Security authentication method, device, apparatus and storage medium
Patent Information
- Application Number
- CN202211393884.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-08
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-11-08
AI Technical Summary
可见,相关技术仅公开了基于加密算法进行安全认证,但却未涉及到对业务、终端和服务器的安全认证等多因素认证的技术方案
[0017]本申请实施例提供的安全认证方法、装置、设备及存储介质,首先基于业务请求中的业务数据以及获取的安全认证网关的网关信息和终端的设备信息进行加密处理,得到加密后的业务数据、加密后的设备信息和加密后的网关信息,然后,基于该加密后的业务数据、加密后的设备信息和加密后的网关信息,对终端进行身份认证,得到身份认证结果,最后,响应于该身份认证结果,以使得实现终端和服务器之间的业务交互。如此,本申请实施例先对终端的业务数据、设备信息和终端与服务器之间的安全认证网关的网关信息进行加密,并通过安全认证网关对加密数据进行解密后进一步地完成终端的身份认证过程。在终端进行身份认证通过后,解决了单因素身份认证方法安全性较差的问题,提高了终端身份认证的安全性和可靠性,实现终端与服务器之间的业务交互,提高业务交互的安全防护能力。
Smart Images

Figure CN116961966B_ABST
Abstract
Claims
1. A security authentication method, characterized in that, Applied to a security authentication gateway, the security authentication gateway including: an end-side gateway, an access gateway, and a security control gateway, the method includes: The receiving terminal sends a service request, which includes service data; In response to the service request, obtain the gateway information of the security authentication gateway and the device information of the terminal; The service data, device information, and gateway information are encrypted using a preset encryption algorithm through the terminal gateway to obtain encrypted service data, encrypted device information, and encrypted gateway information. The access gateway obtains the preset decryption algorithm corresponding to the preset encryption algorithm. Obtain the encrypted business data and the encrypted device information; The encrypted business data and the encrypted device information are decrypted using the preset decryption algorithm to obtain the decrypted business data and the decrypted device information respectively. The decrypted business data and the decrypted device information are sent to the security control gateway. The security control gateway performs identity authentication on the terminal based on the decrypted business data and the decrypted device information to obtain the identity authentication result. In response to the authentication result being successful, the business data is sent to the server.
2. The method according to claim 1, characterized in that, The step of authenticating the terminal through the security control gateway, based on the decrypted business data and the decrypted device information, to obtain the authentication result includes: Obtain the policy identifier of the access control policy corresponding to the security control gateway; The security control gateway invokes the policy engine corresponding to the policy identifier, and performs identity authentication on the terminal based on the decrypted business data and the decrypted device information to obtain the identity authentication result.
3. The method according to claim 1, characterized in that, The method further includes: After the access gateway receives the encrypted gateway information, it uses the preset decryption algorithm to decrypt the encrypted gateway information to obtain the decrypted gateway information. Based on the decrypted gateway information, gateway authentication is performed on the end-side gateway; Correspondingly, when the gateway authentication is successful, the decrypted business data and the decrypted device information are sent to the security control gateway.
4. The method according to claim 2, characterized in that, The method further includes: Acquire operation timing data, which includes at least one timing data related to user operation collected by the terminal within a preset historical time period; Determine the data state of the operation timing data under at least one specific function; Based on the data state, a target model matching the data state is selected from a preset model library; The access policy corresponding to the target model is determined as the access control policy corresponding to the security control gateway.
5. The method according to claim 2, characterized in that, The method further includes: While the security control gateway authenticates the terminal, it also obtains risk assessment information. The risk assessment information is transformed into decision-making reference information to form decision parameter information; Based on the decision parameter information, risk assessments are performed on the terminal, the end-side gateway and access gateway in the security authentication gateway, and the service request, respectively, to obtain risk assessment results; Correspondingly, when the risk assessment result is "risk assessment passed" and the identity authentication result is "authentication passed", the business data is sent to the server.
6. A security authentication device, characterized in that, The device includes: The receiving module is used to receive service requests sent by the terminal, wherein the service requests include service data; The acquisition module is used to acquire the gateway information of the security authentication gateway and the device information of the terminal; the security authentication gateway includes: an end-side gateway, an access gateway, and a security control gateway; The encryption module is used to encrypt the service data, the device information, and the gateway information through the terminal gateway using a preset encryption algorithm, so as to obtain encrypted service data, encrypted device information, and encrypted gateway information. The authentication module is configured to: obtain a preset decryption algorithm corresponding to the preset encryption algorithm through the access gateway; obtain the encrypted service data and the encrypted device information; use the preset decryption algorithm to decrypt the encrypted service data and the encrypted device information respectively, thereby obtaining the decrypted service data and the decrypted device information; send the decrypted service data and the decrypted device information to the security control gateway; and, through the security control gateway, perform identity authentication on the terminal based on the decrypted service data and the decrypted device information to obtain the identity authentication result. The sending module is used to send the business data to the server in response to the authentication result being successful.
7. A security authentication device, characterized in that, include: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the security authentication method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The device stores executable instructions for causing a processor to execute the executable instructions to implement the security authentication method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Sign-on method and sign-on management system for service information system
CN102420836A
Safe authentication method and safe authentication system
CN104683296A