A multi-factor continuous authentication system based on identity-based cryptography

CN117749475BActive Publication Date: 2026-09-29THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311746411.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2026-09-29
Estimated Expiration
2043-12-19

AI Technical Summary

Benefits of technology

[0019]1.保证了持续认证可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117749475B_ABST
    Figure CN117749475B_ABST
Patent Text Reader

Abstract

The application belongs to the field of information security, and discloses a multi-factor continuous authentication system based on identity-based cryptography, which mainly solves the problems of insufficient security and large resource consumption in the prior art. The system comprises an identity-based cryptography generation server, a continuous authentication server and a continuous authentication client. The identity-based cryptography generation server completes initialization of system password parameters, accepts key generation requests of the continuous authentication server and the continuous authentication client, and generates keys for the continuous authentication server and the continuous authentication client. The continuous authentication server accepts an authentication negotiation request of a user, completes confirmation of a continuous authentication attribute, and completes continuous authentication of the continuous authentication client based on the attribute. The continuous authentication client sends an authentication negotiation request to the continuous authentication server, completes authentication negotiation and determines the continuous authentication attribute, and completes identity authentication of the user based on the continuous authentication attribute. The application can improve the security of the continuous authentication protocol and reduce resource consumption, and can be used for security protection of a resource access system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security, specifically relating to a multi-factor continuous verification system based on identifier cryptography. Background Technology

[0002] Identity authentication is fundamental to ensuring the authenticity and reliability of user identities in information systems. Single-time authentication verifies a user's identity only once upon accessing the system, without continuous verification during subsequent use. This allows even authenticated devices to remain accessible to unauthorized users, compromising system security. Continuous authentication, by verifying user identity throughout the entire access process, significantly enhances security, especially multi-factor authentication, which offers even stronger protection. However, current multi-factor continuous authentication schemes rely on independent verification of each factor, failing to validate the legitimacy of access behavior through cross-validation. Furthermore, ensuring the confidentiality and integrity of feature attributes during authentication necessitates encryption of all attributes, increasing communication and computational overhead. Summary of the Invention

[0003] The purpose of this invention is to address the shortcomings of existing technologies by proposing a multi-factor continuous authentication system based on identifier cryptography. This system achieves fusion verification among multiple factors based on identifier cryptography, improves the security of continuous authentication protocols, reduces the communication overhead of continuous authentication, and ensures secure and reliable access to information systems.

[0004] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0005] A multi-factor continuous authentication system based on identifier passwords includes an identifier password generation server, a continuous authentication server, and a continuous authentication client;

[0006] The password generation server includes:

[0007] The password parameter generation submodule is used to receive the system security parameters set by the system administrator, select the identifier cryptographic algorithm standard, generate the identifier cryptographic system public parameters according to the requirements of the system security parameters and the identifier cryptographic algorithm standard, send the identifier cryptographic system public parameters to the key generation submodule, and send the public part of the identifier cryptographic system public parameters to the continuous authentication server and continuous authentication client in the system.

[0008] The key generation submodule is used to receive the identifier private key generation request and identifier ID sent by the continuous authentication server or continuous authentication client, generate the identifier cryptographic private key corresponding to the identifier ID according to the public parameters of the identifier cryptographic system and the identifier cryptographic algorithm standard, and return the identifier cryptographic private key to the requester.

[0009] Continuous authentication servers include:

[0010] The initialization submodule is used to initialize the parameters of the continuous authentication server, including setting the continuous authentication frequency and the identifier ID of the continuous authentication server. s It also retrieves a list of supported authentication attributes and sends initialization parameters to each continuous authentication client; it sets security protection rules based on the security requirements of business resources and sends these rules to the continuous authentication data verification submodule and each continuous authentication client; it obtains a list of feature attributes supported by the continuous authentication server, categorizes the obtained feature information according to its security level, and sends the categorized feature information to each continuous authentication client; and it also identifies the continuous authentication server ID. S Send an identifier password generation request to the identifier private key generation server and receive the identifier password private key SK returned by the identifier password generation server. S And send the identifier password private key to the continuous authentication data verification submodule;

[0011] The continuous authentication data verification submodule receives continuous authentication attribute negotiation requests and selected continuous authentication attributes from continuous authentication clients. It then sets security protection rules based on the security requirements of business resources to determine the compliance of the continuous authentication attributes and returns the continuous authentication attribute negotiation results to the continuous authentication client. Furthermore, it categorizes the attributes in the continuous authentication attribute list into a set of fixed-value attributes and a set of variable-value attributes based on whether the attributes in each dimension are fixed values. Finally, it verifies the data based on the fixed-value attribute set and the continuous authentication client's identifier ID. c Generate a continuous authentication identity ID for this business access by the continuous authentication client. ac And will continue to authenticate identity IDs ac Send to the continuous authentication client, and then set the threshold for each attribute in the variable attribute set: {T b1 T b2 ,…,T bβ}, and sends the set threshold to the attribute compliance judgment submodule; it is also used to send the continuous authentication identifier ID of the continuous authentication client. ac Sends a request to the server's cryptographic service submodule to calculate the identifier public key, and receives the continuous authentication identifier public key PK returned by the server's cryptographic service submodule. acIt receives continuous authentication requests, continuous authentication attribute ciphertext, and continuous authentication attribute signature data from continuous authentication clients, and then forwards the continuous authentication attribute ciphertext and the continuous authentication server identifier private key SK. s The system sends a data decryption request to the server's cryptographic service submodule to obtain the corresponding continuous authentication attribute plaintext. It then combines the continuous authentication attribute plaintext, continuous authentication attribute signature data, and the continuous authentication client's public key PK. ac Send the password service submodule to the server and initiate a signature verification request to obtain the signature verification result; and send the continuous authentication attribute to the attribute compliance judgment submodule and initiate an attribute compliance judgment request, and return the continuous authentication result to the continuous authentication client based on the judgment result;

[0012] The attribute compliance determination submodule is used to determine whether the continuous authentication attributes of the continuous authentication client are compliant. It receives continuous authentication attributes from the continuous authentication data verification submodule and processes them according to the system-defined rules and the variable attribute set threshold {T} set by the continuous authentication data verification submodule. b1 T b2 ,…,T bβ The system assesses the compliance of each attribute in the continuous authentication properties and returns the assessment result.

[0013] The server cryptographic service submodule is used to calculate the public key corresponding to the identifier ID based on the continuous authentication identifier ID input by the continuous authentication data verification submodule, and to complete the decryption and signature verification operations in the continuous authentication process; it also receives the public key calculation request from the continuous authentication data verification submodule and the continuous authentication identifier ID of the continuous authentication client, and calculates the continuous authentication identifier public key PK of the continuous authentication client according to the public parameters of the identifier cryptosystem and the identifier cryptographic algorithm standard. ac The continuous authentication public key PK of the continuous authentication client will be used. ac The data is returned to the continuous authentication data verification submodule; and the continuous authentication attribute ciphertext and the continuous authentication server identifier private key SK are received from the continuous authentication data verification submodule. S Based on the identifier cryptographic algorithm standard and the private key SK of the continuous authentication server. S Calculate the plaintext of the continuous authentication attribute and return it to the continuous authentication data verification submodule; and receive the data signature verification request initiated by the continuous authentication data verification submodule, along with the input plaintext of the continuous authentication attribute and the continuous authentication client's public key PK. ac Based on the identifier cryptography algorithm standard and the public key PK of the continuous authentication identifier of the continuous authentication client. ac Verify the signature of the continuous authentication attribute and return the signature verification result to the continuous authentication data verification submodule;

[0014] Continuous authentication clients include:

[0015] The continuous authentication data generation submodule is used to periodically generate continuous authentication data according to the continuous authentication frequency set by the continuous authentication server and send it to the continuous authentication server; and to send the identifier ID of the continuous authentication server to the client cryptographic service submodule and initiate an identifier public key calculation request, and receive the continuous authentication server identifier public key PK returned by the client cryptographic service submodule. S It is also used to obtain the authentication attributes supported by the current continuous authentication client, generate a continuous authentication attribute list for accessing business resources based on the server's supported feature attribute list and security protection level requirement rules, send the continuous authentication attribute list to the continuous authentication server, and initiate a continuous authentication attribute negotiation request; it is also used to send the continuous authentication client's continuous authentication identifier ID to the identifier password generation server and initiate an identifier private key generation request, and receive the continuous authentication client's continuous authentication identifier private key SK returned by the identifier password generation server. ac ; and according to the continuous authentication frequency set by the continuous authentication server, periodically send information collection requests to the information collection submodule, and receive the continuous authentication attributes returned by the information collection submodule; and transmit the continuous authentication server's public key PK. S It sends the continuous authentication attributes to the client's cryptographic service submodule and initiates a data encryption request to the client's cryptographic service submodule, and receives the ciphertext of the continuous authentication attributes returned by the client's cryptographic service submodule; it is also used to transmit the authentication identifier private key SK of the continuous authentication client. ac It sends the continuous authentication attribute to the client password service submodule, initiates a data signature request to the client password service submodule, and receives the continuous authentication attribute signature returned by the client password service submodule; it is also used to send the received continuous authentication attribute ciphertext and continuous authentication attribute signature data to the continuous authentication server, and initiates a continuous authentication request to the continuous authentication server.

[0016] The client-side cryptographic service submodule receives the identifier public key calculation request and the input continuous authentication server identifier ID from the continuous authentication data generation submodule. It then calculates the continuous authentication server identifier public key PK based on the common part of the identifier cryptographic public parameters and the identifier cryptographic algorithm standard. S The public key PK of the authentication server will be continuously verified. S The data is returned to the continuous authentication data generation submodule; and the continuous authentication attributes and the continuous authentication server identifier public key PK are received from the continuous authentication data generation submodule. S Based on the identifier cryptographic algorithm standard and the public key PK of the continuous authentication server identifier SIt calculates the ciphertext of the continuous authentication attributes and returns it to the continuous authentication data generation submodule; it is also used to receive data signature requests initiated by the continuous authentication data generation submodule and the authentication identifier private key SK of the continuous authentication client. ac Based on the identifier cryptography algorithm standard and the authentication identifier private key SK of the continuous authentication client. ac Calculate the signature of the continuous authentication attribute and return the signature of the continuous authentication attribute to the continuous authentication data generation submodule;

[0017] The information acquisition submodule is used to receive continuous authentication attribute information acquisition requests initiated by the continuous authentication data generation submodule, call local sensors to collect the corresponding attribute values ​​according to the information request requirements, and return the collected continuous authentication attributes to the continuous authentication data generation submodule.

[0018] The present invention has the following advantages:

[0019] 1. Ensures continuous certification reliability.

[0020] This invention generates a user's identifier ID based on fixed attributes, and then generates the user's public and private keys based on this identifier ID. The user's private key is then used to sign variable attributes, thereby completing continuous authentication. This process integrates various dimensions of the continuous authentication client's attributes, enhancing the security of the continuous authentication process.

[0021] 2. Reduced computational and communication overhead during the identity authentication process.

[0022] In the authentication process, the fixed numerical attributes no longer need to be sent to the continuous authentication server for verification. This eliminates the need to encrypt the fixed attribute features and send the ciphertext, thus reducing the computational and communication overhead in the continuous authentication process. Attached Figure Description

[0023] Figure 1 This is a block diagram of the invention system. Detailed Implementation

[0024] The present invention will now be described in further detail with reference to the accompanying drawings.

[0025] Reference Figure 1 A multi-factor continuous authentication system based on identifier-based cryptography comprises three main modules: an identifier-based cryptography generation server, a continuous authentication server, and a continuous authentication client. Among them:

[0026] The identifier password generation server initializes the system password parameters and generates the identifier private key corresponding to the identifier for the continuous authentication server and continuous authentication client.

[0027] The continuous authentication server initializes the system's continuous authentication parameters, negotiates the continuous authentication protocol with the continuous authentication client, and assigns an identifier to the continuous authentication client based on its identifier and fixed attributes; it also completes the continuous authentication of the client represented by the continuous authentication client based on the continuous authentication requests sent by the client.

[0028] The continuous authentication client generates a list of authentication attributes based on the security attributes it supports and the attributes that the current user can provide, and periodically sends continuous authentication information to the continuous authentication server to complete continuous authentication based on the list of authentication attributes.

[0029] The identifier password generation server includes a password parameter generation submodule and a key generation submodule.

[0030] The password parameter generation submodule is used to receive the system security parameters set by the system administrator, select the identification cryptographic algorithm standard, such as "GM / T 0044-2016 SM9 identification cryptographic algorithm" published by the State Cryptography Administration, generate identification cryptographic system public parameters according to the requirements of the system security parameters and the identification cryptographic algorithm standard, send the identification cryptographic system public parameters to the key generation submodule, and send the public part of the identification cryptographic system public parameters to the continuous authentication server and continuous authentication client in the system.

[0031] The key generation submodule is used to receive the identifier private key generation request and identifier ID sent by the continuous authentication server or continuous authentication client, generate the identifier cryptographic private key corresponding to the identifier ID according to the public parameters of the identifier cryptographic system and the identifier cryptographic algorithm standard, and return the identifier cryptographic private key to the requester.

[0032] The continuous authentication server includes a server initialization submodule, a continuous authentication data verification submodule, an attribute compliance judgment submodule, and a server password service submodule.

[0033] The initialization submodule is used to initialize the parameters of the continuous authentication server, including setting the continuous authentication frequency and the identifier ID of the continuous authentication server. s It also retrieves a list of supported authentication attributes and sends initialization parameters to each continuous authentication client; it is used to set security protection rules according to the security protection requirements of business resources and send the security protection rules to the continuous authentication data verification submodule and each continuous authentication client; and it retrieves a list of feature attributes supported by the continuous authentication server and categorizes the retrieved feature information into n classes according to the security level of the feature information: The categorized feature information is then sent to each continuous authentication client, among which... The meaning is that the security level is L. i The feature information contains a total of m i There are: It is also used to identify the continuous authentication server ID. s Send an identifier password generation request to the identifier private key generation server and receive the identifier password private key SK returned by the identifier password generation server. S And send the identifier password private key to the continuous authentication data verification submodule;

[0034] The continuous authentication data verification submodule receives continuous authentication attribute negotiation requests and selected continuous authentication attributes from continuous authentication clients. Based on the security protection requirements of business resources, it sets security protection rules to determine the compliance of the continuous authentication attributes and returns the continuous authentication attribute negotiation results to the continuous authentication client. It also categorizes the attributes in the continuous authentication attribute list into a set of fixed-value attributes G: {g1, g2, ..., g...} based on whether the attributes in each dimension of the continuous authentication attribute list are fixed values. α} and the set of numerically variable attributes B: {b1, b2, ..., b β}, where g i Let b represent a fixed attribute in the continuous authentication attributes, and G represent the set of all fixed attributes in the continuous authentication attributes. i Let B represent a variable attribute in the continuous authentication attributes, and let B represent the set of all variable attributes in the continuous authentication attributes. The attribute set G is fixed based on its numerical values: {g1, g2, ..., g...} α} and the identifier ID of the continuously authenticated client c Generate a continuous authentication identity ID for this business access by the continuous authentication client. ac And will continue to authenticate identity IDs ac Send to the continuous authentication client, and then set the threshold for each attribute in the variable attribute set: {T b1 T b2 ,…,T bβ The threshold indicates when the variable attribute b... i The value of b satisfies i ∈T bi If the condition is met, the attribute is considered reasonable, and the set threshold is sent to the attribute compliance judgment submodule; it is also used to send the continuous authentication identifier ID of the continuous authentication client. ac Sends a request to the server's cryptographic service submodule to calculate the identifier public key, and receives the continuous authentication identifier public key PK returned by the server's cryptographic service submodule. ac It receives continuous authentication requests, continuous authentication attribute ciphertext, and continuous authentication attribute signature data from continuous authentication clients, and then forwards the continuous authentication attribute ciphertext and the continuous authentication server identifier private key SK. SThe system sends a data decryption request to the server's cryptographic service submodule to obtain the corresponding continuous authentication attribute plaintext. It then combines the continuous authentication attribute plaintext, continuous authentication attribute signature data, and the continuous authentication client's public key PK. ac Send the password service submodule to the server and initiate a signature verification request to obtain the signature verification result; and send the continuous authentication attribute to the attribute compliance judgment submodule and initiate an attribute compliance judgment request, and return the continuous authentication result to the continuous authentication client based on the judgment result;

[0035] The attribute compliance judgment submodule is responsible for judging whether the continuous authentication data of the continuous authentication client is compliant; it receives the continuous authentication attributes sent by the continuous authentication data verification submodule, judges the compliance of each attribute in the environment parameters according to the rules set by the system, and returns the judgment result.

[0036] The server cryptographic service submodule is responsible for calculating the public key corresponding to the input identifier ID, and completing the decryption and signature verification operations during the continuous authentication process; it accepts the public key calculation request from the continuous authentication data verification submodule and the continuous authentication identifier ID input from the continuous authentication client. ac The continuous authentication public key (PK) for the continuous authentication client is calculated based on the identifier cryptographic public parameters and the identifier cryptographic algorithm standard. ac And will use the continuous authentication public key PK of the continuous authentication client ac Returns the data to the continuous authentication data verification submodule; accepts the data decryption request initiated by the continuous authentication data verification submodule and the input continuous authentication attribute ciphertext and continuous authentication server identifier private key SK. S Based on the identifier cryptographic algorithm standard and the private key SK of the continuous authentication server. S Calculate the plaintext of the continuous authentication attribute and return it to the continuous authentication data verification submodule; accept the data signature verification request initiated by the continuous authentication data verification submodule and the input plaintext of the continuous authentication attribute and the authentication identifier public key PK of the continuous authentication client. ac Based on the identifier cryptography algorithm standard and the authentication identifier public key PK of the continuous authentication client ac Verify the signature of the continuous authentication attribute and return the signature verification result to the continuous authentication data verification submodule;

[0037] The continuous authentication client includes a continuous authentication data generation submodule, a client password service submodule, and an information collection submodule.

[0038] The continuous authentication data generation submodule is responsible for periodically generating continuous authentication data according to the continuous authentication frequency set by the continuous authentication server, and sending it to the continuous authentication server; it also includes the identifier ID of the continuous authentication server. SSends a request to the client cryptographic service submodule to calculate the identifier public key, and receives the continuous authentication server identifier public key PK returned by the client cryptographic service submodule. S ; Continuous authentication identifier ID of the client ac Send the key to the identifier password generation server and initiate a key generation request, and accept the continuous authentication identifier private key SK returned by the identifier password generation server for the continuous authentication client. ac According to the continuous authentication frequency set by the continuous authentication server, periodically send information collection requests to the information collection submodule and receive continuous authentication attributes returned by the information collection submodule; transfer the continuous authentication server's public key PK. S The system sends the continuous authentication attributes to the client's cryptographic service submodule and initiates a data encryption request to the client's cryptographic service submodule. It also receives the encrypted continuous authentication attributes returned by the client's cryptographic service submodule and sends the client's authentication identifier private key SK. ac The system sends the continuous authentication attribute to the client password service submodule and initiates a data signature request to the client password service submodule. It also receives the continuous authentication attribute signature returned by the client password service submodule. The system then sends the received continuous authentication attribute ciphertext and continuous authentication attribute signature data to the continuous authentication server and initiates a continuous authentication request to the continuous authentication server.

[0039] The client-side cryptographic service submodule is responsible for calculating the public key corresponding to the input identifier ID, and completing the encryption and signing operations during the continuous authentication process; it accepts the public key calculation request from the continuous authentication data generation submodule and the input continuous authentication server identifier ID. S The public key (PK) of the continuous authentication server is calculated based on the public parameters of the identifier cryptography and the identifier cryptography algorithm standard. S And will continuously authenticate the server's public key PK. S Returns the data to the continuous authentication data generation submodule; accepts the data encryption request initiated by the continuous authentication data generation submodule and the input continuous authentication attributes and continuous authentication server identifier public key PK. S Based on the identifier cryptographic algorithm standard and the public key PK of the continuous authentication server identifier S Calculate the ciphertext of the continuous authentication attribute and return it to the continuous authentication data generation submodule; accept the data signature request initiated by the continuous authentication data generation submodule and the authentication identifier private key SK of the continuous authentication client as input. ac Based on the identifier cryptography algorithm standard and the authentication identifier private key SK of the continuous authentication client. ac Calculate the signature of the continuous authentication attribute and return the signature of the continuous authentication attribute to the continuous authentication data generation submodule;

[0040] The information acquisition submodule is responsible for obtaining the client's continuous authentication attributes, accepting the continuous authentication attribute acquisition request initiated by the continuous authentication data generation submodule, calling the local sensor to collect the corresponding attribute values ​​according to the requirements of the continuous authentication attribute request, and returning the collected continuous authentication attributes to the continuous authentication data generation submodule.

Claims

1. A multi-factor continuous verification system based on identifier cryptography, characterized in that, This includes a password generation server, a continuous authentication server, and a continuous authentication client; The password generation server includes: The password parameter generation submodule is used to receive the system security parameters set by the system administrator, select the GM / T 0044-2016 SM9 identifier cryptography algorithm, generate the identifier cryptography system public parameters according to the requirements of the system security parameters and the identifier cryptography algorithm standard, send the identifier cryptography system public parameters to the key generation submodule, and send the public part of the identifier cryptography system public parameters to the continuous authentication server and continuous authentication client in the system. The key generation submodule is used to receive the identifier private key generation request and identifier sent by the continuous authentication server or continuous authentication client, and generate the identifier according to the identifier cryptosystem public parameters and identifier cryptographic algorithm standard. The corresponding identifier password private key is returned to the requester. Continuous authentication servers include: The initialization submodule is used to initialize the parameters of the continuous authentication server, including setting the continuous authentication frequency and the identifier of the continuous authentication server. This module is used to: obtain a list of supported authentication attributes and send initialization parameters to each continuous authentication client; set security protection rules based on the security requirements of business resources and send these rules to the continuous authentication data verification submodule and each continuous authentication client; obtain a list of feature attributes supported by the continuous authentication server, classify the obtained feature information according to its security level, and send the classified feature information to each continuous authentication client; and identify the continuous authentication server. Send an identifier password generation request to the identifier private key generation server and receive the identifier password private key returned by the identifier password generation server. And send the identifier password private key to the continuous authentication data verification submodule; The continuous authentication data verification submodule receives continuous authentication attribute negotiation requests and selected continuous authentication attributes from continuous authentication clients. It then sets security protection rules based on the security requirements of business resources to determine the compliance of the continuous authentication attributes and returns the continuous authentication attribute negotiation results to the continuous authentication client. Furthermore, it categorizes the attributes in the continuous authentication attribute list into a set of fixed-value attributes and a set of variable-value attributes based on whether the attributes in each dimension are fixed values. Finally, it determines the validity of the results based on the fixed-value attribute set and the identifier of the continuous authentication client. Generate a continuous authentication identity identifier for the client's current business access. And will continue to authenticate identity tokens Send to the continuous authentication client, and then set thresholds for each attribute in the variable attribute set: It also sends the set threshold to the attribute compliance judgment submodule; and is used to send the continuous authentication identifier of the continuous authentication client. Send a request to the server's cryptographic service submodule to initiate the public key calculation request, and receive the public key of the continuous authentication client returned by the server's cryptographic service submodule. It receives continuous authentication requests, continuous authentication attribute ciphertext, and continuous authentication attribute signature data from continuous authentication clients, and then forwards the continuous authentication attribute ciphertext and the continuous authentication server identifier private key. The system sends the data to the server cryptographic service submodule and initiates a data decryption request to obtain the corresponding continuous authentication attribute plaintext. It then sends the continuous authentication attribute plaintext, continuous authentication attribute signature data, and the continuous authentication identifier public key of the continuous authentication client to the server cryptographic service submodule and initiates a signature verification request to obtain the signature verification result. Additionally, it sends the continuous authentication attribute to the attribute compliance judgment submodule and initiates an attribute compliance judgment request. Based on the judgment result, it returns the continuous authentication result to the continuous authentication client. The attribute compliance determination submodule is used to determine whether the continuous authentication attributes of the continuous authentication client are compliant. It also receives continuous authentication attributes sent by the continuous authentication data verification submodule and determines compliance according to the rules set by the system and the variable attribute set thresholds set by the continuous authentication data verification submodule. The system assesses the compliance of each attribute in the continuous authentication attributes and returns the assessment result. The server password service submodule is used to verify the continuous authentication identifier input by the continuous authentication data submodule. Calculation identifier The corresponding public key is used to complete the decryption and signature verification operations during the continuous authentication process; and the public key calculation request from the continuous authentication data verification submodule and the continuous authentication identifier of the continuous authentication client are received. The continuous authentication identifier public key for the continuous authentication client is calculated based on the public parameters of the identifier cryptosystem and the identifier cryptography algorithm standard. The continuous authentication public key of the client will be used for continuous authentication. The data is returned to the continuous authentication data verification submodule; and the continuous authentication attribute ciphertext and continuous authentication server identifier private key are received from the continuous authentication data verification submodule. Based on the identifier cryptographic algorithm standard and the identifier private key of the continuous authentication server Calculate the plaintext of the continuous authentication attribute and return it to the continuous authentication data verification submodule; and receive the data signature verification request initiated by the continuous authentication data verification submodule, along with the input plaintext of the continuous authentication attribute and the continuous authentication identifier public key of the continuous authentication client. Based on the identifier cryptography algorithm standard and the public key of the continuous authentication identifier of the continuous authentication client. Verify the signature of the continuous authentication attribute and return the signature verification result to the continuous authentication data verification submodule; Continuous authentication clients include: The continuous authentication data generation submodule is used to periodically generate continuous authentication data according to the continuous authentication frequency set by the continuous authentication server, and send it to the continuous authentication server; and to identify the continuous authentication server. Send a request to the client cryptographic service submodule to calculate the identifier public key, and receive the continuous authentication server identifier public key returned by the client cryptographic service submodule. It is also used to obtain the authentication attributes supported by the current continuous authentication client, generate a continuous authentication attribute list for accessing business resources based on the server's supported feature attribute list and security protection level requirement rules, send the continuous authentication attribute list to the continuous authentication server, and initiate a continuous authentication attribute negotiation request; it is also used to transfer the continuous authentication identifier of the continuous authentication client. Send the identifier password generation server and initiate an identifier private key generation request, and receive the continuous authentication identifier private key returned by the identifier password generation server for the continuous authentication client. ; and according to the continuous authentication frequency set by the continuous authentication server, periodically send information collection requests to the information collection submodule, and receive the continuous authentication attributes returned by the information collection submodule; and transmit the continuous authentication server's public key. It sends the continuous authentication attributes to the client's cryptographic service submodule and initiates a data encryption request to the client's cryptographic service submodule, and receives the ciphertext of the continuous authentication attributes returned by the client's cryptographic service submodule; it is also used to transmit the authentication identifier private key of the continuous authentication client. It sends the continuous authentication attribute to the client password service submodule, initiates a data signature request to the client password service submodule, and receives the continuous authentication attribute signature returned by the client password service submodule; it is also used to send the received continuous authentication attribute ciphertext and continuous authentication attribute signature data to the continuous authentication server, and initiates a continuous authentication request to the continuous authentication server. The client-side cryptographic service submodule receives the public key calculation request from the continuous authentication data generation submodule and the input continuous authentication server identifier. The public key for the continuous authentication server is calculated based on the public part of the identifier cryptographic public parameters and the identifier cryptographic algorithm standard. The server will continuously authenticate the public key. The data is returned to the continuous authentication data generation submodule; and the continuous authentication attributes and the continuous authentication server identifier public key are received from the continuous authentication data generation submodule. Based on the identifier cryptographic algorithm standard and the public key of the continuous authentication server identifier It calculates the ciphertext of the continuous authentication attributes and returns it to the continuous authentication data generation submodule; it is also used to receive data signature requests initiated by the continuous authentication data generation submodule and the authentication identifier private key of the continuous authentication client. Based on the identifier cryptography algorithm standard and the authentication identifier private key of the continuous authentication client. Calculate the signature of the continuous authentication attribute and return the signature of the continuous authentication attribute to the continuous authentication data generation submodule; The information acquisition submodule is used to receive continuous authentication attribute information acquisition requests initiated by the continuous authentication data generation submodule, call local sensors to collect the corresponding attribute values ​​according to the information request requirements, and return the collected continuous authentication attributes to the continuous authentication data generation submodule.

Citation Information

Patent Citations

  • Zero-trust power Internet of Things equipment and user real-time trust degree evaluation method

    CN112055029A

  • Multi-factor authentication key negotiation method for intelligent equipment communication

    CN114125833A