Security Authentication Method, Device and Storage Medium
Through the operator authentication server and blockchain certification technology, the number acquisition verification and authorization are carried out based on the user's native mobile phone number, which solves the problems of high cost of login methods, cumbersome processes and risk of logging in the existing technology, and achieves higher user login security and convenience.
Patent Information
- Application Number
- CN202311349207.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-17
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2043-10-17
AI Technical Summary
In the prior art, the portrait comparison login method is costly and the process is cumbersome, and there is a risk of leakage and logging in a password account, so the user login experience is poor.
Through the operator authentication server, blockchain certification technology is used to check and authorize and authenticate the number based on the user's native mobile phone number to realize secure account login.
It improves the security and convenience of user login, ensures the non-refutability of user operations and the traceability of login, and reduces the risk of login.
Smart Images

Figure CN117579245B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security authentication technologies, and in particular, to a security authentication method, apparatus, and storage medium. Background Art
[0002] At present, some platforms in the market adopt relevant methods of portrait comparison for login, using user avatars in combination with relevant user information such as name and ID card to verify the three elements of the user portrait to ensure real-name login by the user himself. However, the use method of this method has a high cost, and the process during user login is cumbersome and time-consuming, resulting in a poor user login experience.
[0003] There are also some platforms that use password account login without verification. In this way, the user password may be leaked, and there are related phenomena such as unauthorized login by others for the user's login, and the login history cannot be traced. Summary of the Invention
[0004] This application provides a security authentication method, apparatus, and storage medium to at least improve the security and convenience during user login. The technical solution of this application is as follows:
[0005] In a first aspect, an embodiment of this application provides a security authentication method. The security authentication method is applied to an operator authentication server, and includes:
[0006] Receiving a number-taking request from a terminal application, and returning the local mobile phone number of the corresponding terminal to the terminal application;
[0007] Receiving an authorization request sent by the terminal application based on the local mobile phone number, sending an authorization certificate to the terminal application, and storing the authorization-related information on a blockchain;
[0008] Receiving an authentication request carrying the authorization certificate sent by the terminal application, returning an authentication result, and storing the authentication-related information on a blockchain; wherein, the authentication result is used to indicate whether the terminal application allows the corresponding terminal user to log in to the terminal application.
[0009] In some implementation manners, the receiving an authentication request carrying the authorization certificate sent by the terminal application, returning an authentication result, and storing the authentication-related information on a blockchain includes:
[0010] Receiving an authentication request carrying the authorization certificate sent by the terminal application from a third-party service provider;
[0011] Verifying and authenticating the authorization certificate sent by the terminal application, returning an authentication result to the third-party service provider, and storing the authentication-related information on a blockchain.
[0012] In some implementations, verifying and authenticating the authorization credentials sent by the terminal application, returning the authentication result to the third-party service provider, and storing the authentication-related information on the blockchain includes:
[0013] Verifying and authenticating the authorization credentials sent by multiple terminal applications in the form of a multi-threaded workflow queue;
[0014] Storing multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue.
[0015] In some implementations, before storing multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue, it further includes:
[0016] Obtaining a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to multiple pieces of the authentication-related information;
[0017] Determining whether to store multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded working efficiency factor and a preset threshold.
[0018] In some implementations, sending authorization credentials to the terminal application and storing the authorization-related information on the blockchain includes:
[0019] Obtaining a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to multiple pieces of the authorization-related information;
[0020] Determining whether to store multiple authorization-related information on the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded working efficiency factor and a preset threshold;
[0021] After the determination, sending authorization credentials to the terminal application and storing the authorization-related information on the blockchain in the form of a multi-threaded workflow queue.
[0022] In some implementations, before storing on the blockchain, it further includes:
[0023] Extracting key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through a channel phase response key extraction algorithm;
[0024] Verifying the key consistency between the operator authentication server and the blockchain platform based on the extracted key pair information.
[0025] In some implementations, the extracting key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through a channel phase response key extraction algorithm includes:
[0026] Based on the blockchain, receive the mismatched bits containing the correction sequence published by a trusted third party;
[0027] Based on the mismatched bits containing the correction sequence published by the third party, extract key pair information from the key data packet sent by the blockchain platform through the channel phase response key extraction algorithm; wherein, the authorization credential serves as a temporary credibility proof for the entire session between the operator authentication server and the blockchain platform.
[0028] In a second aspect, an embodiment of the present application provides a security authentication method, which is applied to a terminal and includes:
[0029] In response to a terminal application startup operation, obtain the local mobile phone number by taking a number through a gateway;
[0030] Based on the local mobile phone number and the mobile phone number input by the user, perform local number verification;
[0031] After the verification passes, send an authorization request to the operator authentication server and receive the authorization credential returned by the operator authentication server based on the authorization request; wherein, when the operator authentication server returns the authorization credential, it stores the authorization-related information on the blockchain;
[0032] Send the authorization credential to a third-party capability provider, instruct the third-party capability provider to send the authorization credential to the operator authentication server for authentication verification, and receive the authentication result returned by the third-party capability provider; wherein, when the operator authentication server returns the authentication result, it stores the authentication-related information on the blockchain;
[0033] Based on the authentication result, obtain the login authorization of the terminal application.
[0034] In some implementation manners, the obtaining the local mobile phone number by taking a number through a gateway includes:
[0035] Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK;
[0036] Obtain the mobile phone number voucher returned by the operator authentication server based on the mobile phone number voucher application;
[0037] Based on the mobile phone number voucher, send a number-taking voucher application to the operator authentication server through the operator authentication SDK;
[0038] Obtain the number-taking voucher returned by the operator authentication server based on the number-taking voucher application;
[0039] Based on the number-taking voucher, obtain the local mobile phone number of the corresponding terminal from the operator server through the application backend service corresponding to the terminal application.
[0040] In a third aspect, an embodiment of the present application provides a security authentication device, which is configured on the operator authentication server, and the device includes:
[0041] A number-taking processing module, configured to receive a number-taking request from a terminal application and return the local mobile phone number of the corresponding terminal to the terminal application;
[0042] An authorization processing module, configured to receive an authorization request sent by the terminal application based on the local mobile phone number, send an authorization voucher to the terminal application and store the authorization-related information on the blockchain;
[0043] An authentication processing module, configured to receive an authentication request carrying the authorization voucher sent by the terminal application, return an authentication result and store the authentication-related information on the blockchain; wherein, the authentication result is used to indicate whether the terminal application allows the corresponding terminal user to log in to the terminal application.
[0044] In some implementation manners, the authentication processing module is specifically configured to:
[0045] Receive an authentication request carrying the authorization voucher sent by the terminal application from a third-party capability provider;
[0046] Verify and authenticate the authorization voucher sent by the terminal application, return an authentication result to the third-party capability provider and store the authentication-related information on the blockchain.
[0047] In some implementation manners, when the authentication processing module verifies and authenticates the authorization voucher sent by the terminal application, returns an authentication result to the third-party capability provider and stores the authentication-related information on the blockchain, it is specifically configured to:
[0048] Verify and authenticate the authorization vouchers sent by multiple terminal applications in the form of a multi-threaded workflow queue;
[0049] Store multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue.
[0050] In some implementation manners, the authentication processing module is further configured to:
[0051] Obtain a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to multiple pieces of the authentication-related information;
[0052] Determine whether to store multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded working efficiency factor and a preset threshold.
[0053] In some implementations, the authorization processing module is specifically configured to:
[0054] Obtain a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of blockchain tasks corresponding to multiple pieces of the authorization-related information;
[0055] Determine whether to store multiple pieces of authorization-related information in the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded working efficiency factor and a preset threshold;
[0056] After the determination, send an authorization certificate to the terminal application in the form of a multi-threaded workflow queue and perform blockchain evidence storage on the authorization-related information.
[0057] In some implementations, the device further includes a key management module, which is used for:
[0058] Extract key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through a channel phase response key extraction algorithm;
[0059] Verify the key consistency between the operator authentication server and the blockchain platform based on the extracted key pair information.
[0060] In some implementations, when the key management module extracts key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through a channel phase response key extraction algorithm, it is specifically configured to:
[0061] Receive the mismatched bits including the correction sequence published by a trusted third party based on the blockchain;
[0062] Extract key pair information from the key data packet sent by the blockchain platform through a channel phase response key extraction algorithm based on the mismatched bits including the correction sequence published by the third party; wherein, the authorization certificate serves as a temporary credibility proof for the entire session between the operator authentication server and the blockchain platform.
[0063] In a fourth aspect, an embodiment of the present application provides a security authentication device, which is configured in a terminal, and the device includes:
[0064] A number fetching module, which is used to fetch a number through a gateway in response to a terminal application startup operation and obtain the local mobile phone number;
[0065] A verification module, which is used to perform local number verification based on the local mobile phone number and the mobile phone number input by the user;
[0066] A voucher application module, which is used to send an authorization request to the operator authentication server after passing the verification and receive an authorization voucher returned by the operator authentication server based on the authorization request; wherein, when the operator authentication server returns the authorization voucher, it stores the authorization-related information on the blockchain.
[0067] An authentication processing module, which is used to send the authorization voucher to a third-party capability provider, instruct the third-party capability provider to send the authorization voucher to the operator authentication server for authentication verification, and receive the authentication result returned by the third-party capability provider; wherein, when the operator authentication server returns the authentication result, it stores the authentication-related information on the blockchain.
[0068] The authentication processing module is further used to obtain the login authorization of the terminal application based on the authentication result.
[0069] In some implementation manners, the number-taking module is specifically used for:
[0070] Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK;
[0071] Obtain the mobile phone number voucher returned by the operator authentication server based on the mobile phone number voucher application;
[0072] Based on the mobile phone number voucher, send a number-taking voucher application to the operator authentication server through the operator authentication SDK;
[0073] Obtain the number-taking voucher returned by the operator authentication server based on the number-taking voucher application;
[0074] Based on the number-taking voucher, obtain the local mobile phone number from the operator server through the application backend service corresponding to the terminal application.
[0075] In a fifth aspect, an embodiment of the present application provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the security authentication method described in the first aspect embodiment of the present application.
[0076] In a sixth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to cause the computer to execute the security authentication method described in the first aspect embodiment of the present application.
[0077] In a seventh aspect, an embodiment of the present application provides a computer program product, including computer instructions, which when executed by a processor, implement the steps of the security authentication method described in the first aspect embodiment of the present application.
[0078] The technical solution provided by the embodiment of the present application at least brings the following beneficial effects:
[0079] After the gateway obtains a number, security authentication is achieved through the authorization and authentication process, and relevant information for security authentication when the user logs in to the application is stored and certified by the blockchain, ensuring the non-repudiation of the user's operations, ensuring traceability of the login, implementing the verification of obtaining a number based on the user's local mobile phone number, and at the same time, a secure account login method with non-repudiable format for blockchain storage and certification is realized, improving the login security and convenience of the user. The operator authentication server provides authentication services in the form of a multi-threaded workflow, improving the service performance to a certain extent. The operator authentication server and the blockchain platform introduce a key extraction algorithm based on the channel phase response to verify the key consistency between the two communication parties, and use the short-term channel reciprocity and randomness to extract the secret encryption shared key, further strengthening the reliability of the security deposit.
[0080] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0081] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application, and do not constitute an improper limitation of the present application.
[0082] Figure 1 is a flowchart of a security authentication method shown according to an exemplary embodiment.
[0083] Figure 2 is an interaction diagram between a service provider, a capability provider, and an operator authentication server shown according to an example.
[0084] Figure 3 is a flowchart of a security authentication method shown according to another exemplary embodiment.
[0085] Figure 4 is a block diagram of a security authentication device shown according to an exemplary embodiment.
[0086] Figure 5 is a block diagram of a security authentication device shown according to another exemplary embodiment.
[0087] Figure 6 is a block diagram of an electronic device shown according to an exemplary embodiment. Detailed Implementation Manner
[0088] In order to enable those of ordinary skill in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0089] It should be noted that the terms "first", "second", etc. in this application are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.
[0090] In today's society, the phenomenon of telecom mobile phone fraud is common, and there are situations such as unauthorized access to user account information and theft of account information. Related situations such as leakage of user password management and other related private information management also occur frequently. How to effectively protect user accounts and account password information has become an urgent problem to be solved;
[0091] At present, some platforms in the market have adopted relevant methods of portrait comparison for login, using user avatars in combination with relevant user information such as names and ID cards to perform three-factor verification of user portraits to ensure real-name login by the user himself. However, the current usage method of this method has high costs and takes a long time. The login process for users is cumbersome, the login experience is poor, and there is no authentication information storage and evidence collection, etc.
[0092] In consideration of ensuring the security and convenience during the user login process, the technical solution of this application provides a secure account login method based on taking a number and verifying with the user's native phone number, and at the same time performing blockchain evidence storage and issuing non-repudiable formats to replace login methods such as user portrait three factors. To safely and quickly solve the problem of secure user account login, the native phone number is verified based on the user's own mobile phone number to ensure that the user's registered mobile phone number can perform relevant login operations on the native device. At the same time, blockchain evidence storage and issuing are performed to ensure that this operation is traceable and the user cannot deny it. To a certain extent, it greatly improves the security and convenience of user login.
[0093] Figure 1 It is a flowchart of a security authentication method according to an embodiment of this application. It should be noted that the security authentication method in the embodiment of this application can be applied to the security authentication device in the embodiment of this application, and this security authentication device can be configured on electronic devices such as terminals. As Figure 1 shown, the security authentication method may include the following steps.
[0094] Step S101: In response to the start operation of the terminal application, obtain the local mobile phone number by taking a number through the gateway.
[0095] When the user triggers the start operation of the terminal application (application front-end or application APP), the terminal application obtains the local mobile phone number by taking a number through the gateway.
[0096] Exemplarily, the terminal application can be an application APP installed on the mobile phone terminal or a website that requires login authentication, such as a food delivery APP, a shopping APP, etc.
[0097] As an implementation method, the implementation method for the terminal application to obtain the local mobile phone number by taking a number through the gateway includes:
[0098] Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK; obtain the mobile phone number voucher returned by the operator authentication server based on the mobile phone number voucher application; based on the mobile phone number voucher, send a number-taking voucher application to the operator authentication server through the operator authentication SDK; obtain the number-taking voucher returned by the operator authentication server based on the number-taking voucher application; based on the number-taking voucher, obtain the local mobile phone number from the operator server through the application back-end service corresponding to the terminal application.
[0099] It should be noted here that the operator authentication server can be understood as a base station, that is, the operator authentication service provided by the base station, or it can be understood as the security base service of the entire base station. The operator authentication SDK is equivalent to a component for taking a number, and the operator authentication SDK is installed on the terminal.
[0100] Exemplarily, the mobile phone terminal is equipped with an operator authentication SDK. When the mobile phone user starts the application, the application front-end takes a number through the gateway using the mobile phone traffic through the installed operator authentication SDK, initially obtains the mobile phone number mask of the SIM card, and the operator authentication SDK sends relevant information such as the mobile phone number to the operator authentication server and issues mobile phone number voucher information to the application front-end. After the application front-end obtains the mobile phone number voucher information, it authorizes. The application front-end requests the operator authentication server through the mobile phone number voucher information to obtain relevant number-taking voucher token parameters and returns the number-taking voucher token parameters to the operator authentication SDK. The application front-end passes the number-taking voucher to the application server, and the application server requests the operator authentication server through the number-taking voucher to obtain the relevant local mobile phone number.
[0101] Step S102: Based on the local mobile phone number and the mobile phone number input by the user, perform local number verification.
[0102] After the application front-end obtains the local mobile phone number through gateway number fetching, it then performs local number verification with the mobile phone number entered by the local user or the registered mobile phone number to determine whether it is an operation on the local number.
[0103] Step S103, after the verification passes, send an authorization request to the operator authentication server, and receive the authorization credential returned by the operator authentication server based on the authorization request; wherein, when the operator authentication server returns the authorization credential, it stores the authorization-related information on the blockchain.
[0104] The application front-end requests authorization from the operator authentication server and obtains the authorization credential feedback by the operator authentication server.
[0105] Step S104, send the authorization credential to the third-party capability provider, instruct the third-party capability provider to send the authorization credential to the operator authentication server for authentication verification, and receive the authentication result returned by the third-party capability provider; wherein, when the operator authentication server returns the authentication result, it stores the authentication-related information on the blockchain.
[0106] In this embodiment, the service direction sends the authorization credential to the third-party capability provider (referred to as the capability provider for short), instructing the third-party capability provider to send the authorization credential to the operator authentication server for authentication verification.
[0107] That is to say, as Figure 2 shown, after the service party obtains the authorization credential, it transfers the authorization credential to the capability provider, and the capability provider provides the authorization credential to the operator authentication server (service provider) for authentication operation and returns the authentication result.
[0108] Here it should be noted that the service party can be understood as the application, the application front-end and the application service can be understood as the front-end and back-end of the service party, the service party is equivalent to the user of the operator, and the energy cube can be understood as an intermediate agent, which can recommend the operator's products to the service party.
[0109] Step S105, based on the authentication result, obtain the login authorization of the terminal application.
[0110] After the authentication is successful, the user can pass the security authentication and log in to the application.
[0111] After logging in, relevant call record information can also be recorded and pushed to the call record system through the message middleware (kafka / rabbaitMQ), and the information related to call records and authorization authentication is pushed into the database for storage.
[0112] The security authentication method of the embodiment of the present application, after the gateway obtains a number, realizes security authentication through the authorization and authentication processes, and stores and issues relevant information related to the security authentication when the user logs in to the application through the blockchain, ensuring the non-repudiation of the user's operations, ensuring traceability of the login, realizing the verification of obtaining a number based on the user's local mobile phone number, and at the same time implementing a secure account login method with non-repudiable format for blockchain storage and issuance, improving the login security and convenience of the user.
[0113] Figure 3 It is a flowchart of the security authentication method according to an embodiment of the present application. It should be noted that the security authentication method of the embodiment of the present application can be applied to the security authentication device of the embodiment of the present application, and the security authentication device can be configured on electronic devices such as the operator authentication server. As Figure 3 shown, the security authentication method may include the following steps.
[0114] Step S201, receive a number obtaining request from the terminal application, and return the local mobile phone number of the corresponding terminal to the terminal application.
[0115] For the process of the gateway obtaining a number, refer to the specific implementation process of step S101 in the above embodiment, which will not be elaborated here.
[0116] Step S202, receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization credential to the terminal application, and store the authorization-related information in the blockchain.
[0117] The operator authentication server receives the authorization request sent by the terminal application based on the local mobile phone number, sends an authorization credential to the terminal application, and stores the authorization-related information in the blockchain. Sending the authorization credential and storing the authorization-related information in the blockchain are implemented through different threads.
[0118] During the authorization process, two agreements are made for the authorization credential (authorization token):
[0119] 1. Persistence: If the authorization token is specified as a persistent format, then in addition to storing the authorization token in the system cache according to the operation management configuration cache time, the authorization token also needs to be stored in the database. In the storage format, the user and the application service party agree on the storage validity period. When within the valid time, the authorization token is judged to be valid, otherwise, the token is invalid. 2. Non-persistence: If the authorization token is specified as a non-persistent format, then only system caching is required according to the cache time. Among them, the generation format of the authorization token also needs to be associated with the user appid and the ability attributes used by the user.
[0120] In some implementations, the operator authentication server stores multiple authorization-related information from multiple terminals in the blockchain in the form of a multi-threaded workflow queue.
[0121] Step S203: Receive an authentication request carrying the authorization credential sent by the terminal application, return an authentication result, and perform blockchain evidence storage on the authentication-related information; wherein, the authentication result is used to indicate whether the corresponding terminal user is allowed to log in to the terminal application.
[0122] The operator authentication server receives an authentication request carrying the authorization credential sent by the terminal application, returns an authentication result, and performs blockchain evidence storage on the authentication-related information. The authentication-related information may include, but is not limited to, process information related to the authentication process, relevant user information, authentication credentials, user operation information, etc.
[0123] In some implementations, the operator authentication server: receives an authentication request sent by a third-party capability provider and carrying the authorization credential sent by the terminal application; verifies and authenticates the authorization credential sent by the terminal application, returns an authentication result to the third-party capability provider, and performs blockchain evidence storage on the authentication-related information.
[0124] It can be understood that, as Figure 2 shown, the authorization credential received by the operator authentication server is sent by the capability provider. That is, the operator authentication server receives the authorization credential forwarded by the terminal application through the capability provider; verifies and authenticates the authorization credential sent by the terminal application, and returns an authentication result to the capability provider. The capability provider can select multiple authorization credentials and send them to the operator authentication server for verification and authentication of the authorization credentials at the same time. That is, the capability provider as an intermediate agent can select to send multiple authorization credentials and apply for an authentication service from the operator authentication server, that is, apply for token verification and authentication of the security base.
[0125] The operator authentication server can verify and authenticate the authorization credentials sent by multiple terminal applications in the form of a multi-threaded workflow queue; store multiple authentication-related information in the blockchain in the form of a multi-threaded workflow queue; store multiple authorization-related information in the blockchain in the form of a multi-threaded workflow queue. That is to say, the operator authentication server can simultaneously process authorization requests and authentication requests from multiple business parties or capability providers in the form of a multi-threaded workflow queue.
[0126] In some embodiments, before storing multiple authentication-related information in the blockchain in the form of a multi-threaded workflow queue, it further includes: obtaining a multi-threaded work efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to the multiple authentication-related information; determining whether to store the multiple authentication-related information in the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded work efficiency factor and a preset threshold.
[0127] Exemplarily, a user thread (i.e., the application party) submits authentication parameters from multiple terminals to the multi-threaded workflow of the operator authentication server; multiple tasks enter the multi-threaded workflow queue; the multi-threaded tasks dequeue and perform an on-chain operation on the blockchain; the multi-threaded workflow ends and the process life cycle ends; then the user's information is reported to the blockchain platform, and the blockchain performs evidence storage and certification, and the user operation information is uploaded to the chain.
[0128] Among them, the working method of the multi-threaded work queue refers to the following formula:
[0129]
[0130] Among them, f (i) represents the efficiency factor result of the multi-threaded work queue, i represents the number of multi-threaded tasks, m represents the utilization rate of the multi-threaded pool, β represents the CPU performance utilization rate of the server machine, δ represents the amount of text for each on-chain operation, and h cost represents the time-consuming for each on-chain evidence storage.
[0131] Among them,
[0132] This involves the working principle of the multi-threaded pool. ω(i,m) represents the multi-threaded utilization rate, P represents the number of available cores of the CPU. When the number of created threads i is less than p, the thread queue is not created; when the number of created threads i is greater than p, the thread queue is created. The meaning expressed here is that when i is less than p, the efficiency can reach the maximum value, and when i is greater than p, the efficiency decreases in the form of a fractional function.
[0133] Among them,
[0134] Among them, represents the memory usage and utilization rate. Among them, N represents a constant greater than 0, i is the number of threads, sigmoid(i) is the activation function (since i is greater than 0, its value ranges from 0.5 to 1), and V represents the memory size set by the Java service virtual machine.
[0135] Among them,
[0136] Among them, in the fractional function
[0137]
[0138] Among them, τ(i, h cost ) represents the corresponding delay when multiple threads go on-chain:, h ′ (n) represents the time value consumed by the blockchain platform for the nth time, and the average sum is obtained after the cumulative method.
[0139]
[0140] Among them, in the numerator function
[0141] Among them, γ(i, δ) represents the size of the text request body, δ ′ (n) represents the number of texts uploaded by the security deposit platform to the blockchain platform for the nth time, and the average sum is obtained after the cumulative method.
[0142] Among them, for the multi-threaded scheduling method, a work queue mode is set up. Among them, service A plays the role of a consumer. When a task request is made each time, the relevant parameters are encapsulated and pushed into the work queue. According to the fairness principle, the workflow is "first in, first out". Another service group B plays the role of a consumer. When there are work tasks in the work queue, it is woken up and the service group consumes in slices; when there are no work tasks in the work queue, service group B goes to sleep until the work queue wakes up.
[0143] Among them, the efficiency factor represents the multi-threaded working efficiency factor, which represents the execution efficiency of batch authorization token verification and authentication in the multi-threaded state. Among them, there are positive and negative correlation parameters. Compared with the batch token verification of the non-multi-threaded workflow, the efficiency factor can show in what situations to use the multi-threaded workflow and in what situations to use the non-multi-threaded workflow. After conducting multiple tests on normal and stable services, a threshold can be set according to the weighted average Threshold It is affected by relevant parameters such as the memory of the service machine and the number of CPU cores. If:
[0144]
[0145] Then the efficiency factor is valid and the working mode of the multi-threaded workflow can be used. If,
[0146]
[0147] Then the multi-threaded workflow method is not applicable to this business scenario, and the non-multi-threaded workflow mode should be selected.
[0148] Among them, the blockchain information related to authorization mainly emphasizes the process information of the business party, while the blockchain information related to authentication emphasizes the process information of the capability party more.
[0149] In some embodiments, before performing blockchain evidence storage, it further includes:
[0150] Extract key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through the channel phase response key extraction algorithm; based on the extracted key pair information, verify the key consistency between the operator authentication server and the blockchain platform. Utilize short-term channel reciprocity and randomness to extract the secret encryption shared key, further enhancing the reliability of secure evidence storage.
[0151] Among them, the information response of the key channel has gone through three main stages, namely quantization, information reconciliation, and information extraction. The quantization stage is a mapping operation that converts the channel components into bitstreams. The information reconciliation stage is an error correction stage, which involves correcting the mismatched bits caused by imperfect channel reciprocity. The information extraction in the final stage uses a hash operation to maintain the confidentiality of the extracted key. Through the transformation and transmission of information, data information filtering and denoising are performed, and finally inverse transformation is carried out to obtain the target information.
[0152] The following is the content of the channel phase response key extraction algorithm:
[0153] 1. During the interaction between the operator authentication server and the blockchain platform, the key pair can be quantized in binary coding during transmission as:
[0154] F n (secret)
[0155] 2. When the operator authentication server sends the key data packet PV 1 to the blockchain platform at time T 1 , the frequency domain information can be expressed as:
[0156]
[0157] Among them, is a uniformly distributed phase. Since in the interval [0, 2π), it can be known that the information RV 12 received by the blockchain is:
[0158]
[0159] Among them, σ 1 (t) represents Gaussian white noise, and α 1 and θ 1 are the forward link channel gain and phase response. Finally, the noise phase received by the blockchain platform can be approximated as
[0160] 3. Similarly, the information data packet PV sent by the blockchain platform to the operator authentication server 2 , at time T 2 the frequency domain information can be expressed as:
[0161]
[0162] wherein, is a uniformly distributed phase. Since in the interval [0, 2π), it can be known that the information RV received by the operator server 21 is
[0163]
[0164] wherein, σ 2 (t) is expressed as Gaussian white noise, and α 2 and θ 2 are the forward link channel gain and phase response. Finally, the noise phase received by the blockchain platform can be approximated as
[0165] 4. From the above contents in 2 and 3, the final stage components of the operator authentication server and the blockchain platform can be obtained as:
[0166]
[0167]
[0168] wherein, the time interval is all [0, 2π).
[0169] 5. Since both RV 12 (t) and RV 21 (t) have relevant noise information amounts, it is necessary to perform data denoising on them through a filter here. The data denoising filter (curve fitting) is as follows:
[0170]
[0171] wherein, F k is the weighting coefficient, and the basis function is the rotation factor. Threshold setting is performed in the function F k to perform data denoising fitting.
[0172] 6. After the process of data fitting and denoising, the operator authentication server and the blockchain platform perform anti-coding and inverse quantization on the key pair information to obtain the corresponding information values.
[0173] In some embodiments, based on the blockchain, mismatched bits including a correction sequence are received from a trusted third party; based on the mismatched bits including the correction sequence published by the third party, key pair information is extracted from the key data packet sent by the blockchain platform through a channel phase response key extraction algorithm; wherein the authorization credential serves as a temporary credibility proof for the entire session between the operator authentication server and the blockchain platform.
[0174] It can be understood that, in order to further solve the problem that the channel phase method can only coordinate a small number of mismatched bits, resulting in certain risks in security. Also, the low-density parity-check method and turbo code in coding also have the problem of high computational complexity. In this solution, a blockchain-based coordination technology can be further designed to solve these limitations. This technology allows a trusted third party to use blockchain technology based on smart contracts by publishing mismatched bits including a correction sequence. The published user number authentication information serves as a temporary credibility proof for the entire session, rather than transmitting certificates each time, thereby saving communication costs and storage capacity.
[0175] The security authentication method of the embodiments of the present application, after obtaining a number through the gateway, realizes security authentication through an authorization and authentication process, and stores and issues relevant information for security authentication when the user logs in to the application through the blockchain, ensuring the non-repudiation of the user's operations, ensuring traceability of the login, implementing a security account login method based on verifying the number taken from the user's local mobile phone number and simultaneously performing blockchain storage and issuance in a non-repudiable format, improving the login security and convenience of the user. The operator authentication server provides authentication services in the form of a multi-threaded workflow, which improves the service performance to a certain extent. The operator authentication server and the blockchain platform introduce a key extraction algorithm based on channel phase response to verify the key consistency between the two communication parties, and use short-term channel reciprocity and randomness to extract secret encrypted shared keys, further strengthening the reliability of security storage.
[0176] Figure 4 is a block diagram of a security authentication device shown according to an exemplary embodiment. The device is configured in the operator authentication server. Refer to Figure 4 This security authentication device may include: a number obtaining processing module 401, an authorization processing module 402, and an authentication processing module 403.
[0177] Specifically, the number obtaining processing module 401 is configured to receive a number obtaining request from a terminal application and return the local mobile phone number of the corresponding terminal to the terminal application;
[0178] The authorization processing module 402 is configured to receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application, and store the authorization-related information on the blockchain;
[0179] The authentication processing module 403 is configured to receive the authentication request carrying the authorization certificate sent by the terminal application, return the authentication result, and store the authentication-related information on the blockchain; wherein, the authentication result is used to indicate whether the corresponding terminal user is allowed to log in to the terminal application.
[0180] In some implementation manners, the authentication processing module 403 is specifically configured to:
[0181] Receive the authentication request carrying the authorization certificate sent by the terminal application from a third-party capability provider;
[0182] Verify and authenticate the authorization certificate sent by the terminal application, return the authentication result to the third-party capability provider, and store the authentication-related information on the blockchain.
[0183] In some implementation manners, when the authentication processing module 403 verifies and authenticates the authorization certificate sent by the terminal application, returns the authentication result to the third-party capability provider, and stores the authentication-related information on the blockchain, it is specifically configured to:
[0184] Verify and authenticate the authorization certificates sent by multiple terminal applications in the form of a multi-threaded workflow queue;
[0185] Store multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue.
[0186] In some implementation manners, the authentication processing module 403 is further configured to:
[0187] Obtain a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to multiple pieces of the authentication-related information;
[0188] Determine whether to store multiple authentication-related information on the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded working efficiency factor and a preset threshold.
[0189] In some implementation manners, the authorization processing module 402 is specifically configured to:
[0190] Obtain a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to multiple pieces of the authorization-related information;
[0191] Based on the multi-threaded working efficiency factor and the preset threshold, determine whether to store multiple authorization-related information in the blockchain in the form of a multi-threaded workflow queue;
[0192] After the determination, send an authorization certificate to the terminal application in the form of a multi-threaded workflow queue and perform blockchain evidence storage on the authorization-related information.
[0193] In some implementation manners, the device further includes a key management module 404, which is used for:
[0194] Extract key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through a channel phase response key extraction algorithm;
[0195] Based on the extracted key pair information, verify the key consistency between the operator authentication server and the blockchain platform.
[0196] In some implementation manners, when the key management module 404 extracts key pair information from the key data packet sent by the blockchain platform to which the blockchain belongs through a channel phase response key extraction algorithm, it is specifically used for:
[0197] Based on the blockchain, receive the mismatched bits including the correction sequence published by a trusted third party;
[0198] Based on the mismatched bits including the correction sequence published by the third party, extract key pair information from the key data packet sent by the blockchain platform through a channel phase response key extraction algorithm; wherein, the authorization certificate serves as a temporary credibility proof for the entire session between the operator authentication server and the blockchain platform.
[0199] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0200] The security authentication device according to the embodiments of the present application, after obtaining a number through the gateway, realizes security authentication through the authorization and authentication processes, and stores and issues relevant information related to the security authentication when the user logs in to the application through the blockchain, ensuring the non-repudiation of the user's operations, ensuring the traceability of the login, realizing the verification of obtaining a number based on the user's local mobile phone number, and at the same time performing a secure account login method with non-repudiable format for blockchain storage and issuance, improving the login security and convenience of the user. The operator authentication server provides authentication services in the form of a multi-threaded workflow, which improves the service performance to a certain extent. The operator authentication server and the blockchain platform introduce a key extraction algorithm based on the channel phase response to verify the key consistency between the two communication parties, and use the short-term channel reciprocity and randomness to extract the secret encryption shared key, further strengthening the reliability of the secure storage.
[0201] Figure 5 is a block diagram of a security authentication device shown according to an exemplary embodiment. The device is configured in a terminal. Refer to Figure 5 and the security authentication device may include: a number obtaining module 501, a verification module 502, a credential application module 503, and an authentication processing module 504.
[0202] Specifically, the number obtaining module 501 is configured to obtain the local mobile phone number by obtaining a number through the gateway in response to the terminal application startup operation;
[0203] The verification module 502 is configured to perform local number verification based on the local mobile phone number and the mobile phone number input by the user;
[0204] The credential application module 503 is configured to send an authorization request to the operator authentication server after the verification is passed, and receive the authorization credential returned by the operator authentication server based on the authorization request; wherein, the operator authentication server stores the authorization-related information in the blockchain while returning the authorization credential;
[0205] The authentication processing module 504 is configured to send the authorization credential to the third-party capability party, instruct the third-party capability party to send the authorization credential to the operator authentication server for authentication verification, and receive the authentication result returned by the third-party capability party; wherein, the operator authentication server stores the authentication-related information in the blockchain while returning the authentication result;
[0206] The authentication processing module 505 is further configured to obtain the login authorization of the terminal application based on the authentication result.
[0207] In some implementation manners, the number obtaining module 501 is specifically configured to:
[0208] Send a mobile phone number voucher application to the operator authentication server through the operator authentication SDK;
[0209] Obtain the mobile phone number voucher returned by the operator authentication server based on the mobile phone number voucher application;
[0210] Based on the mobile phone number voucher, send a number fetching voucher application to the operator authentication server through the operator authentication SDK;
[0211] Obtain the number fetching voucher returned by the operator authentication server based on the number fetching voucher application;
[0212] Based on the number fetching voucher, obtain the local mobile phone number from the operator server through the application backend service corresponding to the terminal application.
[0213] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0214] The security authentication device of the embodiment of the present application, after the gateway fetches the number, realizes security authentication through the authorization and authentication processes, and stores and issues the relevant information for security authentication when the user logs in to the application through the blockchain, ensuring the non-repudiation of the user's operations, ensuring traceability of the login, realizing the number fetching verification based on the user's local mobile phone number, and at the same time performing the security account login method with non-repudiable format of blockchain storage and issuance, improving the login security and convenience of the user.
[0215] According to the embodiments of the present application, the present application also provides an electronic device and a readable storage medium.
[0216] As Figure 6 shown, it is a block diagram of an electronic device for implementing the method of security authentication according to the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present application described and / or claimed herein.
[0217] As Figure 6As shown, the electronic device includes: one or more processors 601, a memory 602, and interfaces for connecting the components, including a high-speed interface and a low-speed interface. Each component is interconnected using different buses and can be mounted on a common motherboard or otherwise mounted as required. The processor can process instructions executed within the electronic device, including instructions stored in the memory or on the memory for displaying graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In other embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple electronic devices can be connected, with each device providing part of the necessary operations (such as an array of servers, a set of blade servers, or a multi-processor system). Figure 6 In the example, one processor 601 is used.
[0218] The memory 602 is the non-transitory computer-readable storage medium provided by the present application. Among them, the memory stores instructions executable by at least one processor, so that the at least one processor executes the security authentication method provided by the present application. The non-transitory computer-readable storage medium of the present application stores computer instructions, and these computer instructions are used to cause a computer to execute the security authentication method provided by the present application.
[0219] As a non-transitory computer-readable storage medium, the memory 602 can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the security authentication method in the embodiments of the present application (for example, the number-taking processing module 401, the authorization processing module 402, and the authentication processing module 403 shown in the appendix). Figure 4 The processor 601 executes various functional applications and data processing of the server by running the non-transitory software programs, instructions, and modules stored in the memory 602, that is, implements the security authentication method in the above method embodiments.
[0220] The memory 602 can include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the electronic device for security authentication, etc. In addition, the memory 602 can include high-speed random access memory and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 602 optionally includes a memory remotely set relative to the processor 601, and these remote memories can be connected to the electronic device for security authentication through a network. Examples of the above networks include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0221] The electronic device for the method of security authentication may further include: an input device 603 and an output device 604. The processor 601, the memory 602, the input device 603, and the output device 604 may be connected through a bus or other means. Figure 6 Take the connection through the bus as an example.
[0222] The input device 603 can receive input digital or character information, and generate key signal inputs related to the user settings and function control of the electronic device for security authentication, such as input devices like touchscreens, keypads, mice, trackpads, touchpads, pointing sticks, one or more mouse buttons, trackballs, joysticks, etc. The output device 604 may include a display device, an auxiliary lighting device (e.g., LED), and a haptic feedback device (e.g., a vibration motor), etc. The display device may include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, and a plasma display. In some embodiments, the display device may be a touchscreen.
[0223] The various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, dedicated ASICs (application-specific integrated circuits), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0224] These computing programs (also referred to as programs, software, software applications, or code) include machine instructions for a programmable processor, and these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., a disk, an optical disc, a memory, a programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0225] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0226] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0227] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The relationship between the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other.
[0228] In an exemplary embodiment, a computer program product is also provided, which, when the instructions in the computer program product are executed by a processor of an electronic device, enables the electronic device to execute the above method.
[0229] It should also be noted that in the exemplary embodiments mentioned in the present invention, some methods or systems are described based on a series of steps or devices. However, the present invention is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps can be executed simultaneously.
[0230] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only to be considered as exemplary.
[0231] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A security authentication method, characterized in that, the security authentication method is applied to an operator authentication server, and includes: Receiving a number fetching request from a terminal application, and returning the local mobile phone number of the corresponding terminal to the terminal application; Receiving an authorization request sent by the terminal application based on the local mobile phone number, sending an authorization credential to the terminal application and performing blockchain storage of authorization-related information, including: sending an authorization credential to the terminal application and performing blockchain storage of authorization-related information in the form of a multi-threaded workflow queue, wherein the storage format of the authorization-related information includes a persistent format and a non-persistent format; Receiving an authentication request carrying the authorization credential sent by the terminal application, returning an authentication result and performing blockchain storage of authentication-related information, including: based on the blockchain, receiving mismatched bits including a correction sequence published by a trusted third party; based on the mismatched bits including the correction sequence published by the third party, extracting key pair information from the key data packet sent by the blockchain platform through a channel phase response key extraction algorithm; based on the extracted key pair information, verifying the key consistency between the operator authentication server and the blockchain platform; wherein the authentication result is used to indicate whether the corresponding terminal user is allowed to log in to the terminal application, and the authorization credential serves as a temporary credibility proof for the entire session between the operator authentication server and the blockchain platform.
2. The method according to claim 1, characterized in that, the receiving an authentication request carrying the authorization credential sent by the terminal application, returning an authentication result and performing blockchain storage of authentication-related information, includes: Receiving an authentication request sent by a third-party capability party and carrying the authorization credential sent by the terminal application; Verifying and authenticating the authorization credential sent by the terminal application, returning an authentication result to the third-party capability party and performing blockchain storage of authentication-related information.
3. The method according to claim 2, characterized in that, the verifying and authenticating the authorization credential sent by the terminal application, returning an authentication result to the third-party capability party and performing blockchain storage of authentication-related information, includes: Verifying and authenticating the authorization credentials sent by multiple terminal applications in the form of a multi-threaded workflow queue; Storing multiple authentication-related information in the blockchain in the form of a multi-threaded workflow queue.
4. The method according to claim 3, characterized in that, before storing multiple authentication-related information in the blockchain in the form of a multi-threaded workflow queue, further includes: Obtaining a multi-threaded work efficiency factor based on the resource utilization rate of the operator authentication server and the amount of on-chain tasks corresponding to multiple authentication-related information; Determining whether to store multiple authentication-related information in the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded work efficiency factor and a preset threshold.
5. The method according to claim 1, characterized in that, the sending an authorization credential to the terminal application and performing blockchain storage of authorization-related information, includes: Obtain a multi-threaded working efficiency factor based on the resource utilization rate of the operator authentication server and the amount of blockchain tasks corresponding to multiple pieces of the authorization-related information; Determine whether to store multiple pieces of authorization-related information in the blockchain in the form of a multi-threaded workflow queue based on the multi-threaded working efficiency factor and a preset threshold; After the determination, send an authorization certificate to the terminal application in the form of a multi-threaded workflow queue and perform blockchain evidence storage on the authorization-related information.
6. A security authentication method, characterized in that, the security authentication method is applied to a terminal and includes: In response to a terminal application startup operation, obtain the local mobile phone number by taking a number through a gateway; Perform local number verification based on the local mobile phone number and the mobile phone number input by the user; After the verification passes, send an authorization request to the operator authentication server and receive the authorization certificate returned by the operator authentication server based on the authorization request; wherein, when the operator authentication server returns the authorization certificate, it performs blockchain evidence storage on the authorization-related information, including: receiving the authorization certificate returned by the operator authentication server based on the authorization request in the form of a multi-threaded workflow queue, wherein the storage format of the authorization-related information includes a persistent format and a non-persistent format; Send the authorization certificate to a third-party capability provider, instruct the third-party capability provider to send the authorization certificate to the operator authentication server for authentication verification, and receive the authentication result returned by the third-party capability provider; wherein, when the operator authentication server returns the authentication result, it performs blockchain evidence storage on the authentication-related information; Obtain the login authorization of the terminal application based on the authentication result.
7. The method according to claim 6, characterized in that, the obtaining the local mobile phone number by taking a number through a gateway includes: Send a mobile phone number certificate application to the operator authentication server through the operator authentication SDK; Obtain the mobile phone number certificate returned by the operator authentication server based on the mobile phone number certificate application; Based on the mobile phone number certificate, send a number-taking certificate application to the operator authentication server through the operator authentication SDK; Obtain the number-taking certificate returned by the operator authentication server based on the number-taking certificate application; Based on the number-taking certificate, obtain the local mobile phone number from the operator authentication server through the application backend service corresponding to the terminal application.
8. A security authentication device, characterized in that, the device is configured in the operator authentication server, and the device includes: A number-taking processing module, configured to receive a number-taking request from a terminal application and return the local mobile phone number of the corresponding terminal to the terminal application; An authorization processing module, configured to receive the authorization request sent by the terminal application based on the local mobile phone number, send an authorization certificate to the terminal application and perform blockchain evidence storage on the authorization-related information, including: sending an authorization certificate to the terminal application and performing blockchain evidence storage on the authorization-related information in the form of a multi-threaded workflow queue, wherein the storage format of the authorization-related information includes a persistent format and a non-persistent format; An authentication processing module, configured to receive an authentication request carrying an authorization credential sent by the terminal application, return an authentication result, and perform blockchain evidence storage on authentication-related information, including: receiving, based on the blockchain, a mismatched bit including a correction sequence published by a trusted third party; extracting key pair information from a key data packet sent by the blockchain platform through a channel phase response key extraction algorithm based on the mismatched bit including the correction sequence published by the third party; verifying the key consistency between the operator authentication server and the blockchain platform based on the extracted key pair information; wherein, the authentication result is used to indicate whether the terminal application allows the corresponding terminal user to log in to the terminal application, and the authorization credential serves as a temporary credibility proof for the entire session between the operator authentication server and the blockchain platform.
9. A security authentication device, characterized in that, the device is configured in a terminal, and the device includes: A number-taking module, configured to obtain the local mobile phone number by taking a number through a gateway in response to a terminal application startup operation; A verification module, configured to perform local number verification based on the local mobile phone number and the mobile phone number input by the user; A credential application module, configured to send an authorization request to an operator authentication server after passing the verification, and receive an authorization credential returned by the operator authentication server based on the authorization request; wherein, when returning the authorization credential, the operator authentication server performs blockchain evidence storage on authorization-related information, including: receiving the authorization credential returned by the operator authentication server based on the authorization request in the form of a multi-threaded workflow queue, wherein the storage format of the authorization-related information includes a persistent format and a non-persistent format; An authentication processing module, configured to send the authorization credential to a third-party capability party, instruct the third-party capability party to send the authorization credential to the operator authentication server for authentication verification, and receive an authentication result returned by the third-party capability party; wherein, when returning the authentication result, the operator authentication server performs blockchain evidence storage on authentication-related information; The authentication processing module is further configured to obtain the login authorization of the terminal application based on the authentication result.
10. An electronic device, characterized in that, it includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the security authentication method according to any one of claims 1 to 5, or the security authentication method according to claim 6 or 7.
11. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, the computer instructions are used to cause the computer to execute the security authentication method according to any one of claims 1 to 5, or the security authentication method according to claim 6 or 7.
Citation Information
Patent Citations
Data processing method, device and system for block chain and medium
CN111988313A