Information authentication method and data access method, system and electronic device
By combining client login information with a trusted execution environment on the identity source system side, the problem of client login information being easily forged is solved, achieving higher information authentication security and system security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ALIBABA CLOUD COMPUTING CO LTD
- Filing Date
- 2023-05-24
- Publication Date
- 2026-05-12
AI Technical Summary
In the SASE system, client-generated login information is easily forged, resulting in low information authentication security, allowing attackers to bypass identity-based authentication.
By combining the trusted execution environment with the identity source system, the client's login information is bound to the trusted execution environment, and a verification message is generated to ensure that the access credentials are valid on a specific device, preventing forged credentials from passing identity authentication.
It improves the security of information authentication, prevents attackers from bypassing authentication in non-binding environments, and enhances the overall security of the system.
Smart Images

Figure CN116582332B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information processing, and more specifically, to an information authentication method and data access method, system, and electronic device. Background Technology
[0002] Currently, client identity is a core element in ensuring system data security within the Secure Access Service Edge (SASE) system, and protecting identity security is the foundation of overall system security.
[0003] In related technologies, client login information (e.g., identity information) is usually collected and generated by the client (e.g., software). However, the login information generated by the above methods is easily forged, allowing attackers to bypass identity-based authentication, leading to attacks on the information service system and resulting in technical problems of low security in information authentication.
[0004] There is currently no effective solution to the above problems. Summary of the Invention
[0005] This application provides an information authentication method, a data access method, a system, and an electronic device to at least address the technical problem of low security in information authentication.
[0006] According to one aspect of the embodiments of this application, an information authentication method is provided. The method may include: in response to an information verification request from an information service system, verifying access credentials in the information verification request to obtain a verification result, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client resides; in response to the verification result indicating that the login information and the trusted execution environment are valid, generating a verification pass message, so that the information service system sends access data matching the login information to the client in response to the verification pass message.
[0007] According to another aspect of the embodiments of this application, a data access method is also provided. The method may include: sending an information verification request to an identity source system, wherein the information verification request includes access credentials for enabling a client to access the system, the access credentials representing the client's login information and the trusted execution environment of the device on which the client resides; and, if the identity source system responds to the information verification request and verifies that the login information and the trusted execution environment are valid, sending access data matching the login information to the client.
[0008] According to another aspect of the embodiments of this application, another data access method is also provided. This method may include: sending access credentials to an information service system, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client resides; an information verification request, including the access credentials, is sent by the information service system to an identity source system; and, if the identity source system responds to the information verification request and verifies that the login information and the trusted execution environment are valid, receiving access data from the information service system that matches the login information.
[0009] According to another aspect of the embodiments of this application, a data access system is also provided. The system may include: a client, an information service system, and an identity source system, wherein the client is used to obtain access credentials, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client resides; the information service system is used to send an information verification request including the access credentials to the identity source system; the identity source system is used to verify the access credentials in response to the information verification request, obtain a verification result, and generate a verification pass message in response to the verification result indicating that the login information and trusted execution environment are valid; wherein the information service system is used to send access data matching the login information to the client in response to the verification pass message.
[0010] According to another aspect of the embodiments of this application, an electronic device is also provided. The electronic device may include a memory and a processor. The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, they implement any of the above methods.
[0011] According to another aspect of the embodiments of this application, a processor is also provided, which is used to run a program, wherein any of the methods described above are executed when the program is running.
[0012] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored program, wherein, when the program is running, it controls the device where the storage medium is located to execute any of the above methods.
[0013] In this embodiment, in response to an information verification request from the information service system, the access credentials in the information verification request are verified to obtain a verification result. The access credentials represent the client's login information and the trusted execution environment (CEX) of the device on which the client resides. In response to the verification result indicating that the login information and CEX are valid, a verification pass message is generated, causing the information service system to send access data matching the login information to the client. That is, in this embodiment, by combining the trusted execution environment with the identity source system, the client's login information (which can identify the user's identity) is bound to the trusted execution environment (which can be a specific hardware execution environment) to obtain access credentials for accessing the information service system. This provides the information service system with trusted authentication capabilities, preventing attackers from passing authentication in an unbound environment even if they steal the client's access credentials. This achieves the technical effect of improving the security of information authentication and solves the technical problem of low information authentication security.
[0014] It is worth noting that the general description above and the detailed description that follow are merely for illustrative purposes and do not constitute a limitation on this application. Attached Figure Description
[0015] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0016] Figure 1 This is a hardware structure block diagram of a computer terminal (or mobile device) for implementing an information authentication method according to an embodiment of this application;
[0017] Figure 2 This is a structural block diagram of a computing environment according to an embodiment of this application;
[0018] Figure 3 This is a flowchart of an information authentication method according to an embodiment of this application;
[0019] Figure 4 This is a flowchart of a data access method according to an embodiment of this application;
[0020] Figure 5 This is a flowchart of another data access method according to an embodiment of this application;
[0021] Figure 6 This is a schematic diagram of a data access system according to an embodiment of this application;
[0022] Figure 7 This is a flowchart of an enhanced identity authentication method according to an embodiment of this application;
[0023] Figure 8 This is a schematic diagram of an information authentication device according to an embodiment of this application;
[0024] Figure 9 This is a schematic diagram of a data access device according to an embodiment of this application;
[0025] Figure 10 This is a schematic diagram of another data access device according to an embodiment of this application;
[0026] Figure 11 This is a structural block diagram of a computer terminal according to an embodiment of this application;
[0027] Figure 12 This is a block diagram of an electronic device according to an embodiment of the present application of an information authentication method. Detailed Implementation
[0028] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0030] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:
[0031] A Trusted Execution Environment (TEE) is a trusted, isolated, and independent execution environment that exists on a device independently of an untrusted operating system. It provides a secure and confidential space for privacy data and sensitive computations in untrusted environments.
[0032] Secure Access Service Edge (SASE) can be a security model or framework for integrating software-defined wide area network and zero-trust security solutions into a converged cloud delivery platform.
[0033] Secure Encrypted Virtualization (SEV) technology can be used to enable the main memory controller to have encryption capabilities to protect virtual machine memory data;
[0034] Trust Domain Extensions (TDX) are new framework extensions that enable confidential computing in scalable processors. They allow the deployment of virtual machines in a secure arbitration mode with cryptographic central processing unit state and memory, integrity protection, and remote certification. They can be used for virtualization-based trusted execution environment technologies.
[0035] A Trusted Execution Environment (TEE) is a standalone processing environment that has transport and storage capabilities and provides security and integrity protection.
[0036] Software Guard Extensions (SGX) are a set of security-related instructions that can be built into the central processing unit.
[0037] A Trusted Platform Module (TPM) is an international standard for secure cryptographic processors that use a dedicated microcontroller integrated into the device to process encryption keys.
[0038] Example 1
[0039] According to an embodiment of this application, an information authentication method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0040] The information authentication method embodiment provided in Embodiment 1 of this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 This is a hardware structure block diagram of a computer terminal (or mobile device) for implementing an information authentication method according to an embodiment of this application. Figure 1As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor (MCU) or a field-programmable gate array (FPGA), etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0041] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0042] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the information authentication method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned information authentication method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0043] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0044] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0045] Figure 1 The hardware structure block diagram shown can serve not only as an exemplary block diagram of the aforementioned computer terminal 10 (or mobile device), but also as an exemplary block diagram of the aforementioned server. In one optional embodiment, Figure 2 The use of the above is illustrated in a block diagram. Figure 1 The computer terminal 10 (or mobile device) shown is an embodiment of a computing node in computing environment 201. Figure 2 This is a structural block diagram of a computing environment according to an embodiment of this application, such as... Figure 2 As shown, computing environment 201 includes multiple computing nodes (such as servers) running on a distributed network (represented as 210-1, 210-2, ..., in the diagram). Each computing node contains local processing and memory resources, and end user 202 can remotely run applications or store data within computing environment 201. Applications can be provided as multiple services 220-1, 220-2, 220-3, and 220-4 within computing environment 201, representing services "A", "D", "E", and "H", respectively.
[0046] End user 202 can provide and access services through a web browser or other software application on a client. In some embodiments, the provisioning and / or requests of end user 202 can be provided to ingress gateway 230. Ingress gateway 230 may include a corresponding agent to handle the provisioning and / or requests for services (one or more services provided in computing environment 201).
[0047] Services are provided or deployed based on various virtualization technologies supported by the computing environment 201. In some embodiments, services may be provided based on virtual machine (VM)-based virtualization, container-based virtualization, and / or similar methods. VM-based virtualization can simulate a real computer by initializing a virtual machine, executing programs and applications without directly accessing any actual hardware resources. While the machine is virtualized by a virtual machine, container-based virtualization can launch containers to virtualize an entire operating system (OS), allowing multiple workloads to run on a single OS instance.
[0048] In one embodiment based on container virtualization, several containers of a service can be assembled into a single computing unit (e.g., a Kubernetes Pod). For example, such as... Figure 2 As shown, service 220-2 can be equipped with one or more compute units (Pods) Pod240-1, 240-2, ..., 240-N (collectively referred to as Pods). A Pod can include a proxy 245 and one or more containers 242-1, 242-2, ..., 242-M (collectively referred to as containers). One or more containers within a Pod handle requests related to one or more corresponding functions of the service. Proxy 245 typically controls service-related network functions such as routing and load balancing. Other services can also be equipped with Pods similar to Pods.
[0049] During operation, executing a user request from end user 202 may require invoking one or more services in computing environment 201, and executing one or more functions of one service may require invoking one or more functions of another service. For example... Figure 2 As shown, service "A" 220-1 receives user requests from terminal user 202 from ingress gateway 230. Service "A" 220-1 can call service "D" 220-2, and service "D" 220-2 can request service "E" 220-3 to perform one or more functions.
[0050] The aforementioned computing environment can be a cloud computing environment, where resource allocation is managed by cloud services, allowing functionality development without needing to consider implementation, adjustment, or server scaling. This computing environment allows developers to execute event-responsive code without building or maintaining complex infrastructure. Services can be partitioned into a set of functions that can automatically and independently scale, rather than scaling a single hardware device to handle potential loads.
[0051] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application, such as weather forecast results, are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0052] Under the above operating environment, this application provides an information authentication method from the identity source system side. Figure 3 This is a flowchart of an information authentication method according to an embodiment of this application. Figure 3 As shown, the method may include the following steps:
[0053] Step S302: In response to the information verification request from the information service system, the access credentials in the information verification request are verified to obtain the verification result. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located.
[0054] In the technical solution provided in step S304 of this application, the identity source system can receive an information verification request from the information service system. In response to the information verification request, it can verify the access credentials in the information verification request and obtain a verification result. The information verification request can be used to request the identity source system (hereinafter referred to as the identity source) to verify the access credentials. The information verification request can include access credentials used by the client to access the information service system (hereinafter referred to as the information system). The client can be client software, a user's terminal, etc., which are only examples and do not impose specific limitations on the client. The access credentials can be used to represent the client's login information and the trusted execution environment of the device on which the client is located. They can be proof carrying a fingerprint of secret information. The form of the access credentials can be a login password, a token, etc., which are only examples and do not impose specific limitations on the name and form of the access credentials. The login information is used to identify the user's identity. The device on which the client is located can be a specific hardware device, such as a device that supports a trusted execution environment. The trusted execution environment can be a hardware execution environment; in this embodiment, it can be a specific hardware execution environment. The verification result can be used to represent the verification result of whether the access credentials are valid or invalid.
[0055] Optionally, when the identity source system needs to verify access credentials, the information service system can initiate an information verification request to the identity source system to request verification of the access credentials. The identity source system receives the information verification request from the information service system. In response to the information verification request, it can verify the login information and trusted execution environment in the access credentials and obtain the verification result.
[0056] For example, when the identity source system receives an information verification request from the information service system, in response to the information verification request, it can contact the remote authentication service of the identity source system, such as the Trusted Execution Environment (TEE) authentication service, to verify whether the trusted execution environment in the access credentials is valid.
[0057] Step S306: In response to the verification result that the login information and trusted execution environment are valid, a verification pass message is generated, so that the information service system sends access data matching the login information to the client in response to the verification pass message.
[0058] In the technical solution provided in step S306 of this application, the identity source system verifies the access credentials. If the verification result indicates that the login information and the trusted execution environment are valid, a verification pass message is generated. In response to the verification pass message, the information service system sends access data matching the login information to the client. This access data can be data received by the client in the trusted execution environment, or data matching the client's login information. For example, if the login information is "Zhang San," the access data matching the login information could be access data from the group to which "Zhang San" belongs. This is merely an example and does not impose specific restrictions on the access data.
[0059] Optionally, if the identity source system verifies the access credentials and the verification result is valid, the valid verification result can be sent to the information service system so that the information service system can respond to the verification pass message and send access data matching the login information to the client.
[0060] For example, the identity source system verifies the login information and trusted execution environment (TEU) in the access credentials. If the login information and TEU match the verification data, a valid verification result is obtained, which can be returned to the information service system. The information service system can then verify the client's permissions based on the login information. After successful verification, access data matching the login information can be sent to the client. The verification data can be pre-defined; no specific restrictions are placed on its content here.
[0061] In this embodiment, access credentials can be verified. If the access credentials are verified by the remote authentication service, it can be proven that the login information in the access credentials is authentic and valid. Then, the information service system can be controlled to send access data matching the login information to the client.
[0062] In this embodiment of the application, by combining a trusted execution environment and binding the client's login information with the trusted execution environment on the identity source system side, access credentials for accessing the information service system are obtained, thereby providing the information service system with trusted authentication capabilities. Even if an attacker steals the client's access credentials, they will not be able to pass identity authentication in an unbound environment, thus achieving the technical effect of improving the security of information authentication and solving the technical problem of low security of information authentication.
[0063] The method described in this embodiment will be further described below.
[0064] As an optional implementation, the method may further include: in response to an information creation request from a client, creating first key information for login information, wherein the first key information is used to bind with a trusted execution environment, and the bound first key information is used to generate access credentials.
[0065] In this embodiment, the identity source system can receive an information creation request from a client. Upon receiving such a request, the system can create a first key for login information and bind it to a specified environment to generate access credentials. The information creation request can be a user creation request, used to request the creation of the first key for the client's login information. The first key, also known as secret information or a user key, can be generated based on the client's login information and can be random data of a specified length, such as a binary file (0101110) generated from a string of random numbers. It should be noted that this is merely an example and does not impose specific limitations on the content, length, or format of the first key.
[0066] In this embodiment, the identity source system can receive an information creation request from the client. In response to the information creation request, it can create a first key information for login information and bind the login information to a trusted execution environment through the first key information. The bound first key information can be used to generate access credentials, thereby enabling the client to access the information service system on a device that supports a trusted execution environment and obtain access data in the information service system through the access credentials. In this case, even if an attacker steals the access credentials, they cannot use them on other devices, thereby achieving the goal of improving the overall security of the system.
[0067] For example, a client deployed on a device that supports a trusted execution environment initiates an information creation request to the identity source system to request the identity source system to create the first key information for login information. In response to the information creation request, the first key information for login information can be created.
[0068] As an optional implementation, the first key information is returned to the client, wherein the first key information is bound to the trusted execution environment by the client calling the trusted execution environment interface of the device.
[0069] In this embodiment, in response to an information creation request, first key information for login information can be created, and the created first login information can be returned to the client. The client can call the device's Trusted Execution Environment (TEE) interface to seal the first key information returned by the identity source system, thereby achieving the purpose of binding the first key information with the Trusted Execution Environment.
[0070] Optionally, the first key information can be returned to the client. The client can call the device's Trusted Execution Environment (TEE) interface to seal the first key information returned by the identity source system, thereby binding the first key information to the TEE.
[0071] It should be noted that the initialization process of binding login information to the trusted execution environment does not need to be repeated in subsequent uses.
[0072] As an optional implementation, the verification result obtained by the information verification terminal in response to the information verification request and verifying the information creation request; in response to the verification result indicating that the information creation request has been successfully verified, the first key information for creating the login information is allowed in response to the information creation request.
[0073] In this embodiment, an information verification request can be sent to the information verification terminal. The information verification terminal, in response to the request, can verify the information creation request, obtain a verification result, and determine whether the verification result indicates successful verification of the information creation request. If the verification result indicates successful verification, the terminal can allow the creation of the first key information for login information. The information verification terminal can be an administrator, auditor, etc.; this is merely an example and no specific restrictions are imposed on the information verification terminal.
[0074] Optionally, upon receiving an information creation request from a client, the identity source system sends an information verification request to the information verification terminal to notify the administrator to review the information creation request. The information verification terminal responds to the information verification request, verifies the information creation request, and obtains the verification result. If the administrator confirms that the information creation request is correct, and determines that the verification result is successful, the administrator can approve the information creation request and allow the creation of the first key information for login.
[0075] For example, an information verification request can be sent to the information verification end. In the information service system, an information creation request (also known as a user registration request) can be submitted in the form of a form. The information creation request can include client and device information such as the client name, email address, and MAC address of the network interface card (NIC). In response to the information verification request, the administrator can verify the information creation request based on the registration information in the information service system and obtain the verification result. If the verification result is successful, the administrator can approve the creation of the first key information for login; if the verification result is unsuccessful, the administrator can reject the creation of the first key information for login. The registration information can be information provided by the client during registration, and may include the username, device serial number, MAC address, etc. This is only an example and does not impose specific restrictions on the content of the information creation request and registration information.
[0076] As an optional implementation, the verification message includes login information, which is used to enable the information service system to match access data under the access permissions of the login information.
[0077] In this embodiment, in response to receiving an information verification request from the information service system, the access credentials in the information service system can be verified. If the verification result indicates that the login information and trusted execution environment are valid, the created login information can be sent to the information service system. Based on the login information, the information service system can match access data under the access permissions to which the login information belongs. The access permissions to which the login information belongs can be client permissions, also known as user permissions or user-identified execution permissions.
[0078] Optionally, in response to receiving an information verification request from the information service system, the system can verify the access credentials in the information service system. If the verification result indicates that the login information and trusted execution environment are valid, the system can send the created login information to the information service system. Based on the login information, the information service system can match access data under the access permissions belonging to the login information. For example, the login information can be used to match the client's user identity and execution permissions.
[0079] For example, if the matching strategy in the information service system is that the login information is "Zhang San", then the access permissions will only be the data in the test group. If the verification result shows that the login information and the trusted execution environment are valid, the system can send the created login information to the information service system. The information service system can then determine the access data under the access permissions that match the login information based on the pre-set matching strategy, and send the access data under those access permissions to the client.
[0080] In this embodiment, the access credentials collected by the pure software solution lack credibility, making it easy for attackers to forge them and bypass the verification process of the client's access credentials. In this embodiment, by combining the ability of a trusted execution environment to bind specified data to a device (also known as hardware), the client's login information can only be accessed using a specific device. This avoids identity theft caused by stolen access credentials, thereby improving the security of information authentication and solving the technical problem of low information authentication security.
[0081] As an optional implementation, the login information is matched with the signature data in the access credentials. The signature data is a second key information based on the trusted execution environment, which is obtained by digitally signing the first key information bound to the trusted execution environment.
[0082] In this embodiment, the identity source system verifies the access credentials and obtains a verification result. In response to the verification result indicating that the login information and the trusted execution environment (TEU) are valid, it can send login information matching the signature data in the access credentials to the information service system. The signature data can match the login information, can be a fingerprint of secret information, can be a certificate generated by the TEU (also known as a digital signature), or can be obtained by digitally signing the bound first key information based on the second key information of the TEU. The second key information can be a hardware key.
[0083] Optionally, the bound first key information can be digitally signed based on the second key information of the trusted execution environment to obtain signature data. In response to the verification result that the login information and the trusted execution environment are valid, the login information matching the signature data in the access credentials can be sent to the information service system. Based on the login information, the information service system can match the access data under the access permissions of the login information and send the access data to the client.
[0084] In this embodiment, the bound first key information can be signed using the hardware key of the trusted execution environment to obtain signed data. Only after the verification is valid can login information matching the signed data in the access credentials be sent to the information service system. Based on the login information, the information service system can match the access data under the access permissions of the login information, thereby enabling the client to obtain the access data. That is, the bound first key information is signed using the hardware key of the trusted execution environment to obtain signed data. When the access credentials are verified, if the verification result shows that the login information and the trusted execution environment are valid, login information matching the signed data can be sent to the information service system, thereby achieving the purpose of quickly confirming the access data that can be sent to the client. Compared with the method of password or software pulling access data, the accessible key (signature data) has higher security.
[0085] For example, before accessing the information service system, a client can invoke the Trusted Execution Environment (TEE) interface to use a hardware key to perform data signing on specified data (first key information), generating signature data (also known as remote proof). The TEE interface can generate proof carrying the signature data (secret information fingerprint) as access credentials. The information service system can request verification of the access credentials from the identity source system, thus initiating an information verification request. Upon receiving the information verification request from the information service system, the information source system responds by verifying the access credentials and obtaining the verification result. If the verification result indicates that the login information and the TEE are valid, the identity source system can match the client's login information with the signature data carried in the access credentials and send login information matching the signature data in the access credentials to the information service system. The information service system can then verify the client's corresponding permissions based on the login information, and after successful verification, return the access data to the client.
[0086] As an optional implementation, in response to an information verification request from an information service system, the access credentials in the information verification request are verified to obtain a verification result, including: in response to the information verification request, the signature data in the access credentials is verified to obtain a verification result, wherein the signature data is obtained by digitally signing the first key information based on the second key information.
[0087] In this embodiment, when an information verification request is received from the information service system, the signature data in the access credentials can be verified in response to the information verification request to obtain the verification result.
[0088] Optionally, upon receiving an information verification request, in response to the information verification request, partial verification of the access credentials can be performed. That is, the signature data in the access credentials can be verified. If the signature data matches the verification data, a verification result indicating that the login information and the trusted execution environment are valid is obtained. If the signature data does not match the verification data, a verification result indicating that the login information and the trusted execution environment are invalid is obtained.
[0089] In this embodiment, the first key is sealed in a trusted execution environment through digital signature. Devices using the trusted execution environment do not need to log in to the information service system through client passwords or other means, thereby enabling passwordless management and improving the convenience and security of data use.
[0090] As an optional implementation, step S304, in response to an information verification request from an information service system, verifies the access credentials in the information verification request to obtain a verification result, including: sending an information verification request to a third-party server corresponding to the trusted execution environment interface of the device; and obtaining the verification result obtained by the third-party server in response to the information verification request and verifying the access credentials.
[0091] In this embodiment, in response to an information verification request, an information verification request can be sent to a third-party server corresponding to the trusted execution environment interface of the device. The third-party server responds to the information verification request, verifies the access credentials, and obtains the verification result. The identity source system can obtain the verification result. The third-party server can be a trusted execution environment authentication service.
[0092] For example, an information service system can initiate an information verification request to request verification of access credentials from an identity source system. In response, the identity source system can send the verification request to the remote authentication service corresponding to the trusted execution environment interface of the device to verify the validity of the access credentials. The third-party server verifies the access credentials and obtains the verification result. The identity source system can then retrieve the verification result.
[0093] In this embodiment, a trusted execution environment (TEU) is utilized to acquire the ability to bind access credentials to a device. When the bound access credentials are removed from the specified hardware execution environment (TEU), even devices of the same model cannot correctly obtain access data. Simultaneously, the TEU possesses remote authentication capabilities; that is, a third-party server of the TEU (hereinafter referred to as a third-party service) can verify the signature data generated by a specific TEU. The verification result proves whether the verified party is a legitimate TEU. Therefore, even if an attacker steals the client's access credentials, they cannot pass verification in an unbound environment, thereby improving the security of information authentication and solving the technical problem of low information authentication security.
[0094] In this embodiment, by combining a trusted execution environment and binding the client's login information with the trusted execution environment on the identity source system side, access credentials for accessing the information service system are obtained, thereby providing the information service system with trusted authentication capabilities. Even if an attacker steals the client's access credentials, they will not be able to pass identity authentication in an unbound environment, thus achieving the technical effect of improving the security of information authentication and solving the technical problem of low security in information authentication.
[0095] This application also provides a data access method from the perspective of the information service system. Figure 4 This is a flowchart of a data access method according to an embodiment of this application, such as... Figure 4 As shown, the method may include the following steps.
[0096] Step S402: Send an information verification request to the identity source system. The information verification request includes access credentials for enabling the client to access the system. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located.
[0097] In the technical solution provided by step S402 of this application, the information service system can initiate an information verification request to the identity source system.
[0098] Step S404: When the identity source system responds to the information verification request and verifies that the login information and trusted execution environment are valid, it sends access data matching the login information to the client.
[0099] In the technical solution provided in step S404 of this application, the identity source system obtains an information verification request. In response to the request, it verifies the login information and the trusted execution environment. If both are valid, it returns the login information. The information service system obtains the login information and sends access data matching the login information to the client. The client receives the access data within the trusted execution environment.
[0100] Through steps S402 to S404 of this application, an information verification request is sent to the identity source system. The information verification request includes access credentials for enabling the client to access the system. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located. When the identity source system responds to the information verification request and verifies that the login information and trusted execution environment are valid, it sends access data matching the login information to the client. This achieves the technical effect of improving the security of information authentication and solves the technical problem of low security in information authentication.
[0101] As an optional implementation, step S404 involves sending access data matching the login information to the client, including: determining the access permissions to which the login information belongs; and sending access data under the access permissions to the client.
[0102] In this embodiment, the identity source system can obtain an information verification request. In response to the information verification request, it can verify the login information and the trusted execution environment. If the login information and the trusted execution environment are verified to be valid, the system returns the login information. The information service system can obtain the login information, determine the access permissions to which the login information belongs, and send the access data under the access permissions to the client.
[0103] As an optional implementation, access credentials from a client are received, wherein the access credentials are generated by the client requesting the device's Trusted Execution Environment interface.
[0104] In this embodiment, the access credentials may be generated by the client requesting the device's trusted execution environment.
[0105] Optionally, the client requests the creation of login information from the identity source system. In response to the information creation request from the client, the identity source system creates first key information for the client. The client can call the interface of the trusted service system to seal the first key information and obtain access credentials. When the identity source system responds to the information verification request, it can verify the access credentials generated by the client requesting the trusted execution environment interface of the device and obtain the verification result.
[0106] In this embodiment, an information verification request is sent to an identity source system. The information verification request includes access credentials for enabling the client to access the system. These access credentials represent the client's login information and the trusted execution environment of the device on which the client is located. The system then obtains login information returned by the identity source system in response to the information verification request, provided that the login information and the trusted execution environment are valid. Finally, access data matching the login information is sent to the client. This access data is received by the client within the trusted execution environment. This approach improves the security of information authentication and solves the problem of low security in information authentication.
[0107] This application also provides another data access method from the client side. Figure 5 This is a flowchart of another data access method according to an embodiment of this application, such as... Figure 5 As shown, the method may include the following steps.
[0108] Step S502: Send access credentials to the information service system. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located. The information verification request, including the access credentials, is sent by the information service system to the identity source system.
[0109] In the technical solution provided in step S502 of this application, the client can send access credentials to the information service system. These access credentials can be used to represent the client's login information and the trusted execution environment of the device on which the client is located.
[0110] Optionally, the information verification request, including access credentials, can be sent from the information service system to the identity source system for further verification.
[0111] Step S504: When the identity source system responds to the information verification request and verifies that the login information and trusted execution environment are valid, it receives access data from the information service system that matches the login information.
[0112] In the technical solution provided in step S504 of this application, the identity source system obtains an information verification request. In response to the request, it verifies the login information and the trusted execution environment. If both are valid, it returns the login information. The information service system obtains the login information and sends access data matching the login information to the client. The client receives the access data within the trusted execution environment.
[0113] Through steps S502 to S504 of this application, access credentials are sent to the information service system. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located. The information service system sends an information verification request for the access credentials to the identity source system. When the identity source system responds to the information verification request and verifies that the login information and trusted execution environment are valid, it receives access data from the information service system that matches the login information. This achieves the technical effect of improving the security of information authentication and solves the technical problem of low security in information authentication.
[0114] Example 2
[0115] According to an embodiment of this application, an embodiment of a data access system is also provided. Figure 6 This is a schematic diagram of a data access system according to an embodiment of this application, such as... Figure 6 As shown, the information authentication system 600 may include: a client 602, an information service system 604, and an identity source system 606.
[0116] Client 602 is used to obtain access credentials, which are used to identify the client's login information and the trusted execution environment of the device on which the client is located.
[0117] In this embodiment, the client can be used to obtain access credentials. Based on these credentials, the client can access the information service system, and the credentials can be used to characterize the client's login information and the trusted execution environment of the device on which the client is located. The client can be deployed on a device that supports a trusted execution environment, and can be a user, a software application, etc.; this is merely an example and no specific limitation is made on the client type.
[0118] Information service system 604 is used to send an information verification request, including access credentials, to the identity source system.
[0119] Identity source system 606 is used to verify access credentials in response to information verification requests, obtain verification results, and generate a verification pass message in response to the verification results indicating that the login information and trusted execution environment are valid.
[0120] Among them, the information service system 604 is used to send access data matching the login information to the client in response to the verification success message.
[0121] In this embodiment, the identity source system 606 can obtain an information verification request, and in response to the information verification request, verify the access credentials and obtain a verification result. In response to the verification result that the login information and trusted execution environment are valid, a verification pass message can be generated.
[0122] Optionally, the identity source system 606 can be used to issue identity-based access credentials to client 602 for accessing information service system 604. In response to an information verification request, the identity source system 606 can verify the access credentials and obtain a verification result. Information service system 604 can use the access credentials and request the identity source system 606 to verify them, thereby determining the access permissions of client 602 and sending access data matching the login information to client 602.
[0123] In this embodiment, the client 602 can be deployed in a trusted execution environment and can receive access data in the trusted execution environment.
[0124] As an optional embodiment, client 602 is used to send an information creation request to identity source system 606; identity source system 606 is used to respond to the information creation request and create first key information for login information; wherein, client 602 is used to call the trusted execution environment interface of the device to bind the first key information with the trusted execution environment, and the bound first key information is used to generate access credentials.
[0125] In this embodiment, client 602 can send an information creation request to identity source system 606. In response to the information creation request, identity source system 606 creates first key information for login information and can return the first key information to the client. Client 602 calls the device's Trusted Execution Environment (TEE) interface to bind the first key information to the TEE, and generates access credentials based on the bound first key information. When identity source system 606 receives an information verification request from information service system 604, it can obtain the access credentials generated by client 602, verify the access credentials, and obtain a verification result. In response to the verification result indicating that the login information and TEE are valid, identity source system 606 can control information service system 604 to send access data matching the login information to client 602.
[0126] As an optional embodiment, client 602 is used to request and invoke the trusted execution environment interface of the device, and digitally sign the bound first key information based on the second key information of the trusted execution environment to obtain access credentials.
[0127] In this embodiment, the client 602 can request to call the device's Trusted Execution Environment (TEE) interface, and digitally sign the bound first key information based on the second key information of the TEE to obtain access credentials.
[0128] In this embodiment, an information authentication system is provided. The system obtains access credentials through a client 602; sends an information verification request, including the access credentials, to an identity source system 606 through an information service system 604; and, in response to the information verification request, the identity source system 606 verifies the access credentials, obtains a verification result, and, in response to the verification result indicating that the login information and trusted execution environment are valid, sends login information to the information service system 604. This achieves the technical effect of improving the security of information authentication and solves the technical problem of low security in information authentication.
[0129] Example 3
[0130] Currently, client login information (identity) is a core element in ensuring system data security within the secure access service boundary system, and protecting identity security is the foundation of overall system security.
[0131] In one alternative instance, identity verification is typically collected and generated by client software. However, access credentials generated by client software are easily forged, allowing attackers to bypass identity-based authentication and compromise the information service system. For example, after stealing a client's access credentials, an attacker can remotely impersonate the client. Even if the device information of the client's device is linked to the identity, this information is easily forged because it is collected by ordinary software, making it difficult for the authentication process to distinguish whether the access credentials come from the genuine client or the attacker.
[0132] In another alternative example, login information from the information service system can be bound to device information collected by software, such as network card addresses (e.g., MAC addresses), CPU serial numbers, and operating system versions collected by the client. During the authentication phase, the system can determine whether there is any risky access by comparing the device information. However, attackers can forge device information remotely to deceive the authentication process and thus launch attacks. Therefore, the technical problem of low security in information authentication still exists.
[0133] This application proposes a method for binding login information to a specific hardware execution environment by combining trusted execution environment technology and identity source services. This method can provide trusted authentication capabilities for common information service systems and defend against attacks such as credential theft. Through this method, access credentials cannot be used in an unbound environment, preventing attackers from passing authentication even if they steal the client's access credentials. This effectively prevents attackers from intruding into information data systems and greatly improves system security.
[0134] Through the embodiments of this application, the first key information can be sealed within a trusted execution environment. Using this method, there is no need to log in to the system through user passwords or other means, thus achieving passwordless management, making the process more convenient and secure. Combined with desktop instances of Elastic Compute Service (ECS) cloud servers, the above method enables cloud computers to have a hardware root of trust, providing higher security in credential management.
[0135] In this embodiment, data (e.g., login information) can be bound to a hardware execution environment (e.g., a trusted execution environment). When the bound data is removed from the specified hardware execution environment, even hardware of the same model cannot correctly restore the data. Simultaneously, the trusted execution environment technology possesses remote authentication capabilities, meaning a trusted third-party service can verify access credentials (also known as proof) generated by a specific trusted execution environment. The verification result proves whether the verified party is a legitimate trusted execution environment, thereby improving the security of information authentication and solving the technical problem of low information authentication security.
[0136] Figure 7 This is a flowchart of an enhanced identity authentication method according to an embodiment of this application, such as... Figure 7 As shown, the identity authentication method may involve the data transmission process between the management terminal 71, the TEE 73 and client 74 in the TEE-supporting device 72, the identity source 75, the information service system 76, and the TEE authentication service 77. The identity authentication method may include the following steps.
[0137] Step S701: Create login information for client 74.
[0138] In this embodiment, the software of client 74, deployed on a device that supports a trusted execution environment, initiates an identity creation request to identity source 75, requesting identity source 75 to create login information.
[0139] In step S702, identity source 75 responds to the identity creation request and creates secret information.
[0140] In this embodiment, the identity source 75 responds to an identity creation request (which may be an information creation request) and creates secret information for the identity. The secret information may be a random data segment of a specified length, such as binary data generated from a string of random numbers, and may be used as a key.
[0141] In step S703, the client 74 seals the secret information.
[0142] In this embodiment, client 74 can call the interface of the trusted execution environment to seal the secret information returned by the identity source, thereby binding the secret information to the specified device of the identity creation request initiated by client 74.
[0143] In step S704, the identity source 75 notifies the management terminal 71 to verify the identity creation request of the client 74.
[0144] In this embodiment, the identity source 75 responds to the identity creation information, creates secret information for the identity, and notifies the management terminal 71 (which can be an administrator) to review the identity creation request.
[0145] Optionally, the information system can submit a client registration request in the form of a form. The client registration request can include client and device information such as username, email, and network card media access control location address. After the administrator verifies the registration information in the information system, he / she approves or rejects the request, thereby completing the review of the identity creation request.
[0146] In step S705, after the management terminal 71 confirms that the identity creation request is correct, it approves the identity creation request.
[0147] In this embodiment, after the management terminal 71 confirms that the identity creation request is correct, it approves the identity creation request.
[0148] Optionally, the management terminal 71 determines the identity creation request based on the information provided by the client 74 during registration, such as username, device serial number, network card address, etc. Once the management terminal 71 confirms that the identity creation request is correct, it can approve the identity creation request and send the approval request to the identity source 75.
[0149] It should be noted that steps S701 to S705 are the initialization process for binding the login information with the trusted execution environment of the device specified by the client 74, and there is no need to repeat them in subsequent use.
[0150] In step S706, client 74 requests the generation of proof before accessing information service system 76.
[0151] In this embodiment, before accessing the information service system 76, the client 74 can call the Trusted Execution Environment (TEE) interface to request the generation of a certificate. This certificate can be a certificate carrying a fingerprint of secret information, also known as a remote certificate or a TEE certificate, and can be signature data generated by performing a digital signature on specified data (carrying a fingerprint of secret information) using a device key via the TEE interface.
[0152] Step S707: Use the proof carrying the fingerprint of the secret information as the access credential.
[0153] In this embodiment, the proof carrying the secret information fingerprint generated by the TEE can be used as an access credential and sent to the client 74.
[0154] Step S708, Client 74 accesses Information Service System 76.
[0155] In this embodiment, the client 74 obtains a proof carrying a fingerprint of secret information generated by the TEE, and can use the proof carrying the TEE as an access credential to access the information service system 76.
[0156] Step S709, Identity Source 75 verifies access credentials.
[0157] In this embodiment, the client 74 accesses the information service system 76 through access credentials. The information service system 76 can then send the access credentials to the identity source 75, so that the information system 76 can request the identity source 75 to verify the access credentials.
[0158] Step S710: Verify the validity of the access credentials.
[0159] In this embodiment, the identity source 75 can verify the login information and trusted execution environment in the access credentials with a remote authentication service (e.g., TEE authentication service 77) to prove their validity.
[0160] Step S711: Obtain the verification result.
[0161] In this embodiment, if the verification result of the remote authentication service is valid, the identity source 75 can match the client's identity based on the secret information fingerprint it carries and return it to the information service system.
[0162] Optionally, the remote verification service verifies the digital signature portion of the verification. If the signature data matches the verified data, the verification result is valid; otherwise, the verification result is invalid, and the verification result can be sent to the identity source 75.
[0163] In step S712, the information service system 76 verifies the client 74's permissions based on the login information.
[0164] In this embodiment, the information service system 76 can verify the corresponding permissions of the client 74 based on the login information, and can return the access data to the client 74 after the verification is successful.
[0165] Optionally, if the access credentials are verified through remote authentication, the login information carried in the access credentials can be considered genuine and valid. In this case, the information service system 76 can match the login information with the execution permissions according to the matching strategy.
[0166] Step S713: Send the access data to the client 74.
[0167] In this embodiment, after successful verification, access data can be sent from the information service system to the client 74.
[0168] Because data collected purely by software lacks credibility, attackers can easily forge it to bypass the authentication process. This application's embodiment utilizes the ability of a TEE (Trusted Equipment) to bind specified data to hardware, ensuring that user authentication data can only be accessed via a specific device, thus preventing identity theft due to stolen user credentials. Furthermore, through this method, the user key is sealed within the TEE, eliminating the need for password-free login and improving convenience and security.
[0169] In this embodiment of the application, the user identity is bound to a specific hardware device, so that the current user can only access the information system normally on that device. Even if an attacker steals the user's credentials, such as the login password, they cannot use them on other devices or environments, thereby achieving the technical effect of improving the security of information authentication and solving the technical problem of low security of information authentication.
[0170] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0171] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.
[0172] Example 4
[0173] According to embodiments of this application, a method for implementing the above is also provided. Figure 3 The information authentication device shown is an information authentication method.
[0174] Figure 8 This is a schematic diagram of an information authentication device according to an embodiment of this application, such as... Figure 8 As shown, the information authentication device 800 may include a verification unit 802 and a generation unit 804.
[0175] The verification unit 802 is used to respond to an information verification request from the information service system, verify the access credentials in the information verification request, and obtain a verification result. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located.
[0176] The generation unit 804 is used to generate a verification pass message in response to the verification result indicating that the login information and trusted execution environment are valid, so that the information service system can send access data matching the login information to the client in response to the verification pass message.
[0177] It should be noted that the verification unit 802 and the generation unit 804 mentioned above correspond to steps S302 to S304 in Embodiment 1. The two units and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above units can be hardware components or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above units can also be part of the device and run in the computer terminal 10 provided in Embodiment 1.
[0178] According to embodiments of this application, a method for implementing the above is also provided. Figure 4 The data access device for the data access method shown.
[0179] Figure 9 This is a schematic diagram of a data access device according to an embodiment of this application, such as... Figure 9 As shown, the information authentication device 900 may include: a first sending unit 902 and a second sending unit 904.
[0180] The first sending unit 902 is used to send an information verification request to the identity source system. The information verification request includes access credentials for enabling the client to access the system. The access credentials are used to characterize the client's login information and the trusted execution environment of the device where the client is located.
[0181] The second sending unit 904 is used to send access data matching the login information to the client when the identity source system responds to the information verification request and verifies that the login information and trusted execution environment are valid.
[0182] It should be noted that the first transmitting unit 902 and the second transmitting unit 904 mentioned above correspond to steps S402 to S404 in Embodiment 1. The two units and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the above units can be hardware components or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above units can also be part of the device and run in the computer terminal 10 provided in Embodiment 1.
[0183] According to an embodiment of this application, another method for implementing the above is also provided. Figure 5 The data access device for the data access method shown.
[0184] Figure 10 This is a schematic diagram of another data access device according to an embodiment of this application, such as... Figure 10 As shown, the information authentication device 1000 may include a third sending unit 1002 and a receiving unit 1004.
[0185] The third sending unit 1002 is used to send access credentials to the information service system. The access credentials are used to represent the client's login information and the trusted execution environment of the device where the client is located. The information verification request, including the access credentials, is sent by the information service system to the identity source system.
[0186] The receiving unit 1004 is used to receive access data from the information service system that matches the login information when the identity source system responds to the information verification request and verifies that the login information and the trusted execution environment are valid.
[0187] It should be noted that the aforementioned third transmitting unit 1002 and receiving unit 1004 correspond to steps S502 to S504 in Embodiment 1. The two units and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should be noted that the aforementioned units may be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The aforementioned units may also be part of a device and run in the computer terminal 10 provided in Embodiment 1.
[0188] In the aforementioned device, the client's login information is bound to the trusted execution environment to obtain access credentials for accessing the information service system. This provides the information service system with trusted authentication capabilities, preventing attackers from passing authentication in an unbound environment even if they steal the client's access credentials. This achieves the technical effect of improving the security of information authentication and solves the technical problem of low security in information authentication.
[0189] Example 5
[0190] Embodiments of this application may provide a computer terminal, which may be any computer terminal device in a group of computer terminals. Optionally, in this embodiment, the aforementioned computer terminal may also be replaced by a mobile terminal or other terminal device.
[0191] Optionally, in this embodiment, the computer terminal may be located in at least one of a plurality of network devices in a computer network.
[0192] In this embodiment, the computer terminal can execute the program code for the following steps in the information authentication method: in response to an information verification request from the information service system, verifying the access credentials in the information verification request to obtain a verification result, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device where the client is located; in response to the verification result that the login information and the trusted execution environment are valid, generating a verification pass message, so that the information service system sends access data matching the login information to the client in response to the verification pass message.
[0193] Optionally, Figure 11 This is a structural block diagram of a computer terminal according to an embodiment of this application. Figure 11 As shown, the computer terminal A may include one or more (only one is shown in the figure) processors 1102, memory 1104, and transmission devices 1106.
[0194] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the information authentication method and apparatus in this application embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned information authentication method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to computer terminal A via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0195] The processor can invoke information and applications stored in memory via a transmission device to perform the following steps: in response to an information verification request from an information service system, verify the access credentials in the information verification request to obtain a verification result, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client is located; in response to the verification result that the login information and the trusted execution environment are valid, generate a verification pass message so that the information service system sends access data matching the login information to the client in response to the verification pass message.
[0196] Optionally, the processor may also execute program code that performs the following steps: in response to an information creation request from a client, creates first key information for login information, wherein the first key information is used to bind to a trusted execution environment, and the bound first key information is used to generate access credentials.
[0197] Optionally, the processor may also execute program code that returns the first key information to the client, wherein the first key information is bound to the trusted execution environment by the client calling the trusted execution environment interface of the device.
[0198] Optionally, the processor may also execute program code that performs the following steps: obtains the verification result obtained by the information verification terminal responding to the information verification request and verifying the information creation request; in response to the verification result indicating that the information creation request has been successfully verified, allows the creation of the first key information of the login information in response to the information creation request.
[0199] Optionally, the processor may also execute program code that performs the following steps: the verification message includes login information, which is used to enable the information service system to match access data under the access permissions of the login information.
[0200] Optionally, the processor may also execute program code that performs the following steps: matching login information with signature data in access credentials, the signature data being second key information based on a trusted execution environment, and digitally signing the first key information bound to the trusted execution environment.
[0201] Optionally, the processor may also execute program code that performs the following steps: in response to an information verification request from an information service system, verifying the access credentials in the information verification request and obtaining a verification result, including: in response to the information verification request, verifying the signature data in the access credentials and obtaining a verification result, wherein the signature data is obtained by digitally signing the first key information based on the second key information.
[0202] Optionally, the processor may also execute program code that performs the following steps: sending an information verification request to a third-party server corresponding to the trusted execution environment interface of the device; obtaining the third-party server's response to the information verification request, verifying the access credentials, and obtaining the verification result.
[0203] The processor can invoke information and applications stored in memory via a transmission device to perform the following steps: sending an information verification request to the identity source system, wherein the information verification request includes access credentials for enabling the client to access the system, the access credentials being used to characterize the client's login information and the trusted execution environment of the device in which the client is located; and, in response to the information verification request, if the identity source system verifies that the login information and the trusted execution environment are valid, sending access data matching the login information to the client.
[0204] Optionally, the processor may also execute program code that performs the following steps: determines the access permissions to which the login information belongs; and sends access data under the access permissions to the client.
[0205] Optionally, the processor may also execute program code that receives access credentials from a client, wherein the access credentials are generated by the client requesting the trusted execution environment interface of the device.
[0206] The processor can invoke information and applications stored in memory via a transmission device to perform the following steps: sending access credentials to the information service system, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client is located, including an information verification request for the access credentials sent by the information service system to the identity source system; and receiving access data from the information service system that matches the login information if the identity source system responds to the information verification request and verifies that the login information and trusted execution environment are valid.
[0207] This application provides an information authentication method. By binding the client's login information to a trusted execution environment, access credentials for accessing the information service system are obtained. This provides the information service system with trusted authentication capabilities, preventing attackers from passing authentication in an unbound environment even if they steal the client's access credentials. This effectively improves the security of information authentication and solves the technical problem of low information authentication security.
[0208] Those skilled in the art will understand that Figure 11 The structure shown is for illustrative purposes only. Computer terminal A can also be a smartphone (such as an Android phone, iOS phone, etc.), tablet computer, handheld computer, mobile internet device (MID), PAD and other terminal devices. Figure 11This does not limit the structure of the aforementioned computer terminal A. For example, computer terminal A may also include components that are more complex than those described above. Figure 11 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 11 The different configurations shown.
[0209] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0210] Example 6
[0211] Embodiments of this application also provide a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium can be used to store the program code executed by the information authentication method provided in the above embodiments.
[0212] Optionally, in this embodiment, the computer-readable storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0213] Optionally, in this embodiment, the computer-readable storage medium is configured to store information stored in the memory and program code executed by the application program that can be invoked by the processor via a transmission device.
[0214] In this embodiment, the client's login information is bound to a trusted execution environment to obtain access credentials for accessing the information service system, thereby providing the information service system with trusted authentication capabilities. Even if an attacker steals the client's access credentials, they will not be able to pass authentication in an unbound environment, thus achieving the technical effect of improving the security of information authentication and solving the technical problem of low security in information authentication.
[0215] Example 7
[0216] Embodiments of this application may provide an electronic device that may include a memory and a processor.
[0217] Figure 12This is a block diagram of an electronic device according to an embodiment of the information authentication method of this application. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present application described and / or claimed herein.
[0218] like Figure 12 As shown, device 1200 includes a computing unit 1201, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 1202 or a computer program loaded from storage unit 1208 into random access memory (RAM) 1203. RAM 1203 may also store various programs and data required for the operation of device 1200. The computing unit 1201, ROM 1202, and RAM 1203 are interconnected via bus 1204. Input / output (I / O) interface 1205 is also connected to bus 1204.
[0219] Multiple components in device 1200 are connected to I / O interface 1205, including: input unit 1206, such as keyboard, mouse, etc.; output unit 1207, such as various types of monitors, speakers, etc.; storage unit 1208, such as disk, optical disk, etc.; and communication unit 1209, such as network card, modem, wireless transceiver, etc. Communication unit 1209 allows device 1200 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0220] The computing unit 1201 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1201 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1201 performs the various methods and processes described above, such as information authentication methods. For example, in some embodiments, the information authentication method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 1208. In some embodiments, part or all of the computer program may be loaded and / or installed on device 1200 via ROM 1202 and / or communication unit 1209. When the computer program is loaded into RAM 1203 and executed by the computing unit 1201, one or more steps of the information authentication method described above may be performed. Alternatively, in other embodiments, the computing unit 1201 may be configured to perform an information authentication method by any other suitable means (e.g., by means of firmware).
[0221] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard parts (ASSPs), systems-on-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0222] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0223] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0224] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or liquid crystal display, a monitor, etc.); and a keyboard and pointing device (e.g., a mouse or a pathball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0225] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0226] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0227] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0228] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0229] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection of units or modules may be electrical or other forms.
[0230] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0231] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0232] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory, random access memory, portable hard drive, magnetic disk, or optical disk.
[0233] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. An information authentication method, characterized in that, include: In response to an information verification request from an information service system, the access credentials in the information verification request are verified to obtain a verification result, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client is located; In response to the verification result indicating that the login information and the trusted execution environment are valid, a verification pass message is generated, so that the information service system sends access data matching the login information to the client in response to the verification pass message; The verification of the access credentials in the information verification request to obtain a verification result includes: verifying the signature data of the access credentials in the information verification request through a remote authentication service to obtain the verification result; The login information is matched with the signature data in the access credentials. The signature data is obtained by digitally signing the first key information bound to the trusted execution environment based on the second key information of the trusted execution environment. The first key information is created based on the login information.
2. The method according to claim 1, characterized in that, The method further includes: In response to an information creation request from the client, first key information for the login information is created, wherein the first key information is used to bind with the trusted execution environment, and the bound first key information is used to generate the access credentials.
3. The method according to claim 2, characterized in that, The method further includes: The first key information is returned to the client, wherein the first key information is bound to the trusted execution environment by the client calling the trusted execution environment interface of the device.
4. The method according to claim 2, characterized in that, The method further includes: Send an information verification request to the information verification terminal; The verification result is obtained by verifying the information creation request in response to the information verification request from the information verification terminal. In response to the verification result indicating that the information creation request has been successfully verified, the first key information for creating the login information is allowed to be created in response to the information creation request.
5. The method according to claim 1, characterized in that, The verification pass message includes the login information, which is used to enable the information service system to match the access data under the access permissions of the login information.
6. The method according to claim 1, characterized in that, In response to an information verification request from an information service system, the access credentials in the information verification request are verified to obtain a verification result, including: Send the information verification request to the third-party server corresponding to the trusted execution environment interface of the device; The verification result is obtained by obtaining the information verification request response from the third-party server, verifying the access credentials.
7. A data access method, characterized in that, include: Send an information verification request to the identity source system, wherein the information verification request includes access credentials for enabling the client to access the system, the access credentials being used to characterize the client's login information and the trusted execution environment of the device on which the client is located; In response to the information verification request, if the identity source system verifies that the login information and the trusted execution environment are valid, it sends access data matching the login information to the client. The identity source system verifies the signature data of the access credentials through a remote authentication service to determine whether the login information and the trusted execution environment are valid. The login information is matched with the signature data in the access credentials. The signature data is obtained by digitally signing the first key information bound to the trusted execution environment based on the second key information of the trusted execution environment. The first key information is created based on the login information.
8. The method according to claim 7, characterized in that, Sending access data matching the login information to the client includes: Determine the access permissions to which the login information belongs; Send the access data under the access permissions to the client.
9. The method according to claim 7, characterized in that, The method further includes: The access credentials are received from the client, wherein the access credentials are generated by the client requesting the Trusted Execution Environment (TEE) interface of the device.
10. A data access method, characterized in that, include: Sending access credentials to the information service system, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device where the client is located, and the information verification request including the access credentials is sent by the information service system to the identity source system; When the identity source system responds to the information verification request and verifies that the login information and the trusted execution environment are valid, it receives access data from the information service system that matches the login information. The identity source system verifies the signature data of the access credentials through a remote authentication service to determine whether the login information and the trusted execution environment are valid. The login information is matched with the signature data in the access credentials. The signature data is obtained by digitally signing the first key information bound to the trusted execution environment based on the second key information of the trusted execution environment. The first key information is created based on the login information.
11. A data access system, characterized in that, include: Client, information service system and identity source system, among which, The client is used to obtain access credentials, wherein the access credentials are used to characterize the client's login information and the trusted execution environment of the device on which the client is located; The information service system is used to send an information verification request, including the access credentials, to the identity source system; The identity source system is used to verify the access credentials in response to the information verification request, obtain a verification result, and generate a verification pass message in response to the verification result that the login information and the trusted execution environment are valid. The information service system is used to send access data matching the login information to the client in response to the verification pass message; The identity source system is used to verify the access credentials through the following steps to obtain a verification result: verifying the signature data of the access credentials through a remote authentication service to obtain the verification result; The login information is matched with the signature data in the access credentials. The signature data is obtained by digitally signing the first key information bound to the trusted execution environment based on the second key information of the trusted execution environment. The first key information is created based on the login information.
12. The system according to claim 11, characterized in that, The client is used to send an information creation request to the identity source system; The identity source system is used to create the first key information of the login information in response to the information creation request; The client is used to call the trusted execution environment interface of the device to bind the first key information with the trusted execution environment, and the bound first key information is used to generate the access credentials.
13. The system according to claim 12, characterized in that, The client is used to request and invoke the trusted execution environment interface of the device, and digitally sign the bound first key information based on the second key information of the trusted execution environment to obtain the access credentials.
14. An electronic device, characterized in that, include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 10.