An access control system and an access control method

By working together with browsers, third-party servers, authentication centers, and backend servers, the problem of unauthorized access control for H5 pages has been solved, enabling manageable, controllable, and traceable access, reducing access anomalies, and enhancing security.

CN116032622BActive Publication Date: 2025-12-09AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211725484.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-12-09
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

In the internet dissemination of H5 pages, it is impossible to control the illegal use of sensitive pages or the frequency of access, resulting in the inability to block illegal attacks and developers being unable to track the sources and distribution of access.

Method used

By working together with browsers, third-party servers, authentication centers, and backend servers, the signature and verification of identity data are achieved, including multi-layered verification of the first signature information and authentication standard messages, ensuring the legitimacy and security of access.

Benefits of technology

It enables manageable, controllable, and traceable access to H5 pages, reduces access anomaly issues, and enhances the effectiveness and security of access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032622B_ABST
    Figure CN116032622B_ABST
Patent Text Reader

Abstract

The application provides an access control system and an access control method. The system comprises a browser, a third-party server, an authentication center, and a background server. The browser sends an access request of a user, which comprises identity data input by the user. The third-party server receives the identity data sent by the browser, signs the data according to a first certificate to generate first signature information and a first authentication standard message, and forwards the first signature information and the first authentication standard message to the authentication center through the browser. The authentication center performs a first verification on the first signature information and the first authentication standard message. If the first verification is passed, the authentication center signs the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and forwards the second signature information and the second authentication standard message to the background server through the browser. The background server performs a second verification on the second signature information and the second authentication standard message. If the second verification is passed, the background server generates an access result according to the access request, and sends the access result to the browser. In this way, the access control of the H5 page is realized, and the access exception problem of the H5 page is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data processing, in particular to an access control system and an access control method. BACKGROUND

[0002] With the rapid development of mobile Internet, the global economy has entered the digital high-speed channel, and traditional commercial banks are impacted by financial technology companies outside the banking system. HyperText Markup Language 5.0 (H5) is widely used in lightweight scene development due to its rich media and rich application.

[0003] There are problems in the use of H5, such as the illegal use of sensitive H5 in the Internet transmission path, the inability to control H5 access frequency and thus the inability to shield illegal attack behavior, and the inability of H5 developers to count access sources and access distribution. At present, it is urgent to control the access of H5 pages. SUMMARY

[0004] The embodiments of the present application provide an access control system and an access control method, which realize access control of H5 pages and reduce access exceptions when accessing H5 pages. The specific scheme is as follows:

[0005] In a first aspect, the present application provides an access control system, which comprises a browser, a third-party server, an authentication center and a background server.

[0006] The browser is configured to receive an access request of a user, the access request comprising identity data input by the user, and send the identity data to the third-party server.

[0007] The third-party server is configured to receive the identity data sent by the browser, sign the identity data according to a first certificate to generate first signature information and a first authentication standard message, and send the first signature information and the first authentication standard message to the browser.

[0008] The browser is configured to receive the first signature information and the first authentication standard message, and send the first signature information and the first authentication standard message to the authentication center.

[0009] The authentication center is configured to receive the first signature information and the first authentication standard message sent by the browser, perform first verification on the first signature information and the first authentication standard message, if the first verification is passed, perform signature on the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and send the second signature information and the second authentication standard message to the browser.

[0010] The browser is configured to receive the second signature information and the second authentication standard message, and send the second signature information and the second authentication standard message to the background server.

[0011] The background server is configured to receive the second signature information and the second authentication standard message sent by the browser, perform second verification on the second signature information and the second authentication standard message, if the second verification is passed, generate an access result according to the access request, and send the access result to the browser.

[0012] In a possible implementation manner, the authentication center comprises:

[0013] A browser registration center is configured to receive a browser registration request sent by the browser, and send an identity number of the browser and an access path of the browser to the browser according to the browser registration request, the access path being a path for the browser to access the authentication center.

[0014] In a possible implementation manner, the authentication center comprises:

[0015] A user registration center is configured to receive a registration request of a user sent by the browser, the registration request comprising registration information of the user.

[0016] If the registration information is consistent with preset standard information, the first certificate is sent to the third-party server.

[0017] In a possible implementation manner, the first verification on the first signature information and the first authentication standard message comprises:

[0018] The authentication center performs first signature verification on the first signature information according to a public key certificate of the user, and judges whether the unique credential of the user exists in the first authentication standard message.

[0019] If the first signature verification is passed and the unique credential exists, the result of the first verification is that the verification is passed.

[0020] In a possible implementation, the second verification on the second signature information and the second authentication standard message comprises:

[0021] The background server uses the public key certificate of the user in the authentication center to perform second signature verification on the second signature information, and determines whether the check request initiated by the second authentication standard message is a replay attack; if the second signature verification is passed and the check request is not a replay attack, the verification result of the second verification is passed.

[0022] In a second aspect, the application provides an access control method, the method is executed by an access control system, the access control system comprises a browser, a third-party server, an authentication center, a background server, and the method comprises:

[0023] The browser receives an access request of a user, the access request comprising identity data input by the user, and sends the identity data to the third-party server;

[0024] The third-party server receives the identity data sent by the browser, and generates first signature information and a first authentication standard message by signing the identity data according to a first certificate, and sends the first signature information and the first authentication standard message to the browser;

[0025] The browser receives the first signature information and the first authentication standard message, and sends the first signature information and the first authentication standard message to the authentication center;

[0026] The authentication center receives the first signature information and the first authentication standard message sent by the browser, and performs first verification on the first signature information and the first authentication standard message, if the first verification is passed, signs the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and sends the second signature information and the second authentication standard message to the browser;

[0027] The browser receives the second signature information and the second authentication standard message, and sends the second signature information and the second authentication standard message to the background server;

[0028] The background server receives the second signature information and the second authentication standard message sent by the browser, and performs second verification on the second signature information and the second authentication standard message, if the second verification is passed, generates an access result according to the access request, and sends the access result to the browser.

[0029] In a possible implementation, the authentication registration center comprises a browser registration center, and the method further comprises:

[0030] The browser registration center receives a browser registration request sent by the browser, and sends the identity number of the browser and an access path of the browser to the browser according to the browser registration request, the access path being a path for the browser to access the authentication center.

[0031] In a possible implementation, the authentication registration center comprises a user registration center, and the method further comprises:

[0032] The user registration center receives a user registration request sent by the browser, the registration request comprising registration information of the user;

[0033] If the registration information is consistent with preset standard information, the first certificate is sent to the third-party server.

[0034] In a possible implementation, the first verification on the first signature information and the first authentication standard message comprises:

[0035] The authentication center performs first signature verification on the first signature information according to the public key certificate of the user, and determines whether the unique credential of the user exists in the first authentication standard message;

[0036] If the first signature verification passes and the unique credential exists, the first verification result is that the verification passes.

[0037] In a possible implementation, the second verification on the second signature information and the second authentication standard message comprises:

[0038] The background server performs second signature verification on the second signature information using the public key certificate of the user in the authentication center, and determines whether the verification request initiated by the second authentication standard message is a replay attack;

[0039] If the second signature verification passes and the verification request is not a replay attack, the second verification result is that the verification passes.

[0040] Therefore, the application has the following beneficial effects:

[0041] The application provides an access control system and an access control method, which comprises a browser, a third-party server, an authentication center, a background server, the browser is used for receiving an access request of a user, the access request comprises identity data input by the user, and the identity data is sent to the third-party server, the third-party server is used for receiving the identity data sent by the browser, signing the identity data according to a first certificate to generate first signature information and a first authentication standard message, and sending the first signature information and the first authentication standard message to the browser, the browser is used for receiving the first signature information and the first authentication standard message, and sending the first signature information and the first authentication standard message to the authentication center, the authentication center is used for receiving the first signature information and the first authentication standard message sent by the browser, performing first verification on the first signature information and the first authentication standard message, if the first verification is passed, signing the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and sending the second signature information and the second authentication standard message to the browser, the browser is used for receiving the second signature information and the second authentication standard message, and sending the second signature information and the second authentication standard message to the background server, and the background server is used for receiving the second signature information and the second authentication standard message sent by the browser, performing second verification on the second signature information and the second authentication standard message, if the second verification is passed, generating an access result according to the access request, and sending the access result to the browser, so that the access control of the H5 page can be realized, and the access exception problem of the H5 page can be reduced. BRIEF DESCRIPTION OF DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only constitute the embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0043] Figure 1 A structure schematic diagram of an access control system provided by the embodiments of the present application;

[0044] Figure 2 Another structure schematic diagram of an access control system provided by the embodiments of the present application;

[0045] Figure 3 Still another structure schematic diagram of an access control system provided by the embodiments of the present application;

[0046] Figure 4 A structure schematic diagram of an access control system provided by the embodiments of the present application;

[0047] Figure 5Another access control method flow provided by the embodiment of the present application is shown in a schematic diagram. DETAILED DESCRIPTION

[0048] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0049] In the present application, the term "comprising", "containing" or any other variant thereof is intended to cover the non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. Without more limitations, the element defined by the sentence "including a" does not exclude the presence of other identical elements in the process, method, article or equipment including the element.

[0050] In order to facilitate the understanding and explanation of the technical solutions provided by the embodiments of the present application, the following will first explain the possible terms and background technology involved in the present application.

[0051] H5: HTML5 for short, HyperText Markup Language 5, H5, refers to a cross-platform language across Windows, iOS, Android and other mainstream systems, which is a universal web page.

[0052] RSA public key cryptography system: a key system that is computationally infeasible to derive a decryption key from a known encryption key using different encryption and decryption keys.

[0053] APPID: the unique number of the third-party service provider in the open bank.

[0054] Authentication center: the authentication center includes H5 registration authentication center management platform and H5 registration authentication center (gateway).

[0055] Among them, H5 registration authentication center (gateway): H5 page developers can register the developed H5 to H5 registration authentication center. Only registered H5 can be accessed. H5 registration authentication center is the only legal entrance of H5 page.

[0056] H5 registration authentication center management platform: to approve, authorize and issue certificates for third-party service providers accessing H5 application; to approve and issue H5 registration applications for developers who have not registered.

[0057] H5 development template: a set of development templates conforming to the docking standard of the H5 registration and authentication center, and the developer only needs to implement specific business development without needing to pay attention to the docking standard.

[0058] Background server: the full name is H5 background server, which refers to the background server of the H5 page developer providing H5 services.

[0059] Third-party background server: refers to the background server of the third-party partner applying for using the H5 page. The H5 registration and authentication center standard message is hereinafter referred to as the standard message, and the specific format is shown in Table 1:

[0060]

[0061] Table 1

[0062] With the rapid development of mobile Internet, the global economy has entered a digital high-speed channel, and traditional commercial banks are impacted by financial technology companies outside the banking system. Under this market pattern, commercial banks continue to seek digital transformation, and continuously innovate in development mode and operation mode. Among them, H5 is widely used in lightweight scene development due to its rich media and rich application, especially in the scene development taking WeChat as the main transmission channel. The wide use of H5 also brings some problems, for example: the sensitive H5 page cannot be controlled in the Internet transmission channel, and there is a situation of illegal use; the access frequency of H5 cannot be controlled, and illegal attack behavior cannot be shielded; the access source and access distribution of H5 developers cannot be counted.

[0063] The application designs a set of H5 management and control mechanism, which realizes the management, control and traceability of H5 page output by means of the authentication center, and reduces the access exception problems in accessing the H5 page.

[0064] The application provides an access control system and an access control method. The system comprises a browser, a third-party server, an authentication center, and a background server. The browser receives an access request of a user, the access request comprising identity data input by the user, and sends the identity data to the third-party server. The third-party server receives the identity data sent by the browser, signs the identity data according to a first certificate to generate first signature information and a first authentication standard message, and sends the first signature information and the first authentication standard message to the browser. The browser receives the first signature information and the first authentication standard message, and sends the first signature information and the first authentication standard message to the authentication center. The authentication center receives the first signature information and the first authentication standard message sent by the browser, performs a first verification on the first signature information and the first authentication standard message, and if the first verification is passed, signs the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and sends the second signature information and the second authentication standard message to the browser. The browser receives the second signature information and the second authentication standard message, and sends the second signature information and the second authentication standard message to the background server. The background server receives the second signature information and the second authentication standard message sent by the browser, performs a second verification on the second signature information and the second authentication standard message, and if the second verification is passed, generates an access result according to the access request, and sends the access result to the browser. In this way, access control of an H5 page can be realized, and access abnormal problems in accessing the H5 page can be reduced.

[0065] In order to facilitate understanding of the technical solutions provided by the embodiments of the application, the following describes an access control system and an access control method provided by the embodiments of the application with reference to the accompanying drawings.

[0066] First, it should be noted that the embodiments of the application provide an access control system, which is specifically described with reference to Figure 1 The figure is a structural schematic diagram of an access control system provided by the embodiments of the application. The system specifically comprises a browser 101, a third-party server 102, an authentication center 103, and a background server 104.

[0067] The browser 101 receives an access request of a user, the access request comprising identity data input by the user, and sends the identity data to the third-party server

[0068] The third-party server 102 receives the identity data sent by the browser, signs the identity data according to a first certificate to generate first signature information and a first authentication standard message, and sends the first signature information and the first authentication standard message to the browser.

[0069] The signature is: SHA256 (appid+biz_data+nonce+timestamp), wherein SHA256 refers to signature using an RSA certificate.

[0070] In a possible implementation, the first verification on the first signature information and the first authentication standard message comprises:

[0071] The authentication center 103 performs first signature verification on the first signature information according to a public key certificate of the user, and determines whether the unique credential of the user exists in the first authentication standard message.

[0072] If the first signature verification passes and the unique credential exists, the verification result of the first verification is that the verification passes.

[0073] The browser 101 receives the first signature information and the first authentication standard message, and sends the first signature information and the first authentication standard message to the authentication center.

[0074] The authentication center 103 receives the first signature information and the first authentication standard message sent by the browser, and performs first verification on the first signature information and the first authentication standard message. If the first verification passes, the authentication center 103 performs signature on the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and sends the second signature information and the second authentication standard message to the browser.

[0075] The browser 101 receives the second signature information and the second authentication standard message, and sends the second signature information and the second authentication standard message to the background server.

[0076] The background server 104 receives the second signature information and the second authentication standard message sent by the browser 101, and performs second verification on the second signature information and the second authentication standard message. If the second verification passes, the background server 104 generates an access result according to the access request, and sends the access result to the browser 101. Specifically, the second verification on the second signature information and the second authentication standard message can comprise:

[0077] The background server 104 performs second signature verification on the second signature information using a public key certificate of the user in the authentication center 103, and determines whether the verification request initiated by the second authentication standard message is a replay attack. If the second signature verification passes and the verification request is not a replay attack, the verification result of the second verification is that the verification passes.

[0078] It can be understood that the authentication center can include a user registration center and a browser registration center.

[0079] The browser registration center is configured to receive a browser registration request sent by the browser, and send a browser identity number and a browser access path to the browser according to the browser registration request, the access path being a path for the browser to access the authentication center.

[0080] The user registration center is configured to receive a user registration request sent by the browser, the registration request including registration information of the user.

[0081] If the registration information is consistent with preset standard information, the first certificate is sent to the third-party server.

[0082] The access control system provided in the application can realize management, control and tracking of H5 page output through the authentication center, and reduce access exceptions in accessing the H5 page. In the embodiments of the application, the third-party server can be a third-party application server, and the first certificate can be a third-party application certificate. Figure 2 The technical solutions in the application can be further understood with reference to the access control system structure diagram shown in

[0083] As shown in Figure 2 The H5 registration authentication center management platform is responsible for approving the registration application of the H5 product developed by using the H5 development template, and only the H5 product that passes the approval can be applied to use. Further, the H5 registration authentication center management platform is also responsible for the third-party application approval of the H5 product, and only the third-party that passes the approval can use the H5 product.

[0084] The H5 release mainly refers to that the developer completes the development of the H5 product, and then submits an application to apply for an external Internet address of the H5 registration authentication center, through which the H5 product can be accessed.

[0085] The content of the permission control includes which cooperation party can normally access the product, the access frequency of the cooperation party that can normally access the product per day, and the like.

[0086] The specific content of the H5 release application includes a test report, a predicted peak TPS, a daily peak transaction volume, a predicted release time, and the like.

[0087] Next, specific scene embodiments will be introduced in detail, and specific reference can be made to Figure 3 and Figure 4 .

[0088] The user clicks the H5 connection to make the user browser send a user request partner page to the third-party server, while submitting the input elements to the third-party background server (third-party server). After the third-party server receives the information sent by the user browser, it signs using the partner private key, and returns the signed information to the user browser. After the user browser submits the request carrying the signature to the H5 registration authentication center, the H5 registration authentication center verifies the partner signature after receiving the request carrying the signature, and signs the response message using the gateway private key, and then returns 302 redirection to the user browser.

[0089] After the user browser receives the 302 redirection, it sends an access H5 product session verification page to the H5 background. After the H5 background (H5 background server) receives the information, it verifies the signature of the authentication center. If the verification result is that the verification is passed, a session is established, and a specific business page is returned to the user browser. In this way, the user browser can establish an interactive relationship with the H5 background, and the customer can perform business processing between the user browser and the H5 background.

[0090] As shown in Figure 5 The access control method provided by the embodiment of the application can be executed by the access control system. Since the principle of solving the problem of the method is similar to that of the access control system, the implementation of the method can be referred to the implementation of the access control system, and the repeated parts will not be described again. The access control system in the application includes a browser, a third-party server, an authentication center, a background server, and the like, which will be described in detail in the following. Figure 5 , Figure 5 The flowchart of the access control method provided by the embodiment of the application, which specifically includes S101-S106:

[0091] S101, the browser receives an access request of a user, the access request includes identity data input by the user, and sends the identity data to the third-party server.

[0092] S102, the third-party server receives the identity data sent by the browser, and signs the identity data according to a first certificate to generate first signature information and a first authentication standard message, and sends the first signature information and the first authentication standard message to the browser.

[0093] S103, the browser receives the first signature information and the first authentication standard message, and sends the first signature information and the first authentication standard message to the authentication center.

[0094] In the embodiments of the present application, the authentication registration center comprises a browser registration center, and the method further comprises: the browser registration center receiving a browser registration request sent by the browser, and sending an identity number of the browser and an access path of the browser to the browser according to the browser registration request, wherein the access path is a path for the browser to access the authentication center.

[0095] Further, the authentication registration center comprises a user registration center, and the method further comprises:

[0096] The user registration center receives a user registration request sent by the browser, wherein the registration request comprises registration information of the user; and if the registration information is consistent with preset standard information, the first certificate is sent to the third-party server.

[0097] S104, the authentication center receives the first signature information and the first authentication standard message sent by the browser, and performs first verification on the first signature information and the first authentication standard message; if the first verification passes, the first signature information and the first authentication standard message are signed to obtain second signature information and a second authentication standard message, and the second signature information and the second authentication standard message are sent to the browser.

[0098] The first verification on the first signature information and the first authentication standard message is specifically:

[0099] The authentication center performs first signature verification on the first signature information according to the public key certificate of the user, and judges whether the unique credential of the user in the first authentication standard message exists; if the first signature verification passes and the unique credential exists, the result of the first verification is that the verification passes.

[0100] S105, the browser receives the second signature information and the second authentication standard message, and sends the second signature information and the second authentication standard message to the background server.

[0101] The second verification on the second signature information and the second authentication standard message is specifically:

[0102] The background server performs second signature verification on the second signature information using the public key certificate of the user in the authentication center, and judges whether the verification request initiated by the second authentication standard message is a replay attack; if the second signature verification passes and the verification request is not a replay attack, the verification result of the second verification is that the verification passes.

[0103] S106, the background server receives the second signature information and the second authentication standard message sent by the browser, and performs second verification on the second signature information and the second authentication standard message, if the second verification passes, generates an access result according to the access request, and sends the access result to the browser.

[0104] The access control method provided by the embodiments of the present application can realize access control on H5 pages and reduce access exceptions when accessing H5 pages.

[0105] It should be noted that the embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the method disclosed by the embodiments, since it corresponds to the system disclosed by the embodiments, the description is relatively simple, and the relevant part can be referred to the method part.

[0106] It should be understood that in the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" is used to describe the association between the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases: only A, only B, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the front and rear associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c, can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0107] It should also be noted that in this paper, relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0108] The foregoing description of the disclosed embodiments enables a person skilled in the art to make or use the application. Modifications of these embodiments will occur to persons of skill in the art, and that the generic principles defined herein can be applied to other embodiments without departing from the spirit or scope of the application. Therefore, the present application is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An access control system, characterized in that, The system comprises a browser, a third-party server, an authentication center and a background server; The browser is configured to receive an access request of a user, the access request comprising identity data input by the user, and send the identity data to the third-party server; The third-party server is configured to receive the identity data sent by the browser, sign the identity data according to a first certificate to generate first signature information and a first authentication standard message, and send the first signature information and the first authentication standard message to the browser; The browser is configured to receive the first signature information and the first authentication standard message, and send the first signature information and the first authentication standard message to the authentication center; The authentication center is configured to receive the first signature information and the first authentication standard message sent by the browser, perform a first verification on the first signature information and the first authentication standard message, if the first verification is passed, sign the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and send the second signature information and the second authentication standard message to the browser; The browser is configured to receive the second signature information and the second authentication standard message, and send the second signature information and the second authentication standard message to the background server; The background server is configured to receive the second signature information and the second authentication standard message sent by the browser, perform a second verification on the second signature information and the second authentication standard message, if the second verification is passed, generate an access result according to the access request, and send the access result to the browser.

2. The system of claim 1, wherein, The authentication center comprises: A browser registration center configured to receive a browser registration request sent by the browser, and send an identity number of the browser and an access path of the browser to the browser according to the browser registration request, the access path being a path for the browser to access the authentication center.

3. The system of claim 1, wherein, The authentication center comprises: A user registration center configured to receive a registration request of a user sent by the browser, the registration request comprising registration information of the user; If the registration information is consistent with preset standard information, send the first certificate to the third-party server.

4. The system of claim 1, wherein The first verification on the first signature information and the first authentication standard message comprises: The authentication center performs a first signature verification on the first signature information according to a public key certificate of the user, and determines whether a unique credential of the user in the first authentication standard message exists; If the first signature verification is passed and the unique credential exists, the result of the first verification is that the verification is passed.

5. The system of claim 1, wherein, The second verification on the second signature information and the second authentication standard message comprises: The background server uses the public key certificate of the user in the authentication center to perform second signature verification on the second signature information, and judges whether the check request initiated by the second authentication standard message is a replay attack; if the second signature verification is passed and the check request is not a replay attack, the verification result of the second verification is passed.

6. An access control method characterized by, The method is performed by the access control system according to any one of claims 1-5, the access control system comprising a browser, a third-party server, an authentication center, a background server, and the method comprising: The browser receives an access request of a user, the access request comprising identity data input by the user, and sends the identity data to the third-party server; The third-party server receives the identity data sent by the browser, signs the identity data according to a first certificate to generate first signature information and a first authentication standard message, and sends the first signature information and the first authentication standard message to the browser; The browser receives the first signature information and the first authentication standard message, and sends the first signature information and the first authentication standard message to the authentication center; The authentication center receives the first signature information and the first authentication standard message sent by the browser, performs first verification on the first signature information and the first authentication standard message, and if the first verification is passed, signs the first signature information and the first authentication standard message to obtain second signature information and a second authentication standard message, and sends the second signature information and the second authentication standard message to the browser; The browser receives the second signature information and the second authentication standard message, and sends the second signature information and the second authentication standard message to the background server; The background server receives the second signature information and the second authentication standard message sent by the browser, performs second verification on the second signature information and the second authentication standard message, and if the second verification is passed, generates an access result according to the access request, and sends the access result to the browser.

7. The method of claim 6, wherein, The authentication center comprises a browser registration center, and the method further comprises: The browser registration center receives a browser registration request sent by the browser, and sends an identity number of the browser and an access path of the browser to the browser according to the browser registration request, the access path being a path for the browser to access the authentication center.

8. The method of claim 7, wherein, The authentication center comprises a user registration center, and the method further comprises: The user registration center receives a registration request of a user sent by the browser, the registration request comprising registration information of the user; If the registration information is consistent with preset standard information, the first certificate is sent to the third-party server.

9. The method of claim 6, wherein, The first verification on the first signature information and the first authentication standard message comprises: The authentication center performs first signature verification on the first signature information according to the public key certificate of the user, and judges whether the unique credential of the user in the first authentication standard message exists; If the first signature verification passes and the unique credential exists, the result of the first verification is verification pass.

10. The method of claim 6, wherein, The second verification on the second signature information and the second authentication standard message comprises: The background server performs second signature verification on the second signature information using the public key certificate of the user in the authentication center, and judges whether the verification request initiated by the second authentication standard message is a replay attack; If the second signature verification passes and the verification request is not a replay attack, the verification result of the second verification is verification pass.

Citation Information

Patent Citations

  • Address automatic allocation protocol security authentication method and equipment

    CN111314269A

  • Unmanned aerial vehicle authentication method and system, electronic equipment and storage medium

    CN115242396A