A secure access method and system

By calculating hash values ​​and generating random numbers on the client, building secure access requests and generating secure access credentials, the problem of frequent input of accounts and passwords in the prior art is solved, and the effect of simplifying operational processes and improving security is achieved.

CN118740389BActive Publication Date: 2025-05-27HANGZHOU HEALTH ONLINE INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410764733.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-05-27
Estimated Expiration
2044-06-14

AI Technical Summary

Technical Problem

In the prior art, system administrators need to frequently enter an account number and password to access multiple data storage servers, resulting in cumbersome operations and inconvenient management.

Method used

The client calculates the hash value of the password and generates a random number, builds a secure access request and sends it to the secure access server, generates and returns a secure access credential, through which the client and data server perform access verification.

Benefits of technology

It enables users to access multiple data servers with just one account and password, simplifying the operation process, and ensuring security through encrypted credentials and verification mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118740389B_ABST
    Figure CN118740389B_ABST
Patent Text Reader

Abstract

The present invention relates to a secure access method and system. The system includes a client, a secure access server, and multiple data servers. The client applies for a secure access credential through the secure access server and uses the secure access credential to access the data servers. The secure access server verifies the secure access credential submitted by the client and decides whether to accept the client's access according to the verification result. This method facilitates user access to and access of a large number of data servers and ensures sufficient security.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention belongs to the field of computers, and in particular relates to a secure access method and system. [Background technology]

[0002] In the prior art, in order to store massive amounts of data, distributed data storage methods and systems are often used. Such distributed systems usually include multiple data storage servers, each of which stores a portion of the data. Different storage servers are interconnected through a network to form a complete, global, logically centralized, and physically distributed large database.

[0003] Different data storage servers may be distributed in different locations. When a system administrator needs to access these servers, he usually uses a client to access the corresponding server through the network. For example, the system administrator connects to the server through the client and enters the corresponding account and password in the client to access the server. However, for massive databases, there are many data storage servers, and each data storage server may have different security levels and security requirements. If the system administrator needs to enter the account and password every time he accesses a data storage server, it will be very cumbersome. [Summary of the invention]

[0004] In order to solve the above problems in the prior art, the present invention provides a secure access method and system.

[0005] The technical solution adopted by the present invention is specifically as follows:

[0006] A secure access method comprises the following steps:

[0007] Step 100: The user enters his account number and password on the client, and the client calculates the hash value H of the password and generates a random number R;

[0008] Step 200: The client constructs a security access request, which includes the account number, the hash value H and the random number R, and sends the security access request to a security access server;

[0009] Step 300: After receiving the security access request, the security access server verifies the correctness of the account number and the hash value H therein. If they are incorrect, the access is rejected. Otherwise, the security access server determines the corresponding security level K according to the account number.

[0010] Step 400: The secure access server generates a random number R according to the security level K of the account. K , the random number R K The number of digits corresponds to the security level K;

[0011] Step 500: The secure access server generates a secure access credential Cred, namely:

[0012] Cred=Encrypt(R,R K , time, ID)

[0013] Where time is the current time when Cred is generated, ID is the account number, and Encrypt is the encryption algorithm;

[0014] Step 600: The secure access server returns the secure access credential Cred to the client;

[0015] Step 700: When the client needs to access a data server, the client sends the security access credential Cred to the data server, and the data server forwards the received security access credential to the security access server;

[0016] Step 800: The security access server receives the security access credential Cred sent by the data server, decrypts the security access credential Cred, and obtains ID, time, R K ;

[0017] Step 900: The secure access server verifies the information in the secure access credential and notifies the data server of the verification result. The data server decides whether to accept the access of the client according to the verification result.

[0018] The verification must meet the following three conditions at the same time:

[0019] Condition 1: The ID corresponds to the security access credential;

[0020] Condition 2: R K The number of bits meets the security level requirement of the data server;

[0021] Condition 3: The difference between time and the current time meets the security level requirement of the data server.

[0022] Furthermore, the security access server increases the number of decryption times of the security access credential by 1 each time the security access credential is decrypted. If the number of decryption times of the security access credential reaches a predetermined threshold, the security access credential is not authenticated.

[0023] Furthermore, the random number R is a random number of 128 bits or more.

[0024] Furthermore, the hash value H is calculated using the MD5 or SHA-1 algorithm.

[0025] Furthermore, each security level has a preset number of random digits, and the higher the security level, the larger the corresponding number of random digits.

[0026] Furthermore, the verification of condition 3 specifically includes: the security access server obtains the current time of verification, and calculates the time difference between the current time and time. Each security level presets an upper limit value for the difference. When the difference is not greater than the upper limit value required by the security level, condition 3 is verified to pass, otherwise condition 3 is verified to fail.

[0027] Furthermore, the higher the security level, the smaller the upper limit value required, and the lower the security level, the larger the upper limit value required.

[0028] The present invention also provides a secure access system, characterized in that it includes a client, a secure access server and multiple data servers, and the system is used to implement the secure access method of the present invention.

[0029] Furthermore, the data server is used to store data to provide distributed data storage services to the outside world.

[0030] Furthermore, the secure access server provides secure access services to perform secure management on the access process of the client.

[0031] The beneficial effects of the present invention are: facilitating users to access and visit a large number of data servers, and ensuring sufficient security.

Brief Description of the Drawings

[0032] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present application, but do not constitute an improper limitation of the present invention. In the drawings:

[0033] Figure 1 It is a basic architecture diagram of the secure access system involved in the present invention. [Specific implementation method]

[0034] The present invention will be described in detail below in conjunction with the accompanying drawings and specific embodiments, wherein the illustrative embodiments and descriptions are only used to explain the present invention but are not intended to limit the present invention.

[0035] See attached Figure 1 , which shows the basic architecture of the secure access system of the present invention. The system includes a client 1, a secure access server 2 and multiple data servers 3. The client and each server can be connected and communicated with each other through a network.

[0036] The multiple data servers are used to store data, and these data servers can work in parallel to provide distributed data storage services to the outside world. The specific distributed storage method can adopt any method in the prior art, which is not the focus of the present invention and will not be repeated here. Each data server has a corresponding pre-set security level for storing data with different security level requirements.

[0037] The client is a device used by a system administrator or other users. The user can access the data server through the client and then perform operations such as management on the data server.

[0038] The secure access server is the core server used for secure access in the present invention. When a client needs to access any data server, the secure access process can be completed through the secure access server. The secure access server provides secure access services and performs secure management on the client's access process.

[0039] Based on the above system architecture, the secure access method of the present invention is described in detail below.

[0040] Step 100: The user enters his account number and password on the client, and the client calculates the hash value H of the password and generates a random number R.

[0041] Specifically, the system administrator has a system management account and password, and other users may also have corresponding accounts and passwords. Accounts and passwords are pre-registered, and each account is assigned a corresponding security level during registration. The security level here is the same as the security level of the data server. For example, the system administrator has the highest authority and can have the highest security level and can access all data servers, including data servers with the highest security level. User A has a corresponding security level L based on the authority of his account. A , then the user can access the security level no higher than L A Each security level has different security requirements, which will be described in detail later.

[0042] The client can provide the user with a secure access interface, in which the user enters his account number and password. The client calculates the hash value H of the password through a predetermined hash algorithm. The specific hash algorithm can adopt any algorithm in the prior art, such as MD5, SHA-1, etc., and the present invention does not limit this. Then, the client generates a random number R. To ensure security, the random number R should have enough bits, for example, a random number of 128 bits or more can be adopted.

[0043] Step 200: The client constructs a security access request, which includes the account number, the hash value H and the random number R, and sends the security access request to a security access server.

[0044] Specifically, the client can establish a secure connection (e.g., via an SSL connection) with a predetermined secure access server, and send the constructed secure access request to the secure access server via the secure connection. The secure access request includes a triplet <account number, H, R>, which can actually be used as the only representation of the user's secure access request.

[0045] Step 300: After receiving the security access request, the security access server verifies the correctness of the account number and the hash value H therein. If they are incorrect, the access is rejected. Otherwise, the security access server determines the corresponding security level K according to the account number.

[0046] As mentioned above, the account and password are pre-registered by the user. For security reasons, the system does not directly store the password during registration, but stores the hash value of the password. Therefore, after receiving the security access request, the security access server can determine whether the account and the hash value H correspond based on the stored registration information. If they do not correspond, it means that the account or password is entered incorrectly, and access is denied.

[0047] If the security access server determines that the account number and the hash value H correspond, it means that the account number and password are entered correctly. At this time, the security access server can further determine the security level corresponding to the account number based on the stored registration information. For example, the system can divide the security level of the account into level 1, level 2, ..., level N, and determine that the security level of the account number is level K (1≤K≤N) by querying the registration information of the account number.

[0048] Step 400: The secure access server generates a random number R according to the security level K of the account. K , the random number R K The number of bits corresponds to the security level K.

[0049] Specifically, each security level has a preset number of random digits. The higher the security level, the larger the corresponding random digits. A random number R corresponding to the security level K is generated based on the preset number of random digits. K For example, suppose the system has three security levels, from high to low, namely level 1, level 2 and level 3. Level 1 corresponds to 512 bits of random numbers, level 2 corresponds to 256 bits of random numbers, and level 3 corresponds to 128 bits of random numbers. In this way, if the security level of the account is 2, the generated random number R 2 The number of bits is 256.

[0050] The number of random numbers is related to the security level. At a high security level, the larger the number of random numbers provided, the higher the security of subsequent access. At a low security level, the number of random numbers does not need to be too large, which can improve access efficiency while ensuring a certain level of security.

[0051] Step 500: The secure access server generates a secure access credential Cred, namely:

[0052] Cred=Encrypt(R,R K , time, ID)

[0053] Wherein, time is the current time, ID is the account number, and Encrypt is the encryption algorithm.

[0054] That is, the secure access server will R, R K , the current time, and the account number are encrypted together to generate the security access credential Cred. The specific encryption algorithm can adopt any encryption algorithm in the art, and the present invention does not limit this. After generating the security access credential, the security access server stores the security access credential and the account number ID in correspondence for subsequent use.

[0055] Step 600: The secure access server returns the secure access credential Cred to the client.

[0056] At this point, the client obtains a secure access credential by entering the account and password once. Based on the secure access credential, the client can access and visit the corresponding multiple data servers through the candidate steps without having to enter the account and password again.

[0057] Since the secure access credentials are encrypted, the client cannot decrypt them and cannot obtain the R K , nor can secure access credentials be forged.

[0058] Step 700: When the client needs to access a data server, the client sends the security access credential Cred to the data server, and the data server forwards the received security access credential to the security access server.

[0059] Specifically, when a user needs to access a data server, he or she can directly initiate a request to access the data server through the client without entering an account number and password, and the access request includes the security access credential. The data server that receives the security access credential forwards it to the security access server to request the security access server to verify the security access credential.

[0060] Step 800: The security access server receives the security access credential Cred sent by the data server, decrypts the security access credential Cred, and obtains ID, time, R K .

[0061] Specifically, the security access server can decrypt the security access credential Cred to obtain a corresponding decryption result. The decryption result includes the user's account ID, the time when the security access credential was generated, and the random number R generated by the security access server for the security access credential and corresponding to the user's account security level. K .

[0062] Step 900: The secure access server verifies the information in the secure access credential and notifies the data server of the verification result. The data server decides whether to accept the access of the client according to the verification result.

[0063] Specifically, after decrypting the security access certificate, the security access server needs to verify the information therein to decide whether to allow the client to access the data server. The verification includes the following three conditions:

[0064] Condition 1: The ID corresponds to the security access credential.

[0065] As mentioned above, after generating the security access credential, the security access server stores the security access credential and the account in correspondence, so the security access server can verify whether the account ID corresponds to the security credential.

[0066] Condition 2: R K The number of bits meets the security level requirements of the data server.

[0067] As mentioned above, each data server has a corresponding security level, which corresponds to the security level of the account. K The number of digits is determined by the security level of the account, so R K The number of bits should also meet the security level requirements of the data server. The higher the security level, the larger the number of bits required.

[0068] Condition 3: The difference between time and the current time meets the security level requirement of the data server.

[0069] Specifically, the security access server can obtain the current time of verification and calculate the time difference between the current time and time. Different security levels have different requirements for the difference, that is, each security level presets an upper limit value for the difference, requiring that the difference shall not be greater than the upper limit value required by the security level. For example, the upper limit value of security level 1 can be preset to 1 day, and the difference of the above time cannot exceed 1 day. The higher the security level, the smaller the upper limit value required, and the lower the security level, the larger the upper limit value required, thereby achieving different levels of security.

[0070] When the security access credential satisfies the above three conditions at the same time, the security access credential is verified. If any one of the conditions is not met, the verification fails. The security access server notifies the data server of the verification result. If the verification passes, the data server accepts the access of the client, otherwise it denies the access of the client.

[0071] The above steps illustrate the generation and use of the client security access credential of the present invention. Through the above steps, the client can enter the account and password only once within a certain period of time to access the data server of the corresponding security level. The time depends on the security level of the account. If this time is exceeded, the client needs to reapply for the security access credential.

[0072] According to another embodiment of the present invention, the validity of the security access credential can also be determined based on the number of decryption times of the security access credential. That is, each time the security access server decrypts the security access credential, the number of decryption times of the security access credential is increased by 1. If the number of decryption times of the security access credential reaches a predetermined threshold, the security access credential is not authenticated, and the user is notified of the reason why the security access credential was not authenticated. In this way, the abnormal use of the security access credential can be discovered and prevented to a certain extent, thereby improving security.

[0073] The above description is only a preferred embodiment of the present invention, so all equivalent changes or modifications made according to the structure, characteristics and principles described in the scope of the patent application of the present invention are included in the scope of the patent application of the present invention.

Claims

1. A secure access method, characterized in that: The following steps are involved: Step 100: The user enters his account number and password on the client, and the client calculates the hash value H of the password and generates a random number R; Step 200: The client constructs a security access request, which includes the account number, the hash value H and the random number R, and sends the security access request to a security access server; Step 300: After receiving the security access request, the security access server verifies the correctness of the account number and the hash value H therein. If they are incorrect, the access is rejected. Otherwise, the security access server determines the corresponding security level K according to the account number. Step 400: The secure access server generates a random number R according to the security level K of the account. K , the random number R K The number of digits corresponds to the security level K; Step 500: The secure access server generates a secure access credential Cred, namely: Cred=Encrypt(R,R K ,time,ID) Where time is the current time when Cred is generated, ID is the account number, and Encrypt is the encryption algorithm; Step 600: The secure access server returns the secure access credential Cred to the client; Step 700: When the client needs to access a data server, the client sends the security access credential Cred to the data server, and the data server forwards the received security access credential to the security access server; Step 800: The security access server receives the security access credential Cred sent by the data server, decrypts the security access credential Cred, and obtains ID, time, R K ; Step 900: The secure access server verifies the information in the secure access credential and notifies the data server of the verification result. The data server decides whether to accept the access of the client according to the verification result. The verification must meet the following three conditions at the same time: Condition 1: The ID corresponds to the security access credential; Condition 2: R K The number of bits meets the security level requirement of the data server; Condition 3: The difference between time and the current time meets the security level requirement of the data server.

2. The secure access method according to claim 1, characterized in that: The security access server increases the number of decryption times of the security access credential by 1 each time the security access credential is decrypted. If the number of decryption times of the security access credential reaches a predetermined threshold, the security access credential is not authenticated.

3. The secure access method according to any one of claims 1 to 2, characterized in that: The random number R is a random number of 128 bits or more.

4. The secure access method according to any one of claims 1 to 2, characterized in that: The hash value H is calculated using the MD5 or SHA-1 algorithm.

5. The secure access method according to any one of claims 1 to 2, characterized in that: Each security level has a preset number of random digits. The higher the security level, the larger the number of random digits it corresponds to.

6. The secure access method according to claim 1, characterized in that: The verification of condition 3 specifically includes: the security access server obtains the current time of verification and calculates the time difference between the current time and time. Each security level presets an upper limit value for the difference. When the difference is not greater than the upper limit value required by the security level, condition 3 is verified to pass, otherwise condition 3 is verified to fail.

7. The secure access method according to claim 6, characterized in that: The higher the security level, the smaller the upper limit value required, and the lower the security level, the larger the upper limit value required.

8. A secure access system, characterized in that: The system comprises a client, a secure access server and multiple data servers, and is used to implement the secure access method as described in any one of claims 1 to 7.

9. The secure access system according to claim 8, characterized in that: The data server is used to store data to provide distributed data storage services to the outside world.

10. The secure access system according to claim 8, characterized in that: The secure access server provides secure access services to perform secure management on the access process of the client.

Citation Information

Patent Citations

  • Systems and methods for interoperable network token processing

    CN113469670A

  • Method, device and system for accessing server

    CN115277168A