A Data Encryption and Identity Authentication Method and System in a Trusted Computing Environment
By setting up permission information tables and authentication modules in a trusted computing environment, we ensure that the mobile terminal can only be used in a specific area, which solves the problem of preventing and controlling people who have obtained passwords in the existing technology, and improves the security of the mobile terminal.
Patent Information
- Application Number
- CN202410717415.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-04
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-06-04
AI Technical Summary
Existing encryption or verification methods lack technical means to prevent and control people who have obtained passwords, and cannot effectively prevent passwords from being obtained from people who have known passwords.
In a trusted computing environment, by setting the permission information table on the fixed end and setting the identity verification module, wireless connection module and encryption module on the mobile end, the verification of the user identity and wireless network of the mobile end is realized, ensuring that the encryption module of the mobile end can only be used in a specific area.
It effectively prevents the mobile terminal from being cracked after being lost, reduces the security risks of mobile terminal holders, and makes the mobile terminal have no use value when it is separated from the fixed terminal.
Smart Images

Figure CN118862105B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication, and specifically to a data encryption and identity authentication method and system in a trusted computing environment. Background Art
[0002] Trade secrets are the core technical materials of an enterprise, have obvious economic value and are usually protected by encryption means. Based on today's increasingly digital office environment, trade secrets are no longer limited to paper content, but are stored in a digital storage manner in a storage device and encrypted to prevent unauthorized access.
[0003] Existing encryption or authentication methods mostly optimize the encryption and decryption methods themselves, mainly used to prevent confidential content from being opened by people who do not know the password, or to prevent others from monitoring the decryption password through network eavesdropping. In this logic, the situation where the password can be obtained from people who already know the password is ignored, and the existing technology lacks a technical means to prevent people who have obtained the password. Summary of the Invention
[0004] To solve the above technical problems, the present invention provides the following technical solution: A data encryption and identity authentication method in a trusted computing environment, including the steps:
[0005] S1. Set a permission information table at the fixed end, and set the identity authentication standard and network authentication standard of the mobile end through the fixed end, and then proceed to the next step.
[0006] S2. The mobile end verifies the identity of the mobile end user through the identity authentication module, compares the user information obtained by the identity authentication module with the identity authentication standard, judges the user's permissions, and proceeds to the next step after the identity authentication is passed, otherwise stops and issues an alarm.
[0007] S3. Start the wireless connection module in the mobile end to connect to the wireless network transmitting device. After connecting to the wireless network transmitting device, start the wireless authentication module to compare the identifier in the wireless network transmitting device with the set network authentication standard. After the verification is passed, proceed to the next step, otherwise stop and issue an alarm.
[0008] S4. Start the permission information sending module of the mobile end to send the permission information to the fixed end through the wireless network transmitting device. The permission information includes the identity information verified by the identity authentication module, the device code of the mobile end, the identifier of the connected wireless transmitting device, the time when the identity authentication module passed the verification, and the time when the permission information is sent. The fixed end compares the permission information with the permission information list. If it meets the requirements, proceed to the next step, otherwise stop and issue an alarm signal.
[0009] S5. After the authority information is verified, the fixed end sets a password for the encryption module in the mobile end through the wireless network. The user accesses the encryption module in the mobile end through the set password to decrypt and then access the storage module in the mobile end.
[0010] Preferably, the wireless network is a WIFI wireless network, the wireless network transmitting device is a WIFI router, and the wireless network authentication standard includes the SSID information and MAC information of the WIFI router.
[0011] Preferably, the identity authentication module is a fingerprint recognition module.
[0012] Preferably, the permission information table includes identity information that is allowed to access, a device code of a mobile terminal that is allowed to access, and an identification of a wireless transmission device to which the mobile terminal is connected.
[0013] Preferably, in step S4, the fixed end monitors the time difference between the time when the identity authentication module in the permission information sent by the mobile end passes the verification and the time when the permission information is sent, and issues an alarm when the time difference exceeds a threshold.
[0014] Preferably, after the mobile terminal establishes a connection with the wireless network transmitting device in step S3, when the wireless network connection is disconnected, the encryption module is immediately initialized to invalidate the set password.
[0015] Preferably, when the mobile terminal issues an alarm in step S2 and step S3, the mobile terminal re-executes step S2 until the alarm is lifted by verification in step S2.
[0016] Preferably, in step S4, when the fixed end monitors that the permission information sent by the mobile end does not meet the requirements in the permission information table and stops the subsequent process, the wireless network connection with the mobile end is not disconnected, and an alarm is issued that will not be sensed by the mobile end user.
[0017] A data encryption and identity authentication system in a trusted computing environment for executing the above method includes a fixed end and a mobile end, the fixed end and the mobile end are connected via a wireless network, and the mobile end is provided with an identity authentication module, a wireless network connection module, a wireless verification module, an encryption module and a storage module.
[0018] Compared with the prior art, the present invention has the following beneficial effects:
[0019] By connecting the fixed terminal and the mobile terminal to the coverage of the same wireless network transmission device, the mobile terminal can only be used within a specific area, preventing the mobile terminal from being cracked after being lost, which may lead to the decryption and disclosure of the stored content in the mobile terminal;
[0020] The encryption module in the mobile device has no password and can only be accessed after setting a password on the fixed device. This makes the mobile device useless when it is separated from the fixed device, thus reducing the security risk for the holder of the mobile device.
[0021] Other advantages, objects, and features of the present invention will be described to some extent in the following specification, and to some extent, will be obvious to those skilled in the art based on an examination of the following, or can be learned from the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 It is a schematic diagram of the method of the present invention;
[0023] Figure 2 It is a schematic diagram of the functional structure of the mobile device of the present invention;
[0024] Figure 3 It is a schematic diagram of the working process of the system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0026] Please refer to Figures 1 - 3 , the present invention provides a data encryption and identity authentication system in a trusted computing environment for implementing the above method, including a fixed device and a mobile device. The fixed device and the mobile device are connected through a wireless network. The mobile device is provided with an identity authentication module, a wireless network connection module, a wireless authentication module, an encryption module, and a storage module.
[0027] The control method of the system of the present invention includes the steps:
[0028] S1. Set up a permission information table at the fixed end, and set the identity verification standard and network verification standard for the mobile end through the fixed end. In this embodiment, a two-factor verification logic is adopted. For common two-factor verification such as the OTP (one-time password) method, the server needs to send a one-time password to the user additionally. However, it cannot determine whether the device receiving the one-time password is in the user's hands. This verification method actually transfers all the security risks of holding the password to the user, and the verification end only bears the responsibility of verifying the password without considering whether the password is in the hands of the corresponding person. In this embodiment, the fixed end and the mobile end are set to cooperate with each other. By setting the identity verification standard and network verification standard for the mobile end through the fixed end, the mobile end has the ability of self-verification. And the fixed end is provided with a permission information table to conduct a secondary verification on the verified identity of the mobile end. The permission information table at least includes the identity information allowed to access, which is used to check the user identity of the mobile end; the device code of the mobile end allowed to access, which is used to check the identity of the mobile end itself; and the wireless transmission device identifier connected to the mobile end, which is used to check whether the mobile end is within the coverage range of the set wireless network. After setting the verification standards for the fixed end and the mobile end, proceed to the next step.
[0029] S2. The mobile end verifies the identity of the mobile end user through the identity verification module, compares the user information obtained by the identity verification module with the identity verification standard, and determines the user's permission. The mobile end user first verifies the user's identity through the identity verification module. The identity verification adopts a biometric verification method such as iris recognition, face recognition, etc. In this embodiment, common fingerprint recognition is adopted, and it is not limited whether to use short-focus fingerprint or ultrasonic fingerprint specifically. Different from the common methods in the prior art, in this application, the mobile end first verifies the identity of the user who starts the mobile end through a biometric verification method. Adopting a biometric verification method can clearly know the user's identity and prevent situations where the password start or other methods cannot determine whether the password user is the password holder himself. And since the mobile end can only be started by specific users with permissions, setting the identity verification step at the startup stage of the mobile end can prevent unauthorized users from randomly starting the mobile end due to misoperation, thereby enabling the mobile end to exclude unauthorized users at the startup stage. After the identity verification is passed, proceed to the next step. Otherwise, stop and issue an alarm, and another user who meets the identity verification permission restarts step S2 by triggering the identity verification module to turn off the alarm of the mobile end.
[0030] S3. Activate the wireless connection module in the mobile device to connect to the wireless network transmitting device. After connecting to the wireless network transmitting device, activate the wireless authentication module to compare the identifier in the wireless network transmitting device with the set network authentication criteria. The usage environment of this method includes situations where multiple fixed devices or multiple mobile devices are working simultaneously in the same wireless network environment. Therefore, the wireless network in this embodiment is a WIFI wireless network, and the wireless network transmitting device is a WIFI router. Based on the characteristics of the WIFI router, the network authentication criteria include SSID information and MAC address. The network authentication criteria are used to authenticate the identity of the WIFI router and only allow the mobile device to connect to a specific WIFI router. Different from the common method of using positioning modules such as GPS for positioning, the positioning module usually can only obtain the corresponding latitude and longitude coordinates, that is, obtain the planar position where the positioning module is located. In an office building with multiple floors, the positioning module cannot obtain the floor where the mobile device is located. However, the network coverage range of the WIFI router is approximately spherical, and under the obstruction of the building, it is substantially limited to the floor where the WIFI router is located. Therefore, the judgment of the position of the mobile device is more accurate. After the network authentication of the mobile device is passed, activate the encryption module and wait for the fixed device to connect. If the network authentication fails, it means that the connected network of the mobile device is an insecure network. Disconnect the connection and issue an alarm. Another user with the authentication permission can restart step S2 by triggering the authentication module to make the mobile device turn off the alarm.
[0031] S4. Activate the permission information sending module of the mobile device to send the permission information to the fixed device through the wireless network transmitting device. The permission information includes the identity information verified by the identity verification module, the time when the identity verification module passed the verification, the device code of the mobile device, the identifier of the connected wireless transmitting device, and the time when the permission information is sent. The fixed device compares the permission information with the permission information list. The identity verification of the mobile device only serves as a switch to enable the wireless network connection. Once the identity verification is passed, the wireless network connection is enabled, and the specific permissions of the identity are controlled by the fixed device. The functions of the permissions include settings such as adding, modifying, or deleting the identity authentication information of lower-level permissions. The fixed device first determines the user identity information. The mobile device changes the corresponding judgment criteria through the fixed device. Therefore, there may be a situation where the user permissions of the fixed device have been deleted for abandoned users, while the verification criteria of these abandoned users still remain in the mobile device, thus preventing the abandoned users from still being able to pass the identity verification of the mobile device and then enabling the network connection. The device code of the mobile device includes unique numbers such as the device SN code, which is used to determine the identity of the mobile device. By combining with the permissions of the user identity, it ultimately realizes the differentiated access to different storage areas in the mobile device according to different user permissions; it can also ensure that specific mobile devices can only be connected to specific fixed devices, preventing the encrypted information of different departments from being interoperable. The identifier of the wireless transmitting device, such as the MAC address, is used to check whether the fixed device and the mobile device are connected to the same WIFI router, thereby determining that the mobile device and the fixed device are within the connection range of the same router. The time when the identity verification module passes the verification and the time when the permission information is sent are used by the fixed device to judge the time difference between these two times. Under normal operations, after the identity verification module of the mobile device passes the verification, the wireless network connection will be immediately enabled. After the wireless network connection is established, the permission information will be sent immediately. The time difference between the time when the identity verification module passes the verification and the time when the permission information is sent will not be too long. By setting a threshold in the permission information table to exclude a certain time difference, the time difference exceeding the threshold is an abnormal state. In this method, after the identity verification of the mobile device is passed, the wireless network connection starts immediately, and this process cannot be automatically closed because the encryption device should not be used without permission except for decryption purposes. However, if there is no network connection after the identity verification is passed, it means that the user has started the mobile device outside the coverage area of the wireless network, that is, a user with permissions has used the mobile device outside the specified decryption usage area. By setting a threshold for the time difference, the situation where the user uses the mobile device in advance during the process of going to the decryption area is excluded. The longer the time difference between the time when the identity verification module passes the verification and the time when the permission information is sent, the more abnormal it is. Whether the user is trying to crack the network verification standard of the mobile device or other behaviors are not judged here. The fixed device only reports the time difference exceeding the threshold, and the staff will handle the reasons for the excessive time difference between the time when the identity verification module of the mobile device passes the verification and the time when the permission information is sent.Since the specific cause of this situation cannot be determined without manual processing, when the time difference exceeds the threshold, only an alarm is issued without terminating the workflow of this method. Moreover, the continuous accumulation of the time when the wireless network cannot be connected can strengthen this abnormal state, preventing the user from manually closing and thus manually eliminating this abnormal state. The fixed end determines that the permission information of the mobile end meets the requirements and proceeds to the next step; otherwise, it stops and issues an alarm signal. Here, when the permission information of the mobile end does not meet the requirements, the connection is not disconnected, which is used to monitor the location range of the mobile end. That is, when the permission information of the mobile end does not meet the requirements, the staff should be notified to further judge the behavior state of the user holding the mobile end, but the holder of the mobile end should not be alerted. Therefore, the fixed end only stops the subsequent process and issues an alarm that cannot be sensed by the mobile end user to a specific worker, while the user holding the mobile end will always be in the process of the mobile end being connected to the fixed end and waiting to execute the next step. When the fixed end monitors that the mobile end is always in a connected state with the fixed end, it means that the mobile end is within the wireless network coverage of the WIFI router. When the fixed end monitors that the mobile end is disconnected from the fixed end, it means that the mobile end has left the wireless network coverage area.
[0032] After the permission information is verified, the fixed end sets a password for the encryption module in the mobile end through the wireless network. The user accesses the encryption module in the mobile end through the set password for decryption, and then accesses the storage module of the mobile end. Specifically, the method for the fixed end to set a password for the mobile end can refer to conventional existing technologies such as password setting based on key negotiation using the Diffie-Hellman key exchange algorithm, password setting using public key infrastructure (PKI), or password setting based on dynamic passwords. Before this step is executed, the encryption module has no password, so the encryption module cannot be decrypted, and the user holding the mobile end does not need to bear security risks. Even if the mobile end is out of the user's control due to theft, loss, purchase, etc., or the holder of the mobile end is coerced to hand over the mobile end, the leakage of encrypted content will not occur. Since the password is temporarily set for the mobile end by the fixed end through the wireless network, the decryption process must make the mobile end reach a specific area. After the identity verification of the user, the verification of the network environment by the mobile end, and the verification of the mobile end by the fixed end, the identity, location, and permissions of the user are determined. It is the fixed end that sets the password for the mobile end so that the encrypted storage module in the mobile end can be decrypted. Thus, the storage module protected by the encryption module can be accessed through the password. There is no restriction on whether the storage module in the mobile end is transmitted through wire or wireless. The method in this embodiment is the encryption and decryption operation of the encryption module in the mobile end. When the encryption module obtains the decryption password, the storage module is in an open transmission state.
[0033] During the process of the fixed end accessing the mobile end, the wireless network connection of the mobile end should remain connected, that is, the mobile end should always be within the coverage of the wireless network. To prevent the user of the mobile end from taking the mobile end away after decrypting the encryption module when entering the coverage of the wireless network, when the wireless network connection of the mobile end is disconnected, the mobile end immediately initializes the encryption module to invalidate the set password and returns the mobile end to the state of waiting for authentication in step S2. As for the specific state of the mobile end waiting for verification, whether the mobile end enters the sleep state, or connects the fingerprint verification module to the power switch to enable identity verification recognition while pressing the power switch of the mobile end, or other methods can be set according to the actual situation in combination with the existing technology, which will not be elaborated here.
[0034] Based on the above implementation solutions, the processors, modules, corresponding control programs, algorithm programs and other supporting technologies mentioned in the present invention can all be implemented in combination with existing electrical technologies, information technologies, software technologies and general protocols, which are not within the scope of protection required by the present invention and will not be elaborated in this application.
[0035] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting.
Claims
1. A data encryption and identity authentication method in a trusted computing environment, characterized in that: Includes steps: S1. Set the permission information table on the fixed end, and set the identity authentication standard and network authentication standard of the mobile end through the fixed end, and execute the next step; S2. The mobile terminal verifies the identity of the mobile terminal user through the identity authentication module, compares the user information obtained by the identity authentication module with the identity authentication standard, determines the user's authority, and executes the next step if the identity authentication is passed, otherwise stops and issues an alarm; S3. Start the wireless connection module in the mobile terminal to connect to the wireless network transmitting device. After connecting to the wireless network transmitting device, start the wireless verification module to compare the identification in the wireless network transmitting device with the set network verification standard. After the verification is passed, execute the next step, otherwise disconnect and issue an alarm; S4. Start the permission information sending module of the mobile terminal to send the permission information to the fixed terminal through the wireless network transmitting device, the permission information includes the identity information verified by the identity authentication module, the device code of the mobile terminal, the identification in the connected wireless network transmitting device, the time when the identity authentication module passed the verification, and the time when the permission information was sent. The fixed terminal compares the permission information with the permission information list, and executes the next step if it meets the requirements, otherwise stops and issues an alarm; S5. After the authority information is verified, the fixed end sets a password for the encryption module in the mobile end through the wireless network. The user accesses the encryption module in the mobile end through the set password to decrypt and then access the storage module in the mobile end.
2. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: The wireless network is a WIFI wireless network, the wireless network transmitting device is a WIFI router, and the wireless network authentication standard includes SSID information and MAC information of the WIFI router.
3. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: The identity authentication module is a fingerprint recognition module.
4. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: The permission information table includes identity information that is allowed to access, a device code of a mobile terminal that is allowed to access, and an identifier in a wireless network transmitting device to which the mobile terminal is connected.
5. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: In step S4, the fixed end monitors the time difference between the time when the identity authentication module in the permission information sent by the mobile end passes the verification and the time when the permission information is sent, and issues an alarm when the time difference exceeds a threshold.
6. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: After the mobile terminal establishes a connection with the wireless network transmitting device in step S3, when the wireless network connection is disconnected, the encryption module is immediately initialized to invalidate the set password.
7. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: When the mobile terminal issues an alarm in step S2 and step S3, the mobile terminal re-executes step S2 until the alarm is lifted after verification in step S2.
8. The data encryption and identity authentication method in a trusted computing environment according to claim 1, characterized in that: In step S4, when the fixed end monitors that the permission information sent by the mobile end does not meet the requirements in the permission information table and stops the subsequent process, the wireless network connection with the mobile end is not disconnected, and an alarm is issued that will not be sensed by the mobile end user.
9. A data encryption and identity authentication system in a trusted computing environment that executes the method of any one of claims 1 to 8, characterized in that: It includes a fixed terminal and a mobile terminal, which are connected via a wireless network. The mobile terminal is provided with an identity authentication module, a wireless network connection module, a wireless verification module, an authority information sending module, an encryption module and a storage module.
Citation Information
Patent Citations
Network identity verification method and system based on biological characteristics and storage medium
CN112328989A
Encrypted mobile storage system with access control
CN115426109A