A Method for Generating Identity Identification and Trusted Authentication of a Mobile Terminal Operating System
Through the OSID identification code generation and trusted authentication methods, the process redundancy and calculation overhead problems in the identity authentication of the mobile terminal operating system are solved, and fast and trusted identity authentication is realized, which is suitable for mobile terminal operating systems of massive devices.
Patent Information
- Application Number
- CN202310194713.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-03
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2043-03-03
AI Technical Summary
In the identity authentication of mobile terminal operating system, the existing technology has problems such as frequent interaction of digital certificate validity checks, redundant process, large data volume, high computing overhead, no support for rapid authentication and verification, and inability to link with a trusted computing system, especially inefficient in massive device access scenarios.
The OSID identification code generation and trusted authentication methods are adopted, and the Guose Digital Certificate, Guose SM2/SM3 algorithm and random selection algorithm are used to generate and manage the terminal fingerprint characteristics through the identity identification OSID module. Combined with trusted computing technology, it realizes fast identity authentication and full life cycle management, reducing the redundant process and data interaction of digital certificates.
It improves the identity authentication efficiency of massive mobile terminal operating systems, reduces the risk of computing failures, supports rapid authentication of end-end and end-side scenarios, prevents security risks, and meets the credible authentication needs of the public security industry.
Smart Images

Figure CN116321175B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of secure communication, and particularly to a method for generating an identity identifier and performing trusted authentication for a mobile terminal operating system. Background Art
[0002] At present, the operating systems installed on mobile terminal devices in the field of public security mainly rely on the Android system. In recent years, with the rapid development of new technologies such as 5G, mobile Internet, and artificial intelligence, the mobile operating system has evolved to the third generation, featuring a microkernel, being oriented to the full scenario (people, devices, services), and enabling business collaboration for the Internet of Everything. Related mobile terminal devices have gradually been promoted and applied in the public security industry.
[0003] Currently, the new generation of mobile public security system is based on the network security level protection and the trusted computing system for inborn defense, and constructs a security protection architecture for mobile terminals and public security business systems, effectively preventing system security risks brought during the mobile public security business process. In terms of the security of mobile terminal devices, the construction of the public security PKI infrastructure has been basically completed, the mobile public security user identity authentication system has been improved, and the needs of users to engage in public security business using user certificates and mobile public security devices have been addressed.
[0004] At the same time, with the rapid advancement of 5G, there are still many security issues that urgently need to be solved, such as the access of a large number of devices, the complexity of system heterogeneity, and the sharp increase in system complexity. How to construct a fast identity authentication access for "personnel, devices, and systems" in the 5G scenario based on the existing public security PKI system is one of the thorny issues that urgently need to be solved at the current stage. The access authentication of a large number of "things" and the trusted identity authentication of mobile terminal operating systems with complex classification and large-scale heterogeneity have become one of the difficulties and problems that remain to be improved in the current new generation of mobile public security system and that must be faced and solved in the development of new technologies.
[0005] The PKI system is a commonly used technology that ensures information security and verifies the trustworthiness of the identity of digital certificate holders by using public key cryptography and digital signatures. PKI mainly includes logical units such as a public key cryptography system, digital certificates, a CA (certification authority), and an RA (registration authority). Digital certificates representing user identities usually contain information such as the public key of the user, the identity identification information of the user, the validity period (the effective period of the digital certificate), the identification information of the issuer, and the digital signature of the issuer. Digital certificates can be used as identity identifiers and are used in the network world. During interaction, the certificate holder only needs to present the digital certificate, and the other party can verify whether the identity of the certificate holder is legal by judging whether the certificate is forged, whether the certificate holder has the corresponding private key, whether the certificate has been invalidated or frozen, etc., thus conveniently realizing a high-strength identity authentication function.
[0006] However, the above solutions for implementing identity authentication in a mobile terminal operating system have the following disadvantages:
[0007] 1. The validity check of digital certificates requires frequent interaction with the institutional CA, resulting in redundant processes. During end-side identity authentication, the timeliness of network connectivity in a centralized architecture cannot be guaranteed;
[0008] 2. The amount of data carried by digital certificate information is relatively large (single certificate is greater than 2K). In the era of massive mobile Internet, high-concurrency business certificate authentication increases network and computing overheads, reducing service quality;
[0009] 3. Digital certificates do not have the characteristics of fast authentication and verification in the end-to-end and end-edge scenarios, do not support linkage with the trusted computing system, and do not support the construction of a fast collaborative account identity authentication and derivation mechanism through identity identifiers. Secondly, the digital certificate and password service interfaces are not very friendly to the development and invocation of upper-layer mobile applications (frequent invocation of SKF interfaces). Summary of the Invention
[0010] Aiming at the deficiencies of the prior art, the present invention aims to provide a method for generating an identity identifier and performing trusted authentication for a mobile terminal operating system.
[0011] To achieve the above object, the present invention adopts the following technical solutions:
[0012] A method for generating an identity identifier and performing trusted authentication for a mobile terminal operating system, including two parts: OSID identifier generation and OSID identifier trusted authentication:
[0013] I. The specific process of OSID identifier generation is as follows:
[0014] 1.1. After the mobile terminal operating system is powered on for the first time after leaving the factory and completes the application for a digital signature certificate, trusted measurement, and startup of the device management system service component, the identity identifier OSID trusted authentication module working at the operating system framework layer is initialized;
[0015] 1.2. The identity identifier OSID trusted authentication module calls the national cryptography SKF interface to obtain the operating system digital signature certificate information, and calls the device management system service component to obtain the fingerprint features of the mobile terminal; the fingerprint features are generated by performing SM3 hash operation on hardware information such as the device IMEI, MAC address information, and serial number through the password interface according to established rules;
[0016] 1.3. The identity identifier OSID trusted authentication module generates a check bit using a random selection algorithm based on the operating system digital signature certificate information and the mobile terminal fingerprint features in step 1.2, and calls the national cryptography SKF interface to generate data segments 1, 2, and 4 of the UAIC data, where the data segment 4 is the check bit;
[0017] 1.4. The identity identification OSID trusted authentication module calls the national cryptography SKF interface to generate the unsigned data segment 3 of the UAIC data according to the UAIC data segment generated in step 1.3.
[0018] 1.5. The identity identification OSID trusted authentication module applies for the SM2 signature of the CA root certificate, obtains the signature information of the data segment 3 of the UAIC data, and generates the data segment 3 of the signed UAIC data through calculation; the identity identification OSID trusted authentication module generates the UAIC data.
[0019] 1.6. The identity identification OSID trusted authentication module calls the SKF interface to obtain the UAIC data, generates the data segments 1, 2, and 4 of the OSID accordingly, calls the device management system service component interface, obtains the operating system feature information according to the random selection algorithm, and calls the SKF interface to generate the SM3 hash result of the data segments 1, 2 of the UAIC data and the operating system feature information, and generates the unsigned and unvalidated data segment 3 of the OSID.
[0020] 1.7. The identity identification OSID trusted authentication module calls the SKF interface to sign the data segment 3 generated in step 1.6 with the private key of the operating system digital signature certificate to generate the first signed data segment.
[0021] 1.8. The identity identification OSID trusted authentication module applies for the SM2 signature of the CA root certificate and generates the second signed data segment for the signature information of the first signed data segment generated in step 1.7.
[0022] 1.9. The identity identification OSID trusted authentication module splices the first signed data segment generated in step 1.7 and the second signed data segment generated in step 1.8 to generate the data segment 3 containing the signature and verification information.
[0023] 1.10. The identity identification OSID trusted authentication module generates the final OSID data.
[0024] II. The specific OSID trusted authentication process is as follows:
[0025] 2.1. The identity identification OSID trusted authentication module parses the authentication request to obtain the OSID data information and the fingerprint feature of the authenticating party's mobile terminal.
[0026] 2.2. The identity identification OSID trusted authentication module calls the SKF interface to obtain the pre-set CA verification root certificate and verifies the data of the second signed data segment of the data segment 3 in the OSID data information in step 2.1; the CA verification root certificate is obtained by the mobile terminal from the CA in an online or offline manner during the initial process.
[0027] 2.3. If the signature verification in step 2.2 passes, obtain the signature verification certificate of the authenticating party from the CA and verify the first signature data segment of data segment 3 of the OSID data for signature verification.
[0028] 2.4. If the signature verification in step 2.3 passes, parse data segment 4 in the OSID data and verify the authenticity of the fingerprint feature of the authenticating party's mobile terminal obtained in step 2.1 according to the random selection algorithm.
[0029] 2.5. If the verification in step 2.4 passes, return the authentication result true.
[0030] 2.6. The authentication process ends.
[0031] Furthermore, in step 1.5, the identity identification OSID trusted authentication module generates UAIC data and imports it into the hardware password module, TCM or TPCM for storage.
[0032] Furthermore, in step 1.10, the identity identification OSID trusted authentication module generates the final OSID data and stores it in or imports it into the secure storage module.
[0033] Even further, in step 1.10, the secure storage module is a TEE or a hardware password module.
[0034] The beneficial effects of the present invention are as follows: Based on national cryptographic digital certificates, national cryptographic SM2 / SM3 algorithms, random selection algorithms, and trusted computing technologies, etc., the present invention can generate, manage the entire life cycle, and perform trusted authentication on the identity identification OSID for smartphone-type mobile terminals or extended mobile terminals (such as smart watches, smart bracelets, smart gateways, intelligent in-vehicle mobile terminals, or other wearable and extended terminals equipped with intelligent mobile operating systems), accelerate and improve the trusted authentication efficiency of a large number of interconnected mobile intelligent terminal operating systems, eliminate the redundancy of the process and data interaction in the single-system authentication of digital certificates, and the single-point failure risk of certificate verification services. Through the standard structuring of the identity identification OSID data, the operation failures in the process of generating the OSID identity identification and trusted authentication are significantly reduced. It has the same identity recognition and authentication function as the digital certificate authentication system, is suitable for the rapid authentication of the identities of a large number of intelligent Internet of Things mobile terminal operating systems, and at the same time has the ability to prevent security risks such as illegal tampering, malicious exploitation, and malicious attacks, making up for the gap in the security management and trusted authentication of the entire life cycle of the current mobile terminal operating system identity, and can meet the urgent needs of the public security industry for the security and trust of mobile terminals and risk monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 It is the logical structure diagram of the OSID identity identification code of the operating system of the present invention;
[0036] Figure 2Schematic diagram of the logical structure of the UAIC and OSID data segments of the present invention;
[0037] Figure 3 Schematic diagram of the OSID identification generation process in Embodiment 1 of the present invention;
[0038] Figure 4 Schematic diagram of the OSID trusted authentication process in Embodiment 1 of the present invention;
[0039] Figure 5 Schematic diagram of the OSID identification generation process in Embodiment 2 of the present invention;
[0040] Figure 6 Schematic diagram of the OSID trusted authentication process in Embodiment 2 of the present invention. Detailed implementation manner
[0041] The present invention will be further described below in conjunction with the accompanying drawings. It should be noted that this embodiment is based on the present technical solution and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to this embodiment.
[0042] Embodiment 1
[0043] This embodiment provides a method for generating and authenticating the identity of a mobile terminal operating system, establishing an association relationship between each stage of the mobile terminal startup process (operating system certificate application stage, trusted measurement stage, terminal UAIC generation, and OSID generation stage) according to the timing process, and using the hardware password module, trusted password module TCM or trusted platform control module TPCM and trusted execution environment TEE of the mobile terminal operating system as the starting point of the security chain. Based on this, an identity identification OSID system for the initialization, startup, and operation stages of the mobile terminal operating system is constructed to realize trusted identity authentication based on the identity identification of the mobile terminal operating system. Since the operating system identity identification is strongly correlated with the terminal digital certificate, terminal fingerprint information, terminal trusted status, and hardware password module, even if the operating system permissions are obtained through external attacks, it is impossible to arbitrarily tamper with the OSID identity identification and steal sensitive identity information. On the one hand, it can eliminate the problems of redundant identity verification processes and inefficient data information interaction brought by the single digital certificate authentication method. On the other hand, using the OSID identity identification can quickly realize identity trusted verification in the end-to-end and end-edge scenarios, meeting the requirements of trusted identity authentication for the operating systems of a large number of mobile terminal business scenarios in the mobile Internet era.
[0044] The implementation of the method in this embodiment depends on the following three conditions:
[0045] (1) The mobile terminal has obtained the institutional CA verification root certificate and the digital certificate corresponding to the mobile terminal operating system issued by the official CA through online or offline methods during the initial process;
[0046] (2) In the initial startup process of the mobile terminal, a complete trusted chain has been built based on a trusted root (TCM, TPCM, hardware password module, or TEE), and a trusted measurement report has been generated.
[0047] (3) The mobile terminal has pre-installed a device management system service component with the highest system privilege (such as MDM), and provides system function calls (such as system information acquisition) in the form of an interface.
[0048] The overall process of the method in this embodiment is as follows: Obtain hardware fingerprint information through a device management system service component (such as MDM); obtain operating system digital signature certificate information through a national secret SKF interface; obtain the terminal trusted measurement report through a trusted computing platform; perform national secret cryptographic operations and SM3 hashing of data segments through TCM, TPCM, or a hardware password module; obtain application signature data from the official CA center to generate a unique identity identifier OSID for the corresponding mobile terminal operating system, and support adding custom extension information in the OSID data structure.
[0049] The logical structure of the operating system OSID identity identifier is as Figure 1 shown. The support module on the mobile terminal side includes a trusted root (TCM, TPCM, or hardware password module) and a TEE trusted execution environment. In addition, an App identity ID trust chain derivation service is provided for applications based on OSID; the system service network element includes the official agency CA, the password management center, the operating system OSID support, and the security management system service (hereinafter referred to as the "identity identifier management service"), etc. UAIC is the unique authentication identifier for the binding relationship between the mobile terminal, the operating system, and the digital certificate, and OSID is the unique identifier for the identity of the corresponding mobile terminal operating system. Among them, the logical structures of the UAIC and OSID data segments are as Figure 2 shown.
[0050] Among them, the UAIC data segment includes data segment 1 timestamp information (timestamp), data segment 2 device fingerprint information (fingerprint), data segment 3 root CA signature information (sig), and data segment 4 verification information (check); the OSID data segment includes data segment 1 timestamp information (timestamp), data segment 2 unified authentication identifier (uaic), data segment 3 root CA signature information (sig), and data segment 4 verification information (check).
[0051] In this embodiment, UAIC and OSID also have the following characteristics:
[0052] UAIC is strongly related to the terminal hardware fingerprint, the terminal TCM / TPCM hardware password module, and the operating system identity certificate (signature certificate). When the certificate is replaced, the UAIC must be regenerated. OSID is strongly related to UAIC, the operating system information (such as version number, security patch information, etc.), and the operating system identity certificate (digital certificate). When the operating system is upgraded, restored to factory settings, or the certificate is replaced, the OSID information will be regenerated.
[0053] Specifically, the method of this embodiment includes two parts: OSID identification code generation and OSID identification code trusted authentication:
[0054] First, as Figure 3 shown, the specific process of OSID identification code generation is as follows:
[0055] 1.1. After the mobile terminal operating system is powered on for the first time after leaving the factory, after completing the digital signature certificate application, trusted measurement, and starting the device management system service component, the identity identification OSID trusted authentication module working at the operating system framework layer is initialized;
[0056] 1.2. The identity identification OSID trusted authentication module calls the national cryptography SKF interface to obtain the operating system digital signature certificate information, and calls the device management system service component to obtain the mobile terminal fingerprint features; the fingerprint features are generated by performing SM3 hashing operation on hardware information such as the device IMEI, MAC address information, and serial number through the password interface according to the set rules;
[0057] 1.3. The identity identification OSID trusted authentication module generates a check bit using a random selection algorithm based on the operating system digital signature certificate information and the mobile terminal fingerprint features in step 1.2, and calls the national cryptography SKF interface to generate data segment 1, data segment 2, and data segment 4 of the UAIC data, where data segment 4 is the check bit;
[0058] 1.4. The identity identification OSID trusted authentication module calls the national cryptography SKF interface to generate data segment 3 of the unsigned UAIC data according to the UAIC data segments generated in step 1.3;
[0059] 1.5. The identity identification OSID trusted authentication module applies for SM2 signature of the CA root certificate, obtains the signature information of data segment 3 of the UAIC data, and generates data segment 3 of the UAIC data with signature through calculation; the identity identification OSID trusted authentication module generates the UAIC data and imports it into the hardware password module for storage, TCM, or TPCM;
[0060] 1.6. The identity identification OSID trusted authentication module calls the SKF interface to obtain UAIC data, generates data segments 1, 2, and 4 of the OSID based on this, calls the device management system service component interface, obtains the operating system feature information according to the random selection algorithm, and calls the SKF interface to generate the SM3 hash result from data segments 1 and 2 of the UAIC data and the operating system feature information, generating data segment 3 of the unsigned and unvalidated OSID;
[0061] 1.7. For data segment 3 generated in step 1.6, the identity identification OSID trusted authentication module calls the SKF interface to sign it with the private key of the operating system digital signature certificate (i.e., the OS certificate in Figure 3 ) to generate the first signature data segment;
[0062] 1.8. The identity identification OSID trusted authentication module applies for the SM2 signature of the CA root certificate and generates the second signature data segment for the signature information of the first signature data segment generated in step 1.7;
[0063] 1.9. The identity identification OSID trusted authentication module concatenates the first signature data segment generated in step 1.7 and the second signature data segment generated in step 1.8 to generate data segment 3 containing the signature and verification information;
[0064] 1.10. The identity identification OSID trusted authentication module generates the final OSID data and stores or imports it into the secure storage module (TEE or hardware password module, etc.).
[0065] II. As shown in Figure 4 , the specific OSID trusted authentication process is as follows:
[0066] 2.1. The identity identification OSID trusted authentication module parses the authentication request to obtain the OSID data information and the fingerprint feature of the authenticating party's mobile terminal;
[0067] 2.2. The identity identification OSID trusted authentication module calls the SKF interface to obtain the pre-set CA verification root certificate and verifies the data of the second signature data segment in data segment 3 of the OSID data information in step 2.1; The CA verification root certificate is obtained by the mobile terminal from the CA in an online or offline manner during the initial process;
[0068] 2.3. If the verification in step 2.2 passes, obtain the verification certificate of the authenticating party from the CA and verify the first signature data segment of data segment 3 of the OSID data. It should be noted that this step only takes effect in the OSID online authentication (the OSID trusted authentication scenario for system-side services), and other scenarios are skipped;
[0069] 2.4. If the signature verification in step 2.3 passes, parse data segment 4 in the OSID data, and verify the authenticity of the fingerprint feature of the authenticating party's mobile terminal obtained in step 2.1 according to the random selection algorithm;
[0070] 2.5. If the verification in step 2.4 passes, return the authentication result true;
[0071] 2.6. The authentication process ends. Embodiment 2
[0072] This embodiment provides an application example of generating an OSID identifier in the method described in Embodiment 1.
[0073] This embodiment is described by taking the first boot activation process of a mobile terminal A, the generation of the operating system UAIC, and the OSID identity identifier as an example. This terminal supports dual-system container-level isolation and a dual-system architecture (Android and Harmony OS). The OSID trusted authentication module for the identity identifier works at the system framework layer, uses the current mainstream development architecture and technology, and has a certain degree of generality and representativeness.
[0074] All of the preconditions, including the trusted measurement during the startup and running phases of the operating system of mobile terminal A, the initialization of the terminal TCM / TPCM / hardware password module (in the form of an embedded security chip), the operating system digital signature certificate process, and the startup of the device management system service component, are completed.
[0075] As Figure 5 shown, the OSID generation process for the operating system identity identifier includes the following steps:
[0076] Step 1: Initialize the OSID trusted authentication module for the identity identifier, obtain the certificate information of the operating system digital signature certificate sig_cer through the SKF interface, and calculate fingerprint through SM3 hashing operation;
[0077] Step 2: Generate data segment 1 (timestamp, long type, 8 bytes) of the UAIC data, and at the same time call the MDM device management system service component to obtain the check identifier (int type, 4 bytes) of data segment 4 of the UAIC data according to the random selection algorithm;
[0078] Step 3: Call the SKF interface to input sig_cer and fingerprint, and generate data segment 2 (16 bytes) through SM3 hashing;
[0079] Step 4: Apply for the root CA signature information of the data segment of data, where data is the SM3 hash value of data segments 1, 2, and 4 of the UAIC data, with a length of 16 bytes;
[0080] Step 5: The system service side identity management service accepts the signature request in Step 4, verifies the legality of the request, and forwards it to the CA to apply for signature information;
[0081] Step 6: The CA generates signature information sig_ca, and the system service side identity management service forwards sig_ca to the mobile terminal A. The identity OSID trusted authentication module parses and obtains sig_ca as the UAIC data segment 3 (length 72 bytes);
[0082] Step 7: The identity OSID trusted authentication module generates a UAIC unified authentication identification code, whose value is the string after Hex{data segment 1: data segment 2: data segment 3: data segment 4}; calls the SKF interface to import and store it in the TCM / TPCM or the hardware password module;
[0083] Step 9: The identity OSID trusted authentication module obtains the UAIC generated in Step 7, calls the SKF interface to generate an SM3 hash value as the OSID data segment 2 of 16 bytes, and generates the OSID data segment 1 (timestamp, long type, 8 bytes), and then obtains the check flag of the OSID data segment 4 (int type, 4 bytes) according to the random selection algorithm;
[0084] Step 10: The identity OSID trusted authentication module calls the SKF interface to obtain the digital signature certificate of the operating system to sign the data segment data1[{data segment 1: data segment 2: data segment 3}|SM3] to obtain the signature value sig_os, and uses it as the first signature data segment of the OSID data segment 3;
[0085] Step 11: The identity OSID trusted authentication module applies for the root CA signature of data1[{data segment 1: data segment 2: data segment 3}|SM3], where data is the SM3 hash value of data segments 1, 2, and 4, with a length of 16 bytes;
[0086] Step 12: The system service side identity management service accepts the signature request, verifies the legality of the request, and forwards it to the CA to apply for signature information;
[0087] Step 13: The CA generates signature information sig_ca, and the system service side identity management service forwards the signature data sig_ca to the mobile terminal A. The identity OSID trusted authentication module parses and obtains sig_ca and uses it as the second signature data segment of the OSID data segment 3 (length 72 bytes);
[0088] Step 14: Generate an OSID identity identification code, the value of which is the string after Hex{Data segment 1: Data segment 2: Data segment 3: Data segment 4}, where Data segment 3 is [First signature data segment: Second front data segment] generated in Steps 10 and 13.
[0089] Step 15: The OSID generation process ends. Embodiment 3
[0090] This embodiment provides an application example of OSID trusted authentication in the method described in Embodiment 1.
[0091] Taking the OSID online trusted identity authentication of the third-party system service for the mobile terminal B as an example in this embodiment, the online scenario specifically refers to that the mobile terminal can normally access and visit the system-side service, and the OSID trusted authentication for the mobile terminal operating system initiated by the third-party system service A (or the in-network mobile terminal). In this embodiment, the terminal supports dual-system isolation / dual-system architecture (Android and HarmonyOS) and can safely access the mobile public security system. The identity identification OSID trusted authentication module adopts the form of the terminal operating system application service, works at the system framework layer, uses the current mainstream development architecture and technology, and has a certain degree of generality and representativeness.
[0092] All of the trusted measurement during the startup and operation phases of the operating system of the mobile terminal B, the initialization of the TCM / TPCM / hardware password module (in the form of an embedded security chip), the operating system signature certificate process, the startup of the device management system service component, the OSID generation process, etc. included in the preconditions are all completed.
[0093] As Figure 6 shown, the online authentication process of the operating system identity OSID of the terminal B described in this embodiment mainly includes the following steps:
[0094] Step 1: The third-party system application service (or mobile terminal A) deployed in the mobile official business system initiates an OSID trusted authentication request for the operating system identity of the authenticated party mobile terminal B, carrying the authentication type parameter type with a value of 1. (type being 1 indicates initiating online authentication, and 2 indicates initiating offline authentication)
[0095] Step 2: The terminal B receives the OSID trusted authentication request and calls the identity identification OSID trusted authentication module of the terminal to obtain the osid_b information and the fingerprint information fingerprint_b of the terminal B;
[0096] Step 3: The terminal B returns a request response to the authenticating party third-party system application service (or mobile terminal A), carrying osid_b and fingerprint_b;
[0097] Step 4: The third-party system application service of the authenticator (or mobile terminal A) initiates an online OSID authentication check to the identity authentication management service center, carrying osid_b and fingerprint_b returned by terminal B;
[0098] Step 5: The identity authentication management service center calls the root CA signature verification public key to verify the legality of the second signature data segment of the signature data segment 3 of osid_b;
[0099] Step 6: The identity authentication management service center parses osid_b and fingerprint_b, and obtains the terminal information corresponding to osid_b in the management service center database according to the osid identifier;
[0100] Step 7: The identity authentication management service center has a check data segment for parsing osid_b. Using a random selection algorithm for corresponding strategies, it calculates the SM hash value and compares it with the corresponding data segment of osid_b in the request;
[0101] Step 8: If the verifications in Step 5, Step 6, and Step 7 all pass, return the verification result (true: trusted authentication check passed, false: failed) to the third-party system application service of the authenticator (or mobile terminal A);
[0102] Step 9: The third-party system application service of the authenticator (or mobile terminal A) returns the online OSID trusted authentication result to terminal B;
[0103] Step 10: The OSID online trusted authentication process ends.
[0104] For those skilled in the art, various corresponding changes and deformations can be given according to the above technical solutions and concepts, and all such changes and deformations should be included within the protection scope of the claims of the present invention.
Claims
1. A method for generating an identity identifier and performing trusted authentication for a mobile terminal operating system, characterized in that It includes two parts: OSID identification code generation and OSID identification code trusted authentication: I. The specific process of OSID identification code generation is as follows: 1.
1. After the mobile terminal operating system is powered on for the first time after leaving the factory, after completing the digital signature certificate application, trusted measurement, and startup of the device management system service component, the identity identification OSID trusted authentication module working at the operating system framework layer is initialized; 1.
2. The identity identification OSID trusted authentication module calls the national cryptographic SKF interface to obtain the operating system digital signature certificate information, and calls the device management system service component to obtain the mobile terminal fingerprint feature; the fingerprint feature is generated by performing the SM3 hashing operation on the device IMEI, MAC address information, and serial number according to the established rules through the cryptographic interface; 1.
3. The identity identification OSID trusted authentication module generates a check bit using a random selection algorithm based on the operating system digital signature certificate information and the mobile terminal fingerprint feature in step 1.2, and calls the national cryptographic SKF interface to generate data segments 1, 2, and 4 of the UAIC data, where data segment 4 is the check bit; among them, the UAIC data includes data segment 1 timestamp information, data segment 2 device fingerprint information, data segment 3 root CA signature information, and data segment 4 check information; 1.
4. The identity identification OSID trusted authentication module calls the national cryptographic SKF interface to generate data segment 3 of the unsigned UAIC data according to the UAIC data segments generated in step 1.3; 1.
5. The identity identification OSID trusted authentication module applies for the SM2 signature of the CA root certificate, obtains the signature information of data segment 3 of the UAIC data, and generates data segment 3 of the UAIC data with signature through calculation; the identity identification OSID trusted authentication module generates the UAIC data; 1.
6. The identity identification OSID trusted authentication module calls the SKF interface to obtain the UAIC data, generates data segments 1, 2, and 4 of the OSID accordingly, calls the device management system service component interface, obtains the operating system feature information according to the random selection algorithm, calls the SKF interface to generate the SM3 hashing result of data segments 1, 2 of the UAIC data, and the operating system feature information, and generates data segment 3 of the unsigned and unchecked OSID; the OSID data includes data segment 1 timestamp information, data segment 2 unified authentication identification code, data segment 3 root CA signature information, and data segment 4 check information; 1.
7. The identity identification OSID trusted authentication module calls the SKF interface to sign data segment 3 generated in step 1.6 with the private key of the operating system digital signature certificate to generate the first signature data segment; 1.
8. The identity identification OSID trusted authentication module applies for the SM2 signature of the CA root certificate and generates the second signature data segment for the signature information of the first signature data segment generated in step 1.7; 1.
9. The identity identification OSID trusted authentication module splices the first signature data segment generated in step 1.7 and the second signature data segment generated in step 1.8 to generate data segment 3 containing signature and check information; 1.
10. The identity identification OSID trusted authentication module generates the final OSID data; II. The specific process of OSID trusted authentication is as follows: 2.
1. The identity identification OSID trusted authentication module parses the authentication request to obtain the OSID data information and the fingerprint features of the authenticator's mobile terminal; 2.
2. The identity identification OSID trusted authentication module calls the SKF interface to obtain the pre-set CA verification signature root certificate, and verifies the second signature data segment data of data segment 3 in the OSID data information in step 2.1; The CA verification signature root certificate is obtained by the mobile terminal from the CA in an online or offline manner during the initial process; 2.
3. If the verification in step 2.2 passes, obtain the verification signature certificate of the authenticator from the CA, and verify the first signature data segment of data segment 3 of the OSID data; 2.
4. If the verification in step 2.3 passes, parse data segment 4 in the OSID data, and verify the authenticity of the fingerprint features of the authenticator's mobile terminal obtained in step 2.1 according to the random selection algorithm; 2.
5. If the verification in step 2.4 passes, return the authentication result true; 2.
6. The authentication process ends.
2. The method according to claim 1, characterized in that, In step 1.5, the identity identification OSID trusted authentication module generates UAIC data and imports it into the hardware password module, TCM or TPCM for storage.
3. The method according to claim 1, wherein In step 1.10, the identity identification OSID trusted authentication module generates the final OSID data and stores it in or imports it into the secure storage module.
4. The method according to claim 3, characterized in that, In step 1.10, the secure storage module is a TEE or a hardware password module.
Citation Information
Patent Citations
Identity verification method based on equipment identification code, server and medium
CN109492378A
Risk control protection system design method based on intelligent terminal identification
CN110210858A