Authentication method, terminal device, service platform, authentication platform and storage medium

By using dynamic password authentication, which utilizes dynamic tokens and authentication methods generated by third-party authentication platforms, the security and flexibility issues of existing authentication methods are resolved, achieving higher security and wider applicability of identity authentication.

CN118827083BActive Publication Date: 2026-04-17CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2023-08-28
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing authentication methods such as usernames/passwords, mobile phone numbers/authentication codes, and biometrics have problems with insufficient security and poor flexibility. In particular, they face issues such as memory and storage security, strong dependence on the network, high risk of personal privacy leakage, and inability to change authentication methods.

Method used

A dynamic password authentication method is introduced, which generates a first authentication password based on dynamic factors, basic factors, and time through a dynamic password token. Combined with a third-party authentication platform, the user identity is authenticated. The dynamic password is highly flexible and has the characteristics of being resistant to attacks and randomness.

Benefits of technology

It improves the security and flexibility of user identity authentication, avoids the security risks of traditional authentication methods, has a wider range of applications, reduces the risk of personal information leakage, and supports identity authentication for multiple business platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827083B_ABST
    Figure CN118827083B_ABST
Patent Text Reader

Abstract

This application discloses an authentication method, a terminal device, a service platform, an authentication platform, and a storage medium. The authentication method applied to the terminal device includes: sending user identity information and a dynamic password to the service platform, so that the service platform sends an identity authentication request carrying the user identity information and the dynamic password to the authentication platform, and performs user identity authentication through the authentication platform; wherein, the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor, and the calculation time of the first password.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to an authentication method, terminal device, service platform, authentication platform and storage medium. Background Technology

[0002] Modern society has entered the information society stage, and human identity information has been digitized. To verify the legitimacy of user identity information, various user authentication methods have emerged. Username / password is the simplest and most widely used traditional method; users can directly complete identity authentication after setting a username / password. Mobile phone number / verification code eliminates the hassle of setting and remembering usernames / passwords. The mobile phone number becomes a unified user identifier, and authentication is completed by receiving a verification code via mobile phone each time, making it another secure, reliable, and convenient authentication method. In addition, there are identity authentication methods based on physiological characteristics such as fingerprints and iris scans, which rely on the uniqueness of human physiological features and the complexity of forgery.

[0003] However, the aforementioned authentication methods lack sufficient security. Specifically, username / password authentication requires users to register and configure settings multiple times for different service providers. Setting different usernames / passwords raises memory and storage security issues, while using the same username / password can lead to the failure of all authentication methods or security risks due to the leakage of a single piece of information. Mobile phone number / verification code authentication heavily relies on mobile phones and networks, limiting its scope and posing a security risk of malicious network attacks. Biometric characteristics are considered personal privacy and cannot be changed; currently, there is a lack of effective regulation, leading to problems of illegal collection and misuse. Leakage could cause irreparable consequences. Summary of the Invention

[0004] This application provides an authentication method, terminal device, business platform, authentication platform, and storage medium, which improves the security and flexibility of user identity authentication.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] This application provides an authentication method applied to a terminal device, the method comprising:

[0007] Send user identity information and dynamic password to the business platform, so that the business platform sends an identity authentication request carrying the user identity information and dynamic password to the authentication platform, and performs user identity authentication through the authentication platform;

[0008] The dynamic password includes a dynamic factor and a first authentication password, wherein the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor and the first authentication password calculation time.

[0009] In the above method, before sending user identity information and dynamic password to the business platform, the method further includes:

[0010] Access the business platform to obtain the dynamic factor, provide the dynamic factor to the dynamic token, and generate the first authentication password through the dynamic token;

[0011] The dynamic token is pre-generated and stores the basic factor, and the first token calculation time is the time when the dynamic token obtains the dynamic factor.

[0012] In the above method, the basic factor is generated based on the user identity information and the user key.

[0013] In the above method, the dynamic factor is generated based on the business platform number and a random number of the business platform.

[0014] This application provides an authentication method applied to a business platform, the method comprising:

[0015] The device receives user identity information and a dynamic password sent by a terminal device; wherein the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor and the first password calculation time;

[0016] Send an authentication request carrying the user's identity information and the dynamic password to the authentication platform;

[0017] The system receives the authentication result corresponding to the user's identity information, sent by the authentication platform in response to the authentication request.

[0018] In the above method, the basic factor is generated based on the user identity information and the user key.

[0019] In the above method, before receiving the user identity information and dynamic password sent by the receiving terminal device, the method further includes:

[0020] Establish a communication connection with the authentication platform and obtain the business platform number assigned by the authentication platform to the business platform;

[0021] When the terminal device accesses the service platform, the dynamic factor is generated based on the service platform number and a random number, and the dynamic factor is provided to the terminal device.

[0022] This application provides an authentication method applied to an authentication platform, the method comprising:

[0023] Receive an identity authentication request sent by the business platform, carrying user identity information and a dynamic password; wherein, the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic token based on the dynamic factor, the basic factor and the first password calculation time;

[0024] Based on the dynamic password, determine the identity authentication result corresponding to the user's identity information;

[0025] Send the identity authentication result to the business platform.

[0026] In the above method, determining the authentication result corresponding to the user's identity information based on the dynamic password includes:

[0027] Determine the second password calculation time, which is the time before the current time and a preset time interval away from the current time, where the current time is the time when the identity authentication request is received;

[0028] The pre-generated and stored basic factor is invoked, and a second authentication password is generated based on the dynamic factor, the basic factor, and the second password calculation time.

[0029] If the first authentication password is the same as the second authentication password, the authentication result is determined to be successful.

[0030] If the first authentication password is different from the second authentication password, the authentication result is determined to be authentication failure.

[0031] In the above method, before invoking the pre-generated and stored basic factor, the method further includes:

[0032] Set the user identity information and user key;

[0033] The basic factor is generated based on the user identity information and the user key, and the basic factor is stored.

[0034] In the above method, before receiving the authentication request carrying user identity information and dynamic password sent by the business platform, the method further includes:

[0035] A communication connection is established with the service platform, and a service platform number is assigned to the service platform so that when the terminal device accesses the service platform, the service platform provides the dynamic factor to the terminal device based on the service platform number and a random number.

[0036] This application provides a terminal device, including: a first processor, a first communication module, a first memory, and a first communication bus;

[0037] The first communication bus is used to realize the communication connection between the first processor, the first communication module and the first memory;

[0038] The first processor is configured to execute one or more computer programs stored in the first memory, and implement an authentication method applied to a terminal device through the first communication module.

[0039] This application provides a service platform, including: a second processor, a second communication module, a second memory, and a second communication bus;

[0040] The second communication bus is used to realize the communication connection between the second processor, the second communication module and the second memory;

[0041] The second processor is used to execute one or more computer programs stored in the second memory, and to implement an authentication method applied to the business platform through the second communication module.

[0042] This application provides an authentication platform, including: a third processor, a third communication module, a third memory, and a third communication bus;

[0043] The third communication bus is used to realize the communication connection between the third processor, the third communication module and the third memory;

[0044] The third processor is used to execute one or more computer programs stored in the third memory, and to implement the authentication method applied to the authentication platform through the third communication module.

[0045] This application provides a computer-readable storage medium storing a computer program thereon, characterized in that the computer program implements the above-described authentication method when executed by a processor.

[0046] This application provides an authentication method, terminal device, service platform, authentication platform, and storage medium. The authentication method applied to the terminal device includes: sending user identity information and a dynamic password to the service platform, causing the service platform to send an authentication request carrying the user identity information and dynamic password to the authentication platform, and performing user authentication through the authentication platform. The dynamic password includes a dynamic factor and a first authentication password, which is generated by the dynamic token based on the dynamic factor, a basic factor, and the calculation time of the first password. The authentication method provided in this application introduces a third-party authentication platform for user authentication. The first authentication password, generated by the dynamic token based on the basic factor, the dynamic factor, and the calculation time of the first password, possesses strong resistance to attacks and randomness, thus improving the security of identity authentication. Attached Figure Description

[0047] Figure 1 A flowchart illustrating an authentication method provided in this application embodiment. Figure 1 ;

[0048] Figure 2 A flowchart illustrating an authentication method provided in this application embodiment. Figure 2 ;

[0049] Figure 3 A flowchart illustrating an authentication method provided in this application embodiment. Figure 3 ;

[0050] Figure 4 An interactive diagram illustrating an identity authentication method provided in an embodiment of this application;

[0051] Figure 5 A schematic diagram of the structure of a terminal device provided in this application embodiment. Figure 1 ;

[0052] Figure 6 A schematic diagram of the structure of a terminal device provided in this application embodiment. Figure 2 ;

[0053] Figure 7 A schematic diagram of the structure of a service platform provided in this application embodiment. Figure 1 ;

[0054] Figure 8 A schematic diagram of the structure of a service platform provided in this application embodiment. Figure 2 ;

[0055] Figure 9 A schematic diagram of the structure of an authentication platform provided in this application embodiment. Figure 1 ;

[0056] Figure 10 A schematic diagram of the structure of an authentication platform provided in this application embodiment. Figure 2 . Detailed Implementation

[0057] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0058] The technical solutions of this application and how they solve the aforementioned technical problems will be described in detail below through embodiments and in conjunction with the accompanying drawings. The embodiments below can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0059] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0060] This application provides an authentication method, involving a terminal device, a business platform, and an authentication platform. The business platform can be a platform providing services such as email, instant messaging, and financial services. The authentication platform takes the form of a server or cryptographic machine. It configures each dynamic token with the same password protocol and basic factors, and performs real-time dynamic password calculation based on this. It also verifies the legality of the authentication information submitted by the business provider. Furthermore, the authentication method also involves a dynamic token, which consists of a numeric keypad, a display, a computing chip, and a storage chip, possessing input, output, and calculation capabilities, and is an independent hardware device. The relevant steps are detailed below.

[0061] Figure 1 A flowchart illustrating an authentication method provided in this application embodiment. Figure 1 .like Figure 1 As shown in the embodiments of this application, the authentication method applied to a terminal device mainly includes the following steps:

[0062] S101. Send user identity information and dynamic password to the business platform, so that the business platform sends an identity authentication request carrying user identity information and the dynamic password to the authentication platform, and performs user identity authentication through the authentication platform; wherein, the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor and the first password calculation time.

[0063] In the embodiments of this application, the terminal device sends user identity information and dynamic password to the service platform for user identity authentication.

[0064] It is understood that in the embodiments of this application, a third-party authentication platform is introduced to perform user identity authentication. The terminal device provides user identity information and dynamic password to the business platform, and then the business platform sends an identity authentication request carrying user identity information and dynamic password to the authentication platform. The dynamic password is highly flexible, can be dynamically updated, and has strong resistance to attacks and randomness, thereby improving the security of identity authentication.

[0065] It should be noted that in the embodiments of this application, the terminal device has input capability, and the user can independently input user identity information and dynamic password on the terminal device for identity authentication.

[0066] In the embodiments of this application, before the terminal device sends user identity information and dynamic password to the service platform, it may also perform the following steps: access the service platform to obtain dynamic factors, provide the dynamic factors to the dynamic token, and generate a first authentication password through the dynamic token; wherein, the dynamic token pre-generates and stores basic factors, and the first password calculation time is the time when the dynamic token obtains the dynamic factors.

[0067] It should be noted that, in the embodiments of this application, the first authentication password is generated by the dynamic token based on a dynamic factor, a basic factor, and the first password calculation time. The dynamic token pre-generates and stores the basic factor. The first password calculation time is the time when the dynamic token obtains the dynamic factor, which can be determined autonomously by the dynamic token. The dynamic factor is stored on the business platform, and the terminal device can obtain it by accessing the business platform. The terminal device is typically equipped with a display to show the dynamic factor. Users can view the dynamic factor on the display and manually input it into the dynamic token for the dynamic token to generate the first authentication password. Correspondingly, the dynamic token can also be equipped with a display to show the generated first authentication password for users to view and understand. In this way, users can input the first authentication password on the terminal device to support subsequent identity authentication.

[0068] In the embodiments of this application, the base factor is generated based on user identity information and user key.

[0069] It should be noted that, in the embodiments of this application, the basic factor can specifically be a value calculated using a cryptographic algorithm on the user's identity information and user key. The specific key algorithm can be a commercial cryptographic algorithm or an international cryptographic algorithm. This application embodiment does not limit the specific algorithm. The calculation protocol can be as shown in the following formula:

[0070] P i =H(ID) user ||ID key (1)

[0071] Among them, P i H represents the fundamental factor, H represents the cryptographic algorithm used, and ID represents the fundamental factor. user Indicates user identity information, ID key The string represents the user key, and || represents a string concatenation.

[0072] It should be noted that, in the embodiments of this application, the dynamic token can be initialized with user identity information and user key, which are then used to generate the base factor.

[0073] It is understood that, in the embodiments of this application, user identity information and user key are used as information for generating basic factors. The randomness of the dynamic password generated based on the basic factors can be guaranteed by utilizing the anti-preimage attack, anti-second preimage attack, and strong collision resistance of the cryptographic hash algorithm.

[0074] In the embodiments of this application, the dynamic factor is generated based on the business platform number and a random number. The business platform number is assigned by the authentication platform when a communication connection is established between the authentication platform and the business platform. The random number is generated in real time by the business platform when the terminal device accesses the platform.

[0075] It should be noted that, in the embodiments of this application, the dynamic factor can specifically be a combination of the business platform number and a random number, as shown in the following formula:

[0076] P d =(Business Platform Number||Random Number) (2)

[0077] Among them, P d Represents a dynamic factor.

[0078] It is understood that, in the embodiments of this application, the business platform number of the business platform can be used to distinguish different business platforms, so as to realize the password authentication support of a single dynamic token for multiple business platforms. The business platform number, as part of the dynamic factor, can solve the problem that dynamic passwords are sensitive to time precision.

[0079] In the embodiments of this application, combining the above equations (1) and (2), the calculation protocol for calculating the first authentication password using a dynamic token can be specifically shown in the following equation:

[0080] P = H(P) i ||P d ||T1) (3)

[0081] Where P represents the first authentication password, H represents the cryptographic algorithm used, and T1 represents the calculation time of the first password. The dynamic password sent by the terminal to the service platform is P. d ||P.

[0082] It is understood that, in the embodiments of this application, the method of calculating dynamic passwords based on basic factors and dynamic factors can solve the problem that traditional dynamic passwords are time-sensitive and therefore prone to losing synchronization. In addition, the generation and application of dynamic passwords are simple and have strong ease of use.

[0083] Figure 2 A flowchart illustrating an authentication method provided in this application embodiment. Figure 2 .like Figure 2As shown in the embodiments of this application, the authentication method applied to the business platform mainly includes the following steps:

[0084] S201. Receive user identity information and dynamic password sent by terminal device; wherein, the dynamic password includes dynamic factor and first authentication password, and the first authentication password is generated by the dynamic password token based on the dynamic factor, basic factor and first password calculation time.

[0085] In the embodiments of this application, the service platform can receive user identity information and dynamic passwords sent by the terminal device.

[0086] It should be noted that, in the embodiments of this application, the basic factor used to generate the first authentication password is generated based on the user's identity information and user key. For details regarding the definitions of the specific first authentication password, basic factor, dynamic factor, and first password calculation time, please refer to the relevant content in the method steps on the terminal device side described above, and will not be repeated here.

[0087] In the embodiments of this application, before the service platform receives the user identity information and dynamic password sent by the terminal device, it may also perform the following steps: establish a communication connection with the authentication platform and obtain the service platform number assigned to the service platform by the authentication platform; when the terminal device accesses the service platform, generate a dynamic factor based on the service platform number and a random number, and provide the dynamic factor to the terminal device.

[0088] It should be noted that, in the embodiments of this application, as described in the method steps on the terminal device side, the terminal device obtains dynamic factors by accessing the service platform to provide them to the dynamic token for generating the first authentication password. For this purpose, the service platform needs to first establish a communication connection with the authentication platform to obtain the service platform number assigned to it, which is used to combine with a random number to generate dynamic factors to provide to the terminal device. The random number is generated in real time by the service platform when the terminal device accesses the platform.

[0089] S202. Send an authentication request carrying user identity information and dynamic password to the authentication platform.

[0090] In the embodiments of this application, after receiving the user's identity information and dynamic password, the business platform sends an identity authentication request carrying the user's identity information and dynamic password to the authentication platform.

[0091] It should be noted that, in the embodiments of this application, identity authentication services are provided through an authentication platform. Based on this, the business platform can request the authentication platform to authenticate the legality of the user's identity information. The identity authentication request carries the user's identity information to indicate the object that needs to be authenticated, and the dynamic password is used for the authentication platform to perform identity authentication.

[0092] S203. Receive the authentication result corresponding to the user's identity information sent by the authentication platform in response to the authentication request.

[0093] In the embodiments of this application, after the business platform sends an identity authentication request carrying user identity information and dynamic password to the authentication platform, it can receive the identity authentication result corresponding to the user identity information sent by the authentication platform in response to the identity authentication request.

[0094] It is understood that, in the embodiments of this application, the authentication platform, in response to an identity authentication request, can perform identity authentication and send the identity authentication result to the business platform. The business platform can then perform subsequent operations based on the identity authentication result. Specifically, if the identity authentication result is successful, indicating that the user's identity information is legitimate, the business platform can allow the terminal device to access the business platform and provide it with business services. Conversely, if the identity authentication result is invalid, indicating that the user's identity information is illegitimate, the business platform will not allow the terminal device to access the business platform.

[0095] Figure 3 A flowchart illustrating an authentication method provided in this application embodiment. Figure 3 .like Figure 3 As shown in the embodiments of this application, the authentication method applied to the authentication platform mainly includes the following steps:

[0096] S301. Receive an authentication request sent by the business platform, which carries user identity information and a dynamic password; wherein, the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic token based on the dynamic factor, the basic factor and the first password calculation time.

[0097] In the embodiments of this application, the authentication platform receives an authentication request sent by the business platform, which carries user identity information and a dynamic password.

[0098] It should be noted that, in the embodiments of this application, the specific definitions of the first authentication password, basic factor, dynamic factor, and first password calculation time are detailed in the relevant content of the method steps on the terminal device side, and will not be repeated here.

[0099] In the embodiments of this application, before the authentication platform receives the authentication request carrying user identity information and dynamic password sent by the business platform, it may also perform the following steps: establish a communication connection with the business platform and assign a business platform number to the business platform so that when the terminal device accesses the business platform, the business platform provides a dynamic factor for the terminal device based on the business platform number and a random number.

[0100] It is understood that, in the embodiments of this application, the authentication platform needs to first establish a communication connection with the business platform and assign it a business platform number, so that when the terminal device accesses the platform, the business platform can provide dynamic factors to the terminal device to support the terminal device in ultimately obtaining a dynamic password for requesting identity authentication.

[0101] S302. Based on the dynamic password, determine the authentication result corresponding to the user's identity information.

[0102] In the embodiments of this application, after receiving an authentication request carrying user identity information and a dynamic password, the authentication platform can determine the authentication result corresponding to the user identity information based on the dynamic password.

[0103] In the embodiments of this application, the authentication platform determines the authentication result corresponding to the user's identity information based on a dynamic password, including: determining the second password calculation time, where the second password calculation time is the time before the current time and a preset time interval from the current time, and the current time is the time when the authentication request was received; calling a pre-generated and stored basic factor, and generating a second authentication password based on the dynamic factor, the basic factor, and the second password calculation time; if the first authentication password and the second authentication password are the same, determining the authentication result as successful; if the first authentication password and the second authentication password are different, determining the authentication result as unsuccessful.

[0104] It should be noted that, in the embodiments of this application, the preset time interval can be pre-configured in the authentication platform. The preset time interval can be set based on the time difference between obtaining the dynamic factor from the dynamic token to generate the dynamic password under normal circumstances and the transmission of the dynamic password to the authentication platform. In this way, the authentication platform can deduce the second password calculation time based on the preset time interval and the time of receiving the identity authentication request, i.e., the current time. Under normal circumstances, the second password calculation time should be the same as the first password calculation time. Of course, if there are abnormal situations such as timeout or authentication password forgery, the second password calculation time will be different from the first password calculation time, and naturally, the generated second authentication password will also be different.

[0105] It should be noted that, in the embodiments of this application, the authentication platform pre-generates and stores basic factors for generating the second authentication password. Before calling the pre-generated and stored basic factors, the authentication platform may perform the following steps: setting user identity information and user key; generating basic factors based on user identity information and user key, and storing the basic factors.

[0106] It should be noted that, in the embodiments of this application, the authentication platform can set user identity information and user keys during initialization, thereby generating basic factors. The specific method for generating basic factors is consistent with the relevant content described in the method steps on the terminal device side above, and will not be repeated here.

[0107] S303. Send the identity authentication result to the business platform.

[0108] In the embodiments of this application, after obtaining the identity authentication result, the authentication platform can send the identity authentication result to the business platform, thereby enabling the business platform to perform subsequent operations based on the identity authentication result.

[0109] Figure 4 This is an interactive diagram illustrating an identity authentication method provided in an embodiment of this application. For example... Figure 4 As shown, the main steps involved are as follows:

[0110] S401. Initialize the installation, set the time and dynamic password authentication protocol.

[0111] It should be noted that both dynamic tokens and authentication platforms execute step S401.

[0112] S402. Initialization, setting user identity information ID user and user key ID key .

[0113] It should be noted that both the dynamic token and the authentication platform execute step S402. In addition, the authentication platform also sets a preset time interval.

[0114] S403, Based on User Identity Information ID user and user key ID key Calculate the fundamental factor P i And store, delete user key ID key .

[0115] It should be noted that both the dynamic token and the authentication platform perform step S403, deleting the user key ID. key This can avoid communication security risks caused by the leakage of user keys.

[0116] S404. The business platform establishes a communication connection with the authentication platform, and the authentication platform assigns a business platform number to the business platform.

[0117] S405, Terminal devices access the service platform and obtain dynamic factor P. d .

[0118] S406. Input dynamic factor P into the dynamic token. d The dynamic token is used to calculate and display the first authentication password P.

[0119] S407, The terminal device sends the user identity information ID to the service platform. user and dynamic password P d ||P.

[0120] S408, The business platform sends a user ID carrying user identity information to the authentication platform. user and dynamic password P d ||P's authentication request.

[0121] S409. The authentication platform calculates the second authentication password P' and compares it with the first authentication password P. If they are the same, the authentication is successful; otherwise, the authentication fails.

[0122] S410, the authentication platform reports the identity authentication results back to the business platform.

[0123] It should be noted that the business platform can perform subsequent operations based on the identity authentication result. In addition, if the authentication is successful, step S411 can be executed.

[0124] S411, The business platform notifies the terminal device that authentication was successful.

[0125] It is understood that the authentication method provided in this application has several advantages. First, compared to username / password authentication, it offers higher security; compared to SMS verification code authentication, it has a wider range of applications, is not limited by mobile phone and network conditions, and can avoid network attacks; compared to biometric authentication, it avoids issues related to personal information leakage and the equipment requirements for collecting biometric features. Second, without compromising security, it can complete identity authentication services for multiple services through a single dynamic token, offering high implementation convenience. Third, the dynamic token generation method provided in this application, by introducing random variables as dynamic factors, not only ensures security and convenience but also avoids the problem of synchronization between the authentication parties caused by the excessive sensitivity of traditional dynamic tokens and business systems using dynamic tokens to time precision.

[0126] This application provides a terminal device. Figure 5 A schematic diagram of the structure of a terminal device provided in this application embodiment. Figure 1 .like Figure 5 As shown, the terminal device includes:

[0127] The first communication module 501 is used to send user identity information and dynamic password to the business platform, so that the business platform sends an identity authentication request carrying the user identity information and dynamic password to the authentication platform, and performs user identity authentication through the authentication platform.

[0128] The dynamic password includes a dynamic factor and a first authentication password, wherein the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor and the first authentication password calculation time.

[0129] In one embodiment of this application, the first communication module 501 is further configured to access the business platform to obtain the dynamic factor, so as to provide the dynamic factor to the dynamic token and generate the first authentication password through the dynamic token;

[0130] The dynamic token is pre-generated and stores the basic factor, and the first token calculation time is the time when the dynamic token obtains the dynamic factor.

[0131] In one embodiment of this application, the basic factor is generated based on the user identity information and the user key.

[0132] In one embodiment of this application, the dynamic factor is generated based on the business platform number and a random number of the business platform.

[0133] Figure 6 A schematic diagram of the structure of a terminal device provided in this application embodiment. Figure 2 .like Figure 6 As shown, the terminal device includes: a first processor 601, a first communication module 602, a first memory 603, and a first communication bus 604;

[0134] The first communication bus 604 is used to realize the communication connection between the first processor 601, the first communication module 602 and the first memory 603.

[0135] The first processor 601 is used to execute one or more computer programs stored in the first memory 603, and to implement an authentication method applied to a terminal device through the first communication module 602.

[0136] This application provides a business platform. Figure 7 A schematic diagram of the structure of a service platform provided in this application embodiment. Figure 1 .like Figure 7 As shown, the business platform includes:

[0137] The second communication module 701 is used to receive user identity information and dynamic password sent by the terminal device; wherein, the dynamic password includes a dynamic factor and a first authentication password, the first authentication password being generated by the dynamic token based on the dynamic factor, the basic factor, and the first password calculation time; to send an identity authentication request carrying the user identity information and the dynamic password to the authentication platform; and to receive the identity authentication result corresponding to the user identity information sent by the authentication platform in response to the identity authentication request.

[0138] In one embodiment of this application, the basic factor is generated based on the user identity information and the user key.

[0139] In one embodiment of this application, the second communication module 701 is further configured to establish a communication connection with the authentication platform, obtain the business platform number assigned by the authentication platform to the business platform, and generate the dynamic factor based on the business platform number and a random number when the terminal device accesses the business platform, and provide the dynamic factor to the terminal device.

[0140] Figure 8 A schematic diagram of the structure of a service platform provided in this application embodiment. Figure 2 .like Figure 8 As shown, the business platform includes: a second processor 801, a second communication module 802, a second memory 803, and a second communication bus 804;

[0141] The second communication bus 804 is used to realize the communication connection between the second processor 801, the second communication module 802 and the second memory 803;

[0142] The second processor 801 is used to execute one or more computer programs stored in the second memory 803, and to implement an authentication method applied to the business platform through the second communication module 802.

[0143] This application provides an authentication platform. Figure 9 A schematic diagram of the structure of an authentication platform provided in this application embodiment. Figure 1 .like Figure 9 As shown, the authentication platform includes:

[0144] The third communication module 901 is used to receive an identity authentication request sent by the business platform, which carries user identity information and a dynamic password; wherein, the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic token based on the dynamic factor, the basic factor and the first password calculation time.

[0145] Processing module 902 is used to determine the identity authentication result corresponding to the user identity information based on the dynamic password;

[0146] The third communication module 901 is also used to send the identity authentication result to the business platform.

[0147] In one embodiment of this application, the processing module 902 is configured to determine a second password calculation time, wherein the second password calculation time is a time interval prior to the current time and a preset time interval from the current time, and the current time is the time when the identity authentication request is received; to call the pre-generated and stored basic factors, and to generate a second authentication password based on the dynamic factors, the basic factors, and the second password calculation time; to determine that the identity authentication result is successful if the first authentication password and the second authentication password are the same; and to determine that the identity authentication result is unsuccessful if the first authentication password and the second authentication password are different.

[0148] In one embodiment of this application, the processing module 902 is further configured to set the user identity information and user key; generate the basic factor based on the user identity information and user key; and store the basic factor.

[0149] In one embodiment of this application, the third communication module 901 is further configured to establish a communication connection with the service platform and assign a service platform number to the service platform, so that when the terminal device accesses the service platform, the service platform provides the dynamic factor to the terminal device based on the service platform number and a random number.

[0150] Figure 10 A schematic diagram of the structure of an authentication platform provided in this application embodiment. Figure 2 .like Figure 10 As shown, the authentication platform includes: a third processor 1001, a third communication module 1002, a third memory 1003, and a third communication bus 1004;

[0151] The third communication bus 1004 is used to realize the communication connection between the third processor 1001, the third communication module 1002 and the third memory 1003;

[0152] The third processor 1001 is used to execute one or more computer programs stored in the third memory 1003, and to implement the authentication method applied to the authentication platform through the third communication module 1002.

[0153] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the aforementioned authentication method. The computer-readable storage medium may be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or it may be a device including one or any combination of the above-mentioned memories, such as a mobile phone, computer, tablet device, personal digital assistant, etc.

[0154] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0155] This application is described with reference to schematic and / or block diagrams of implementations of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the schematic and / or block diagrams can be implemented by computer program instructions, and combinations of blocks in the schematic and / or block diagrams can be implemented. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the schematic and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0156] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the implementation flow diagram. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0157] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0158] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An authentication method, characterized in that, Applied to a terminal device, the method includes: Send user identity information and dynamic password to the business platform, so that the business platform sends an identity authentication request carrying the user identity information and dynamic password to the authentication platform, and performs user identity authentication through the authentication platform; The dynamic password includes a dynamic factor and a first authentication password, wherein the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor and the first password calculation time; The dynamic factor is generated based on the business platform number and a random number, which is generated in real time by the business platform when the terminal device accesses the service.

2. The method according to claim 1, characterized in that, Before sending user identity information and dynamic password to the business platform, the method further includes: Access the business platform to obtain the dynamic factor, provide the dynamic factor to the dynamic token, and generate the first authentication password through the dynamic token; The dynamic token is pre-generated and stores the basic factor, and the first token calculation time is the time when the dynamic token obtains the dynamic factor.

3. The method according to claim 1 or 2, characterized in that, The basic factor is generated based on the user identity information and user key.

4. An authentication method, characterized in that, Applied to a business platform, the method includes: The device receives user identity information and a dynamic password sent by a terminal device; wherein the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic password token based on the dynamic factor, the basic factor and the first password calculation time; Send an authentication request carrying the user's identity information and the dynamic password to the authentication platform; Receive the authentication result corresponding to the user's identity information sent by the authentication platform in response to the identity authentication request; Before receiving the user identity information and dynamic password sent by the receiving terminal device, the method further includes: Establish a communication connection with the authentication platform and obtain the business platform number assigned by the authentication platform to the business platform; When the terminal device accesses the service platform, the dynamic factor is generated based on the service platform number and a random number, and the dynamic factor is provided to the terminal device.

5. The method according to claim 4, characterized in that, The basic factor is generated based on the user identity information and user key.

6. An authentication method, characterized in that, Applied to an authentication platform, the method includes: Receive an identity authentication request sent by the business platform, carrying user identity information and a dynamic password; wherein, the dynamic password includes a dynamic factor and a first authentication password, and the first authentication password is generated by the dynamic token based on the dynamic factor, the basic factor and the first password calculation time; Based on the dynamic password, determine the identity authentication result corresponding to the user's identity information; Send the identity authentication result to the business platform; Before receiving the authentication request carrying user identity information and dynamic password sent by the service platform, the method further includes: A communication connection is established with the service platform, and a service platform number is assigned to the service platform so that when the terminal device accesses the service platform, the service platform provides the dynamic factor to the terminal device based on the service platform number and a random number.

7. The method according to claim 6, characterized in that, The step of determining the authentication result corresponding to the user's identity information based on the dynamic password includes: Determine the second password calculation time, which is the time before the current time and a preset time interval away from the current time, where the current time is the time when the identity authentication request is received; The pre-generated and stored basic factor is invoked, and a second authentication password is generated based on the dynamic factor, the basic factor, and the second password calculation time. If the first authentication password is the same as the second authentication password, the authentication result is determined to be successful. If the first authentication password is different from the second authentication password, the authentication result is determined to be authentication failure.

8. The method according to claim 7, characterized in that, Before invoking the pre-generated and stored basic factor, the method further includes: Set the user identity information and user key; The basic factor is generated based on the user identity information and the user key, and the basic factor is stored.

9. A terminal device, characterized in that, include: A first processor, a first communication module, a first memory, and a first communication bus; The first communication bus is used to realize the communication connection between the first processor, the first communication module and the first memory; The first processor is configured to execute one or more computer programs stored in the first memory, and to implement the authentication method according to any one of claims 1-3 through the first communication module.

10. A business platform, characterized in that, include: A second processor, a second communication module, a second memory, and a second communication bus; The second communication bus is used to realize the communication connection between the second processor, the second communication module and the second memory; The second processor is configured to execute one or more computer programs stored in the second memory, and to implement the authentication method according to any one of claims 4-5 through the second communication module.

11. An authentication platform, characterized in that, include: A third processor, a third communication module, a third memory, and a third communication bus; The third communication bus is used to realize the communication connection between the third processor, the third communication module and the third memory; The third processor is used to execute one or more computer programs stored in the third memory, and to implement the authentication method according to any one of claims 6-8 through the third communication module.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the authentication method as described in any one of claims 6-8.

Citation Information

Patent Citations

  • Identity authentication method based on fingerprint information

    CN104683115A