A method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms
Through the high-performance and strong identity authentication method of the API interface of the Guo Secret algorithm, the automatic destruction mechanism of the session key and the SM2 key encryption and decryption are adopted, which solves the security and complexity of the API interface identity authentication, and realizes the security of data transmission and the improvement of interface performance.
Patent Information
- Application Number
- CN202310049409.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-01
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2043-02-01
AI Technical Summary
The identity authentication method of the existing API interface is low in security and cannot effectively prevent replay attacks and data tampering. Third-party application systems need to manage their own keys, increasing platform complexity.
The National Secretariat algorithm is adopted, and the key is automatically destroyed through one key at a timeout. The API interface platform generates an SM2 key pair. The third-party application system presets the public key, and the data is transmitted and the data is encrypted and decrypted and digest verification is performed to reduce certificate management, and symmetric keys are used for data encryption and HMAC verification.
It improves data transmission security, reduces the hassle of digital certificate management, reduces terminal storage and computing pressure, simplifies key management of third-party application systems, and improves interface performance.
Smart Images

Figure CN116192474B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method for high-performance strong identity authentication of an API interface based on a national secret algorithm. Background Art
[0002] Without network security, there will be no national security, no stable operation of the economy and society, and the interests of the general public will be difficult to protect. Cryptography is a standard feature of major countries, and is known as one of the three major supporting technologies for national security, along with nuclear technology and aerospace technology. Using cryptographic algorithms developed by China itself to solve network security is the most effective, reliable, and economical way. It is the core technology and basic support for maintaining network security and a strategic resource for protecting national security. The promotion and use of national cryptographic algorithms in all walks of life is also imminent.
[0003] With the advancement of the Internet industry, more and more businesses are handled online, and more third-party operating platforms will provide users with online API interfaces. The method of user identity authentication is also very simple. Simple identity authentication is performed through username and password or token. The security is extremely low and cannot solve problems such as replay attacks and tampering prevention. Therefore, a high-intensity identity authentication method based on national secret algorithms is imminent. Summary of the invention
[0004] The present invention provides a method for high-performance strong identity authentication of an API interface based on a national secret algorithm, which solves the problem in the above background technology that when a user uses an API interface, the user only needs to perform simple identity authentication through a simple username and password or a token, which has low security and cannot solve the problems of retransmission attacks and tampering prevention.
[0005] The present invention provides the following technical solutions: a high-performance strong identity authentication method for an API interface based on a national secret algorithm, which adopts one key per session and automatically destroys the key upon timeout, thereby improving the security of the system. Third-party application systems do not need to generate identity keys themselves, and the API interface platform does not need to be configured with identity keys for each third-party application system. The API interface platform only needs to generate a pair of identity keys (SM2 keys) for itself, thereby reducing the complexity and difficulty of use of the API interface platform.
[0006] A method for high-performance strong identity authentication of an API interface based on a national secret algorithm, comprising the following steps:
[0007] Step 1: Register the third-party application system on the API interface platform. The registration information includes the application name, application IP address, application device unique identifier and application password;
[0008] Step 2: The API interface platform generates an SM2 key pair, which includes a public key and a private key. The third-party application system pre-sets the SM2 public key generated by the API interface platform in the configuration file or in the code.
[0009] Step 3: The third-party application system generates a 16-byte random number as the key for subsequent Hmac operations. The random number, the unique identifier of the application device, and the application password are concatenated in sequence. The concatenated content is hashed using the SM3 algorithm to generate a hash value. The concatenated content is encrypted using the SM2 encryption algorithm with the SM2 public key of the API platform. The ciphertext data and the hash value are transmitted to the API interface platform.
[0010] Step 4: The API interface platform decrypts using the corresponding SM2 private key through the SM2 decryption algorithm to obtain the unique identifier of the application device, the random number, and the application password. The password of the previously registered application is queried through the unique identifier of the application device. It is compared whether the password decrypted by the third-party application system is consistent with the password registered on the platform. If they are consistent, the identity authentication passes.
[0011] Step 5: The random number, the unique identifier of the application device, and the application password are concatenated and hashed using the SM3 algorithm, and compared with the hash value transmitted by the third-party application system. If the hash values are consistent, the data has not been tampered with and the verification is completed.
[0012] Preferably, only the third application and the API interface platform know the application password in the registration information.
[0013] Preferably, the API interface platform saves the corresponding relationship between the unique identifier of the application device and the decrypted 16-byte random number, with a validity period of 15 minutes. If the key has not been used for more than 15 minutes continuously, the API interface platform destroys the key and cancels the binding relationship.
[0014] Preferably, the 16-byte random number generated by decryption in Step 4 is used as a symmetric key to encrypt the key data for subsequent communication using SM4, and an HMAC signature is made on the message.
[0015] Preferably, after the data is tampered with, the tampered data is discarded, no content processing is performed, and an error prompt is returned to the application system.
[0016] Preferably, the necessary operation before data verification is: after receiving the data, the API interface platform searches for the corresponding symmetric key according to the unique identifier of the application device, and decrypts the data and performs HMAC verification using the symmetric key.
[0017] Compared with the prior art, the present invention has the following beneficial effects:
[0018] 1. The method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms realizes secure encryption of data transmission based on national cryptographic algorithms, preventing data from being eavesdropped and stolen during transmission. It uses one key for each session and automatically destroys the key when it times out, improving system security. The certificate-free system design eliminates the need to use digital certificates, reducing the trouble of digital certificate management and alleviating the storage pressure and computing pressure on the terminal.
[0019] 2. The method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms does not require third-party application systems to generate their own identity keys, nor does the API interface platform need to configure the identity keys of each third-party application system. The API interface platform only needs to generate a pair of its own identity keys, which can reduce the complexity and usage difficulty of the API interface platform. The message data is encrypted and verified by HMAC using a symmetric key, improving the interface performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a schematic flowchart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0022] The present invention provides a method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms. The flowchart is as shown in the accompanying drawings of the specification Figure 1 and the implementation method is as follows:
[0023] 1). First, register the third-party application system on the API interface platform. The registration information includes the application name, application IP address, unique identifier of the application device, and application password. Only the third-party application and the API interface platform know the unique identifier of the application device and the corresponding application password generated according to the application information, improving system security.
[0024] 2). The API interface platform generates an SM2 key pair, which includes a public key and a private key. The third-party application system pre-sets the SM2 public key generated by the API interface platform in the configuration file or code. With this setting, the third-party application system does not need to generate its own identity key, and the API interface platform does not need to configure the identity keys of each third-party application system, and it can reduce the complexity and usage difficulty of the API interface platform.
[0025] 3) The third-party application system generates a 16-byte random number as the key for subsequent Hmac operations, concatenates the random number, the unique identifier of the application device, and the application password, and splices them in the order of random number || unique identifier of the application device || application password. Generate a digest value by performing a digest on the concatenated content using the SM3 algorithm. Encrypt the concatenated content using the SM2 encryption algorithm with the SM2 public key of the API platform, and transmit the ciphertext data and the digest value to the API interface platform.
[0026] 4) The API interface platform decrypts using the corresponding SM2 private key through the SM2 decryption algorithm to obtain the decrypted unique identifier of the application device, random number, and application password. Query the password of the previously registered application through the unique identifier of the application device, and compare whether the password decrypted by the third-party application system is the same as the password registered on the platform. If they are the same, the identity authentication passes; if not, continue with the identity authentication. Concatenate the random number, the unique identifier of the application device, and the application password and perform a digest using the SM3 algorithm, and compare it with the digest value transmitted by the third-party application system. If the digest values are the same, the data has not been tampered with, and the verification is completed. Save the relationship between the decrypted 16-byte random number as the symmetric key and the unique identifier of the application device. Otherwise, return an error to the third-party application system. If the data is tampered with, discard the tampered data, do not perform content processing, and return an error message to the third-party application system. And the necessary operations before data verification are: After receiving the data, the API interface platform looks up the corresponding symmetric key according to the unique identifier of the application device, and decrypts the data and performs HMAC verification using the symmetric key.
[0027] 5) After successful identity authentication, encrypt the transmitted data and perform HMAC verification using the 16-byte random number. According to the unique identifier of the application device, find the corresponding symmetric key to decrypt the data, perform business processing, and encrypt the corresponding message and perform HMAC verification using the corresponding symmetric key to improve the interface performance.
[0028] During the process of the above steps, the API interface platform saves the corresponding relationship between the unique identifier of the application device and the decrypted 16-byte random number, with a validity period of 15 minutes. If the key has not been used for more than 15 minutes continuously, the API interface platform destroys the key and cancels the binding relationship, thereby improving the system performance and system security.
[0029] This identity authentication method has no certificate system design and does not require the use of digital certificates to achieve, reducing the trouble of digital certificate management. At the same time, it also reduces the storage pressure and operation pressure of the terminal.
[0030] In summary, when using the method for high-performance strong identity authentication of API interfaces based on national cryptographic algorithms, according to the session, the API interface platform generates an SM2 key pair, the third-party application system generates an SM2 public key, and the third-party application system generates a 16-byte random number. The random number, the unique identifier of the application device, and the application password are concatenated in sequence. The concatenated content is hashed using the SM3 algorithm to generate a hash value. The concatenated content is encrypted using the SM2 public key of the API platform through the SM2 encryption algorithm. The ciphertext data and the hash value are transmitted to the API interface platform. The API interface platform decrypts the received data using the corresponding SM2 private key to obtain the unique identifier of the application device, the random number, and the application password. The password of the previously registered application is queried through the unique identifier of the application device. It is compared whether the password decrypted by the third-party application system is the same as the password registered on the platform. If they are the same, the identity authentication passes. After receiving the data, the API interface platform searches for the corresponding symmetric key according to the unique identifier of the application device, decrypts the data and performs HMAC verification to see if it has been tampered with. If the data has been tampered with, the data packet is discarded, no content processing is performed, and an error message is returned to the third-party application system. If the symmetric key cannot be found through the unique identifier of the application device, the interface is returned, and the authentication fails. Identity authentication needs to be performed again. After successful authentication, data verification is performed.
[0031] The standard parts used in the present invention can all be purchased from the market. The special-shaped parts can be customized according to the description in the specification and the drawings. The specific connection methods of each part all adopt conventional means such as bolts, rivets, and welding that are mature in the prior art. The machines, parts, and equipment all adopt conventional models in the prior art, which will not be elaborated here. The content not described in detail in this specification belongs to the prior art well-known to those skilled in the art. Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for high-performance and strong identity authentication of API interfaces based on national cryptography algorithms, characterized in that It includes the following steps: Step 1: Register the third-party application system on the API interface platform. The registration information includes the application name, application IP address, unique application device identifier, and application password; Step 2: The API interface platform generates an SM2 key pair, which includes a public key and a private key. The third-party application system pre-sets the SM2 public key generated by the API interface platform in the configuration file or in the code; Step 3: The third-party application system generates a 16-byte random number as the key for subsequent Hmac operations. Concatenate the random number, unique application device identifier, and application password in sequence. Use the SM3 algorithm to generate a digest value for the concatenated content. Encrypt the concatenated content using the SM2 encryption algorithm with the SM2 public key of the API platform. Transmit the ciphertext data and the digest value to the API interface platform; Step 4: The API interface platform decrypts using the corresponding SM2 private key through the SM2 decryption algorithm to obtain the unique application device identifier, random number, and application password. Query the password of the previously registered application through the unique application device identifier. Compare whether the password decrypted by the third-party application system is the same as the password registered on the platform. If they are the same, the identity authentication passes; Step 5: The API interface platform concatenates the random number, unique application device identifier, and application password and uses the SM3 algorithm to generate a digest, and compares it with the digest value transmitted by the third-party application system. If the digest values are the same, the data has not been tampered with, and the verification is completed.
2. The method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms according to claim 1, wherein: Only the third application and the API interface platform know the application password in the registration information.
3. A method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms according to claim 1, characterized in that: The API interface platform saves the corresponding relationship between the unique application device identifier and the decrypted 16-byte random number, and the validity period is 15 minutes.
4. A method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms according to claim 1, characterized in that: The 16-byte random number generated by decryption in Step 4 is used as a symmetric key to encrypt the key data for subsequent communication using SM4, and an HMAC signature is made on the message.
5. A method for high-performance and strong identity authentication of API interfaces based on national cryptographic algorithms according to claim 1, characterized in that: After the data is tampered with, the tampered data is discarded, no content processing is performed, and an error prompt is returned to the application system.
6. A method for high-performance and strong identity authentication of API interfaces based on national cryptography algorithms according to claim 4, characterized in that: The necessary operation before data verification is: After receiving the data, the API interface platform searches for the corresponding symmetric key according to the unique application device identifier, and uses the symmetric key to decrypt the data and perform HMAC verification.
Citation Information
Patent Citations
SIP security authentication method based on commercial passwords
CN104735068A