on any of the above embodiments, the user authentication method provided in the embodiment can further include the following processes: receiving a data update request sent by the unified identity authentication platform, the data update request including updated hybrid authentication summary data; the updated hybrid authentication summary data is authentication summary data generated by the unified identity authentication platform by encoding and mixing authentication feature data of a plurality of users in the updated user database when it is determined that the user's access rights have changed; and storing the updated hybrid authentication summary data.

[0073] Specifically, the access rights of different users can be the same or different, the access rights of the same user in different levels or different identities can be the same or different, and when the user's access rights change, the user's authentication feature data will also change accordingly, and the generated hybrid authentication summary data also needs to change. Therefore, when the unified identity authentication platform determines that the user's access rights have changed, it will generate hybrid authentication summary data again according to the above-mentioned method, which is denoted as updated hybrid authentication summary data, and then send the updated hybrid authentication summary data to the authentication agent, so as to perform identity authentication on the subsequent user's access.

[0074] It should be noted that at least one authentication agent can be distributed under the unified identity authentication platform, and the number of authentication agents can be related to the number of users currently provided by the authentication service. The more users, the more authentication agents can be set to reduce the burden of each authentication agent. In addition, when a user performs authentication, he / she can send an authentication request to the authentication agent close to him / her, or randomly select an authentication agent. Different authentication agents can provide authentication services for the same user or different users, which can be set according to the actual application scenario.

[0075] Therefore, in any embodiment of this application, user identity authentication is performed by an authentication proxy instead of by a unified identity authentication platform. This not only improves authentication efficiency but also avoids the problem of excessive burden and low efficiency caused by unified authentication by the unified identity authentication platform. It also avoids the situation where the unified identity authentication platform crashes due to excessive burden when performing identity authentication during peak access periods.

[0076] Based on the same inventive concept, this application also provides a user authentication method applied to a unified identity authentication platform. When implementing the user authentication method, the unified identity authentication platform can follow... Figure 2 The illustrated process includes the following steps:

[0077] S201. Extract authentication feature data of several users from the user database.

[0078] In this step, the user database records the authentication feature data of each user when they first register on the unified identity authentication platform. To ensure the accuracy of the authentication results, this embodiment can randomly extract the authentication feature data of several users from the user database.

[0079] In addition to storing and managing user authentication feature data, the unified identity authentication platform can also manage user permissions. To avoid excessive authentication pressure on the unified identity authentication platform, multiple authentication proxies are configured for it, and these proxies then authenticate the user's identity. To enable the authentication proxies to authenticate the user, the unified identity authentication platform executes the user authentication process provided in this embodiment.

[0080] S202. Generate corresponding authentication summary data based on the extracted authentication feature data.

[0081] In this step, the extracted authentication feature data is processed to generate authentication digest data. For example, the generated authentication digest data can be denoted as {S1, S2, ... S...} i …S n}, where each S i This represents a single authentication digest data. The value of n can be configured according to actual conditions, and this embodiment does not limit it.

[0082] It should be noted that the aforementioned authentication feature data may include, but is not limited to, user account information and passwords.

[0083] S203. Encode each generated authentication digest data according to the encoding method agreed upon with the authentication agent to obtain the encoded authentication digest data.

[0084] The encoding manner in this step can be previously informed to the unified identity authentication platform, or can be negotiated with the unified identity authentication platform, and can be selected according to actual conditions.

[0085] S204, mixing each encoded authentication digest data to obtain mixed authentication digest data.

[0086] By encoding and mixing the authentication feature data, the security of the authentication feature data of the user is effectively ensured, that is, the protection of the personal privacy data of the user is realized.

[0087] S205, sending the mixed authentication digest data to the authentication agent, so that the authentication agent receives the authentication request of the user, the authentication request including authentication feature data; generating authentication digest data according to the authentication feature data; encoding the authentication digest data according to the encoding manner agreed with the unified identity authentication platform to obtain encoded digest data; obtaining mixed authentication digest data; if it is confirmed that the encoded digest data matches the mixed authentication digest data, it is confirmed that the authentication of the user is passed.

[0088] In this step, after generating the mixed authentication digest data, the unified identity authentication platform can distribute it to the authentication agent as needed, for example, it can be distributed to all authentication agents; or it can be distributed to the authentication agent responsible for the identity authentication of the user according to the level, access authority and the like of the user.

[0089] By distributing the mixed authentication digest data to the authentication agent, the authentication agent can perform identity authentication on the user accessing the authentication agent based on the mixed authentication digest data. In this way, the identity of the user can be authenticated, and the loss of the authentication feature data (account information) of the user can be ensured, and even if the mixed authentication digest data recorded in the authentication agent is stolen, it is impossible to restore any valuable authentication feature data of the user, so that the security of the personal privacy data is improved in the case of centralized management of the personal privacy data of the user by the unified identity authentication platform.

[0090] Based on the above embodiment, the step S203 can be performed according to the following process: orthogonal encoding each authentication digest data to obtain the corresponding encoded authentication digest data.

[0091] Specifically, after orthogonal encoding each authentication digest data, the corresponding encoded authentication digest data can be obtained, for example, the encoded authentication digest data obtained by orthogonal encoding the above n authentication digest data can be denoted as {CS1, CS2,..., CSn}. n}.

[0092] It should be noted that, according to the basic principle of orthogonal encoding, the authentication digest data after orthogonal encoding needs to meet the following conditions:

[0093]

[0094] In the above formula, i can represent the encoded authentication digest data obtained after the i th authentication digest data is orthogonal encoded; j can represent the encoded authentication digest data obtained after the j th authentication digest data is orthogonal encoded.

[0095] By orthogonal encoding the authentication feature data, the security of the user's authentication feature data is effectively guaranteed, that is, the protection of the user's personal privacy data is realized.

[0096] Based on any of the above embodiments, in the present embodiment, step S204 can be performed according to the following method: superimposing each encoded authentication digest data to obtain mixed authentication digest data.

[0097] Specifically, superimposition processing can be performed according to the following formula to obtain mixed authentication digest data CH:

[0098] CH = CS1 + CS2 + … + CS n

[0099] In this way, the mixed authentication digest data for identity authentication can be obtained, and then the mixed authentication digest data is sent to the authentication agent.

[0100] Specifically, when sending the mixed authentication digest data, the mixed authentication digest data can be sent to the authentication agent through a secure channel, so that the authentication agent stores the received mixed authentication digest data and uses it to authenticate the user. By mixing the authentication feature data, the security of the user's authentication feature data is effectively guaranteed, that is, the protection of the user's personal privacy data is realized.

[0101] Alternatively, based on any of the above embodiments, the user authentication method provided in the present embodiment can further include the following process: when the user's authority is changed, updating the user database; obtaining authentication feature data of a plurality of users from the updated user database, and then generating corresponding authentication digest data according to each extracted authentication feature data; encoding each obtained authentication digest data according to the encoding method agreed with the authentication agent to obtain encoded authentication digest data; mixing each encoded authentication digest data to obtain updated mixed authentication digest data; and sending the updated mixed authentication digest data to the authentication agent.

[0102] Specifically, the access rights of different users can be the same or different, the access rights of the same user in different levels or different identities can be the same or different, when the user rights of a user are changed, the authentication feature data of the user will also change accordingly, and the mixed authentication digest data generated will also change. Therefore, when the unified identity authentication platform confirms that the user rights are changed, it will generate mixed authentication digest data again according to the above-mentioned method, denoted as updated mixed authentication digest data, and then send the updated mixed authentication digest data to the authentication agent, so that the authentication agent performs identity authentication on the subsequent user access.

[0103] Any embodiment of the present application adopts an authentication agent to perform user identity authentication, instead of the unified identity authentication platform, so that not only the authentication efficiency is improved, but also the problem of excessive burden and low efficiency caused by unified authentication of the unified identity authentication platform is avoided, and the situation that the unified identity authentication platform is down due to excessive burden when performing identity authentication during the access peak period is also avoided. By orthogonal encoding and mixing the authentication feature data of the user, the protection of the authentication feature data of the privacy of the user is realized.

[0104] Based on the same inventive concept, the present application also provides a user authentication device corresponding to the above-mentioned user authentication method of the authentication agent side. The implementation of the user authentication device can refer to the description of the user authentication method of the authentication agent, which will not be discussed one by one here.

[0105] Referring to Figure 3 , Figure 3 is a user authentication device provided by an exemplary embodiment of the present application, which is arranged in an authentication agent. The device comprises:

[0106] The first receiving module 301 is configured to receive an authentication request of a user, wherein the authentication request comprises authentication feature data;

[0107] The generating module 302 is configured to generate authentication digest data according to the authentication feature data;

[0108] The encoding module 303 is configured to encode the authentication digest data according to an encoding mode agreed with the unified identity authentication platform, to obtain encoded digest data;

[0109] The obtaining module 304 is configured to obtain mixed authentication digest data, wherein the mixed authentication digest data is obtained by encoding and mixing the authentication digest data of a plurality of users in a user database generated by the unified identity authentication platform according to the encoding mode;

[0110] The confirmation module 305 is configured to confirm that the user authentication is passed if it is confirmed that the encoded summary data matches the mixed authentication summary data.

[0111] Optionally, based on the above-mentioned embodiments, in this embodiment, the confirmation module 305 is specifically configured to perform filtering operation processing on the encoded summary data and the mixed authentication summary data to obtain an authentication decision value; and if the authentication decision value satisfies an authentication passing condition, it is confirmed that the encoded summary data matches the mixed authentication summary data.

[0112] Optionally, based on any of the above-mentioned embodiments, in this embodiment, the encoding module 303 is specifically configured to perform orthogonal encoding processing on the authentication summary data to obtain the encoded summary data.

[0113] Optionally, based on any of the above-mentioned embodiments, the user authentication device provided in this embodiment can further include:

[0114] The second receiving module (not shown in the figure) is configured to receive a data update request sent by the unified identity authentication platform, wherein the data update request includes updated mixed authentication summary data; the updated mixed authentication summary data is authentication summary data generated by performing encoding processing on authentication feature data of a plurality of users in an updated user database according to the encoding mode by the unified identity authentication platform when it is confirmed that the user rights have changed;

[0115] The storage module (not shown in the figure) is configured to store the updated mixed authentication summary data.

[0116] Based on the same inventive concept, the present application also provides a user authentication device corresponding to the above-mentioned user authentication method of the unified identity authentication platform side. The implementation of the user authentication device can be specifically referred to the description of the user authentication method of the unified identity authentication platform, which will not be discussed here one by one.

[0117] Referring to Figure 4 , Figure 4 is a user authentication device provided by an exemplary embodiment of the present application, which is arranged in a unified identity authentication platform, and the device includes:

[0118] The extraction module 401 is configured to extract authentication feature data of a plurality of users from a user database;

[0119] The generation module 402 is configured to generate corresponding authentication summary data according to each of the extracted authentication feature data;

[0120] The encoding module 403 is configured to perform encoding processing on each of the generated authentication summary data according to an encoding mode agreed with an authentication agent to obtain encoded authentication summary data;

[0121] a mixing module 404, configured to perform mixing processing on the respective encoded authentication digest data to obtain mixed authentication digest data;

[0122] a sending module 405, configured to send the mixed authentication digest data to the authentication agent, so that the authentication agent receives an authentication request of a user, the authentication request including authentication feature data; generates authentication digest data according to the authentication feature data; encodes the authentication digest data according to an encoding manner agreed with the unified identity authentication platform to obtain encoded authentication digest data; obtains mixed authentication digest data; and confirms that the user is authenticated successfully if the encoded authentication digest data matches the mixed authentication digest data.

[0123] Optionally, based on the above-mentioned embodiments, in this embodiment, the encoding module 403 is specifically configured to perform orthogonal encoding processing on each authentication digest data to obtain encoded authentication digest data corresponding to the authentication digest data.

[0124] Optionally, based on any of the above-mentioned embodiments, in this embodiment, the mixing module 404 is specifically configured to perform superposition processing on the respective encoded authentication digest data to obtain mixed authentication digest data.

[0125] Optionally, based on any of the above-mentioned embodiments, the user authentication apparatus provided in this embodiment further includes:

[0126] an updating module (not shown in the figure), configured to update the user database when a user right is changed;

[0127] On this basis, the extraction module 401 is further configured to obtain authentication feature data of a plurality of users from the updated user database;

[0128] The generation module 402 is further configured to generate corresponding authentication digest data according to the respective extracted authentication feature data;

[0129] The encoding module 403 is further configured to perform encoding processing on the respective obtained authentication digest data according to an encoding manner agreed with the authentication agent to obtain encoded authentication digest data;

[0130] The mixing module 404 is further configured to perform mixing processing on the respective encoded authentication digest data to obtain updated mixed authentication digest data;

[0131] The sending module 405 is further configured to send the updated mixed authentication digest data to the authentication agent.

[0132] Based on the same inventive concept, the embodiments of the present application provide an electronic device, which can be but is not limited to the above-mentioned authentication agent or unified identity authentication platform. As shown in FIG. 8, the electronic device includes a processor 801, a memory 802 and a communication interface 803.Figure 5 As shown, the electronic device can include a processor 501 and a machine readable storage medium 502, the machine readable storage medium 502 stores a computer program which can be executed by the processor 501, and the processor 501 is prompted by the computer program to execute the user authentication method provided by any embodiment of the present application. In addition, the electronic device further includes a communication interface 503 and a communication bus 504, wherein the processor 501, the communication interface 503, and the machine readable storage medium 502 complete the communication among each other through the communication bus 504.

[0133] The communication bus mentioned above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or only one type of bus.

[0134] The communication interface is used for communication between the above-mentioned electronic device and other devices.

[0135] The above-mentioned machine readable storage medium 502 can be a memory, which can include a Random Access Memory (RAM), a DDR SRAM (Double Data Rate Synchronous Dynamic Random Access Memory), and can also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory can also be at least one storage device located away from the above-mentioned processor.

[0136] The above-mentioned processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.

[0137] For the electronic device and the machine readable storage medium embodiments, since the method contents involved are basically similar to the foregoing method embodiments, the description is relatively simple, and the relevant parts are referred to the part of the method embodiment.

[0138] It should be noted that the terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0139] The implementation process of the functions and roles of each unit / module in the above device is specifically described in the implementation process of the corresponding steps in the above method, which will not be repeated here.

[0140] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts are referred to the part of the method embodiment. The device embodiments described above are only illustrative, and the units / modules described as separate components can or can not be physically separated, and the components displayed as units / modules can or can not be physical units / modules, i.e. they can be located in one place or distributed on multiple network units / modules. Part or all of the units / modules can be selected to achieve the purpose of the present application according to actual needs. Those skilled in the art can understand and implement it without creative labor.

[0141] The above description is only the preferred embodiment of the present application, and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the scope of protection of the present application.

Claims

1. A user authentication method characterized by, The method applied to the authentication agent, comprising: receiving an authentication request of a user, the authentication request comprising authentication feature data; generating authentication summary data according to the authentication feature data; encoding the authentication summary data according to an encoding mode agreed with a unified identity authentication platform to obtain encoded summary data; obtaining mixed authentication summary data, the mixed authentication summary data being obtained by encoding and mixing authentication summary data of authentication feature data of a plurality of users in a user database according to the encoding mode by the unified identity authentication platform; the mixed authentication summary data cannot restore the authentication feature data of the user; if it is confirmed that the encoded summary data matches the mixed authentication summary data, it is confirmed that the authentication of the user is passed; the method specifically matches the encoded summary data and the mixed authentication summary data by the following way: judging whether the mixed authentication summary data contains the encoded summary data, when containing, it indicates that the user authentication is passed, otherwise it indicates that the user authentication is not passed.

2. The method of claim 1, wherein, The encoded summary data and the mixed authentication summary data are matched according to the following method: filtering operation processing is performed on the encoded summary data and the mixed authentication summary data to obtain an authentication decision value; if the authentication decision value meets the authentication passing condition, it is confirmed that the encoded summary data matches the mixed authentication summary data.

3. The method of claim 1, wherein, The authentication summary data is encoded according to the encoding mode agreed with the unified identity authentication platform to obtain the encoded summary data, comprising: orthogonal encoding processing is performed on the authentication summary data to obtain the encoded summary data.

4. The method of claim 1, wherein, Further comprising: receiving a data update request sent by the unified identity authentication platform, the data update request comprising updated mixed authentication summary data; the updated mixed authentication summary data being obtained by encoding and mixing authentication summary data of authentication feature data of a plurality of users in an updated user database according to the encoding mode by the unified identity authentication platform when confirming that the user authority is changed; storing the updated mixed authentication summary data.

5. A user authentication method characterized by, The method applied to the unified identity authentication platform, comprising: extracting authentication feature data of a plurality of users from a user database; generating corresponding authentication summary data according to each extracted authentication feature data; encoding each generated authentication summary data according to an encoding mode agreed with an authentication agent to obtain encoded authentication summary data; mixing each encoded authentication summary data to obtain mixed authentication summary data; the mixed authentication summary data cannot restore the authentication feature data of the user; The mixed authentication digest data is sent to the authentication agent, so that the authentication agent receives an authentication request of a user, the authentication request including authentication feature data; authentication digest data is generated according to the authentication feature data; and the authentication digest data is encoded according to an encoding mode agreed with the unified identity authentication platform, to obtain encoded digest data; the mixed authentication digest data is obtained; and if it is confirmed that the encoded digest data matches the mixed authentication digest data, it is confirmed that the user is authenticated successfully; The authentication agent specifically matches the encoded digest data and the mixed authentication digest data in the following manner: it is judged whether the mixed authentication digest data contains the encoded digest data; when it contains, it indicates that the user is authenticated successfully; otherwise, it indicates that the user is not authenticated successfully.

6. The method of claim 5, wherein, Each authentication digest data is encoded according to the encoding mode agreed with the authentication agent, to obtain encoded authentication digest data, including: Each authentication digest data is orthogonally encoded, to obtain the encoded authentication digest data corresponding to the authentication digest data.

7. The method of claim 5, wherein, The mixed authentication digest data is obtained by mixing the encoded authentication digest data, including: The mixed authentication digest data is obtained by superimposing the encoded authentication digest data.

8. The method of claim 5, wherein, Further including: When the user permission is changed, the user database is updated; The authentication feature data of a plurality of users is obtained from the updated user database; According to the extracted authentication feature data, corresponding authentication digest data is generated; Each authentication digest data is encoded according to the encoding mode agreed with the authentication agent, to obtain encoded authentication digest data; The mixed authentication digest data is obtained by mixing the encoded authentication digest data; The updated mixed authentication digest data is sent to the authentication agent.

9. A user authentication apparatus characterized by comprising: The device is arranged in the authentication agent, including: A first receiving module for receiving an authentication request of a user, the authentication request including authentication feature data; A generating module for generating authentication digest data according to the authentication feature data; An encoding module for encoding the authentication digest data according to an encoding mode agreed with the unified identity authentication platform, to obtain encoded digest data; An obtaining module for obtaining mixed authentication digest data, the mixed authentication digest data being authentication digest data generated by the unified identity authentication platform by encoding a plurality of authentication feature data of users in a user database and mixing; the mixed authentication digest data cannot restore the authentication feature data of the user; A confirming module for confirming that the user is authenticated successfully if it is confirmed that the encoded digest data matches the mixed authentication digest data; The confirming module specifically matches the encoded digest data and the mixed authentication digest data in the following manner: it is judged whether the mixed authentication digest data contains the encoded digest data; when it contains, it indicates that the user is authenticated successfully; otherwise, it indicates that the user is not authenticated successfully.

10. A user authentication apparatus characterized by comprising: The device is arranged in the unified identity authentication platform, including: An extraction module is configured to extract authentication feature data of a plurality of users from a user database; A generation module is configured to generate corresponding authentication digest data according to the extracted authentication feature data respectively; An encoding module is configured to encode each of the generated authentication digest data according to an encoding manner agreed with an authentication agent, to obtain encoded authentication digest data; A mixing module is configured to mix each of the encoded authentication digest data, to obtain mixed authentication digest data; the mixed authentication digest data cannot restore the authentication feature data of the user; A sending module is configured to send the mixed authentication digest data to the authentication agent, so that the authentication agent receives an authentication request of the user, the authentication request including authentication feature data; generates authentication digest data according to the authentication feature data; encodes the authentication digest data according to an encoding manner agreed with the unified identity authentication platform, to obtain encoded digest data; acquires mixed authentication digest data; and confirms that the user is authenticated if the encoded digest data matches the mixed authentication digest data; The authentication agent matches the encoded digest data with the mixed authentication digest data by the following manner: judging whether the mixed authentication digest data contains the encoded digest data; if yes, the user is authenticated; otherwise, the user is not authenticated.

Citation Information

Patent Citations

  • Time-space hybrid code authentication method and system based on Beidou system

    CN108197673A

  • Authentication method and apparatus

    CN108243148A

  • Micro-service access proxy method and device thereof and storage medium

    CN113676336A