Network service security authentication method, system, device and computer equipment
Through the UAF authentication protocol and trust evaluation model, the authentication process is dynamically adjusted, which solves the problem of not being able to deal with dynamic security risks in existing network services, realizes more reliable and flexible identity verification, and improves system security.
Patent Information
- Application Number
- CN202311076599.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-24
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2043-08-24
AI Technical Summary
The existing network service authentication methods cannot effectively deal with dynamic security risks and cannot meet users' security needs during continuous access to Internet resources.
UAF authentication protocol is adopted to pass the first and second UAF authentication requests, authenticators with different authentication factors are used for authentication, and trust evaluation is performed after the authentication is successful. The trust evaluation model is used to evaluate the user terminal's trust level, and the authentication process is dynamically adjusted.
It improves the security and reliability of network services, provides flexible authentication solutions, reduces the risk of system attacks, and enhances overall security.
Smart Images

Figure CN117061188B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method, system, apparatus, computer device, readable storage medium, and computer program product for secure authentication of network services. Background Art
[0002] With the development of network security technology, various authentication methods such as password authentication, fingerprint authentication, and face authentication have emerged one after another. However, even a private unique identification code may lead to the risk of information leakage. Hybrid authentication methods have gradually occupied the market. The most popular multi-factor authentication method is that users must pass two or more authentication factor identification mechanisms before they are authorized to use Internet resources. The superposition of the two authentication methods has, to a certain extent, guaranteed the security of users' use of Internet services.
[0003] However, the current traditional authentication methods cannot meet the security needs of users in dealing with dynamic security risks during their continuous access to Internet resources. Summary of the Invention
[0004] Based on this, it is necessary to provide a security authentication method, system, device, computer equipment, readable storage medium and computer program product for network services that can meet the dynamic security needs of users in the process of continuous access to Internet resources, in order to address the technical problem of not being able to meet the security needs of users in dealing with dynamic security risks.
[0005] In a first aspect, the present application provides a method for secure authentication of a network service, characterized in that the method is applied to a server corresponding to a target network service, and includes:
[0006] In response to a login operation by a user terminal to a server, sending a first UAF authentication request for the user terminal to the user terminal, and receiving a first authentication response matching the first UAF authentication request, obtained by the user terminal by invoking an authenticator matching the first UAF authentication request;
[0007] If the first authentication response information indicates that the authentication is successful, sending an authentication success message to the user terminal;
[0008] After the user terminal logs in to the server based on the authentication success message, if the preset security authentication trigger condition is met, the credit assessment feature matched by the user terminal is input into the preset trust assessment model to obtain the trust assessment result of the user terminal;
[0009] If the trust evaluation result meets the preset conditions, a second UAF authentication request for the user terminal is sent to the user terminal, and the user terminal receives a second authentication response information matching the second UAF authentication request, obtained by calling the authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors.
[0010] In one embodiment, the first authentication response information includes: first digital signature information and authenticator response information; the first digital signature information is generated by the authenticator matching the first UAF authentication request based on a pre-generated user certificate private key associated with the server and the user terminal;
[0011] If the first authentication response information indicates that the authentication is successful, an authentication success message is sent to the user terminal, including:
[0012] Parsing the first authentication response message to obtain first digital signature information;
[0013] Decrypt and verify the first digital signature information using the public key of the user certificate associated with the server and the user terminal pre-stored on the server, and after the decryption and verification of the first digital signature information passes, obtain the authentication result represented by the authenticator response information;
[0014] If the authentication result represented by the response information of the authenticator is authentication passed, an authentication success message is sent to the user terminal.
[0015] In one embodiment, before decrypting and verifying the first digital signature information using the public key of the user certificate associated with the server and the user terminal pre-stored on the server, the method further includes:
[0016] In response to a registration operation by a user terminal with respect to a server, a registration request for the user terminal is sent to the user terminal, and a registration response message matching the registration request is received by the user terminal by invoking an authenticator matching the registration request; the registration response message includes a public key of a user certificate associated with the server and the user terminal;
[0017] Parse the registration response information, and if the registration response message indicates that the authentication is successful, obtain and store the public key of the user certificate associated with the server and the user terminal from the registration response information, and send a registration success message to the user terminal.
[0018] In another embodiment, the registration response message further includes: second digital signature information and authenticator registration response information; the second digital signature information is generated by the authenticator that matches the registration request based on the authenticator private key of the authenticator;
[0019] If the registration response message indicates that the authentication is successful, obtaining and storing the public key of the user certificate associated with the user terminal from the registration response message, and sending a registration success message to the user terminal include:
[0020] Get the authenticator public key of the authenticator that matches the registration request;
[0021] Decrypt and verify the second digital signature information using the authenticator public key, and after the decryption and verification of the second digital signature information passes, obtain the authentication result represented by the authenticator registration response information;
[0022] When the authentication result represented by the registration response information of the authenticator is authentication passed, the public key of the user certificate associated with the server and the user terminal is obtained from the registration response information and stored, and a registration success message is sent to the user terminal.
[0023] In one embodiment, the trust assessment result is represented by a trust score of the user terminal;
[0024] If the trust evaluation result meets the preset conditions, a second UAF authentication request for the user terminal is sent to the user terminal, including:
[0025] If the trust score is less than the preset trust score threshold, a second UAF authentication request is sent to the user terminal.
[0026] In a second aspect, the present application further provides a method for secure authentication of a network service, characterized in that it is applied to a user terminal and comprises:
[0027] Triggering a login operation to the server corresponding to the target network service, and receiving a first UAF authentication request returned by the server in response to the login operation;
[0028] Based on the first UAF authentication request, call the authenticator that matches the first UAF authentication request, obtain first authentication response information that matches the first UAF authentication request, and send the first authentication response information to the server;
[0029] Receiving an authentication success message returned by the server when the first authentication response information indicates that the authentication is successful;
[0030] After logging into the server based on the authentication success message, if a second UAF authentication request is received from the server, the authenticator matching the second UAF authentication request is called, and a second authentication response information matching the second UAF authentication request is obtained, and the second authentication response information is sent to the server; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors; the second UAF authentication request is made by the server, under the premise of meeting the preset security authentication trigger condition, by inputting the credit assessment feature matched by the user terminal into the preset trust assessment model, obtaining the trust assessment result of the user terminal, and sending it to the user terminal if the trust assessment result meets the preset conditions.
[0031] In one embodiment, based on the first UAF authentication request, calling an authenticator that matches the first UAF authentication request, obtaining first authentication response information that matches the first UAF authentication request, includes:
[0032] Parse the first UAF authentication request, determine the authenticator that matches the first UAF authentication request, and call the ASM authentication module; the ASM authentication module is used to generate a key handle access token, access the authenticator that matches the first UAF authentication request through the key handle access token, and receive the authenticator response information returned by the authenticator that matches the first UAF authentication request;
[0033] Receive authenticator response information from the ASM authentication module and generate first authentication response information that matches the authenticator response information.
[0034] In another embodiment, the authenticator that matches the first UAF authentication request is further configured to obtain a pre-generated user certificate private key that associates the server with the user terminal, generate first digital signature information corresponding to the authenticator response information using the user certificate private key, and return the first digital signature information and the authenticator response information to the ASM authentication module.
[0035] Receiving authenticator response information from the ASM authentication module and generating first authentication response information that matches the authenticator response information, including:
[0036] Receive authenticator response information and first digital signature information from the ASM authentication module, and generate first authentication response information according to the authenticator response information and the first digital signature information.
[0037] In another embodiment, before parsing the first UAF authentication request, the method further includes:
[0038] Trigger a registration operation to the server and receive a registration request returned by the server in response to the login operation;
[0039] Parse the registration request, determine the authenticator that matches the registration request, and call the ASM authentication module; the ASM authentication module is used to generate a key handle access token, access the authenticator that matches the registration request through the key handle access token, and receive the authenticator registration response information returned by the authenticator that matches the registration request;
[0040] Receive the authenticator registration response information from the ASM authentication module, generate registration response information corresponding to the authenticator registration response information, and send it to the server; the server is used to parse the registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication result is passed, send a registration success message to the user terminal.
[0041] In one embodiment, the authenticator that matches the registration request is further configured to generate and store a user certificate private key and a user certificate public key associated with the server and the user terminal, and to generate second digital signature information corresponding to the authenticator registration response information using the authenticator private key of the authenticator, and to return the user certificate public key, the second digital signature information, and the authenticator registration response information to the ASM authentication module;
[0042] Receive the authenticator registration response information from the ASM authentication module, generate the registration response information corresponding to the authenticator registration response information, and send it to the server, including:
[0043] Receive the user certificate public key, the second digital signature information and the authenticator registration response information from the ASM authentication module, and generate the registration response information based on the user certificate public key, the second digital signature information and the authenticator registration response information, and send it to the server; the server is used to parse the registration response information, and use the authenticator public key of the authenticator that matches the pre-acquired registration request to decrypt and verify the second digital signature information, and after the decryption and verification of the second digital signature information is passed, obtain the authentication result represented by the authenticator registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication is passed, obtain the user certificate public key associated with the server and the user terminal from the registration response information and store it, and send a registration success message to the user terminal.
[0044] In a third aspect, the present application further provides a network service security authentication system, characterized in that it includes: a server and a user terminal corresponding to a target network service;
[0045] The server is configured to send a first UAF authentication request for the user terminal to the user terminal in response to a login operation of the user terminal to the server;
[0046] The user terminal is configured to call, based on the first UAF authentication request, an authenticator that matches the first UAF authentication request, obtain first authentication response information that matches the first UAF authentication request, and send the first authentication response information to the server;
[0047] The server is further configured to, if the first authentication response information indicates that the authentication is successful, send an authentication success message to the user terminal; and after the user terminal logs in to the server based on the authentication success message, if a preset security authentication trigger condition is satisfied, input the credit assessment feature matched by the user terminal into a preset trust assessment model to obtain a trust assessment result of the user terminal; if the trust assessment result satisfies the preset condition, send a second UAF authentication request for the user terminal to the user terminal; the authenticator matched by the first UAF authentication request and the authenticator matched by the second UAF authentication request are authenticators with different authentication factors;
[0048] The user terminal is further configured to call an authenticator that matches the second UAF authentication request, obtain second authentication response information that matches the second UAF authentication request, and send the second authentication response information to the server.
[0049] One of the embodiments is characterized in that it also includes: an ASM authentication module.
[0050] The user terminal is further configured to parse the first UAF authentication request, determine an authenticator that matches the first UAF authentication request, and call an ASM authentication module;
[0051] The ASM authentication module is configured to generate a key handle access token, access the authenticator that matches the first UAF authentication request through the key handle access token, and receive an authenticator response message returned by the authenticator that matches the first UAF authentication request;
[0052] The user terminal is further configured to receive authenticator response information from the ASM authentication module and generate first authentication response information matching the authenticator response information.
[0053] In a fourth aspect, the present application further provides a network service security authentication device, characterized in that it is applied to a server corresponding to a target network service, and the device includes:
[0054] a response message receiving module, configured to, in response to a login operation of the user terminal to the server, send a first UAF authentication request for the user terminal to the user terminal, and receive a first authentication response message matching the first UAF authentication request, obtained by the user terminal by invoking an authenticator matching the first UAF authentication request;
[0055] An information representation authentication module, configured to send an authentication success message to the user terminal if the first authentication response information indicates that the authentication is successful;
[0056] An evaluation result generation module is used to input the credit evaluation features matched by the user terminal into a preset trust evaluation model to obtain a trust evaluation result of the user terminal after the user terminal logs in to the server based on the authentication success message, if the preset security authentication trigger condition is met;
[0057] An authentication module configured to, if a trust evaluation result satisfies a preset condition, send a second UAF authentication request for the user terminal to the user terminal, and receive a second authentication response information matching the second UAF authentication request, obtained by the user terminal by invoking an authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request being authenticators with different authentication factors.
[0058] In a fifth aspect, the present application further provides a network service security authentication device, characterized in that it is applied to a user terminal and comprises:
[0059] An authentication request receiving module triggers a login operation to the server corresponding to the target network service and receives a first UAF authentication request returned by the server in response to the login operation;
[0060] a response message generation module, based on the first UAF authentication request, calling an authenticator that matches the first UAF authentication request, obtaining first authentication response information that matches the first UAF authentication request, and sending the first authentication response information to the server;
[0061] A success message receiving module receives an authentication success message returned by the server when the first authentication response information indicates that the authentication is successful;
[0062] The authentication module, after logging into the server based on the authentication success message, if receiving a second UAF authentication request sent by the server, calls the authenticator that matches the second UAF authentication request, obtains second authentication response information that matches the second UAF authentication request, and sends the second authentication response information to the server; the authenticator that matches the first UAF authentication request and the authenticator that matches the second UAF authentication request are authenticators with different authentication factors; the second UAF authentication request is executed by the server, under the premise of satisfying a preset security authentication trigger condition, by inputting the credit assessment feature matched by the user terminal into a preset trust assessment model, obtaining a trust assessment result of the user terminal, and sending the trust assessment result to the user terminal if the trust assessment result meets the preset condition.
[0063] In a sixth aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the network service security authentication method as described in any one of the embodiments of the first aspect or the second aspect is implemented.
[0064] In a seventh aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network service security authentication method as described in any one of the embodiments of the first aspect or the second aspect.
[0065] In an eighth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the network service security authentication method as described in any one of the embodiments of the first aspect or the second aspect.
[0066] The above-mentioned network service security authentication method, system, apparatus, computer device, readable storage medium and computer program product, in response to a login operation of a user terminal to a server, sends a first UAF authentication request for the user terminal to the user terminal, and receives a first authentication response information matching the first UAF authentication request obtained by the user terminal by invoking an authenticator matching the first UAF authentication request; if the first authentication response information indicates that the authentication is successful, sends an authentication success message to the user terminal; after the user terminal logs in to the server based on the authentication success message, if a preset security authentication trigger condition is met, inputs the credit assessment feature matched by the user terminal into a preset trust assessment model to obtain a trust assessment result of the user terminal; if the trust assessment result meets the preset condition, sends a second UAF authentication request for the user terminal to the user terminal, and receives a second authentication response information matching the second UAF authentication request obtained by the user terminal by invoking an authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors. Multi-factor authentication, which decouples local authentication methods from the UAF protocol, improves security and scalability, providing a more reliable and flexible authentication solution. After the service successfully sends an authentication success message and then satisfies the trust evaluation conditions, the server can dynamically authenticate the user by combining different authentication factors, thereby reducing the risk of attack and enhancing the overall security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 A diagram illustrating an application environment of a network service security authentication method according to an embodiment;
[0068] Figure 2 A schematic flow chart of a method for secure authentication of a network service in one embodiment;
[0069] Figure 3 A schematic flow chart of a security authentication method for a network service according to another embodiment;
[0070] Figure 4 A schematic diagram of a user registration process in one embodiment;
[0071] Figure 5 A block diagram of a security authentication system for network services in one embodiment;
[0072] Figure 6 A block diagram of a user terminal system in a security authentication system for network services in another embodiment;
[0073] Figure 7 A schematic diagram of an application environment for a network service security authentication method in one embodiment
[0074] Figure 8 A detailed flowchart of a security authentication method for a network service in one embodiment;
[0075] Figure 9 A detailed flowchart of a security authentication method for a network service in one embodiment;
[0076] Figure 10 A structural block diagram of a network service security authentication method and apparatus according to another embodiment;
[0077] Figure 11 A structural block diagram of a network service security authentication method and apparatus according to an embodiment;
[0078] Figure 12 FIG. 4 is a diagram showing the internal structure of a computer device in another embodiment. DETAILED DESCRIPTION
[0079] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0080] The embodiment of the present application provides a network service security authentication method, which can be applied to Figure 1In the application environment shown, there are a user terminal 102 and a server 104. The user terminal triggers a login operation and receives a first UAF authentication request from the server. The user terminal uses a matching authenticator to obtain a first authentication response message and sends it to the server. If the authentication is successful, the server sends an authentication success message. After the user terminal logs in to the server, if the security authentication trigger condition is met, the server inputs the user terminal's credit assessment characteristics into a trust assessment model to obtain a trust assessment result. If the preset conditions are met, the server sends a second UAF authentication request to the user terminal. The user terminal uses a matching authenticator to obtain a second authentication response message and sends it to the server. The first UAF authentication request and the second UAF authentication request use authenticators with different authentication factors. User devices may include, but are not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, smart car devices, etc. Portable wearable devices may include smart watches, smart bracelets, head-mounted devices, etc. The server may be implemented as a standalone server or a server cluster consisting of multiple servers.
[0081] In one embodiment, Figure 2 As shown, a network service security authentication method is provided, which is applied to Figure 1 Taking the server 104 in the example as an example, the following steps are included:
[0082] In step S201, in response to a login operation of a user terminal to the server, the server sends a first UAF authentication request for the user terminal to the user terminal, and receives a first authentication response information matching the first UAF authentication request, obtained by the user terminal by invoking an authenticator matching the first UAF authentication request.
[0083] Specifically, when a user initiates a login operation to the server 104 through the user terminal 102, the server 104 may respond to the login operation and send a first UAF authentication request to the user terminal 102. The user terminal 102 may then call the authenticator that matches the first UAF authentication request to obtain a first response corresponding to the first UAF authentication request and return it to the server 104.
[0084] Step S202 : When the first authentication response information indicates that the authentication is successful, an authentication success message is sent to the user terminal 102 .
[0085] After receiving the first authentication response information, the server 104 may parse the first authentication response information to verify whether the first authentication response information indicates that the authentication is successful. If so, the server 104 may send an authentication success message to the user terminal 102 .
[0086] Step S203: After the user terminal logs in to the server based on the authentication success message, if the preset security authentication trigger condition is met, the credit assessment feature matched by the user terminal is input into the preset trust assessment model to obtain the trust assessment result of the user terminal.
[0087] The preset security authentication trigger condition can be a pre-set condition for triggering security authentication, for example, a set interval time. The trust assessment feature can be understood as an authenticator identifier, a server identifier, a user terminal, an ASM (Authenticator Specific Module), an authenticator metadata statement (including authentication method and authentication characteristics), a server, and a first authentication response message, etc., which are used to assess the trustworthiness of the user terminal 102. Among them, the trust assessment model can be a neural network model for evaluating the user terminal 102. The model can be based on logarithmic probability regression or logistic regression in machine learning. The logarithmic probability regression is trained by an arbitrary-order differentiable convex function.
[0088] Optionally, when the user terminal 102 successfully logs in to the server 104 and meets the preset security authentication trigger conditions, the server 104 can also input the credit assessment characteristics of the user terminal 102 into a preset trust assessment model for evaluation, thereby obtaining the trust assessment result of the user terminal, which can be a real number between 0 and 1.
[0089] In step S204, if the trust evaluation result satisfies the preset conditions, a second UAF authentication request for the user terminal is sent to the user terminal, and a second authentication response information matching the second UAF authentication request is received by the user terminal by invoking the authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors.
[0090] The preset condition may refer to whether the condition is less than a pre-set threshold, the second UAF authentication request may refer to a request for authentication with an authenticator that uses an authentication factor different from that of the first UAF authentication request, and the second authentication response information may refer to the response information corresponding to the second UAF authentication request.
[0091] Specifically, when the trust evaluation result obtained by the server 104 satisfies a preset condition, for example, when it is less than a preset threshold, the server 104 may further send a second UAF authentication request for the user terminal 102 to the user terminal 102. The user terminal 102 may then again call the authenticator that matches the second UAF authentication request to perform authentication, so that the user terminal 102 again receives a second authentication response message which is returned to the server 104.
[0092] In the aforementioned network service security authentication method, the server responds to the login operation of user terminal 102 by sending a first UAF authentication request and receiving a matching first authentication response. If the first authentication succeeds, server 104 sends an authentication success message to the user terminal. After user terminal 102 logs in to the server based on the authentication success message, if the preset security authentication trigger conditions are met, server 104 inputs the user terminal's credit assessment characteristics into a trust assessment model to obtain a trust assessment result. If the trust assessment result meets the preset conditions, server 104 sends a second UAF authentication request and receives a matching second authentication response. The authenticators of the first and second UAF authentication requests belong to different authentication factors. Multi-factor authentication, which decouples the user terminal's local authentication methods from the UAF protocol, can improve security and provide scalability, thereby providing a more reliable and flexible identity authentication solution. After the server 104 sends the authentication success message, it re-inputs the trust assessment model to determine if the preset conditions are met and then sends a second UAF authentication request. This allows server 104 to implement dynamic and reliable user identity authentication and trust assessment, enhancing the overall security of the system.
[0093] In one embodiment, the first authentication response information includes: first digital signature information and authenticator response information; the first digital signature information is generated by the authenticator matching the first UAF authentication request based on a pre-generated user certificate private key associated with the server 104 and the user terminal 104; when the first authentication response information indicates that the authentication is successful, an authentication success message is sent to the user terminal 102, including: parsing the first authentication response message to obtain the first digital signature information; using the user certificate public key associated with the server and the user terminal pre-stored on the server 104 to decrypt and verify the first digital signature information, and after the decryption and verification of the first digital signature information is successful, obtaining the authentication result represented by the authenticator response information; when the authentication result represented by the authenticator response information is that the authentication is successful, an authentication success message is sent to the user terminal 102.
[0094] The first digital signature information may be understood as relevant information digitally signed by the matched authenticator based on the pre-generated private key of the user certificate associated with the server and the user terminal.
[0095] Optionally, the first digital signature information is first extracted from the obtained first authentication response message by parsing it, and then decrypted using a pre-stored, pre-generated public key of a user certificate associated with the server 104 and the user terminal 102. The first digital signature information generated based on a pre-generated private key of a user certificate associated with the server 104 and the user terminal 102 is verified. The information encryption and decryption process greatly ensures the confidentiality of the interactive data and is not easily cracked or obtained midway, thereby protecting the security of the user terminal 102 when using the network system.
[0096] In one embodiment, before decrypting and verifying the first digital signature information using the user certificate public key associated with the server 104 and the user terminal 102 pre-stored on the server 104, it also includes: in response to the user terminal 102's registration operation on the server 104, sending a registration request for the user terminal 102 to the user terminal 1102, and receiving a registration response information matching the registration request obtained by the user terminal 102 by calling the authenticator matching the registration request; the registration response information includes the user certificate public key associated with the server 104 and the user terminal 102; parsing the registration response information, and when the registration response message indicates that the authentication is passed, obtaining the user certificate public key associated with the server 104 and the user terminal 102 from the registration response information and storing it, and sending a registration success message to the user terminal 102.
[0097] For example, a user registers with server 104 through client 102. In response, server 104 sends a registration request and receives a registration response message from the client, which is obtained by invoking an authenticator that matches the registration request. After parsing and verifying the registration response message, server 104 extracts and stores the public key of the user certificate associated with user terminal 102 and sends a successful registration message to the client. Pre-storing the public key required for authentication during registration reduces unnecessary operations, saves time, and improves authentication efficiency.
[0098] In one embodiment, the registration response message also includes: second digital signature information and authenticator registration response information; the second digital signature information is generated by the authenticator that matches the registration request based on the authenticator private key of the authenticator. When the registration response message indicates that the authentication is successful, the user certificate public key associated with the server 104 and the user terminal 102 is obtained from the registration response information and stored, and a registration success message is sent to the user terminal 102, including: obtaining the authenticator public key of the authenticator that matches the registration request; using the authenticator public key to decrypt and verify the second digital signature information, and after the decryption and verification of the second digital signature information is successful, obtaining the authentication result represented by the authenticator registration response information; when the authentication result represented by the authenticator registration response information indicates that the authentication result is successful, obtaining the user certificate public key associated with the server 104 and the user terminal 102 from the registration response information and stored, and sending a registration success message to the user terminal 102.
[0099] The second digital signature information can be understood as relevant information digitally signed by the authentication private key of the matching authenticator itself, and the authenticator public key can be understood as the authentication public key.
[0100] Optionally, server 104 obtains the authentication public key of the matching authenticator and uses it to decrypt the encrypted second digital signature information. Only after the representation of the registration response information has been verified can server 104 obtain and store the user certificate public key associated with server 104 and user terminal 102 from the registration response information, then return a registration success message to the client. The authenticator's own authentication public and private key pair used during registration acts as a lock and key combination to protect information from disclosure. Simultaneously, the user certificate public key associated with server 104 and user terminal 102 is successfully sent to server 104, facilitating subsequent authentication and ensuring that information is not stolen during the user registration process, protecting the user's personal privacy and enhancing the overall security of the system.
[0101] In one embodiment, the trust evaluation result is represented by a trust score of the user terminal 102; if the trust evaluation result satisfies a preset condition, a second UAF authentication request for the user terminal 102 is sent to the user terminal 102, including: if the trust score is less than a preset trust score threshold, sending the second UAF authentication request to the user terminal 102.
[0102] For example, the trust evaluation result is less than the trust score threshold. Only when the output result is less than this threshold, the server 104 will send a second authentication request with a different authentication factor to the client, thereby performing multi-factor authentication to further determine the user's identity and ensure the identity security of the user in continuous use of Internet services.
[0103] In one embodiment, if Figure 3 As shown, a network service security authentication method is provided, which is applied to Figure 1 Taking the user terminal 102 in the example as an example, the following steps are included:
[0104] Step S301: triggering a login operation to the server 104 corresponding to the target network service, and receiving a first UAF authentication request returned by the server 104 in response to the login operation.
[0105] Alternatively, a user logs in to server 104 through a client, triggering an information exchange between the client and server 104. The client then receives a first UAF authentication request from server 104 in response to this operation. This UAF authentication method allows server 104 to verify the client's identity, improving the scalability and flexibility of the authentication method.
[0106] Step S302: Based on the first UAF authentication request, call an authenticator that matches the first UAF authentication request, obtain first authentication response information that matches the first UAF authentication request, and send the first authentication response information to the server 104.
[0107] For example, the user terminal 102 parses the first UAF request, calls the corresponding authenticator through the matching authenticator identifier and pre-registered key registration data carried therein, and sends a first authentication response message to the FIDO server 104. The UAF authentication method is combined with the local authentication method.
[0108] Step S303: Receive an authentication success message returned by the server 104 when the first authentication response information indicates that the authentication is successful.
[0109] Optionally, the receiving device receives an authentication success message returned by the server 104 after verifying that the first authentication response information representation is successful.
[0110] Step S304: After logging into the server 104 based on the authentication success message, if a second UAF authentication request sent by the server 104 is received, the authenticator matching the second UAF authentication request is called to obtain second authentication response information matching the second UAF authentication request, and the second authentication response information is sent to the server 104; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors; the second UAF authentication request is processed by the server 104 under the premise of satisfying a preset security authentication trigger condition, inputting the credit assessment feature matched by the user terminal 102 into a preset trust assessment model, obtaining a trust assessment result of the user terminal 102, and sending the trust assessment result to the user terminal 102 when the preset condition is met.
[0111] For example, if the client receives a second authentication request, steps S302 to S304 are repeated to implement a multi-factor authentication, and the second authentication request carries a different authentication factor from the first one during the repetition process.
[0112] In this embodiment, a login operation is triggered to the server 104 corresponding to the target network service and a first UAF authentication request returned by the server 104 is received; based on the first UAF authentication request, a matching authenticator is called to obtain a first authentication response message and send it to the server 104; an authentication success message returned by the server 104 is received; after logging into the server 104, if a second UAF authentication request is received, a matching authenticator is called to obtain a second authentication response message and send it to the server 104; the authenticators of the first UAF authentication request and the second UAF authentication request belong to authenticators of different authentication factors; the second UAF authentication request is input by the server 104 into a trust assessment model according to the credit assessment characteristics of the user terminal 102 to obtain a trust assessment result, and is sent to the user terminal 102 when the preset conditions are met, thereby achieving multi-factor authentication in which the local authentication means of the user terminal 102 are decoupled from the UAF protocol, which can improve security and provide scalability, thereby providing a more reliable and flexible identity authentication solution. As long as the second authentication request sent by the server 104 is received, the multi-factor decision is performed as usual after receiving the authentication success message. The user terminal 102 can achieve more reliable user identity authentication and trust evaluation, thereby enhancing the overall security of the system.
[0113] In one embodiment, it is characterized in that, based on a first UAF authentication request, calling an authenticator that matches the first UAF authentication request, and obtaining first authentication response information that matches the first UAF authentication request, includes: parsing the first UAF authentication request, determining the authenticator that matches the first UAF authentication request, and calling an ASM authentication module; the ASM authentication module is used to generate a key handle access token, and access the authenticator that matches the first UAF authentication request through the key handle access token, and receive authenticator response information returned by the authenticator that matches the first UAF authentication request; receiving authenticator response information from the ASM authentication module, and generating first authentication response information that matches the authenticator response information.
[0114] The ASM authentication module can be understood as an abstract FIDO authenticator function, providing a standardized set of interface specifications (APIs) for the upper-layer user terminal 102, adapting to various specific authenticators at the lower layer. The key handle access token can be understood as a passkey for accessing the authenticator.
[0115] For example, after parsing the first UAF authentication request, user terminal 102 determines a matching authenticator. It then invokes the matching authenticator through the ASM authentication module. Simultaneously, it receives the authenticator's response message from the ASM authentication module to generate a matching first authentication message. By adding a relay cloud platform ASM authentication module between user terminal 102 and the authenticator, the module interconnects with multiple authenticators with different authentication factors, improving efficiency in finding matching authenticators and reducing authentication time.
[0116] In another embodiment, it is characterized in that the authenticator matching the first UAF authentication request is further used to obtain a pre-generated user certificate private key associated with the server 104 and the user terminal 102, and use the user certificate private key to generate first digital signature information corresponding to the authenticator response information, and return the first digital signature information and the authenticator response information to the ASM authentication module; receive the authenticator response information from the ASM authentication module, and generate first authentication response information matching the authenticator response information, including: receiving the authenticator response information and the first digital signature information from the ASM authentication module, and generating the first authentication response information based on the authenticator response information and the first digital signature information.
[0117] Optionally, the corresponding authenticator obtains and utilizes the pre-generated user certificate private key associated with server 104 and user terminal 102 to generate a first digital signature corresponding to the authenticator response message. Both are then returned to the ASM authentication module. User terminal 102 then receives the authenticator response message and generates a first authentication response message based on the first digital signature. By utilizing the user certificate private key and digital signature technology, data integrity, identity authentication, and bidirectional authentication can be ensured during the authentication process. This helps prevent unauthorized access and protects communication security between user terminal 102 and the authentication module.
[0118] In one embodiment, Figure 4 As shown, it is characterized in that before parsing the first UAF authentication request, the following steps are included:
[0119] Step S401 : triggering a registration operation to the server 104 , and receiving a registration request returned by the server 104 in response to the login operation.
[0120] For example, the user terminal 102 initiates a registration operation and receives a registration request returned by the service in response to the operation. The user terminal 102 can interact with the server 104 to complete the registration process and obtain a registration result.
[0121] Step S402: Parse the registration request, determine the authenticator that matches the registration request, and call the ASM authentication module; the ASM authentication module is used to generate a key handle access token, access the authenticator that matches the registration request through the key handle access token, and receive the authenticator registration response information returned by the authenticator that matches the registration request;
[0122] Optionally, user terminal 102 parses the registration request, identifies, and calls a matching authenticator through the ASM authentication module. Upon receiving the command from user terminal 102 to find a matching authenticator, the ASM authentication module generates a key handle access token (KHAccessToken). This token serves as the access token for the authenticator, protecting it from unauthorized access. The management and scheduling of the ASM authentication module ensures the correct authenticator is selected and generates a key handle access token to protect the authenticator's security.
[0123] Step S403, receiving the authenticator registration response information from the ASM authentication module, and generating registration response information corresponding to the authenticator registration response information, and sending it to the server 104; the server 104 is used to parse the registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication result is passed, a registration success message is sent to the user terminal 102.
[0124] For example, the user terminal 102 receives the authenticator registration response information from the ASM authenticator module, generates a corresponding registration response message and sends it to the server 104, and then receives a registration success message sent after the server 104 parses the registration response information and the information representation of the information passes.
[0125] In the above-disclosed embodiments, during the registration process, the server 104 and the user terminal 102 can interact in a timely manner and provide each other with feedback on the registration results. Furthermore, the corresponding matching authenticator can be more conveniently called through the ASM authentication module, thereby ensuring the timeliness of the interaction and the convenience of the operation, which is conducive to protecting user information security and improving registration efficiency.
[0126] In another embodiment, it is characterized in that the authenticator that matches the registration request is further used to generate and store a user certificate private key and a user certificate public key associated with the server 104 and the user terminal 102, and use the authenticator private key of the authenticator to generate a second digital signature information corresponding to the authenticator registration response information, and return the user certificate public key, the second digital signature information and the authenticator registration response information to the ASM authentication module; receive the authenticator registration response information from the ASM authentication module, and generate registration response information corresponding to the authenticator registration response information, and send it to the server 104, including: receiving the user certificate public key, the second digital signature information and the authenticator registration response information from the ASM authentication module , and generates registration response information based on the user certificate public key, the second digital signature information and the authenticator registration response information, and sends it to the server 104; the server 104 is used to parse the registration response information, and use the authenticator public key of the authenticator that matches the registration request obtained in advance to decrypt and verify the second digital signature information, and after the decryption and verification of the second digital signature information is passed, obtain the authentication result represented by the authenticator registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication result is passed, obtain the user certificate public key associated with the server 104 and the user terminal 102 from the registration response information and store it, and send a registration success message to the user terminal 102.
[0127] Among them, the authenticator private key and the authenticator private key can be understood as the authenticator authentication private key and the authenticator authentication public key, which are equivalent to the key pair used to verify the authenticator identity and communication security. The authenticator's own private key and the user-associated authentication certificate private key are stored in the user terminal 102 security area.
[0128] The user terminal 102 receives the user certificate public key, the second digital signature information and the authenticator registration response information from the ASM authentication module, and generates a registration response information based on the user certificate public key, the second digital signature information and the authenticator registration response information, and sends it to the server 104; the server 104 is used to parse the registration response information, and use the authenticator public key of the authenticator that matches the pre-acquired registration request to decrypt and verify the second digital signature information, and after the decryption and verification of the second digital signature information is passed, obtain the authentication result represented by the authenticator registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication is passed, obtain the user certificate public key associated with the server 104 and the user terminal 102 from the registration response information and store it, and send a registration success message to the user terminal 102. The second digital signature information here is encrypted using the authenticator private key in the user terminal 102 and decrypted using the authenticator public key in the server 104. The encryption and decryption process ensures the security of the user's identity information, and at the same time can reconfirm whether the selected authenticator is correct and can achieve repeated verification. The authenticator authentication private key and the user-associated authentication certificate private key are stored in the secure area of the user terminal 102, rather than being centrally stored in the server 104, which greatly enhances the key security and greatly improves the communication security and fault tolerance of the system.
[0129] In one embodiment, Figure 5 As shown, a security authentication system for a network service is characterized by comprising: a server 501 and a user terminal 502 corresponding to a target network service;
[0130] The server 501 is configured to send a first UAF authentication request for the user terminal to the user terminal in response to a login operation of the user terminal to the server;
[0131] Based on the first UAF authentication request, the user terminal 502 calls the authenticator that matches the first UAF authentication request, obtains first authentication response information that matches the first UAF authentication request, and sends the first authentication response information to the server;
[0132] The server 501 is configured to, if the first authentication response information indicates that the authentication is successful, send an authentication success message to the user terminal. After the user terminal logs in to the server based on the authentication success message, if a preset security authentication trigger condition is satisfied, input the credit assessment feature matched by the user terminal into a preset trust assessment model to obtain a trust assessment result of the user terminal. If the trust assessment result satisfies the preset condition, send a second UAF authentication request for the user terminal to the user terminal. The authenticator matched by the first UAF authentication request and the authenticator matched by the second UAF authentication request are authenticators with different authentication factors.
[0133] The user terminal 502 is further configured to call an authenticator that matches the second UAF authentication request, obtain second authentication response information that matches the second UAF authentication request, and send the second authentication response information to the server.
[0134] For example, the specific definition of a security authentication system for a network service can be found in the above-mentioned definition of a security authentication method for a network service, applied to a server corresponding to a target network service, and a security authentication method for a network service, applied to a user terminal, which will not be repeated here. Each module in the above-mentioned security authentication system for a network service can be implemented in whole or in part by software, hardware, and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0135] In one embodiment, Figure 6 As shown, the user terminal module is characterized in that it also includes: an ASM authentication module 602 and a user terminal 601;
[0136] The user terminal 601 is configured to parse the first UAF authentication request, determine an authenticator that matches the first UAF authentication request, and call the ASM authentication module;
[0137] The ASM authentication module 602 is configured to generate a key handle access token, access the authenticator that matches the first UAF authentication request through the key handle access token, and receive an authenticator response message returned by the authenticator that matches the first UAF authentication request;
[0138] The user terminal 601 is further configured to receive authenticator response information from the ASM authentication module and generate first authentication response information matching the authenticator response information.
[0139] For example, the specific definition of the ASM authentication module can be found in the above-mentioned definition corresponding to the calling of the authenticator matching the first UAF authentication request based on the first UAF authentication request to obtain the first authentication response information matching the first UAF authentication request, and will not be repeated here. The above-mentioned ASM authentication module can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.
[0140] In a detailed embodiment, the application Figure 7The application environment shown in the figure mainly includes seven components: web client, FIDO client, ASM (Authenticator Specific Module), FIDO authenticator, web server, FIDO server, and FIDO metadata service.
[0141] The details are as follows:
[0142] Web client: This can be an SDK, app, or browser, acting as a user agent for the FIDO client. The web client communicates with the web server using the TLS secure protocol.
[0143] FIDO client: calls the ASM authenticator-specific module API to interact with a specific FIDO authenticator; uses the web client as a user agent to interact with the FIDO server using UAF (Universal Authentication Framework) protocol messages (registration, authentication, transaction confirmation, and logout).
[0144] ASM Authenticator Specific Module: Acts as an abstract FIDO authenticator function, provides a standard API for upper-layer FIDO clients, and adapts to various specific FIDO authenticators at the lower layer.
[0145] FIDO Authenticator: A secure entity connected to or encapsulated within a FIDO user device. It has built-in matchers for biometric authentication, including facial recognition, fingerprint recognition, voiceprint recognition, and iris recognition. It can create key material associated with a relying party (relying party user-linked authentication certificate public and private keys, digital signatures, and hashes). The authenticator's own authentication private key and the user-linked authentication certificate private key are stored in a secure area on the device. These keys can be used to participate in FIDO strong authentication protocols, such as generating responses to cryptographic challenges to authenticate the authenticator to a relying party.
[0146] Web server: Provides web online services; acts as a proxy for the FIDO server, transmitting UAF protocol messages between the FIDO client and the FIDO server.
[0147] FIDO Server: Uses a web server as a proxy to exchange UAF protocol messages (registration, authentication, transaction confirmation, and deregistration) with FIDO clients. It accepts metadata services such as FIDO authenticator public key certificates from FIDO authenticator vendors. The FIDO security authentication policy uses a trust assessment model (such as log-probability regression or logistic regression in machine learning) to make multi-factor authentication decisions based on the trust score, achieving dynamic security authentication.
[0148] FIDO Metadata Service: Provides metadata services such as FIDO authenticator vendor public key certificates to FIDO servers.
[0149] The above applies to Figure 7 In a detailed embodiment of the application environment shown, a secure registration method for a network service is as follows: Figure 8 The specific implementation steps are as follows:
[0150] In step S801, the FIDO server obtains metadata such as the FIDO authenticator manufacturer's public key certificate from the metadata service.
[0151] Step S802: The user enters the username and password and logs in to the relying party's Web service through the Web client (TLS).
[0152] In step S803, after the web server successfully verifies the user password, the FIDO server triggers a UAF registration request and sends a UAF registration request message containing the user name, dependent service identifier (AppID), random challenge number, and UAF registration policy to the FIDO client.
[0153] In step S804, the FIDO client parses the UAF registration request message, selects a specific authenticator based on the UAF registration policy, and the ASM authenticator-specific module generates a KHAccessToken key handle access token to protect the authenticator's UAF certificate from being illegally used.
[0154] In step S805, the authenticator (Authenticator Attestation ID) verifies the user through the device's built-in matcher (typically including facial recognition, fingerprint recognition, voiceprint recognition, iris recognition, and other biometric authentication methods). It then generates a public-private key certificate associated with the dependent service provider's username and AppID. The authenticator's own Attestation authentication private key and the user-associated authentication certificate private key are stored in the device's secure area. KeyRegistrationData (KRD) key registration data is generated and digitally signed with the authenticator's own Attestation private key.
[0155] Step S806: The FIDO client generates a UAF registration response message (including KRD).
[0156] In step S807, the FIDO server parses the FIDO client's UAF registration response message to ensure that it complies with its UAF registration policy. After decrypting and verifying the relevant information using the FIDO authenticator's own Attestation public key, it sends a UAF registration success message to the FIDO client.
[0157] The above applies to Figure 7 In another detailed embodiment of the application environment shown, a security authentication method for network services is as follows: Figure 9 The specific implementation steps are as follows:
[0158] Step S901: A user logs in to a relying party's Web service via a Web client (TLS).
[0159] In step S902, the FIDO server triggers a UAF authentication request, sending a UAF authentication request message to the FIDO client containing the username, the relying service identifier (AppID), a random challenge number, and the UAF authentication policy. Unlike the UAF registration policy, the combination of the FIDO authenticator ID and its registered key (AAID, KeyID) is added to the accept portion of the UAF authentication policy.
[0160] In step S903, the FIDO client parses the UAF authentication request message, selects a specific authenticator based on the UAF authentication policy, and the ASM generates a KHAccessToken key handle access token.
[0161] In step S904, the authenticator verifies the user through the device's built-in matcher (generally including biometric authentication such as face recognition, fingerprint recognition, voiceprint recognition, and iris recognition), generates an authenticator response message, and digitally signs it with the private key of the relying party user certificate generated by the previous registration.
[0162] Step S905: The FIDO client generates a UAF authentication response message.
[0163] In step S906, the FIDO server parses the FIDO authentication response message, verifies that it complies with its UAF authentication policy and the authenticator metadata declaration data characteristics, decrypts and verifies the signature information using the previously registered relying party user certificate public key, and then sends a UAF authentication success message to the FIDO client.
[0164] In step S907, the FIDO server authentication policy module calls a trust assessment model (for example, based on logarithmic probability regression or logistic regression in machine learning) and makes a multi-factor authentication decision based on the trust score. If the multi-factor authentication policy is met, repeat steps 2-6 to achieve dynamic security authentication. The input feature variables of the trust assessment model based on logarithmic probability regression (Logistic Regression) include authenticator AAID, relying party AppID, FIDO client, ASM, authenticator metadata statement (including authentication method and authentication characteristics), relying party user, user role, UAF authentication response message, etc., and the output is a real number in the interval (0,1). The FIDO server authentication policy module makes a multi-factor authentication decision based on the output score of the trust assessment model and the pre-set threshold. Logarithmic probability regression is an arbitrary order differentiable convex function. There is no need to assume the data distribution in advance. The gradient descent method and Newton method can be applied to obtain the optimal solution.
[0165] The above disclosed embodiments have the following advantages compared with the prior art:
[0166] 1. This application proposes a method for secure authentication of network services, which implements multi-factor authentication by decoupling the authentication means and authentication protocols between user devices, Web service clients, and Web servers; makes multi-factor authentication decisions based on scores from a trust assessment model (e.g., log-probability regression or logistic regression based on machine learning), thereby achieving dynamic secure authentication.
[0167] 2. Implement multi-factor authentication that decouples authentication methods and protocols between user devices, web service clients, and web servers. The authenticator's self-authentication private key and the user's associated authentication certificate private key are stored in a secure area on the user terminal, rather than centrally on the relying party's web server, greatly enhancing key security. Local authentication methods (typically including biometric authentication such as facial recognition, fingerprint recognition, voiceprint recognition, and iris recognition) are decoupled from the UAF universal authentication framework, ensuring high compatibility and scalability of the authentication system.
[0168] 3. Make multi-factor authentication decisions based on the scores of trust assessment models (such as log-probability regression or logistic regression in machine learning) to achieve dynamic security authentication.
[0169] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0170] Based on the same inventive concept, the embodiments of the present application also provide a network service security authentication device for implementing the aforementioned network service security authentication method. The implementation solution provided by the device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of the embodiments of the network service security authentication device provided below can be found in the above-mentioned limitations of the network service security authentication method, and will not be repeated here.
[0171] In one embodiment, Figure 10 As shown, a network service security authentication device is provided, characterized in that it is applied to a server corresponding to a target network service, and includes: a response message receiving module 1001, a success message sending module 1002, an evaluation result generating module 1003 and a multi-factor judgment module 1004, wherein:
[0172] a response message receiving module 1001 configured to send a first UAF authentication request for the user terminal to the user terminal in response to a login operation of the user terminal to the server, and receive a first authentication response message matching the first UAF authentication request, obtained by the user terminal by invoking an authenticator matching the first UAF authentication request;
[0173] A success message sending module 1002 is configured to send an authentication success message to the user terminal if the first authentication response information indicates that the authentication is successful;
[0174] Evaluation result generation module 1003 is used to input the credit evaluation features matched by the user terminal into a preset trust evaluation model to obtain a trust evaluation result of the user terminal after the user terminal logs in to the server based on the authentication success message, if the preset security authentication trigger condition is met;
[0175] The decision module 1004 is configured to, if the trust evaluation result satisfies a preset condition, send a second UAF authentication request for the user terminal to the user terminal, and receive a second authentication response information matching the second UAF authentication request obtained by the user terminal by invoking the authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors.
[0176] In one embodiment, the response message receiving module 1002 further includes a parsing submodule, a verification submodule, and a sending submodule. The first authentication response information includes: first digital signature information and authenticator response information; the first digital signature information is generated by the authenticator matching the first UAF authentication request based on a pre-generated user certificate private key associated with the server and the user terminal, wherein:
[0177] The parsing submodule is used to parse the first authentication response message to obtain the first digital signature information.
[0178] The verification submodule is used to decrypt and verify the first digital signature information using the user certificate public key associated with the server and the user terminal pre-stored on the server, and obtain the authentication result represented by the authenticator response information after the decryption and verification of the first digital signature information is passed.
[0179] The sending submodule is configured to send an authentication success message to the user terminal when the authentication result represented by the response information of the authenticator is authentication passed.
[0180] In one embodiment, the verification submodule is specifically configured to, in response to a registration operation of the user terminal with respect to the server, send a registration request for the user terminal to the user terminal, and receive registration response information matching the registration request obtained by the user terminal by invoking an authenticator matching the registration request; the registration response information includes a public key of a user certificate associated between the server and the user terminal;
[0181] Parsing the registration response information, the registration response message also includes: second digital signature information and authenticator registration response information; the second digital signature information is generated by the authenticator matching the registration request based on the authenticator private key of the authenticator;
[0182] If the registration response message indicates that the authentication is successful, obtaining and storing the public key of the user certificate associated with the user terminal from the registration response message, and sending a registration success message to the user terminal include:
[0183] Get the authenticator public key of the authenticator that matches the registration request;
[0184] Decrypt and verify the second digital signature information using the authenticator public key, and after the decryption and verification of the second digital signature information passes, obtain the authentication result represented by the authenticator registration response information;
[0185] When the authentication result represented by the registration response information of the authenticator is authentication passed, the public key of the user certificate associated with the server and the user terminal is obtained from the registration response information and stored, and a registration success message is sent to the user terminal.
[0186] The decision module 1004 is specifically configured to represent the trust evaluation result through the trust score of the user terminal;
[0187] If the trust evaluation result meets the preset conditions, a second UAF authentication request for the user terminal is sent to the user terminal, including:
[0188] If the trust score is less than the preset trust score threshold, a second UAF authentication request is sent to the user terminal.
[0189] In one embodiment, Figure 11 As shown, a network service security authentication device is provided, characterized in that it is applied to a user terminal and includes: an authentication request receiving module 1101, a response message generating module 1102, a success message receiving module 1103 and a multi-factor authentication module 1104, wherein:
[0190] The authentication request receiving module 1101 is configured to trigger a login operation on the server corresponding to the target network service and receive a first UAF authentication request returned by the server in response to the login operation.
[0191] A response message generation module 1102 is configured to, based on the first UAF authentication request, call an authenticator that matches the first UAF authentication request, obtain first authentication response information that matches the first UAF authentication request, and send the first authentication response information to the server;
[0192] A success message receiving module 1103 is configured to receive an authentication success message returned by the server when the first authentication response information indicates that the authentication is successful;
[0193] Authentication module 1104 is configured to, after logging into the server based on a successful authentication message, if a second UAF authentication request is received from the server, call an authenticator that matches the second UAF authentication request, obtain second authentication response information that matches the second UAF authentication request, and send the second authentication response information to the server; the authenticator that matches the first UAF authentication request and the authenticator that matches the second UAF authentication request are authenticators with different authentication factors; the second UAF authentication request is executed by the server, upon satisfying a preset security authentication trigger condition, by inputting the credit assessment features matched by the user terminal into a preset trust assessment model, obtaining a trust assessment result of the user terminal, and sending the trust assessment result to the user terminal if the trust assessment result satisfies the preset condition.
[0194] In one embodiment, the response message receiving module 1103 further includes: a parsing submodule and a generating submodule, characterized in that, based on the first UAF authentication request, the authenticator matching the first UAF authentication request is called to obtain first authentication response information matching the first UAF authentication request, wherein:
[0195] Parsing submodule: Parses the first UAF authentication request, determines the authenticator that matches the first UAF authentication request, and calls the ASM authentication module; the ASM authentication module is used to generate a key handle access token, access the authenticator that matches the first UAF authentication request through the key handle access token, and receive the authenticator response information returned by the authenticator that matches the first UAF authentication request.
[0196] Generation submodule: receives authenticator response information from the ASM authentication module and generates first authentication response information matching the authenticator response information.
[0197] In another embodiment, it is characterized in that the authenticator matching the first UAF authentication request is further used to obtain a pre-generated user certificate private key that associates the server with the user terminal, and uses the user certificate private key to generate first digital signature information corresponding to the authenticator response information, and returns the first digital signature information and the authenticator response information to the ASM authentication module; receives the authenticator response information from the ASM authentication module, and generates first authentication response information that matches the authenticator response information. The generation submodule is mainly used to receive the authenticator response information and the first digital signature information from the ASM authentication module, and generate the first authentication response information based on the authenticator response information and the first digital signature information.
[0198] In another embodiment, before entering the parsing submodule, the method further includes: triggering a registration operation to the server, and receiving a registration request returned by the server in response to the login operation;
[0199] Parse the registration request, determine the authenticator that matches the registration request, and call the ASM authentication module; the ASM authentication module is used to generate a key handle access token, access the authenticator that matches the registration request through the key handle access token, and receive the authenticator registration response information returned by the authenticator that matches the registration request;
[0200] Receive the authenticator registration response information from the ASM authentication module, generate registration response information corresponding to the authenticator registration response information, and send it to the server; the server is used to parse the registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication result is passed, send a registration success message to the user terminal.
[0201] In one embodiment, the authenticator that matches the registration request is further configured to generate and store a user certificate private key and a user certificate public key associated with the server and the user terminal, and to generate second digital signature information corresponding to the authenticator registration response information using the authenticator private key of the authenticator, and to return the user certificate public key, the second digital signature information, and the authenticator registration response information to the ASM authentication module;
[0202] Receive the authenticator registration response information from the ASM authentication module, generate the registration response information corresponding to the authenticator registration response information, and send it to the server, including:
[0203] Receive the user certificate public key, the second digital signature information and the authenticator registration response information from the ASM authentication module, and generate the registration response information based on the user certificate public key, the second digital signature information and the authenticator registration response information, and send it to the server; the server is used to parse the registration response information, and use the authenticator public key of the authenticator that matches the pre-acquired registration request to decrypt and verify the second digital signature information, and after the decryption and verification of the second digital signature information is passed, obtain the authentication result represented by the authenticator registration response information, and when the authentication result represented by the authenticator registration response information is that the authentication is passed, obtain the user certificate public key associated with the server and the user terminal from the registration response information and store it, and send a registration success message to the user terminal.
[0204] Each module in the aforementioned network service security authentication device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0205] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 12As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data such as the authenticator manufacturer's public key certificate. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a security authentication method for a network service is implemented.
[0206] Those skilled in the art will understand that Figure 12 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0207] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the network service security authentication method of the above-disclosed embodiment when executing the computer program.
[0208] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the network service security authentication method of the above-disclosed embodiment is implemented.
[0209] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the network service security authentication method of the above disclosed embodiment is implemented.
[0210] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0211] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0212] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0213] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A security authentication method for network services, characterized in that: Applied to a server corresponding to a target network service, the method includes: In response to a login operation by a user terminal to the server, sending a first UAF authentication request for the user terminal to the user terminal, and receiving a first authentication response information matching the first UAF authentication request, obtained by the user terminal by invoking an authenticator matching the first UAF authentication request; If the first authentication response information indicates that the authentication is successful, sending an authentication success message to the user terminal; After the user terminal logs in to the server based on the authentication success message, if a preset security authentication trigger condition is met, the credit assessment feature matched by the user terminal is input into a preset trust assessment model to obtain a trust assessment result of the user terminal; If the trust evaluation result satisfies a preset condition, a second UAF authentication request for the user terminal is sent to the user terminal, and a second authentication response information matching the second UAF authentication request is received by the user terminal by invoking the authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors.
2. The method according to claim 1, characterized in that The first authentication response information includes: first digital signature information and authenticator response information; the first digital signature information is generated by the authenticator matching the first UAF authentication request based on a pre-generated user certificate private key associated with the server and the user terminal; The sending an authentication success message to the user terminal when the first authentication response information indicates that the authentication is successful includes: Parsing the first authentication response message to obtain the first digital signature information; decrypting and verifying the first digital signature information using a public key of a user certificate associated with the server and the user terminal, which is pre-stored on the server, and obtaining an authentication result represented by a response information of the authenticator after the decryption and verification of the first digital signature information passes; When the authentication result represented by the authenticator response information is authentication passed, an authentication success message is sent to the user terminal.
3. The method according to claim 2, characterized in that Before decrypting and verifying the first digital signature information using the public key of the user certificate associated with the server and the user terminal pre-stored on the server, the method further includes: In response to a registration operation by the user terminal with respect to the server, sending a registration request for the user terminal to the user terminal, and receiving registration response information matching the registration request, obtained by the user terminal by invoking an authenticator matching the registration request; the registration response information including a public key of a user certificate associated between the server and the user terminal; Parse the registration response information, and if the registration response message indicates that the authentication is successful, obtain and store the public key of the user certificate associated with the server and the user terminal from the registration response information, and send a registration success message to the user terminal.
4. The method according to claim 3, characterized in that The registration response message further includes: second digital signature information and authenticator registration response information; the second digital signature information is generated by the authenticator matching the registration request based on the authenticator private key of the authenticator; When the registration response message indicates that the authentication is successful, obtaining and storing the public key of the user certificate associated between the server and the user terminal from the registration response message, and sending a registration success message to the user terminal include: Obtaining an authenticator public key of an authenticator that matches the registration request; Decrypt and verify the second digital signature information using the authenticator public key, and after the decryption and verification of the second digital signature information passes, obtain the authentication result represented by the authenticator registration response information; When the authentication result represented by the authenticator registration response information is authentication success, the user certificate public key associated between the server and the user terminal is obtained from the registration response information and stored, and a registration success message is sent to the user terminal.
5. The method according to claim 1, wherein The trust evaluation result is represented by a trust score of the user terminal; The sending, when the trust evaluation result satisfies a preset condition, a second UAF authentication request for the user terminal to the user terminal includes: If the trust score is less than a preset trust score threshold, sending the second UAF authentication request to the user terminal.
6. A security authentication method for network services, characterized in that: Applied to a user terminal, the method includes: Triggering a login operation for the server corresponding to the target network service, and receiving a first UAF authentication request returned by the server in response to the login operation; Based on the first UAF authentication request, invoking an authenticator that matches the first UAF authentication request, obtaining first authentication response information that matches the first UAF authentication request, and sending the first authentication response information to the server; receiving an authentication success message returned by the server when the first authentication response information indicates that the authentication is successful; After logging into the server based on the authentication success message, if a second UAF authentication request sent by the server is received, the authenticator matching the second UAF authentication request is called to obtain second authentication response information matching the second UAF authentication request, and the second authentication response information is sent to the server; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors; the second UAF authentication request is processed by the server, under a preset security authentication trigger condition, by inputting the credit assessment feature matched by the user terminal into a preset trust assessment model to obtain a trust assessment result of the user terminal, and the trust assessment result is sent to the user terminal if the preset condition is met.
7. The method according to claim 6, characterized in that The calling, based on the first UAF authentication request, an authenticator that matches the first UAF authentication request, and obtaining first authentication response information that matches the first UAF authentication request includes: Parsing the first UAF authentication request, determining an authenticator that matches the first UAF authentication request, and invoking an ASM authentication module; the ASM authentication module is configured to generate a key handle access token, access the authenticator that matches the first UAF authentication request through the key handle access token, and receive an authenticator response information returned by the authenticator that matches the first UAF authentication request; The authenticator response information is received from the ASM authentication module, and first authentication response information matching the authenticator response information is generated.
8. The method according to claim 7, characterized in that The authenticator that matches the first UAF authentication request is further configured to obtain a pre-generated user certificate private key associated with the server and the user terminal, generate first digital signature information corresponding to the authenticator response information using the user certificate private key, and return the first digital signature information and the authenticator response information to the ASM authentication module; The receiving the authenticator response information from the ASM authentication module and generating first authentication response information matching the authenticator response information includes: The authenticator response information and the first digital signature information are received from the ASM authentication module, and the first authentication response information is generated according to the authenticator response information and the first digital signature information.
9. The method according to claim 8, characterized in that Before parsing the first UAF authentication request, the method further includes: triggering a registration operation to the server, and receiving a registration request returned by the server in response to the login operation; Parsing the registration request, determining an authenticator that matches the registration request, and calling the ASM authentication module; the ASM authentication module is used to generate a key handle access token, access the authenticator that matches the registration request through the key handle access token, and receive authenticator registration response information returned by the authenticator that matches the registration request; The authenticator registration response information is received from the ASM authentication module, and registration response information corresponding to the authenticator registration response information is generated and sent to the server; the server is used to parse the registration response information, and when the authentication result represented by the authenticator registration response information is authentication passed, a registration success message is sent to the user terminal.
10. The method according to claim 9, characterized in that The authenticator that matches the registration request is further configured to generate and store a user certificate private key and a user certificate public key associated with the server and the user terminal, and to generate second digital signature information corresponding to the authenticator registration response information using the authenticator private key of the authenticator, and to return the user certificate public key, the second digital signature information, and the authenticator registration response information to the ASM authentication module; The receiving the authenticator registration response information from the ASM authentication module, generating registration response information corresponding to the authenticator registration response information, and sending the registration response information to the server includes: The user certificate public key, the second digital signature information and the authenticator registration response information are received from the ASM authentication module, and the registration response information is generated based on the user certificate public key, the second digital signature information and the authenticator registration response information, and sent to the server; the server is used to parse the registration response information, and use the authenticator public key of the authenticator that matches the registration request obtained in advance to decrypt and verify the second digital signature information, and after the decryption and verification of the second digital signature information is passed, obtain the authentication result represented by the authenticator registration response information, and when the authentication result represented by the authenticator registration response information is authentication passed, obtain the user certificate public key associated with the server and the user terminal from the registration response information and store it, and send a registration success message to the user terminal.
11. A security authentication system for network services, characterized in that: include: The server and user terminal corresponding to the target network service; The server is configured to send a first UAF authentication request for the user terminal to the user terminal in response to a login operation of the user terminal to the server; the user terminal being configured to call, based on the first UAF authentication request, an authenticator matching the first UAF authentication request, obtain first authentication response information matching the first UAF authentication request, and send the first authentication response information to the server; The server is further configured to, if the first authentication response information indicates that the authentication is successful, send an authentication success message to the user terminal; and after the user terminal logs in to the server based on the authentication success message, if a preset security authentication trigger condition is satisfied, input the credit assessment feature matched by the user terminal into a preset trust assessment model to obtain a trust assessment result for the user terminal; If the trust evaluation result satisfies a preset condition, sending a second UAF authentication request for the user terminal to the user terminal; the authenticator that matches the first UAF authentication request and the authenticator that matches the second UAF authentication request are authenticators with different authentication factors; The user terminal is further configured to call an authenticator that matches the second UAF authentication request, obtain second authentication response information that matches the second UAF authentication request, and send the second authentication response information to the server.
12. The system according to claim 11, wherein: Also includes: ASM certification module; The user terminal is further configured to parse the first UAF authentication request, determine an authenticator that matches the first UAF authentication request, and call the ASM authentication module; The ASM authentication module is configured to generate a key handle access token, access the authenticator that matches the first UAF authentication request through the key handle access token, and receive an authenticator response information returned by the authenticator that matches the first UAF authentication request; The user terminal is further configured to receive the authenticator response information from the ASM authentication module and generate first authentication response information matching the authenticator response information.
13. A security authentication device for network services, characterized in that: Applicable to the server corresponding to the target network service, including: a response message receiving module, in response to a login operation of the user terminal to the server, sending a first UAF authentication request for the user terminal to the user terminal, and receiving a first authentication response message matching the first UAF authentication request, obtained by the user terminal by invoking an authenticator matching the first UAF authentication request; a success message sending module, configured to send an authentication success message to the user terminal when the first authentication response information indicates that the authentication is successful; an evaluation result generating module, which, after the user terminal logs in to the server based on the authentication success message, inputs the credit evaluation features matched by the user terminal into a preset trust evaluation model if a preset security authentication trigger condition is satisfied, to obtain a trust evaluation result of the user terminal; The judgment module sends a second UAF authentication request for the user terminal to the user terminal if the trust evaluation result satisfies a preset condition, and receives a second authentication response information matching the second UAF authentication request, obtained by the user terminal by invoking the authenticator matching the second UAF authentication request; the authenticator matching the first UAF authentication request and the authenticator matching the second UAF authentication request are authenticators with different authentication factors.
14. A security authentication device for network services, characterized in that: Applied to user terminals, including: an authentication request receiving module that triggers a login operation on a server corresponding to a target network service and receives a first UAF authentication request returned by the server in response to the login operation; a response message generation module that, based on the first UAF authentication request, calls an authenticator that matches the first UAF authentication request, obtains first authentication response information that matches the first UAF authentication request, and sends the first authentication response information to the server; a success message receiving module, receiving an authentication success message returned by the server when the first authentication response information indicates that the authentication is successful; The authentication module, after logging into the server based on the authentication success message, if receiving a second UAF authentication request sent by the server, calls an authenticator that matches the second UAF authentication request, obtains second authentication response information that matches the second UAF authentication request, and sends the second authentication response information to the server; the authenticator that matches the first UAF authentication request and the authenticator that matches the second UAF authentication request are authenticators with different authentication factors; the server, under a preset security authentication trigger condition, inputs the credit assessment feature matched by the user terminal into a preset trust assessment model to obtain a trust assessment result of the user terminal, and sends the trust assessment result to the user terminal if the trust assessment result meets a preset condition.
15. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.
16. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
17. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
Citation Information
Patent Citations
Identity authentication method and identity authentication system
CN112953970A
Identity authentication method and device
CN114760040A