Double Encryption Single Sign-On Method, System, Device and Medium

Through dual encryption technology, the RSA public key generation dynamic key and AES symmetric encryption algorithm are used to solve the security and data storage problems of single sign-on system, and a safer and more convenient user experience and system reliability are achieved.

CN118487801BActive Publication Date: 2025-07-18INSPUR ZHUOSHU BIG DATA IND DEV CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410547320.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-06
Publication Date
2025-07-18
Estimated Expiration
2044-05-06

AI Technical Summary

Technical Problem

The existing single sign-on system has difficulties in managing static keys, low security and network security risks, affecting user experience and data security.

Method used

Dual encryption technology is adopted, RSA public key encryption is used to generate dynamic keys for data transmission, and sensitive data is encrypted using AES symmetric encryption algorithm, combining the fixed and random parts of the dynamic key generation and management.

Benefits of technology

Improves the security of data transmission and storage, reduces the risk of password stolen and replay attacks, enhances the convenience of user experience and system reliability, and provides flexibility and compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118487801B_ABST
    Figure CN118487801B_ABST
Patent Text Reader

Abstract

The present invention discloses a dual - encryption single sign - on method, system, device and medium, belonging to the field of network security and encryption technology. The technical problem to be solved by the present invention is how to improve the security of the single sign - on system, ensure the security of data transmission and the secure storage of data. The adopted technical solution is as follows: This method generates a dynamic key and uses RSA public - key encryption technology for data transmission to ensure the security of data transmission; at the same time, it uses the AES symmetric encryption algorithm to encrypt sensitive data to ensure the secure storage of data. The system includes a user client, an authentication server, a data server and a key automatic generation system. The user client, the authentication server, the data server and the key automatic generation system communicate through encrypted data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security and encryption technology, and specifically to a dual-encryption single sign-on method, system, device and medium. Background Art

[0002] With the popularization of the Internet, users need to log in to multiple different application systems, and each application system requires users to enter a username and password for identity verification. This method is not only cumbersome to operate, but also has a high risk of password leakage. Single sign-on technology can enable users to log in to other associated platforms only by performing identity verification on one platform, greatly improving the convenience and security of user use. However, with the increasing prominence of network security issues, single sign-on technology, as a convenient and secure authentication method, has been widely used in multiple application systems.

[0003] However, traditional single sign-on systems usually use static keys, which may have security risks such as password theft and replay attacks. At the same time, there are problems such as difficult key management and low security, which bring many inconveniences to users.

[0004] Therefore, how to improve the security of single sign-on systems, ensure the security of data transmission, and the secure storage of data are currently technical problems that need to be solved urgently. Summary of the Invention

[0005] The technical task of the present invention is to provide a dual-encryption single sign-on method, system, device and medium to solve the problems of how to improve the security of single sign-on systems, ensure the security of data transmission, and the secure storage of data.

[0006] The technical task of the present invention is achieved in the following way. A dual-encryption single sign-on method generates a dynamic key and uses RSA public key encryption technology for data transmission to ensure the security of data transmission; at the same time, it uses the AES symmetric encryption algorithm to encrypt sensitive data to ensure the secure storage of data.

[0007] Preferably, the dynamic key includes a fixed part key and a random part key; among them, the random part key is generated according to user information, timestamp and other random factors.

[0008] More preferably, the method is specifically as follows:

[0009] Enter user information including account number and password on the user client for login;

[0010] The authentication server receives the user information and generates a dynamic key;

[0011] The authentication server encrypts the fixed part of the dynamic key using RSA public key encryption technology and sends the encrypted fixed part of the dynamic key to the user client;

[0012] The user client receives the encrypted fixed part of the dynamic key and decrypts it using the private key to obtain the fixed part of the dynamic key; meanwhile, the user client generates a random data segment;

[0013] The user client sends the decrypted fixed part of the dynamic key, the random data segment, and the user information to the authentication server for verification;

[0014] The authentication server verifies the legality of the user information, the fixed part of the dynamic key, and the random data segment:

[0015] If the verification passes, the user is allowed to log in;

[0016] The key automatic generation system receives the random part of the dynamic key and other verification information sent by the authentication server, and the key automatic generation system generates a specific data encryption key based on the random part of the dynamic key and other verification information, and performs AES symmetric encryption on the sensitive data using the data encryption key;

[0017] The authentication server sends the encrypted sensitive data to the user client;

[0018] The user client receives the encrypted sensitive data, and uses the random part of the dynamic key and other verification information to perform re-verification to ensure the integrity and authenticity of the data;

[0019] If the verification passes, the user client decrypts the data using the AES symmetric encryption algorithm and the specific data encryption key to obtain the sensitive data.

[0020] Preferably, the key automatic generation system generates an RSA dynamic key based on the user client random parameters, the authentication server fixed parameters, and other data segment information.

[0021] A dual-encryption single sign-on system, which includes a user client, an authentication server, a data server, and a key automatic generation system. The user client, the authentication server, the data server, and the key automatic generation system communicate through encrypted data transmission;

[0022] Among them, the authentication server is used to generate a dynamic key, encrypt the fixed part of the dynamic key using RSA public key encryption technology, and send the encrypted fixed part of the dynamic key to the user client;

[0023] The user client is used to receive the fixed part key of the encrypted dynamic key, decrypt it using the private key to obtain the fixed part key of the dynamic key. At the same time, the user client generates a random data segment, and sends the decrypted fixed part key of the dynamic key, the random data segment, and the user information to the authentication server for verification. The authentication server verifies the legality of the user information, the fixed part key of the dynamic key, and the random data segment. If the verification passes, the user is allowed to log in.

[0024] The data server is used to receive the random part key of the dynamic key and other verification information sent by the authentication server, generate a specific data encryption key according to the random part key of the dynamic key and other verification information, and perform AES symmetric encryption on the sensitive data using the data encryption key. The authentication server sends the encrypted data to the user client, and the user client receives the encrypted sensitive data and performs re-verification using the random part key of the dynamic key and other verification information.

[0025] The key automatic generation system generates an RSA dynamic key according to the user client random parameters, the authentication server fixed parameters, and other data segment information.

[0026] Preferably, the double-encryption single sign-on system further includes a data storage module and a log recording module;

[0027] Among them, the data storage module is used to store the user name, password, dynamic key, private key, and transmission data;

[0028] The log recording module is used to record the communication information between the user client, the authentication server, the data server, and the key automatic generation system.

[0029] Preferably, the user client is also used to receive the encrypted dynamic key and decrypt it using the private key.

[0030] Preferably, the authentication server is also used to generate the dynamic key and encrypt the fixed part key of the dynamic key using the RSA public key encryption technology.

[0031] An electronic device, characterized in that it includes: a memory and at least one processor;

[0032] Among them, a computer program is stored on the memory;

[0033] The at least one processor executes the computer program stored in the memory, so that the at least one processor executes the double-encryption single sign-on method as described above.

[0034] A computer-readable storage medium stores a computer program, and the computer program can be executed by a processor to implement the dual-encryption single sign-on method as described above.

[0035] The dual-encryption single sign-on method, system, device, and medium of the present invention have the following advantages:

[0036] (1) The present invention provides a more secure and convenient single sign-on solution to enhance the security and convenience of user information. That is, by dynamically generating an AES key to encrypt and decrypt user data, and at the same time using an RSA public key to encrypt and transmit the AES key, the security of data transmission and the reliability of single sign-on are improved.

[0037] (2) By combining the AES dynamic key and RSA encryption technology, the present invention realizes dual-encryption single sign-on, which not only ensures the security of data transmission but also further enhances the security of data storage, greatly reducing the risk of security threats such as password theft and replay attacks.

[0038] (3) Through the dual-encryption design, combining the AES symmetric encryption algorithm and RSA public key encryption technology, the present invention greatly improves the security of the system, which not only ensures the security of data transmission but also further enhances the security of data storage, reducing the risk of security threats such as password theft and replay attacks.

[0039] (4) Users of the present invention only need to log in once to access multiple applications or services, greatly improving the convenience of user use.

[0040] (5) The present invention uses RSA public key encryption technology for data transmission to ensure the integrity and authenticity of data.

[0041] (6) The present invention can be integrated and interoperated with other traditional single sign-on systems, providing greater flexibility and compatibility for users and developers.

[0042] (7) The generation and management of the dynamic key of the present invention can be centrally managed or distributed, improving the efficiency and security of key management. At the same time, regularly changing the key can enhance the security of the system.

[0043] In summary, the dual-encryption single sign-on system based on the AES dynamic key and RSA encryption technology provides a more secure and convenient login experience for users, and at the same time provides greater flexibility and compatibility for developers, making single sign-on more reliable and secure. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] The present invention will be further described below with reference to the accompanying drawings.

[0045] AppendixFigure 1 Schematic diagram of the dual - encryption single - sign - on method. Detailed implementation manners

[0046] The dual - encryption single - sign - on method, system, device and medium of the present invention will be described in detail below with reference to the accompanying drawings of the specification and specific embodiments.

[0047] Embodiment 1:

[0048] As shown in the Figure 1 accompanying drawings, this embodiment provides a dual - encryption single - sign - on method. This method generates a dynamic key and uses RSA public - key encryption technology for data transmission to ensure the security of data transmission. At the same time, it uses the AES symmetric encryption algorithm to encrypt sensitive data to ensure the secure storage of data. Specifically as follows:

[0049] S1. Input user information of the account and password at the user client for login;

[0050] S2. The authentication server receives the user information and generates a dynamic key. Among them, the dynamic key includes two parts: a fixed - part key and a random - part key. The random - part key is generated according to the user information, timestamp and other random factors;

[0051] S3. The authentication server uses RSA public - key encryption technology to encrypt the fixed - part key of the dynamic key and sends the encrypted fixed - part key of the dynamic key to the user client;

[0052] S4. The user client receives the encrypted fixed - part key of the dynamic key, decrypts it using the private key to obtain the fixed - part key of the dynamic key. At the same time, the user client generates a random data segment;

[0053] S5. The user client sends the decrypted fixed - part key of the dynamic key, the random data segment and the user information to the authentication server for verification;

[0054] S6. The authentication server verifies the legality of the user information, the fixed - part key of the dynamic key and the random data segment:

[0055] If the verification passes, the user is allowed to log in;

[0056] S7. The key automatic generation system receives the random - part key of the dynamic key and other verification information sent by the authentication server, and the key automatic generation system generates a specific data encryption key according to the random - part key of the dynamic key and other verification information, and uses the data encryption key to perform AES symmetric encryption on sensitive data;

[0057] S8. The authentication server sends the encrypted sensitive data to the user client;

[0058] S9. The user client receives the encrypted sensitive data, uses the random partial key of the dynamic key and other verification information to generate and conduct re-verification to ensure the integrity and authenticity of the data;

[0059] If the verification passes, the user client uses the AES symmetric encryption algorithm and a specific data encryption key to decrypt the data to obtain the sensitive data.

[0060] In this embodiment, the key automatic generation system generates an RSA dynamic key according to the user client random parameters, the authentication server fixed parameters, and other data segment information.

[0061] Embodiment 2:

[0062] This embodiment provides a dual-encryption single sign-on system, which includes a user client, an authentication server, a data server, and a key automatic generation system. The user client, the authentication server, the data server, and the key automatic generation system communicate through encrypted data transmission;

[0063] Among them, the authentication server is used to generate a dynamic key, encrypt the fixed partial key of the dynamic key using RSA public key encryption technology, and send the encrypted fixed partial key of the dynamic key to the user client;

[0064] The user client is used to receive the encrypted fixed partial key of the dynamic key, decrypt it using the private key to obtain the fixed partial key of the dynamic key. At the same time, the user client generates a random data segment, and sends the decrypted fixed partial key of the dynamic key, the random data segment, and the user information to the authentication server for verification. The authentication server verifies the legitimacy of the user information, the fixed partial key of the dynamic key, and the random data segment. If the verification passes, the user is allowed to log in;

[0065] The data server is used to receive the random partial key of the dynamic key and other verification information sent by the authentication server, generate a specific data encryption key according to the random partial key of the dynamic key and other verification information, and use the data encryption key to perform AES symmetric encryption on the sensitive data. The authentication server sends the encrypted data to the user client, and the user client receives the encrypted data and uses the random partial key of the dynamic key and other verification information to generate and conduct re-verification;

[0066] The key automatic generation system generates an RSA dynamic key according to the user client random parameters, the authentication server fixed parameters, and other data segment information.

[0067] In this embodiment, the dual-encryption single sign-on system further includes a data storage module and a log recording module;

[0068] Among them, the data storage module is used to store the user name, password, dynamic key, private key, and transmitted data;

[0069] The log recording module is used to record the communication information between the user client, authentication server, data server, and key automatic generation system.

[0070] The user client in this embodiment is further used to receive the encrypted dynamic key and decrypt it using the private key.

[0071] The authentication server in this embodiment is further used to generate a dynamic key and encrypt the fixed part key of the dynamic key using RSA public key encryption technology.

[0072] Embodiment 3:

[0073] This embodiment also provides an electronic device, including: a memory and at least one processor;

[0074] Among them, the memory stores computer execution instructions;

[0075] The at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the dual-encryption single sign-on method in any embodiment of the present invention.

[0076] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0077] The memory can be used to store computer programs and / or modules. The processor realizes various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory can also include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash memory card, at least one magnetic disk storage period, flash memory device, or other volatile solid-state storage devices.

[0078] Embodiment 4:

[0079] An embodiment of the present invention also provides a computer-readable storage medium, which stores multiple instructions that are loaded by a processor to cause the processor to execute the dual-encryption single sign-on method in any embodiment of the present invention. Specifically, a system or device equipped with a storage medium can be provided. On this storage medium, software program codes for implementing the functions of any one of the above embodiments are stored, and the computer (or CPU or MPU) of the system or device is caused to read and execute the program codes stored in the storage medium.

[0080] In this case, the program code read from the storage medium itself can implement the functions of any one of the above embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of the present invention.

[0081] Embodiments of the storage medium for providing program codes include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RYM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code can be downloaded from a server computer via a communication network.

[0082] In addition, it should be clear that not only can the functions of any one of the above embodiments be realized by executing the program code read by the computer, but also by causing an operating system or the like operating on the computer based on the instructions of the program code to complete part or all of the actual operations.

[0083] In addition, it can be understood that the program code read from the storage medium is written into the memory provided in the expansion board inserted into the computer or the memory provided in the expansion unit connected to the computer, and then based on the instructions of the program code, the CPU or the like installed on the expansion board or the expansion unit is caused to execute part and all of the actual operations, thereby realizing the functions of any one of the above embodiments.

[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A dual-encryption single sign-on method, characterized in that, This method ensures the security of data transmission by generating a dynamic key and using RSA public key encryption technology for data transmission. At the same time, it uses the AES symmetric encryption algorithm to encrypt sensitive data to ensure the secure storage of data. Among them, the dynamic key includes a fixed part key and a random part key. Among them, the random part key is generated according to user information, timestamp and other random factors. Specifically as follows: Enter user information including account number and password at the user client for login; The authentication server receives the user information and generates a dynamic key; The authentication server uses RSA public key encryption technology to encrypt the fixed part key of the dynamic key and sends the encrypted fixed part key of the dynamic key to the user client; The user client receives the encrypted fixed part key of the dynamic key and decrypts it using the private key to obtain the fixed part key of the dynamic key. At the same time, the user client generates a random data segment; The user client sends the decrypted fixed part key of the dynamic key, the random data segment and the user information to the authentication server for verification; The authentication server verifies the legitimacy of the user information, the fixed part key of the dynamic key and the random data segment: If the verification passes, the user is allowed to log in; The key automatic generation system receives the random part key of the dynamic key and other verification information sent by the authentication server, and the key automatic generation system generates a data encryption key according to the random part key of the dynamic key and other verification information, and uses the data encryption key to perform AES symmetric encryption on the sensitive data; The authentication server sends the encrypted sensitive data to the user client; The user client receives the encrypted sensitive data, and uses the random part key of the dynamic key and other verification information to perform re-verification to ensure the integrity and authenticity of the data; If the verification passes, the user client uses the AES symmetric encryption algorithm and the data encryption key to decrypt the data to obtain the sensitive data; Among them, the key automatic generation system generates an RSA dynamic key according to the user client random parameters, the authentication server fixed parameters and other data segment information.

2. A dual-encryption single sign-on system, characterized in that, This system includes a user client, an authentication server, a data server and a key automatic generation system. The user client, the authentication server, the data server and the key automatic generation system communicate through encrypted data transmission; Among them, the authentication server is used to generate a dynamic key, use RSA public key encryption technology to encrypt the fixed part key of the dynamic key, and send the encrypted fixed part key of the dynamic key to the user client; The user client is used to receive the encrypted fixed part key of the dynamic key, decrypt it using the private key to obtain the fixed part key of the dynamic key. At the same time, the user client generates a random data segment, and sends the decrypted fixed part key of the dynamic key, the random data segment and the user information to the authentication server for verification. The authentication server verifies the legitimacy of the user information, the fixed part key of the dynamic key and the random data segment. If the verification passes, the user is allowed to log in; The data server is used to receive the random partial key of the dynamic key and other verification information sent by the authentication server, generate a data encryption key according to the random partial key of the dynamic key and other verification information, and perform AES symmetric encryption on sensitive data using the data encryption key. The authentication server sends the encrypted data to the user client, and the user client receives the encrypted sensitive data and uses the dynamic partial key of the dynamic key and other verification information to perform re-verification; The key automatic generation system generates an RSA dynamic key according to the random parameters of the user client, the fixed parameters of the authentication server, and other data segment information; The dual-encryption single sign-on system further includes a data storage module and a log record module; Among them, the data storage module is used to store the user name, password, dynamic key, private key, and transmission data; The log record module is used to record the communication information between the user client, the authentication server, the data server, and the key automatic generation system; The user client is also used to receive the encrypted dynamic key and decrypt it using the private key; The authentication server is also used to generate a dynamic key and encrypt the fixed partial key of the dynamic key using RSA public key encryption technology.

3. An electronic device, characterized in that, Including: A memory and at least one processor; Among them, a computer program is stored on the memory; The at least one processor executes the computer program stored in the memory, so that the at least one processor executes the dual-encryption single sign-on method according to claim 1.

4. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and the computer program can be executed by a processor to implement the dual-encryption single sign-on method according to claim 1.

Citation Information

Patent Citations

  • Hybrid encryption method for instant messaging

    CN108848091A

  • Information transmission method and device, client, server and storage medium

    CN110460439A

  • Data transmission method and system based on hybrid encryption algorithm

    CN110535868A

  • Data encryption transmission method and system

    CN114338239A

  • Client and server data encryption transmission method and device and storage medium

    CN115442132A