Signature Authentication Method and Device

By determining whether the terminal device is contaminated on the server side and using dynamic signature parameters for authentication, the signature authentication security problem caused by the leakage of service private keys in TEE is solved, and higher security and reliability are achieved.

CN115941207BActive Publication Date: 2025-07-29ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211673945.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-26
Publication Date
2025-07-29
Estimated Expiration
2042-12-26

AI Technical Summary

Technical Problem

The existing signature authentication method is not secure enough, especially after the service private key is leaked in the TEE of the terminal device, the attacker can counterfeit signatures for authentication, resulting in unsafe business process.

Method used

On the server side, determine whether the terminal device is a contaminated device. If so, re-determine using dynamic signature parameters for signature authentication instead of using inherent information. The dynamic signature parameter library includes fingerprint ID, device ID, APP package name, business scenario and user ID, etc., and determine the parameters by random or one by one.

Benefits of technology

Improve the security of signature authentication, prevent attackers from forging signature authentication successfully, and enhance the security and reliability of the business process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941207B_ABST
    Figure CN115941207B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a signature authentication method and apparatus, which are applied to a server, and the server performs signature authentication on a terminal device. In this signature authentication method, the business private key required for signature authentication is pre-embedded in the trusted execution environment (TEE) of the terminal device, and the TEE verifies the biometrics input by the user. After the verification is successful, the TEE completes the signature required for the signature authentication request. The method includes: the server receives a signature authentication request from the terminal device; determines whether the terminal device that sent the signature authentication request is a contaminated device, and if so, determines the dynamic signature parameters required for this signature authentication; reauthorizes the terminal device to activate verification authority, and notifies the terminal device to collect the dynamic signature parameters; receives the value of the dynamic signature parameter sent by the terminal device; and performs signature authentication based on the value of the dynamic signature parameter. The embodiments of this specification can improve the security of signature authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to network communication technologies, and particularly to signature authentication methods and apparatuses. Background Art

[0002] With the development of Internet technologies, in many business scenarios, biometric recognition has been used as an identity authentication method. That is to say, the biometric features of a user, such as fingerprint information or face-scanning information, are used to replace the password manually input by the user, such as a password in digital / letter form, to authenticate the identity of the user.

[0003] To ensure the convenience, security, and trustworthiness of using biometric recognition as an identity authentication method, a new signature authentication technology has emerged, called the Internet Finance Authentication Alliance (IFAA). See Figure 1 , in this new signature technology, before a terminal device such as a mobile phone leaves the factory, a service private key for signature authentication is pre-embedded in the trusted execution environment (TEE) of the terminal device, and the client and the TEE cooperate to complete the signature. In various business scenarios such as face authentication, the terminal device can perform a signature based on this new signature authentication technology, and the server authenticates the signature. After successful authentication, the server provides services.

[0004] However, the current signature authentication method is not secure enough. Summary of the Invention

[0005] One or more embodiments of this specification describe signature authentication methods and apparatuses that can improve the security of signature authentication.

[0006] According to a first aspect, a signature authentication method is provided, which is applied to a server to perform signature authentication on a terminal device; in this signature authentication method, a service private key required for signature authentication is pre-embedded in the TEE of the terminal device, and the TEE verifies the biometric features input by the user. After successful verification, the TEE completes the signature required for the signature authentication request; wherein, it includes:

[0007] Receiving a signature authentication request sent by the terminal device;

[0008] Determining whether the terminal device that sent this signature authentication request is a contaminated device,

[0009] If so, determining the dynamic signature parameters to be used for this signature authentication;

[0010] Re-authorizing the terminal device to open the verification permission and notifying the terminal device to collect the dynamic signature parameters;

[0011] Receiving the value of the dynamic signature parameter sent by the terminal device;

[0012] Signature authentication is performed according to the value of the dynamic signature parameter.

[0013] The determining whether the terminal device that sends the signature authentication request is a contaminated device includes:

[0014] Obtain the model information of the terminal device or the protocol version information used by the signature carried in the signature authentication request;

[0015] It is determined whether the obtained model information or version information of the terminal device can be found in the pre-obtained blacklist. If so, it is determined that the terminal device that sends the signature authentication request is a contaminated device.

[0016] The dynamic signature parameters required for this signature authentication are as follows:

[0017] The dynamic signature parameters required for this signature authentication are selected from a preset dynamic signature parameter library using a random selection method or a one-by-one selection method.

[0018] The dynamic signature parameter library includes:

[0019] Fingerprint ID, device ID, application package name, business scenario, and user ID.

[0020] The dynamic signature parameter library includes parameters associated with the service.

[0021] The method further comprises: setting a corresponding parameter serial number for each parameter in the dynamic signature parameter library;

[0022] The notifying the terminal device to collect the dynamic signature parameters includes: sending a notification message to the terminal device, the first field in the notification message including the parameter serial number corresponding to the dynamic signature parameter required for this signature authentication; the second field in the notification message is used to indicate the length of the first field.

[0023] According to a second aspect, a signature authentication device is provided, which is applied to a server and performs signature authentication on a terminal device. In this signature authentication method, a service private key required for signature authentication is pre-embedded in the TEE of the terminal device, and the TEE verifies the biometric features input by the user. After successful verification, the TEE completes the signature required for the signature authentication request. The signature authentication device includes:

[0024] An authentication request receiving module configured to receive a signature authentication request sent by a terminal device;

[0025] A judgment module, configured to judge whether the terminal device that sends the signature authentication request is a contaminated device.

[0026] A dynamic signature parameter determination module, configured to determine the dynamic signature parameters required for this signature authentication after judging that the terminal device that sends the signature authentication request is a contaminated device.

[0027] A restart verification module, configured to re-authorize the terminal device to open the verification permission and notify the terminal device to collect the dynamic signature parameters.

[0028] A re-authentication execution module, configured to receive the value of the dynamic signature parameters sent by the terminal device and perform signature authentication according to the value of the dynamic signature parameters.

[0029] Among them, the restart verification module is configured to send a notification message to the terminal device. The first field in the notification message includes the parameter serial number corresponding to the dynamic signature parameters required for this signature authentication. The second field in the notification message is used to indicate the length of the first field.

[0030] According to a third aspect, a computing device is provided, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in any embodiment of this specification is implemented.

[0031] The signature authentication method and apparatus provided by the embodiments of this specification modify the existing signature authentication process. When the server receives a signature authentication request sent by a terminal device, instead of directly performing signature authentication using the inherent information carried in the signature authentication request, such as the device ID, it first determines whether the terminal device that sent the signature authentication request is a contaminated device. Here, a contaminated device refers to a terminal device in which the service private key in the TEE has been leaked. If the terminal device is a contaminated device, then it is very likely that after the service private key is leaked, the signature authentication request is initiated by an attacker imitating the signature. At this time, if signature authentication is still performed according to the prior art using the inherent information carried in the signature authentication request, such as the device ID, the attacker will be authenticated successfully, resulting in the insecurity of the business process. Therefore, in the embodiments of this specification, after it is determined that the terminal device is a contaminated device, signature authentication will not be performed using the inherent information carried in the signature authentication request, such as the device ID. Instead, the dynamic signature parameters to be used for this signature authentication are re-determined. That is to say, first, signature authentication needs to be restarted; second, the existing inherent information is no longer used for signature authentication, but dynamic signature parameters are adopted, that is, the parameters used for each signature authentication are different and the parameters are dynamically changed. Since attackers usually can only steal signatures and cannot steal the values of dynamic signature parameters, such as the application (APP) package name, the server performs signature authentication based on the value of the dynamic signature parameter. If the value of the dynamic signature parameter, such as the APP package name, is a normal value that conforms to the current business scenario, then the signature authentication is successful, indicating that the current terminal device is a terminal device conducting normal business. If the value of the dynamic signature parameter, such as the APP package name, is an abnormal value that does not conform to the current business scenario, then the signature authentication fails, indicating that the current terminal device is an attacker.

[0032] In addition, since future adaptations will be diverse, and even some models cannot complete the cooperation of burning the key in the TEE. However, for the development of the business scenario, corresponding measures will also be taken. Therefore, once some important private keys are leaked, it poses a very great test to the security of the entire system. Therefore, this solution adds a function for detecting the degree of contamination, and sets the sampled fields to be dynamic, which can complete the timely repair of the device type and device vulnerabilities, so as to continue to maintain the security and reliability characteristics. Description of the Drawings

[0033] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0034] Figure 1 It is a schematic diagram of the system architecture applied in an embodiment of this specification.

[0035] Figure 2 It is a flowchart of the signature authentication method in an embodiment of this specification.

[0036] Figure 3 It is a schematic structural diagram of the signature authentication device in an embodiment of this specification. Detailed implementation manners

[0037] With the application and adaptation of emerging signature authentication methods such as the IFAA protocol, more and more terminal devices such as mobile phones burn the service private key required for signature authentication into the TEE of the terminal device before leaving the factory. However, due to the misunderstanding of third-party manufacturers, some vulnerabilities that are difficult to control and repair will occur. For example, the third-party manufacturer burns a test version, that is, burns the test interface / modulation interface into the TEE of the terminal device. In this way, attackers can easily steal the service private key in the TEE through the test interface / modulation interface, and thus can steal the signature and carry out attack behaviors.

[0038] The following describes the solution provided in this specification with reference to the accompanying drawings.

[0039] First of all, it should be noted that the terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "the" and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0040] For the convenience of understanding the method provided in this specification, the system architecture involved and applicable in this specification is first described. As Figure 1 shown, the system architecture mainly includes two types of network nodes: terminal devices and servers.

[0041] Among them, the terminal device may include but is not limited to, for example: intelligent mobile terminals, smart home devices, network devices, wearable devices, intelligent medical devices, PCs (personal computers), etc. Among them, intelligent mobile devices may include, for example, mobile phones, tablets, laptops, PDAs (personal digital assistants), Internet cars, etc. Smart home devices may include smart home appliance devices, such as smart TVs, smart air conditioners, smart water heaters, smart refrigerators, smart air purifiers, etc. Smart home devices may also include smart door locks, smart sockets, smart lights, smart cameras, etc. Network devices may include, for example, switches, wireless APs, servers, etc. Wearable devices may include, for example, smart watches, smart glasses, smart bracelets, virtual reality devices, augmented reality devices, mixed reality devices (i.e., devices that can support virtual reality and augmented reality), etc. Intelligent medical devices may include, for example, intelligent thermometers, intelligent blood pressure monitors, intelligent blood glucose meters, etc.

[0042] The server refers to the server device of the provider that provides network services. It can be a single server or a server group composed of multiple servers. It is responsible for providing network services for various applications, such as security authentication, management of network service levels, etc.

[0043] The terminal device includes the IFAA SDK and the application client. The application client can be various types of application programs (APPs), and performs IFAA signature authentication by calling the IFAA SDK.

[0044] It should be understood that Figure 1 the number of APPs, the IFAA SDK, terminal devices, and servers in is merely illustrative. According to the implementation requirements, any number can be selected and arranged.

[0045] Figure 2 is a flowchart of the signature authentication method in an embodiment of this specification. The execution subject of this method is the server. It can be understood that this method can also be executed by any device, equipment, platform, or device cluster with computing and processing capabilities. Refer to Figure 2 and this method includes:

[0046] Step 201: The server receives the signature authentication request sent by the terminal device.

[0047] Step 203: The server determines whether the terminal device that sent this signature authentication request is a contaminated device. If so, execute Step 207; otherwise, execute Step 205.

[0048] Step 205: Perform signature authentication in the prior art and end the current process.

[0049] Step 207: The server determines the dynamic signature parameters required for this signature authentication.

[0050] Step 209: The server re-authorizes the terminal device to open the verification permission and notifies the terminal device to collect the dynamic signature parameters.

[0051] Step 211: The server receives the value of the dynamic signature parameters sent by the terminal device.

[0052] Step 213: The server performs signature authentication based on the value of the dynamic signature parameters.

[0053] According to the above Figure 2 As can be seen from the process shown above, the embodiments of this specification modify the existing signature authentication process. When the server receives a signature authentication request sent by a terminal device, instead of directly performing signature authentication using the inherent information carried in the signature authentication request, such as the device ID, it first determines whether the terminal device that sent the signature authentication request is a contaminated device. Here, a contaminated device refers to a device in which the service private key in the TEE of the terminal device has been leaked. If the terminal device is a contaminated device, then it is very likely that the signature authentication request was initiated by an attacker imitating the signature after the service private key was leaked. At this time, if signature authentication is still performed using the inherent information carried in the signature authentication request, such as the device ID, as in the prior art, the attacker will be authenticated successfully, resulting in the insecurity of the business process. Therefore, in the embodiments of this specification, after it is determined that the terminal device is a contaminated device, signature authentication will not be performed using the inherent information carried in the signature authentication request, such as the device ID. Instead, the dynamic signature parameters to be used for this signature authentication are re-determined. That is to say, first, signature authentication needs to be restarted; second, the existing inherent information is no longer used for signature authentication, but dynamic signature parameters are used. That is, the parameters used for each signature authentication are different and the parameters are dynamically changing. Because attackers usually can only steal signatures and cannot steal the values of dynamic signature parameters, such as the application (APP) package name, the server performs signature authentication based on the value of the dynamic signature parameters. If the value of the dynamic signature parameter, such as the APP package name, is a normal value that conforms to the current business scenario, then the signature authentication is successful, indicating that the current terminal device is a terminal device performing normal business. If the value of the dynamic signature parameter, such as the APP package name, is an abnormal value that does not conform to the current business scenario, then the signature authentication fails, indicating that the current terminal device is likely to be an attacker.

[0054] The following uses a specific example to Figure 2 illustrate the process shown above.

[0055] First, for step 201: The server receives a signature authentication request sent by the terminal device.

[0056] Here, the terminal device can call the SDK (Software Development Kit) when initiating a business process, such as the login process of a business system or the payment process of online shopping, to perform signature authentication in the business process. The signature authentication request initiated by the terminal device to the server will carry the terminal device user's biometric information, such as facial image or fingerprint.

[0057] On the terminal device side, the business private key required for signature authentication is pre-embedded in the TEE of the terminal device, and the TEE verifies the biometric features entered by the user. After the verification is successful, the TEE completes the signature required for the signature authentication request; and the client in the terminal device sends the signature authentication request with the completed signature to the server, so that the server receives the signature authentication request sent by the terminal device.

[0058] Next, in step 203 , the server determines whether the terminal device that sends the signature authentication request is a contaminated device. If so, step 207 is executed; otherwise, step 205 is executed.

[0059] Here, if an attacker has stolen the business private key in the TEE of a terminal device through a test interface or modulation interface, then the terminal device is a contaminated device. In actual business implementation, when the business private key in the TEE is leaked, the server will obtain a blacklist that stores the information of all contaminated devices.

[0060] In actual business implementation, a group of terminal devices of the same type are often contaminated. Therefore, a blacklist can be set according to the model information of the terminal device to determine whether the terminal device that sends the signature authentication request is a contaminated device.

[0061] Of course, it is often the same version of the business private key that is leaked. Therefore, a blacklist can be set based on the protocol version information used for the signature, such as the version information of the IFAA protocol, to determine whether the terminal device that sends the signature authentication request is a contaminated device.

[0062] That is to say, the process of this step 203 may include: obtaining the model information or version information of the terminal device carried in the signature authentication request; judging whether the obtained model information or version information of the terminal device can be found in the pre-obtained blacklist, and if so, determining that the terminal device that sent the signature authentication request is a contaminated device.

[0063] Step 205: The server performs signature authentication in the prior art, and ends the current process.

[0064] Step 207: The server determines the dynamic signature parameters to be used for this signature authentication.

[0065] When executing this step 207, since it has been determined that the terminal device that sent the signature authentication request is a contaminated device, therefore, this signature authentication request may be sent by an attacker imitating the signature. Therefore, in the embodiments of this specification, first, the signature authentication needs to be restarted; second, the existing inherent information is no longer used for subsequent signature authentication, but dynamic signature parameters are adopted, that is, the parameters used for each signature authentication are different and the parameters are dynamically changed. Because attackers usually can only steal signatures and cannot steal the values of dynamic signature parameters, such as unable to steal the application (APP) package name. Therefore, in this step 207, the server determines the dynamic signature parameters to be used for this signature authentication.

[0066] A dynamic signature parameter library can be preset. The dynamic signature parameter library includes numerous dynamic signature parameters, and each type of dynamic signature parameter corresponds to a business requirement. In this step 207, according to the current business requirement, the dynamic signature parameters to be used for this signature authentication are determined.

[0067] Specifically, this step 207 may include:

[0068] Using a randomly selected method or a sequential selection method, select the dynamic signature parameters to be used for this signature authentication from the preset dynamic signature parameter library. For example, the dynamic signature parameter library includes parameters associated with the business.

[0069] In an embodiment of this specification, the dynamic signature parameter library includes: fingerprint ID, device ID, APP package name, business scenario, user ID, etc.

[0070] Therefore, in the embodiments of this specification, in this step 207, for example, the APP package name can be dynamically selected as the dynamic signature parameter to be used for this signature authentication.

[0071] In an embodiment of this specification, the method further includes: presetting a corresponding parameter serial number for each parameter in the dynamic signature parameter library; for example, setting it in the following form:

[0072] Parameter serial number:

[0073] 0x01: Fingerprint ID

[0074] 0x02: Device ID

[0075] 0x03: APP package name

[0076] 0x04: Business scenario

[0077] 0x05: User ID

[0078] In this sample step 207, specifically, it may be to determine the parameter serial number of the dynamic signature parameter to be used in this signature authentication.

[0079] Step 209: The server re-authorizes the terminal device to open the verification permission and notifies the terminal device to collect dynamic signature parameters.

[0080] The specific process of this step 209 may include: The server sends a notification message to the terminal device. The first field in the notification message includes the parameter serial number corresponding to the dynamic signature parameter to be used in this signature authentication; the second field in the notification message is used to indicate the length of the first field.

[0081] Here, because in the embodiments of this specification, the signature authentication process is changed, and the terminal device does not know how many and what dynamic signature parameters the server requires it to collect. That is to say, the parameters collected by the terminal device during signature authentication become variable bytes. Therefore, in order to ensure the correct progress of the service, the server can carry the first field and the second field in the notification message. Among them, the second field is used to indicate the length of the first field, so as to notify the terminal device of the length of the field of this part of the dynamic signature parameter, so that the terminal device knows how many dynamic signature parameters need to be collected. Among them, the first field is used to indicate the parameter serial number corresponding to the dynamic signature parameter to be used in this signature authentication, so that the terminal device knows what dynamic signature parameters need to be collected. It can be seen that by using the first field and the second field, the terminal device can know how many and what dynamic signature parameters to collect.

[0082] After that, after receiving the notification, the terminal device will call the system function to collect the values of the corresponding dynamic signature parameters, such as the APP package name and / or the user ID, according to the first field and the second field, and then send the values of the collected dynamic signature parameters to the server.

[0083] Next is step 211: The server receives the values of the dynamic signature parameters sent by the terminal device.

[0084] Next is step 213: The server performs signature authentication according to the values of the dynamic signature parameters.

[0085] In this way, during the signature authentication process, the server no longer uses the original fixed parameters for authentication, but changes the parameters used for authentication into variable bytes.

[0086] Here, if the server performs signature authentication according to the values of the dynamic signature parameters and the authentication is successful, the server will store the signature relationship corresponding to the new device fingerprint.

[0087] One embodiment of this specification also proposes a signature authentication device, which is applied to a server and performs signature authentication on a terminal device. On the terminal device side, the TEE of the terminal device is pre-embedded with the business private key required for signature authentication, and the TEE verifies the biometrics input by the user. After the verification is successful, the TEE completes the signature required for the signature authentication request; and the client in the terminal device sends the completed signature authentication request to the server. Figure 3 , the device comprises:

[0088] The authentication request receiving module 301 is configured to receive a signature authentication request sent by a terminal device;

[0089] The judgment module 302 is configured to judge whether the terminal device that sends the signature authentication request is a contaminated device.

[0090] The dynamic signature parameter determination module 303 is configured to determine the dynamic signature parameters required for the current signature authentication after determining that the terminal device that sent the signature authentication request is a contaminated device;

[0091] Restart the verification module 304, configured to re-authorize the terminal device to activate the verification permission and notify the terminal device to collect the dynamic signature parameters;

[0092] The re-authentication execution module 305 is configured to receive the value of the dynamic signature parameter sent by the terminal device; and perform signature authentication according to the value of the dynamic signature parameter.

[0093] In one embodiment of the apparatus of this specification, the determination module 302 is configured to execute:

[0094] Obtain the model information or version information of the terminal device carried in the signature authentication request;

[0095] It is determined whether the obtained model information or version information of the terminal device can be found in the pre-obtained blacklist. If so, it is determined that the terminal device that sends the signature authentication request is a contaminated device.

[0096] In one embodiment of the apparatus of this specification, the dynamic signature parameter determination module 303 is configured to execute: selecting the dynamic signature parameters required for the current signature authentication from a preset dynamic signature parameter library by a random selection method or a one-by-one selection method.

[0097] In one embodiment of the apparatus of this specification, the dynamic signature parameter library includes:

[0098] Fingerprint ID, device ID, APP package name, business scenario, user ID.

[0099] In one embodiment of the device in this specification, the dynamic signature parameter library includes parameters associated with services.

[0100] In one embodiment of the device in this specification, each parameter setting in the dynamic signature parameter library corresponds to a parameter serial number;

[0101] The restart verification module 304 is configured to execute: sending a notification message to the terminal device, where the first field in the notification message includes the parameter serial number corresponding to the dynamic signature parameter to be used in this signature authentication; the second field in the notification message is used to indicate the length of the first field.

[0102] It should be noted that the above-mentioned devices are usually implemented on the server side, and can be respectively set on independent servers, or some or all of the devices can be combined and set on the same server. The server can be a single server or a server cluster composed of multiple servers. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system. The above-mentioned devices can also be implemented on a computer terminal with strong computing power.

[0103] One embodiment of this specification provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, it causes the computer to execute the method in any one of the embodiments in this specification.

[0104] One embodiment of this specification provides a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, it implements the method in any one of the embodiments in this specification.

[0105] It can be understood that the structure schematically shown in the embodiments of this specification does not constitute a specific limitation on the devices in the embodiments of this specification. In other embodiments of this specification, the above-mentioned devices may include more or fewer components than those shown in the figures, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figures can be implemented in hardware, software, or a combination of software and hardware.

[0106] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments.

[0107] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, add-ons, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0108] The specific embodiments described above have further elaborated on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the present invention shall be included in the protection scope of the present invention.

Claims

1. Signature authentication method, applied to the server, which performs signature authentication on the terminal device. In this signature authentication method, the terminal device's trusted execution environment (TEE) pre-embeds the business private key required for signature authentication, and the TEE verifies the biometrics input by the user. After successful verification, the TEE completes the signature required for the signature authentication request. Among them, The server and the terminal device use the Internet Financial Identity Authentication Alliance (IFAA) technology to perform signature authentication; Among them, including: Receive the signature authentication request sent by the terminal device; Determine whether the terminal device that sent the signature authentication request is a contaminated device; a contaminated device means that the business private key burned into the TEE of the terminal device has been leaked; If yes, determine the dynamic signature parameters required for this signature authentication; the dynamic signature parameters used for each signature authentication are different and change dynamically; Re-authorizing the terminal device to open the verification authority and notifying the terminal device to collect the dynamic signature parameters; Receiving the value of the dynamic signature parameter sent by the terminal device; Perform signature authentication according to the value of the dynamic signature parameter; The determining of the dynamic signature parameters required for the current signature authentication includes: selecting the dynamic signature parameters required for the current signature authentication from a pre-set dynamic signature parameter library using a random selection method or a one-by-one selection method; the dynamic signature parameter library includes parameters associated with the business.

2. The method according to claim 1, wherein The determining whether the terminal device that sends the signature authentication request is a contaminated device includes: Obtain the model information or version information of the terminal device carried in the signature authentication request; It is determined whether the obtained terminal device model information or the protocol version information used by the signature can be found in the pre-obtained blacklist. If so, it is determined that the terminal device that sends the signature authentication request is a contaminated device.

3. The method according to claim 1, wherein, The dynamic signature parameter library includes: Fingerprint ID, device ID, application package name, business scenario, and user ID.

4. The method according to claim 1, wherein The method further includes: setting a corresponding parameter sequence number for each parameter in the dynamic signature parameter library; The notifying the terminal device to collect the dynamic signature parameters includes: sending a notification message to the terminal device, the first field in the notification message including the parameter serial number corresponding to the dynamic signature parameter required for this signature authentication; the second field in the notification message is used to indicate the length of the first field.

5. The signature authentication device is applied to the server, and the server performs signature authentication on the terminal device. The business private key required for signature authentication is embedded in the trusted execution environment (TEE) of the terminal device, and the TEE verifies the biometrics input by the user. After successful verification, the TEE completes the signature required for the signature authentication request. Among them, The server and the terminal device use the Internet Financial Identity Authentication Alliance (IFAA) technology to perform signature authentication; The signature verification device includes: An authentication request receiving module configured to receive a signature authentication request sent by a terminal device; A judgment module, configured to judge whether the terminal device that sends the signature authentication request is a contaminated device, where a contaminated device refers to a device in which the service private key burned in the TEE of the terminal device has been leaked; A dynamic signature parameter determination module, configured to determine the dynamic signature parameters required for this signature authentication after judging that the terminal device that sends the signature authentication request is a contaminated device; wherein, the dynamic signature parameters used for each signature authentication are different, and the dynamic signature parameters change dynamically; A restart verification module, configured to re-authorize the terminal device to open the verification permission and notify the terminal device to collect the dynamic signature parameters; A re-authentication execution module, configured to receive the value of the dynamic signature parameter sent by the terminal device; perform signature authentication according to the value of the dynamic signature parameter; Wherein, determining the dynamic signature parameters required for this signature authentication includes: selecting the dynamic signature parameters required for this signature authentication from a pre-set dynamic signature parameter library by using a randomly selected method or a sequentially selected method; the dynamic signature parameter library includes parameters associated with the service.

6. The device according to claim 5, wherein, A restart verification module, configured to send a notification message to the terminal device, where the first field in the notification message includes the parameter serial number corresponding to the dynamic signature parameter required for this signature authentication; the second field in the notification message is used to indicate the length of the first field.

7. A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed in a computer, the computer is made to execute the method according to any one of claims 1-4.

8. A computing device, including a memory and a processor, where an executable code is stored in the memory, and when the processor executes the executable code, the method according to any one of claims 1-4 is implemented.

Citation Information

Patent Citations

  • Method, user terminal device and identity authentication server for recognizing identity through biological feature

    CN107241317A

  • Identity authentication method and device of one-time cryptographic algorithm based on time

    CN114679276A