Identity authentication methods, systems and related equipment
By leveraging the collaborative work of a security platform and a security agent, and using the CA public key to decrypt communication tokens, generate user identity tickets, and query the user's true identity, the system addresses the issue of insufficient identity authentication in video conferencing systems. This enables trusted verification of user identities and secure information transmission, thereby improving system security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2021-12-01
- Publication Date
- 2026-07-17
AI Technical Summary
Existing video conferencing systems are unable to effectively verify the identities of participants, allowing criminals to impersonate company employees and steal company secrets, posing a security risk.
By working together with a security platform and a security agent, the communication token is decrypted using the CA public key, user identity tickets are generated, and the user's real identity is queried. Combined with whitelists and access control mechanisms, the legitimacy and security of user access are ensured.
It achieves trusted verification of user identity and secure transmission of information, improves the security of application systems, reduces the risk of unauthorized access, and requires no hardware modification.
Smart Images

Figure CN116208334B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to an identity authentication method, system and related equipment. Background Technology
[0002] Video conferencing systems are widely used across various industries. In these applications, meeting content typically involves sensitive or high-value information from enterprises and institutions. Currently, users of video conferencing products primarily access the system via a meeting ID and password, or the video conference organizer uses management measures to restrict the number of participants to mitigate security risks. Summary of the Invention
[0003] After analysis, the inventors discovered that most current video conferencing products are unable to effectively verify the identity of participants. If criminals obtain meeting information, impersonate company employees, and steal company secrets, it will cause huge economic losses.
[0004] One of the technical problems to be solved by the embodiments of the present invention is: how to provide a more secure identity authentication method.
[0005] According to a first aspect of some embodiments of the present invention, an identity authentication method is provided, comprising: in response to a security platform verifying a user on a client, the security platform sending a corresponding user identity ticket to the client, so that the client generates a communication token with a digital signature based on the user identity ticket and an obtained CA security certificate; the security platform receiving the communication token sent by the client; after the client sends a user access request to a security agent, the security platform sending the user's communication token to the security agent; the security platform receiving a user query request sent by the security agent, wherein the user query request includes the communication token; the security platform decrypting the communication token using a CA public key to obtain the user identity ticket; the security platform querying the user's real identity based on the user identity ticket; and the security platform sending the user's real identity to the security agent, so that the security agent or an application system connected to the security agent can control the user's access based on the user's real identity.
[0006] In some embodiments, the authentication method further includes: in response to the security platform's successful verification of the client's user, the security platform sends an application whitelist to the client, wherein the application whitelist includes application systems.
[0007] In some embodiments, the identity authentication method further includes: a security platform receiving an authentication request sent by a client, wherein the authentication request includes user-side information corresponding to the client's user, wherein the user-side information includes the user's real identity; the security platform verifying the user-side information; and in response to the security platform's successful verification of the client's user, the security platform generating a user identity ticket for the user.
[0008] In some embodiments, user-side information may also include device information or environmental information.
[0009] In some embodiments, the identity authentication method further includes: the security platform counting the number of user query requests sent by the security agent within a preset time period, so as to send the user's real identity to the security agent if the number is less than a preset threshold, and to reject the user query request from the security agent if the number is not less than the preset threshold.
[0010] According to a second aspect of some embodiments of the present invention, an identity authentication method is provided, comprising: a security agent receiving an access request from a user's client; the security agent obtaining a communication token from a security platform based on the access request, wherein the communication token is generated by the client based on a user identity ticket sent by the security platform and an obtained CA security certificate after the security platform verifies the user, and the client sending the communication token to the security platform; the security agent sending a user query request to the security platform, wherein the user query request includes the communication token, so that the security platform can decrypt the communication token using a CA public key to obtain a user identity ticket, and query the user's real identity based on the user identity ticket; and the security agent receiving the user's real identity sent by the security platform, so that the security agent or an application system connected to the security agent can control the user's access based on the user's real identity.
[0011] In some embodiments, the authentication method further includes: a security agent sending the user's real identity to the application system; the security agent receiving the access control result for the user sent by the application system; and the security agent sending the access control result to the client.
[0012] In some embodiments, the authentication method further includes: a security agent obtaining a list of users allowed to access the application system; the security agent determining whether the user is in the user list based on the user's real identity; if the user is in the user list, the security agent sending an access permission message to the client; if the user is not in the user list, the security agent sending an access denial message to the client.
[0013] According to a third aspect of some embodiments of the present invention, a security platform for identity authentication is provided, comprising: a user identity ticket sending module configured to send a corresponding user identity ticket to a client in response to successful authentication of a user by the security platform, so that the client generates a communication token with a digital signature based on the user identity ticket and an obtained CA security certificate; a communication token receiving module configured to receive the communication token sent by the client; a communication token sending module configured to send the user's communication token to a security agent after the client sends a user access request to a security agent; a query request receiving module configured to receive a user query request sent by the security agent, wherein the user query request includes the communication token; a decryption module configured to decrypt the communication token using a CA public key to obtain the user identity ticket; an identity query module configured to query the user's real identity based on the user identity ticket; and an identity sending module configured to send the user's real identity to the security agent, so that the security agent or an application system connected to the security agent can control the user's access based on the user's real identity.
[0014] In some embodiments, the security platform further includes a whitelist sending module, configured to send an application whitelist to the client in response to the security platform's successful verification of the client's user, wherein the application whitelist includes application systems.
[0015] In some embodiments, the security platform further includes: a verification module configured to receive an authentication request sent by a client, wherein the authentication request includes user-side information corresponding to the client's user, wherein the user-side information includes the user's real identity; verify the user-side information; and generate a user identity ticket for the user in response to the security platform's successful verification of the client's user.
[0016] In some embodiments, the security platform further includes a statistics module, configured to count the number of user query requests sent by the security agent within a preset time period, so as to send the user's real identity to the security agent when the number is less than a preset threshold, and to reject the user query requests from the security agent when the number is not less than the preset threshold.
[0017] According to a fourth aspect of some embodiments of the present invention, a security platform for identity authentication is provided, comprising: a memory; and a processor coupled to the memory, the processor being configured to execute any of the aforementioned identity authentication methods based on instructions stored in the memory.
[0018] According to a fifth aspect of some embodiments of the present invention, a security proxy for identity authentication is provided, comprising: an access request receiving module configured to receive an access request sent by a user's client; a communication token acquisition module configured to acquire a user's communication token from a security platform according to the access request, wherein the communication token is generated by the client based on a user identity ticket sent by the security platform and an acquired CA security certificate after the security platform verifies the user, and the client sends the communication token to the security platform; a query request sending module configured to send a user query request to the security platform, wherein the user query request includes the communication token, so that the security platform can decrypt the communication token using a CA public key to obtain a user identity ticket and query the user's real identity based on the user identity ticket; and a real identity receiving module configured to receive the user's real identity sent by the security platform, so that the security proxy or an application system connected to the security proxy can control the user's access based on the user's real identity.
[0019] In some embodiments, the security agent further includes: a first access control module configured to send the user's real identity to the application system; receive the access control result for the user sent by the application system; and send the access control result to the client.
[0020] In some embodiments, the security agent further includes: a second access control module configured to obtain a list of users allowed to access the application system; determine whether the user is in the user list based on the user's real identity; if the user is in the user list, send an access permission message to the client; if the user is not in the user list, send an access denial message to the client.
[0021] According to a sixth aspect of some embodiments of the present invention, a security agent for identity authentication is provided, comprising: a memory; and a processor coupled to the memory, the processor being configured to execute any of the aforementioned identity authentication methods based on instructions stored in the memory.
[0022] According to a seventh aspect of some embodiments of the present invention, an identity authentication system is provided, comprising: any of the aforementioned security platforms; and any of the aforementioned security agents.
[0023] In some embodiments, the identity authentication system further includes a client.
[0024] According to an eighth aspect of some embodiments of the present invention, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements any of the aforementioned authentication methods.
[0025] Some embodiments of the above invention have the following advantages or beneficial effects. The embodiments of the present invention can provide trusted identity services for application systems, ensuring the authenticity and reliability of the identities of users accessing the application system, thereby improving the security of the application system. Furthermore, the above embodiments can achieve trusted verification of user communication identities and secure transmission of identity information. This process is based on software implementation, requiring no hardware modification and having no special hardware requirements.
[0026] Other features and advantages of the invention will become clear from the following detailed description of exemplary embodiments of the invention with reference to the accompanying drawings. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 A flowchart illustrating an identity authentication method according to some embodiments of the present invention is shown.
[0029] Figure 2 A flowchart illustrating an identity authentication method according to other embodiments of the present invention is shown.
[0030] Figure 3 A schematic diagram of the structure of a security platform for identity authentication according to some embodiments of the present invention is shown.
[0031] Figure 4 A schematic diagram of the structure of a security agent for identity authentication according to some embodiments of the present invention is shown.
[0032] Figure 5 A schematic diagram of the structure of an identity authentication system according to some embodiments of the present invention is shown.
[0033] Figure 6 A schematic diagram of the network structure of an identity authentication system according to some embodiments of the present invention is shown.
[0034] Figure 7 A schematic diagram of the structure of an identity authentication device according to some embodiments of the present invention is shown.
[0035] Figure 8 A schematic diagram of the structure of an identity authentication device according to other embodiments of the present invention is shown. Detailed Implementation
[0036] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the present invention or its application or use. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0037] Unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps described in these embodiments do not limit the scope of the invention.
[0038] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.
[0039] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.
[0040] In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.
[0041] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0042] Figure 1 A flowchart illustrating an authentication method according to some embodiments of the present invention is shown. Figure 1 As shown, the identity authentication method in this embodiment includes steps S102 to S118.
[0043] In step S102, in response to the successful authentication of the client's user by the security platform, the security platform sends a user identity ticket to the client.
[0044] In some embodiments, the client is a security client used to perform real-time security detection on the user terminal device where the client is located.
[0045] In some embodiments, the security platform runs on a general-purpose server.
[0046] In some embodiments, in response to successful user authentication by the security platform, the platform sends an application whitelist to the client in addition to the user identity ticket. This whitelist includes application systems. This informs the user which application systems are accessible to them.
[0047] In step S104, the client generates a digitally signed communication token for the user based on the user identity ticket and the obtained CA (Certificate Authority) security certificate.
[0048] In step S106, the client sends the communication token to the security platform.
[0049] In step S108, the client sends the user's access request to the security agent.
[0050] In some embodiments, the security agent runs on the application system's server. For example, if the application system is a video conferencing system, the security agent runs on the video conferencing server.
[0051] In step S110, the security agent obtains the user's communication token from the security platform based on the access request.
[0052] In some embodiments, the security agent requests the user's communication token from the security platform. The security platform queries the communication token database to confirm whether there is a token for communication between the user and the application system. If the corresponding token is found, it is returned to the security agent.
[0053] In step S112, the security agent sends a user query request to the security platform, wherein the user query request includes a communication token.
[0054] In step S114, the security platform uses the CA public key to decrypt the communication token and obtain the user identity ticket.
[0055] In step S116, the security platform queries the user's real identity based on the user's identity ticket.
[0056] In step S118, the security platform sends the user's real identity to the security agent so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity.
[0057] In some embodiments, the security platform counts the number of user query requests sent by the security agent within a preset time period. If the number of requests is less than a preset threshold, the platform will send the user's real identity to the security agent; if the number of requests is not less than the preset threshold, the platform will reject the user query requests from the security agent. Thus, when the security agent makes frequent queries, its query behavior is prohibited for a certain period, further improving security.
[0058] In some embodiments, if access is allowed, the security agent sends an access-allow message to the client; if access is denied, the security agent sends an access-deny message to the client.
[0059] The method described in the above embodiment is based on a zero-trust mechanism. First, the client interacts with the security platform to achieve secure authentication of the user's identity. After successful authentication, the security platform issues a user identity ticket to the client. The client dynamically generates a trusted communication token based on the user identity ticket and sends an access request to the application system. The trusted security proxy, based on the client's access request and the trusted security token, queries the security platform for the user's identity, ultimately presenting the trusted identity in the application system.
[0060] In this process, firstly, the trusted identity verification mechanism enables the secure transmission of identity information. The secure client dynamically generates a communication token with a digital signature for each communication based on the identity ticket, and the secure agent queries the user's real identity through the communication token. Secondly, based on the "authenticate before connecting" mechanism, the user's identity is authenticated before a connection request can be established. The user's trusted identity is confirmed by the application system before a connection can be established, which can effectively improve the security of the application system. Thirdly, the above process provides an application authorization management mechanism, that is, access to the video conferencing system requires authorization from the security platform, which can effectively reduce the risk of unauthorized personnel or terminals accessing the application system.
[0061] Therefore, the above embodiments can provide trusted identity services for application systems, ensuring the authenticity and reliability of the identities of users accessing the application system, thereby improving the security of the application system. Furthermore, the above embodiments can achieve trusted verification of user communication identities and secure transmission of identity information. This process is software-based, requiring no hardware modification and having no special hardware requirements.
[0062] Figure 2 A flowchart illustrating an authentication method according to other embodiments of the present invention is shown. For example... Figure 2 As shown, the identity authentication method in this embodiment includes steps S202 to S206, and steps S102 to S122. For a detailed implementation of steps S102 to S122, please refer to... Figure 1 Examples are not described here.
[0063] In step S202, the security platform receives an authentication request sent by the client, wherein the authentication request includes user-side information corresponding to the client's user, and the user-side information includes the user's real identity.
[0064] In some embodiments, user-side information may also include device information or environmental information. For example, a security platform verifies whether a device or environment meets security requirements, whether it meets a preset version, etc.
[0065] In step S204, the security platform verifies the user-side information.
[0066] In step S206, in response to the successful verification of the client's user by the security platform, the security platform generates the user's identity ticket.
[0067] Therefore, authenticating the user's identity before establishing a connection can improve the security of the application system.
[0068] After the security agent obtains the user's real identity, there are multiple ways to control user access. Two methods are described below as examples.
[0069] In some embodiments, the security agent sends the user's real identity to the application system; the security agent receives the access control result for the user sent by the application system; and the security agent sends the access control result to the client. Take a video conferencing system as an example. The meeting initiator initiates a quick meeting, only providing the participants with the participation method, without entering a participant list into the video conferencing system. When a client on a terminal initiates an access request for the video conference, the security agent presents the trusted identity of the corresponding participant on the terminal in the video conference's interactive interface, and the meeting initiator must confirm whether access is permitted.
[0070] In some embodiments, the security agent obtains a list of users allowed to access the application system. Based on the user's real identity, the security agent determines whether the user is on the user list. If the user is on the user list, the security agent sends an access permission message to the client; if the user is not on the user list, the security agent sends an access denial message to the client. Taking a video conferencing system as an example, the meeting initiator enters a list of participants into the video conferencing system. When a client on a terminal initiates an access request for the video conference, the security agent compares the trusted identity of the participant corresponding to the terminal with the participant list. If the terminal initiating the access is not on the participant list, the access request is directly denied.
[0071] Figure 3 A schematic diagram of the structure of a security platform for identity authentication according to some embodiments of the present invention is shown. Figure 3As shown, the security platform 300 in this embodiment includes: a user identity ticket sending module 3100, configured to send a corresponding user identity ticket to the client in response to the security platform's successful verification of the client's user, so that the client can generate a communication token with a digital signature based on the user identity ticket and the obtained CA security certificate; a communication token receiving module 3200, configured to receive the communication token sent by the client; a communication token sending module 3300, configured to send the user's communication token to the security agent after the client sends a user access request to the security agent; a query request receiving module 3400, configured to receive a user query request sent by the security agent, wherein the user query request includes the communication token; a decryption module 3500, configured to decrypt the communication token using the CA public key to obtain the user identity ticket; an identity query module 3600, configured to query the user's real identity based on the user identity ticket; and an identity sending module 3700, configured to send the user's real identity to the security agent, so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity.
[0072] In some embodiments, the security platform 300 further includes a whitelist sending module 3800, configured to send an application whitelist to the client in response to the security platform's successful verification of the client's user, wherein the application whitelist includes application systems.
[0073] In some embodiments, the security platform 300 further includes: a verification module 3900 configured to receive an authentication request sent by a client, wherein the authentication request includes user-side information corresponding to the client's user, wherein the user-side information includes the user's real identity; verify the user-side information; and generate a user identity ticket for the user in response to the security platform's successful verification of the client's user.
[0074] In some embodiments, the security platform 300 further includes a statistics module 3000, configured to count the number of user query requests sent by the security agent within a preset time period, so as to send the user's real identity to the security agent when the number is less than a preset threshold, and to reject the user query request from the security agent when the number is not less than the preset threshold.
[0075] Figure 4 A schematic diagram of a security proxy for identity authentication according to some embodiments of the present invention is shown. Figure 4As shown, the security agent 400 in this embodiment includes: an access request receiving module 4100, configured to receive an access request sent by a user's client; a communication token acquisition module 4200, configured to acquire a user's communication token from a security platform based on the access request, wherein the communication token is generated by the client based on the user identity ticket sent by the security platform and the acquired CA security certificate after the security platform verifies the user, and the client sends the communication token to the security platform; a query request sending module 4300, configured to send a user query request to the security platform, wherein the user query request includes the communication token, so that the security platform can decrypt the communication token using the CA public key, obtain the user identity ticket, and query the user's real identity based on the user identity ticket; and a real identity receiving module 4400, configured to receive the user's real identity sent by the security platform, so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity.
[0076] In some embodiments, the security agent 400 further includes: a first access control module 4500, configured to send the user's real identity to the application system; receive the access control result for the user sent by the application system; and send the access control result to the client.
[0077] In some embodiments, the security agent 400 further includes: a second access control module 4600, configured to obtain a list of users allowed to access the application system; determine whether a user is in the user list based on the user's real identity; if the user is in the user list, send an access permission message to the client; if the user is not in the user list, send an access denial message to the client.
[0078] Figure 5 A schematic diagram of the structure of an identity authentication system according to some embodiments of the present invention is shown. For example... Figure 5 As shown, the identity authentication system 50 in this embodiment includes a security platform 300 and a security agent 400.
[0079] In some embodiments, the identity authentication system 50 also includes a client 500.
[0080] Figure 6 A schematic diagram of the network structure of an identity authentication system according to some embodiments of the present invention is shown. This embodiment describes a situation where the user terminal and the application system server belong to different operators. Figure 6As shown, user terminal 61, equipped with a security client, is located in operator A's network. Operator A's IP gateway includes IBCF (Interconnection Border Control Functions) 62 and TrGW (Transition Gateway) 63. User terminal 61 communicates with IBCF 62 and TrGW 63 via RTP (Real-time Transport Protocol). Additionally, user terminal 61 communicates with CSCF (Call Session Control Function) 64 via SIP (Session Initiation Protocol), and IBCF 62 and TrGW 63 also communicate with CSCF 64 via SIP. The application system's security agent 68 is located in operator B's network. Operator B's IP gateway includes IBCF 65 and TrGW 66. Security agent 68 communicates with IBCF 65 and TrGW 66 via RTP. Furthermore, security agent 68 communicates with CSCF 67 via SIP, and IBCF 65 and TrGW 66 communicate via RTP. 66 also communicates with CSCF 67 via the SIP protocol; the security platform 69 communicates with user terminal 61 and security agent 68 via the Internet; user terminal 61 and security agent 68 communicate through IP gateways in their respective operator networks, and the two IP gateways communicate via SIP and RTP protocols.
[0081] Figure 7 A schematic diagram of an identity authentication device according to some embodiments of the present invention is shown. This identity authentication device is a security platform or a security agent. Figure 7 As shown, the identity authentication device 70 of this embodiment includes: a memory 710 and a processor 720 coupled to the memory 710. The processor 720 is configured to execute the identity authentication method of any of the foregoing embodiments based on instructions stored in the memory 710.
[0082] The memory 710 may include, for example, system memory, fixed non-volatile storage media, etc. The system memory may store, for example, the operating system, application programs, boot loader, and other programs.
[0083] Figure 8 A schematic diagram of an identity authentication device according to other embodiments of the present invention is shown, which is a security platform or a security agent. Figure 8As shown, the authentication device 80 in this embodiment includes a memory 810 and a processor 820, and may also include an input / output interface 830, a network interface 840, a storage interface 850, etc. These interfaces 830, 840, 850, and the memory 810 and processor 820 can be connected, for example, via a bus 860. The input / output interface 830 provides a connection interface for input / output devices such as a display, mouse, keyboard, and touchscreen. The network interface 840 provides a connection interface for various networked devices. The storage interface 850 provides a connection interface for external storage devices such as SD cards and USB flash drives.
[0084] Embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, characterized in that the program, when executed by a processor, implements any of the aforementioned authentication methods.
[0085] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable non-transitory storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0086] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0087] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0088] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0089] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An identity authentication method, comprising: In response to the successful verification of the client's user by the security platform, the security platform sends a corresponding user identity ticket to the client, so that the client can generate a communication token with a digital signature based on the user identity ticket and the obtained Certificate Authority (CA) security certificate; The security platform receives the communication token sent by the client; After the client sends the user's access request to the security agent, the security platform sends the user's communication token to the security agent; The security platform receives a user query request sent by the security agent, wherein the user query request includes the communication token; The security platform uses the CA public key to decrypt the communication token and obtain the user identity ticket; The security platform queries the user's real identity based on the user identity ticket; The security platform sends the user's real identity to the security agent, so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity. This includes the security agent or video conferencing system presenting the real identity in the interactive interface of the video conference for the meeting initiator to confirm whether access is allowed. The application system includes a video conferencing system.
2. The identity authentication method according to claim 1 further includes: In response to the security platform's successful verification of the client's user, the security platform sends an application whitelist to the client, wherein the application whitelist includes the application system.
3. The identity authentication method according to claim 1 further includes: The security platform receives an authentication request sent by the client, wherein the authentication request includes user-side information corresponding to the user of the client, wherein the user-side information includes the user's real identity; The security platform verifies the user-side information; In response to the successful verification of the client's user by the security platform, the security platform generates a user identity ticket for the user.
4. The identity authentication method according to claim 3, wherein, The user-side information also includes device information or environmental information.
5. The identity authentication method according to claim 1 further includes: The security platform counts the number of user query requests sent by the security agent within a preset time period, so that if the number is less than a preset threshold, the user's real identity is sent to the security agent, and if the number is not less than the preset threshold, the user query request from the security agent is rejected.
6. An authentication method, comprising: The security agent receives the user's access request sent by the user's client; The security agent obtains the user's communication token from the security platform according to the access request. The communication token is generated by the client based on the user identity ticket sent by the security platform and the obtained CA security certificate after the security platform verifies the user. The client then sends the communication token to the security platform. The security agent sends a user query request to the security platform, wherein the user query request includes the communication token, so that the security platform can use the CA public key to decrypt the communication token, obtain the user identity ticket, and query the user's real identity based on the user identity ticket; The security agent receives the user's real identity sent by the security platform, so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity. This includes: the security agent or video conferencing system presenting the real identity in the interactive interface of the video conference for the meeting initiator to confirm whether access is allowed, wherein the application system includes a video conferencing system.
7. The authentication method according to claim 6 further includes: The security agent sends the user's real identity to the application system; The security agent receives the access control result for the user sent by the application system; The security agent sends the access control result to the client.
8. The authentication method according to claim 6 further includes: The security agent obtains a list of users allowed to access the application system; The security agent determines whether the user is in the user list based on the user's real identity; If the user is in the user list, the security agent sends an access permission message to the client; If the user is not on the user list, the security agent sends an access denied message to the client.
9. A security platform for identity authentication, comprising: The user identity ticket sending module is configured to send a corresponding user identity ticket to the client in response to the security platform's successful verification of the client's user, so that the client can generate a communication token with a digital signature for the user based on the user identity ticket and the obtained CA security certificate; A communication token receiving module is configured to receive the communication token sent by the client; The communication token sending module is configured to send the user's communication token to the security agent after the client sends the user's access request to the security agent; The query request receiving module is configured to receive user query requests sent by the security agent, wherein the user query request includes the communication token; The decryption module is configured to decrypt the communication token using the CA public key to obtain the user identity ticket; The identity query module is configured to query the user's real identity based on the user identity ticket; An identity sending module is configured to send the user's real identity to the security agent, so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity. This includes: the security agent or video conferencing system presenting the real identity in the interactive interface of the video conferencing for the meeting initiator to confirm whether access is allowed, wherein the application system includes a video conferencing system.
10. The security platform according to claim 9, further comprising: The whitelist sending module is configured to send an application whitelist to the client in response to the security platform's successful verification of the client's user, wherein the application whitelist includes the application system.
11. The security platform according to claim 9, further comprising: The verification module is configured to receive an authentication request sent by the client, wherein the authentication request includes user-side information corresponding to the user of the client, wherein the user-side information includes the user's real identity; verify the user-side information; and generate a user identity ticket for the user in response to the security platform's successful verification of the client's user.
12. The security platform according to claim 9 further includes: The statistics module is configured to count the number of user query requests sent by the security agent within a preset time period, so that if the number is less than a preset threshold, the user's real identity is sent to the security agent, and if the number is not less than the preset threshold, the user query request is rejected by the security agent.
13. A security platform for identity authentication, comprising: Memory; as well as A processor coupled to the memory, the processor being configured to execute the authentication method as described in any one of claims 1 to 5 based on instructions stored in the memory.
14. A security proxy for identity authentication, comprising: The access request receiving module is configured to receive access requests from the user's client. The communication token acquisition module is configured to acquire the user's communication token from the security platform according to the access request, wherein the communication token is generated by the client based on the user identity ticket sent by the security platform and the acquired CA security certificate after the security platform verifies the user, and the client sends the communication token to the security platform; The query request sending module is configured to send a user query request to the security platform, wherein the user query request includes the communication token, so that the security platform can use the CA public key to decrypt the communication token, obtain the user identity ticket, and query the user's real identity based on the user identity ticket; The real identity receiving module is configured to receive the user's real identity sent by the security platform, so that the security agent or the application system connected to the security agent can control the user's access based on the user's real identity. This includes: the security agent or video conferencing system presenting the real identity in the interactive interface of the video conferencing for the meeting initiator to confirm whether access is allowed, wherein the application system includes a video conferencing system.
15. The security agent according to claim 14, further comprising: The first access control module is configured to send the user's real identity to the application system; Receive the access control result for the user sent by the application system; The access control result is sent to the client.
16. The security agent according to claim 14, further comprising: The second access control module is configured to obtain a list of users allowed to access the application system. Based on the user's real identity, determine whether the user is in the user list; If the user is in the user list, send an access permission message to the client; if the user is not in the user list, send an access denial message to the client.
17. A security proxy for identity authentication, comprising: Memory; as well as A processor coupled to the memory, the processor being configured to execute the authentication method as described in any one of claims 6 to 8 based on instructions stored in the memory.
18. An identity authentication system, comprising: The security platform according to any one of claims 9 to 13; as well as The security agent according to any one of claims 14 to 17.
19. The identity authentication system according to claim 18, further comprising: Client.
20. A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the authentication method of any one of claims 1 to 8.